
RSC Detect CVE 2025 55182
हल्का डिटेक्शन यूटिलिटी जो React Server Components और Next.js एप्लिकेशन की पहचान करता है
RSC-Detect एक सरल, केंद्रित उपकरण है जो React Server Components (RSC) और Next.js फ्रेमवर्क का उपयोग करने वाली वेबसाइटों की पहचान करने के लिए डिज़ाइन किया गया है। यह निम्नलिखित के लिए उपयोगी है:
यह गाइड Windows और Linux इंस्टॉलेशन का समर्थन करता है; macOS के लिए DMG फ़ाइल उपलब्ध है।
सुनिश्चित करें कि Git और Python उपलब्ध हैं।
Git लिंक: https://git-scm.com/install/windows
Python लिंक: https://www.python.org/ftp/python/3.13.12/python-3.13.12-amd64.exe
GIT CMD चलाएँ।
git clone https://github.com/fBUZk2BH/RSC-Detect-CVE-2025-55182.git
cd RSC-Detect-CVE-2025-55182
py -m pip install -r requirements.txt
py main.py
requests)main.py में targetList संपादित करें:
if __name__ == "__main__":
targetList = [
"https://example.com",
"https://another-site.com",
]
for urlItem in targetList:
analyzeTarget(urlItem)
python main.py
Analyzing target: https://example.com
[Framework Indicators] Detected: ['__NEXT_DATA__', '/_next/static/']
[Framework Headers] Detected: ['x-powered-by: next.js']
Analyzing target: https://another-site.com
No framework indicators detected
1. Send HTTP GET request to target URL
2. Parse HTML content and response headers
3. Pattern match against known indicators
4. Report findings
HTML_RSC_PATTERNS = [
'__flight__', # RSC streaming marker
'react-server-streaming', # Server streaming indicator
'__REACT_SERVER_APP__', # RSC application flag
]
CONTENT_TYPE_RSC_PATTERNS = [
'text/x-component', # RSC content type
'text/vnd.rsc', # Vendor RSC type
'application/x-react-server-component', # Full RSC MIME
]
HTML_NEXTJS_PATTERNS = [
"__NEXT_DATA__", # Next.js data hydration
"/_next/static/", # Static asset paths
"/_next/data/", # Data fetching routes
"next-head", # Head component
"next-font", # Font optimization
"next/script", # Script component
]
RSC-Detect-CVE-2025-55182/
├── main.py # Main detection script
├── requirements.txt # Python dependencies
└── README.md # Documentation
targetList = [
"https://site1.com",
"https://site2.com",
"https://site3.com/app",
]
# Add new RSC patterns
HTML_RSC_PATTERNS.append('your-custom-pattern')
# Add new Next.js patterns
HTML_NEXTJS_PATTERNS.append('custom-next-indicator')
# Modify request timeout (default: 10 seconds)
httpResponse = requests.get(targetUrl, timeout=30)
def loadTargetsFromFile(filepath):
with open(filepath, 'r') as f:
return [line.strip() for line in f if line.strip()]
if __name__ == "__main__":
targetList = loadTargetsFromFile('targets.txt')
for urlItem in targetList:
analyzeTarget(urlItem)
import json
def analyzeTargetJson(targetUrl):
results = {
'url': targetUrl,
'rsc_markers': [],
'content_types': [],
'nextjs_html': [],
'nextjs_headers': []
}
try:
httpResponse = requests.get(targetUrl, timeout=10)
htmlContentLower = httpResponse.text.lower()
headersContentLower = str(httpResponse.headers).lower()
results['rsc_markers'] = [p for p in HTML_RSC_PATTERNS if p.lower() in htmlContentLower]
results['content_types'] = [p for p in CONTENT_TYPE_RSC_PATTERNS if p.lower() in headersContentLower]
results['nextjs_html'] = [p for p in HTML_NEXTJS_PATTERNS if p.lower() in htmlContentLower]
results['nextjs_headers'] = [p for p in HEADER_NEXTJS_PATTERNS if p.lower() in headersContentLower]
except Exception as e:
results['error'] = str(e)
return results
# Usage
results = [analyzeTargetJson(url) for url in targetList]
print(json.dumps(results, indent=2))
from concurrent.futures import ThreadPoolExecutor
def scanConcurrently(targets, maxWorkers=5):
with ThreadPoolExecutor(max_workers=maxWorkers) as executor:
executor.map(analyzeTarget, targets)
# Add retry logic
from requests.adapters import HTTPAdapter
from urllib3.util.retry import Retry
session = requests.Session()
retries = Retry(total=3, backoff_factor=0.5)
session.mount('https://', HTTPAdapter(max_retries=retries))
# Disable SSL verification (not recommended for production)
httpResponse = requests.get(targetUrl, timeout=10, verify=False)
# Handle different encodings
httpResponse.encoding = httpResponse.apparent_encoding
यह उपकरण निम्नलिखित के लिए है:
हमेशा सुनिश्चित करें कि आपके पास उन लक्ष्यों को स्कैन करने की अनुमति है जिनके आप मालिक नहीं हैं।
requests>=2.28.0
urllib3>=1.26.0
योगदान का स्वागत है! आप मदद कर सकते हैं:
MIT लाइसेंस - व्यक्तिगत और व्यावसायिक उपयोग के लिए मुफ्त।
सरल • तेज़ • प्रभावी
⭐ उपयोगी लगे तो स्टार करें!
| श्रेणी | पैटर्न का पता चला |
|---|
| 🔵 RSC मार्कर | __flight__, react-server-streaming, __REACT_SERVER_APP__ |
| 📄 सामग्री-प्रकार | text/x-component, text/vnd.rsc, application/x-react-server-component |
| ⚡ Next.js HTML | __NEXT_DATA__, /_next/static/, next-font, next/script |
| 📋 हेडर | x-powered-by: next.js |
| फ्रेमवर्क | डिटेक्शन दर | नोट्स |
|---|
| Next.js 13+ | उच्च | एकाधिक संकेतक मौजूद |
| Next.js 12 | उच्च | __NEXT_DATA__ विश्वसनीय |
| React RSC | मध्यम | कार्यान्वयन पर निर्भर करता है |
| Custom React | निम्न | कस्टम पैटर्न की आवश्यकता |