Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
React2Shell_Hunter — AWS संगठन-व्यापी पहचान टूलकिट CVE-2025-55182 और CVE-2025-66478 (React Server Components / Next.js RCE कमजोरियाँ) के लिए | Kitploit
उपकरण/GitHubGitHub/rocklambros/react2shell_hunter
रक्षात्मक उपकरणभेद्यता स्कैनरशोषणवेब सुरक्षाक्लाउड सुरक्षाखतरा खुफियाघुसपैठ का पता लगानाघटना प्रतिक्रियालॉग विश्लेषण
GitHubrocklambros/react2shell_hunter

React2Shell_Hunter

AWS संगठन-व्यापी पहचान टूलकिट CVE-2025-55182 और CVE-2025-66478 (React Server Components / Next.js RCE कमजोरियाँ) के लिए

18 महीने पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें

React2Shell Hunter

CVE-2025-55182 और CVE-2025-66478 हेतु AWS संगठन-व्यापी डिटेक्शन टूलकिट


⚠️ महत्वपूर्ण अस्वीकरण - उपयोग से पहले कृपया पढ़ें

यह टूलकिट उत्पादन AWS वातावरण में परीक्षण नहीं किया गया है।

बुनियादी ढांचे की बाधाओं के कारण, इस परियोजना को केवल कोड समीक्षा, स्थैतिक विश्लेषण और दस्तावेज़ सत्यापन के माध्यम से विकसित और मान्य किया गया है। इसे सक्रिय GuardDuty, WAF, EventBridge, या CloudTrail सेवाओं वाले लाइव AWS वातावरण में तैनात या परीक्षण नहीं किया गया है।

इसका आपके लिए क्या अर्थ है:

घटकस्थिति
Python स्कैनर लॉजिक✅ कोड समीक्षित, Snyk मान्य
Terraform सिंटैक्स✅ मान्य, लागू नहीं
IAM नीतियाँ⚠️ आपके वातावरण के लिए समायोजन की आवश्यकता हो सकती है
EventBridge नियम⚠️ AWS दस्तावेज़ीकरण पर आधारित फाइंडिंग पैटर्न
WAF नियम⚠️ लाइव ट्रैफ़िक पर अपरीक्षित रीजेक्स पैटर्न
Athena क्वेरीज़⚠️ स्कीमा धारणाओं में संशोधन की आवश्यकता हो सकती है

अनुशंसाएँ:

  1. पहले गैर-उत्पादन खाते में तैनात करें - सभी घटकों का सैंडबॉक्स वातावरण में परीक्षण करें
  2. IAM नीतियों की सावधानीपूर्वक समीक्षा करें - अपने संगठन की आवश्यकताओं से मेल खाने के लिए अनुमतियाँ समायोजित करें
  3. Terraform योजनाओं को मान्य करें - लागू करने से पहले terraform plan चलाएँ और समीक्षा करें
  4. EventBridge पैटर्न का परीक्षण करें - सत्यापित करें कि फाइंडिंग प्रकार स्ट्रिंग्स आपके GuardDuty आउटपुट से मेल खाती हैं
  5. CloudWatch लॉग्स की निगरानी करें - तैनाती के बाद त्रुटियों की जाँच करें

दायित्व:

यह सॉफ़्टवेयर बिना किसी वारंटी के "जैसा है" प्रदान किया जाता है। लेखक इस टूलकिट के उपयोग से होने वाली किसी भी क्षति, सुरक्षा घटना, या AWS लागत के लिए कोई ज़िम्मेदारी नहीं लेते हैं। अपने जोखिम पर उपयोग करें।

यदि आप इस टूलकिट को सफलतापूर्वक तैनात और परीक्षण करते हैं, तो कृपया इसे समुदाय के लिए बेहतर बनाने हेतु अपने निष्कर्षों को वापस योगदान करने पर विचार करें।


AWS वातावरणों में React2Shell शोषण प्रयासों का पता लगाने के लिए एक व्यापक सुरक्षा टूलकिट। यह टूलकिट गंभीर React Server Components RCE भेद्यता के लिए वास्तविक समय पहचान, खतरे का शिकार करने की क्षमताएँ और स्वचालित प्रतिक्रिया प्रदान करता है।


विषय-सूची

  1. यह टूलकिट क्या पता लगाता है
  2. पूर्वापेक्षाएँ
  3. स्थापना
  4. त्वरित प्रारंभ
  5. आर्किटेक्चर गहन अध्ययन
  6. घटक संदर्भ
  7. तैनाती मार्गदर्शिका
  8. IOC संदर्भ
  9. समस्या निवारण
  10. अक्सर पूछे जाने वाले प्रश्न

यह टूलकिट क्या पता लगाता है

CVE-2025-55182 (React Server Components)

  • CVSS स्कोर: 10.0 (अधिकतम गंभीरता)
  • हमला वेक्टर: नेटवर्क, कोई प्रमाणीकरण आवश्यक नहीं
  • मूल कारण: React के "Flight" प्रोटोकॉल में असुरक्षित डिसीरियलाइज़ेशन के माध्यम से प्रोटोटाइप प्रदूषण
  • शोषण: __proto__:then हेरफेर process.mainModule.require('child_process').execSync() के माध्यम से मनमाने कोड निष्पादन सक्षम करता है

CVE-2025-66478 (Next.js)

  • डाउनस्ट्रीम प्रभाव: संवेदनशील React संस्करणों का उपयोग करने वाले Next.js फ्रेमवर्क
  • प्रभावित संस्करण: Next.js 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6, और 14.3.0-canary.77+

हमला श्रृंखला जिसका यह टूलकिट पता लगाता है```

  1. INITIAL ACCESS → WAF detects Next-Action header + prototype pollution payloads
  2. EXECUTION → GuardDuty ThreatIntelSet detects C2 IP connections
  3. CREDENTIAL THEFT → CloudTrail detects GetCallerIdentity from EC2 roles
  4. LATERAL MOVEMENT → EventBridge rules detect SSM SendCommand/StartSession
  5. EXFILTRATION → DNS exfiltration to ceye.io/dnslog.cn detected
  6. CRYPTOMINING → GuardDuty detects cryptocurrency mining activity
root@kitploit:~
---

## पूर्वापेक्षाएँ

### आवश्यक अनुमतियाँ```
# Minimum IAM permissions for the detection script
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cloudtrail:LookupEvents",
        "logs:StartQuery",
        "logs:GetQueryResults",
        "guardduty:ListDetectors",
        "guardduty:ListFindings",
        "guardduty:GetFindings",
        "guardduty:CreateThreatIntelSet",
        "guardduty:UpdateThreatIntelSet",
        "guardduty:ListThreatIntelSets",
        "guardduty:GetThreatIntelSet",
        "s3:PutObject",
        "s3:GetObject",
        "sts:GetCallerIdentity",
        "sts:AssumeRole"
      ],
      "Resource": "*"
    }
  ]
}

# For Security Hub integration, add:
"securityhub:BatchImportFindings"

# For SNS alerting, add:
"sns:Publish"

# For organization-wide scanning, add:
"organizations:ListAccounts"

सॉफ़्टवेयर आवश्यकताएँ


स्थापना

चरण 1: क्लोन करें और निर्भरताएँ स्थापित करें```bash

Navigate to project

cd React2Shell_Hunter

Create virtual environment (RECOMMENDED)

python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate

Install dependencies

pip install -r requirements.txt

root@kitploit:~
### चरण 2: AWS क्रेडेंशियल्स कॉन्फ़िगर करें```bash
# Option A: Use AWS CLI profile
aws configure --profile security-scanner

# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"

# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource

चरण 3: स्थापना सत्यापित करें```bash

Test AWS connectivity

aws sts get-caller-identity

Test Python dependencies

python -c "import boto3, yaml; print('Dependencies OK')"

Test IOC loading

python -c " import yaml with open('config/iocs.yaml') as f: iocs = yaml.safe_load(f) print(f'Loaded {len(iocs["network_iocs"]["malicious_ips"])} malicious IPs') "

root@kitploit:~
---

## त्वरित आरंभ

### वर्तमान खाता स्कैन करें (पिछले 24 घंटे)```bash
python src/react2shell_detector.py --hours 24

अपेक्षित आउटपुट:``` 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script 2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan... 2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs... 2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...

Total findings: 0 CRITICAL: 0 HIGH: 0 MEDIUM: 0

root@kitploit:~
### पूर्ण प्रोडक्शन स्कैन```bash
python src/react2shell_detector.py \
    --organization \
    --role-name SecurityAuditRole \
    --security-hub \
    --guardduty-bucket my-threat-intel-bucket-12345 \
    --vpc-log-group /aws/vpc/flowlogs \
    --waf-log-group aws-waf-logs-react2shell \
    --sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
    --output json \
    --output-file findings-$(date +%Y%m%d).json \
    --hours 72

आर्किटेक्चर डीप डाइव

महत्वपूर्ण अवधारणा: GuardDuty डिटेक्शन कैसे काम करता है

आप GUARDDUTY में कस्टम डिटेक्शन नियम नहीं बना सकते।

GuardDuty findings उत्पन्न करने के लिए ML मॉडल और थ्रेट इंटेलिजेंस का उपयोग करता है। React2Shell का पता लगाने के लिए:

  1. ThreatIntelSet: C2 IPs को GuardDuty में अपलोड करें → MaliciousIPCaller.Custom findings उत्पन्न करता है
  2. EventBridge: विशिष्ट finding प्रकारों को फ़िल्टर करें → SNS/Lambda/CloudWatch पर रूट करें
  3. प्रतिक्रिया: अलर्ट प्राप्त करें, ऑटोमेशन ट्रिगर करें, जांच करें``` ┌─────────────────────────────────────────────────────────────────────────────┐ │ DETECTION ARCHITECTURE │ ├─────────────────────────────────────────────────────────────────────────────┤ │ │ │ DATA SOURCES DETECTION ENGINE RESPONSE │ │ ════════════ ════════════════ ════════ │ │ │ │ ┌──────────┐ ┌─────────────────┐ ┌───────────┐ │ │ │CloudTrail│────────────>│ GuardDuty │───────>│EventBridge│ │ │ │ Logs │ │ Detector │ │ Rules │ │ │ └──────────┘ │ │ └─────┬─────┘ │ │ │ ┌─────────────┐ │ │ │ │ ┌──────────┐ │ │ThreatIntel │ │ ▼ │ │ │VPC Flow │────────────>│ │Set (C2 IPs) │ │ ┌───────────┐ │ │ │ Logs │ │ └─────────────┘ │ │ SNS │ │ │ └──────────┘ └─────────────────┘ │ Topic │ │ │ └─────┬─────┘ │ │ ┌──────────┐ ┌─────────────────┐ │ │ │ │DNS Query │────────────>│ Route 53 │ ▼ │ │ │ Logs │ │ Resolver │ ┌───────────┐ │ │ └──────────┘ └─────────────────┘ │ Lambda │ │ │ │ (Enrich) │ │ │ ┌──────────┐ ┌─────────────────┐ └─────┬─────┘ │ │ │ WAF │────────────>│ WAF WebACL │ │ │ │ │ Logs │ │ (HTTP Rules) │ ▼ │ │ └──────────┘ └─────────────────┘ ┌───────────┐ │ │ │ Security │ │ │ │ Hub │ │ │ └───────────┘ │ └─────────────────────────────────────────────────────────────────────────────┘
root@kitploit:~
### EventBridge नियम पैटर्न

Terraform 7 विशिष्ट EventBridge नियम बनाता है:

| नियम | फ़ाइंडिंग टाइप पैटर्न | गंभीरता |
|------|---------------------|----------|
| `react2shell-malicious-ip-caller` | `MaliciousIPCaller.Custom` | CRITICAL |
| `react2shell-credential-exfiltration` | `InstanceCredentialExfiltration.*` | CRITICAL |
| `react2shell-dns-exfiltration` | `DNSDataExfiltration` | HIGH |
| `react2shell-cryptocurrency-mining` | `CryptoCurrency:*` | HIGH |
| `react2shell-unusual-network-ports` | `NetworkPortUnusual` | MEDIUM |
| `react2shell-malicious-domain` | `MaliciousDomainRequest.*` | HIGH |
| `react2shell-high-severity-catchall` | Severity >= 7 | VARIES |

### WAF सुरक्षा परतें

WAF WebACL प्राथमिकता क्रम में 9 नियम लागू करता है:

| प्राथमिकता | नियम | क्रिया | यह क्या पता लगाता है |
|----------|------|--------|-----------------|
| 1 | Block Malicious IPs | BLOCK | 9 ज्ञात C2 IPs से कनेक्शन |
| 2 | Next-Action Header Values | BLOCK | `next-action` हेडर जिसमें `$ACTION` या `__proto__` पैटर्न हों |
| 3 | RSC-Action-ID Header Values | BLOCK | `rsc-action-id` हेडर जिसमें `$ACTION` या `__proto__` पैटर्न हों |
| 4 | Prototype Pollution | BLOCK | बॉडी में `__proto__` या `constructor.prototype` |
| 5 | RCE Patterns | BLOCK | `process.mainModule.require`, `child_process`, `execSync` |
| 6 | ACTION Parameter | BLOCK | POST बॉडी में `$ACTION_0:0` या `$ACTION_REF` |
| 7 | Suspicious User-Agents | COUNT | `Go-http-client`, `Assetnote`, `python-requests` |
| 8 | AWS Known Bad Inputs | INHERIT | AWS प्रबंधित नियम समूह |
| 9 | AWS Common Rule Set | INHERIT | AWS प्रबंधित नियम समूह |

> **नोट**: नियम 2 और 3 दुर्भावनापूर्ण हेडर मानों (सिर्फ हेडर की उपस्थिति नहीं) का पता लगाने के लिए कई `byte_match_statement` जाँचों के साथ `or_statement` का उपयोग करते हैं। AWS WAF हेडर मिलान में regex का समर्थन नहीं करता, इसलिए प्रत्येक पैटर्न के लिए एक अलग स्टेटमेंट आवश्यक होता है। WAF द्वारा आवश्यक अनुसार हेडर नाम lowercase होते हैं।

---

## कंपोनेंट संदर्भ

### प्रोजेक्ट संरचना```
React2Shell_Hunter/
├── config/
│   └── iocs.yaml                    # IOC database (IPs, domains, patterns) - 452 lines
├── src/
│   └── react2shell_detector.py      # Main detection script - 1141 lines
├── terraform/
│   ├── guardduty.tf                 # GuardDuty + ThreatIntelSet + S3 - 405 lines
│   ├── eventbridge_rules.tf         # 7 EventBridge rules - 533 lines
│   └── waf_rules.tf                 # WAF WebACL with 9 rules - 681 lines
├── lambda/
│   └── ioc_scanner/
│       └── handler.py               # Real-time Lambda scanner - 381 lines
├── athena_queries/
│   └── detection_queries.sql        # 18 threat hunting queries - 483 lines
├── tests/
│   ├── __init__.py                  # Test package init
│   ├── conftest.py                  # Pytest fixtures (project_root, ioc_config, etc.)
│   ├── test_ioc_matching.py         # IOC pattern validation tests
│   ├── test_terraform.py            # Terraform configuration validation
│   └── test_waf_patterns.py         # WAF regex pattern tests
├── docs/
│   ├── THREAT_INTELLIGENCE_REPORT.md
│   └── GUARDDUTY_EVENTBRIDGE_SETUP_GUIDE.md
├── requirements.txt                 # Python dependencies (boto3, pyyaml, pytest, python-hcl2)
├── README.md
└── CLAUDE.md

पायथन स्क्रिप्ट क्लासेस

CLI आर्ग्युमेंट संदर्भ


डिप्लॉयमेंट गाइड

चरण 1: Terraform इंफ्रास्ट्रक्चर तैनात करें```bash

cd terraform

Initialize Terraform

terraform init

Preview changes (ALWAYS DO THIS FIRST)

terraform plan
-var="threat_intel_bucket=react2shell-threat-intel-$(aws sts get-caller-identity --query Account --output text)"
-var="enable_guardduty=true"
-var="enable_waf=true"
-var="waf_scope=REGIONAL"

Apply changes

terraform apply
-var="threat_intel_bucket=react2shell-threat-intel-$(aws sts get-caller-identity --query Account --output text)"

root@kitploit:~
**Terraform चर:**

| चर | आवश्यक | डिफ़ॉल्ट | विवरण |
|----------|----------|---------|-------------|
| `threat_intel_bucket` | हाँ | - | खतरा इंटेल फ़ाइलों के लिए S3 बकेट नाम |
| `enable_guardduty` | नहीं | true | GuardDuty डिटेक्टर सक्षम करें |
| `enable_waf` | नहीं | true | WAF WebACL बनाएँ |
| `waf_scope` | नहीं | REGIONAL | `REGIONAL` या `CLOUDFRONT` |
| `block_mode` | नहीं | BLOCK | `BLOCK` या `COUNT` |
| `enable_lambda_automation` | नहीं | false | स्वचालित प्रतिक्रिया के लिए Lambda सक्षम करें |

### चरण 2: WAF को संसाधनों के साथ संबद्ध करें

WAF WebACL आपके संसाधनों के साथ संबद्ध होना चाहिए:```bash
# Associate with ALB
aws wafv2 associate-web-acl \
    --web-acl-arn $(terraform output -raw web_acl_arn) \
    --resource-arn arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/my-alb/1234567890

# Associate with API Gateway
aws wafv2 associate-web-acl \
    --web-acl-arn $(terraform output -raw web_acl_arn) \
    --resource-arn arn:aws:apigateway:us-east-1::/restapis/abc123/stages/prod

चरण 3: SNS अलर्ट्स की सदस्यता लें```bash

Get SNS topic ARN

SNS_TOPIC=$(terraform output -raw sns_topic_arn)

Subscribe email

aws sns subscribe
--topic-arn $SNS_TOPIC
--protocol email
--notification-endpoint [email protected]

Subscribe Slack webhook (via Lambda)

aws sns subscribe
--topic-arn $SNS_TOPIC
--protocol lambda
--notification-endpoint arn:aws:lambda:us-east-1:123456789012:function:slack-notifier

root@kitploit:~
### चरण 4: Athena टेबल बनाएँ```bash
# Open Athena console or use AWS CLI
# Run the CREATE TABLE statements from athena_queries/detection_queries.sql

# CloudTrail table
aws athena start-query-execution \
    --query-string "CREATE EXTERNAL TABLE cloudtrail_logs ..." \
    --work-group primary \
    --query-execution-context Database=default

IOC संदर्भ

दुर्भावनापूर्ण IP पते

दुर्भावनापूर्ण डोमेन

संदिग्ध पोर्ट

पोर्टउपयोग
652PowerShell स्टेजर
2045कस्टम C2
8000, 8080वैकल्पिक HTTP C2
12000, 45178कस्टम C2

HTTP संकेतक


समस्या निवारण

सामान्य समस्याएँ

कोई GuardDuty डिटेक्टर नहीं मिला```bash

Check if GuardDuty is enabled

aws guardduty list-detectors

If empty, enable GuardDuty

aws guardduty create-detector --enable

Or use Terraform

terraform apply -var="enable_guardduty=true"

root@kitploit:~
#### "सदस्य खाते में भूमिका ग्रहण करने में विफल"```bash
# Verify role exists in target account
aws iam get-role --role-name SecurityAuditRole

# Verify trust policy allows your account
aws iam get-role --role-name SecurityAuditRole --query 'Role.AssumeRolePolicyDocument'

# Test role assumption
aws sts assume-role \
    --role-arn arn:aws:iam::TARGET_ACCOUNT:role/SecurityAuditRole \
    --role-session-name test

"ThreatIntelSet ACTIVATING में अटका हुआ"```bash

Check ThreatIntelSet status

DETECTOR_ID=$(aws guardduty list-detectors --query 'DetectorIds[0]' --output text) aws guardduty list-threat-intel-sets --detector-id $DETECTOR_ID

Verify S3 bucket permissions

aws s3api get-bucket-policy --bucket your-threat-intel-bucket

Verify IP list format (one IP per line, no CIDR)

aws s3 cp s3://your-bucket/threat-intel/react2shell-ips.txt -

root@kitploit:~
#### "WAF नियम ब्लॉक नहीं कर रहा"```bash
# Check if WebACL is associated
aws wafv2 list-resources-for-web-acl \
    --web-acl-arn $(terraform output -raw web_acl_arn)

# Check sampled requests
aws wafv2 get-sampled-requests \
    --web-acl-arn $(terraform output -raw web_acl_arn) \
    --rule-metric-name React2Shell-Malicious-IP-Blocked \
    --scope REGIONAL \
    --time-window StartTime=2025-12-06T00:00:00Z,EndTime=2025-12-06T23:59:59Z \
    --max-items 10

"कोई निष्कर्ष उत्पन्न नहीं हुआ"```bash

Generate sample findings to test pipeline

DETECTOR_ID=$(aws guardduty list-detectors --query 'DetectorIds[0]' --output text) aws guardduty create-sample-findings
--detector-id $DETECTOR_ID
--finding-types "UnauthorizedAccess:IAMUser/MaliciousIPCaller.Custom"

Check EventBridge rule invocations

aws cloudwatch get-metric-statistics
--namespace AWS/Events
--metric-name Invocations
--dimensions Name=RuleName,Value=react2shell-malicious-ip-caller
--start-time $(date -u -d '1 hour ago' +%Y-%m-%dT%H:%M:%SZ)
--end-time $(date -u +%Y-%m-%dT%H:%M:%SZ)
--period 300
--statistics Sum

root@kitploit:~
---

## FAQ

### Q: क्या यह पैचिंग की जगह लेता है?

**नहीं।** यह एक डिटेक्शन टूलकिट है, रोकथाम समाधान नहीं। आपको पैच करना अनिवार्य है:
- React: 19.0.1, 19.1.2, या 19.2.1
- Next.js: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, या 16.0.7

### Q: क्या यह सभी React2Shell हमलों का पता लगाएगा?

**कोई भी डिटेक्शन 100% नहीं है।** यह टूलकिट पता लगाता है:
- ज्ञात C2 IPs से कनेक्शन (यदि हमलावर नए IPs का उपयोग करता है, तो पता नहीं चलेगा)
- ज्ञात पेलोड पैटर्न (यदि हमलावर obfuscate करता है, तो WAF को बायपास कर सकता है)
- पोस्ट-एक्सप्लॉइटेशन व्यवहार (क्रेडेंशियल चोरी, लेटरल मूवमेंट)

### Q: मुझे स्कैनर कितनी बार चलाना चाहिए?

अनुशंसित शेड्यूल:
- **निरंतर**: GuardDuty + EventBridge (रियल-टाइम)
- **प्रति घंटा**: `--hours 1` के साथ Python स्क्रिप्ट
- **दैनिक**: पूर्ण Athena थ्रेट हंट क्वेरीज़

### Q: मैं नए IOC कैसे जोड़ूँ?

`config/iocs.yaml` संपादित करें और उपयुक्त अनुभागों में जोड़ें:```yaml
network_iocs:
  malicious_ips:
    - ip: "NEW.IP.ADDRESS.HERE"
      port: 8080
      context: "Description"
      confidence: high
      source: "Your source"

फिर ThreatIntelSet अपडेट करें:```bash python src/react2shell_detector.py --guardduty-bucket your-bucket

root@kitploit:~
---

## टेस्ट चलाना```bash
# Install test dependencies
pip install -r requirements.txt

# Run all tests
pytest tests/ -v

# Run specific test categories
pytest tests/test_terraform.py -v      # Terraform validation
pytest tests/test_ioc_matching.py -v   # IOC pattern tests
pytest tests/test_waf_patterns.py -v   # WAF regex tests

# Run with coverage
pytest tests/ --cov=src --cov-report=html

संदर्भ

  • CVE-2025-55182 - NVD
  • React2Shell आधिकारिक साइट
  • Datadog Security Labs
  • AWS Security Blog
  • Datadog IOC Repository

अस्वीकरण: यह टूलकिट केवल रक्षात्मक सुरक्षा उद्देश्यों के लिए है। सिस्टम को स्कैन करने से पहले सुनिश्चित करें कि आपके पास उचित प्राधिकरण है।

टूल डाउनलोड करें
सॉफ़्टवेयरसंस्करणउद्देश्य
Python3.9+डिटेक्शन स्क्रिप्ट रनटाइम
Terraform1.0+इंफ्रास्ट्रक्चर तैनाती
AWS CLI2.xAWS प्रमाणीकरण
boto31.34+Python के लिए AWS SDK
क्लासउद्देश्यमुख्य विधियाँ
IOCLoaderYAML से IOC लोड करेंget_malicious_ips(), get_suspicious_ports(), get_malicious_domains()
CloudTrailAnalyzerAPI-आधारित IOC का पता लगाएंanalyze_recent_events(hours)
VPCFlowLogAnalyzerनेटवर्क IOC का पता लगाएंanalyze_flow_logs(log_group, hours)
GuardDutyManagerथ्रेट इंटेल प्रबंधित करेंcreate_threat_intel_set(bucket), get_relevant_findings(hours)
WAFLogAnalyzerHTTP IOC का पता लगाएंanalyze_waf_logs(log_group, hours)
OrganizationScannerक्रॉस-अकाउंट स्कैनिंगscan_organization(hours, role_name)
SecurityHubReporterफाइंडिंग्स आयात करेंimport_findings(findings)
SNSAlerterअलर्ट भेजेंsend_alert(findings)
आर्ग्युमेंटप्रकारडिफ़ॉल्टविवरण
--configstringconfig/iocs.yamlIOC कॉन्फ़िगरेशन फ़ाइल का पथ
--hoursint24विश्लेषण के लिए लॉग के घंटे
--organizationflagfalseसंपूर्ण AWS ऑर्गनाइज़ेशन स्कैन करें
--role-namestringOrganizationAccountAccessRoleसदस्य खातों में ग्रहण करने के लिए भूमिका
--sns-topicstringnoneअलर्ट के लिए SNS टॉपिक ARN
--security-hubflagfalseSecurity Hub में फाइंडिंग्स आयात करें
--guardduty-bucketstringnoneGuardDuty थ्रेट इंटेल के लिए S3 बकेट
--vpc-log-groupstringnoneVPC फ्लो लॉग्स CloudWatch लॉग ग्रुप
--waf-log-groupstringnoneWAF लॉग्स CloudWatch लॉग ग्रुप
--outputenumtextआउटपुट प्रारूप: json, text, csv
--output-filestringnoneआउटपुट फ़ाइल पथ
--debugflagfalseडीबग लॉगिंग सक्षम करें
IP पतापोर्टविश्वास स्तरसंदर्भस्रोत
93.123.109.2478000उच्चप्राथमिक C2 सर्वरDatadog
45.77.33.1368080उच्चप्राथमिक C2 सर्वरDatadog
194.246.84.132045उच्चप्राथमिक C2 सर्वरDatadog
141.11.240.10345178उच्चप्राथमिक C2 सर्वरDatadog
23.235.188.3652उच्चPowerShell स्टेजरGreyNoise
46.36.37.8512000उच्चपेलोड स्टेजिंगGreyNoise
144.202.115.23480मध्यमपेलोड होस्टिंगDatadog
162.215.170.263000मध्यमद्वितीयक पेलोडGreyNoise
45.32.158.54-मध्यमस्कैनरGreyNoise
डोमेनश्रेणीविश्वास स्तर
ceye.ioDNS एक्सफ़िल्ट्रेशनउच्च
dnslog.cnDNS एक्सफ़िल्ट्रेशनउच्च
*.oastify.comBurp Collaboratorमध्यम
sapo.shk0x.netC2उच्च
xwpoogfunv.zaza.eu.orgC2उच्च
*.c3pool.comक्रिप्टोमाइनिंगउच्च
3333, 5555, 14433, 14444क्रिप्टोमाइनिंग
पैटर्नगंभीरताविवरण
next-action: *गंभीरRSC शोषण हेडर (WAF में लोअरकेस)
rsc-action-id: *गंभीरRSC एक्शन पहचानकर्ता (WAF में लोअरकेस)
$ACTION_0:0गंभीरRSC एक्शन पैरामीटर
__proto__:thenगंभीरप्रोटोटाइप प्रदूषण
process.mainModule.requireगंभीरNode.js RCE
child_processगंभीरकमांड निष्पादन
Go-http-client/1.1मध्यमस्कैनर यूज़र एजेंट