Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/h0tak88r/next88
Vulnerability ScannersExploitationWeb Application ExploitationWAF BypassPenetration TestingRed Teaming
GitHubh0tak88r/next88

next88

React Server Components RCE 취약점(CVE-2025-55182 및 CVE-2025-66478) 탐지를 위한 고성능 Go 구현.

저장소 보기
1169개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

next88 - React Server Components RCE 스캐너

React Server Components RCE 취약점(CVE-2025-55182 및 CVE-2025-66478)을 탐지하기 위한 고성능 Go 구현체입니다.

기능

  • 🚀 고성능: goroutine 기반 동시성을 갖춘 컴파일된 Go 바이너리
  • 🔍 다중 탐지 방식:
    • 안전한 부채널(side-channel) 탐지
    • RCE PoC 검사
    • WAF 우회 기법 (정크 데이터, 이중 인코딩, 세미콜론 우회)
    • Vercel 전용 WAF 우회
    • ACTION_ID 추출을 통한 소스 코드 노출 탐지
  • 🎯 유연한 스캔: 단일 호스트, 호스트 목록 또는 사용자 지정 경로
  • 📊 JSON 출력: 통합을 위한 구조화된 결과
  • 🎨 컬러 출력: 터미널 친화적인 컬러 출력

설치

소스에서 설치

go install github.com/h0tak88r/next88@latest

로컬 빌드

git clone https://github.com/h0tak88r/next88.git
cd next88
go build -o next88 .

사용법

기본 사용법

# Scan single host
next88 -u https://example.com

# Scan from file
next88 -l hosts.txt

# With custom threads
next88 -l hosts.txt -t 50

고급 옵션

# Safe check (side-channel detection)
next88 -u https://example.com -safe-check

# WAF bypass with custom size
next88 -u https://example.com -waf-bypass -waf-bypass-size 256

# Vercel WAF bypass
next88 -u https://example.com -vercel-waf-bypass

# Double URL encoding bypass
next88 -u https://example.com -double-encode

# Semicolon bypass
next88 -u https://example.com -semicolon-bypass

# Source code exposure check
next88 -u https://example.com -check-source-exposure

# DoS test (send multiple requests)
next88 -u https://example.com --dos-test --dos-requests 200

# Custom paths
next88 -u https://example.com -path /_next -path /api

# Path file
next88 -u https://example.com -path-file paths.txt

# Windows payload
next88 -u https://example.com -windows

# Output to JSON
next88 -l hosts.txt -o results.json -all-results

# With Discord webhook notifications (real-time alerts)
next88 -l hosts.txt --discord-webhook https://discord.com/api/webhooks/...

옵션

  -u, --url <url>              Single URL/host to check
  -l, --list <file>            File containing list of hosts (one per line)
  -t, --threads <num>          Number of concurrent threads (default: 10)
  --timeout <seconds>          Request timeout in seconds (default: 10)
  -o, --output <file>          Output file for results (JSON format)
  --all-results                Save all results to output file, not just vulnerable hosts
  -k, --insecure               Disable SSL certificate verification (default: true)
  -v, --verbose                Verbose output (show response snippets for all hosts)
  -q, --quiet                  Quiet mode (only show vulnerable hosts)
  --no-color                   Disable colored output
  --safe-check                 Use safe side-channel detection instead of RCE PoC
  --windows                    Use Windows PowerShell payload instead of Unix shell
  --waf-bypass                 Add junk data to bypass WAF content inspection (default: 128KB)
  --waf-bypass-size <KB>       Size of junk data in KB for WAF bypass (default: 128)
  --vercel-waf-bypass          Use Vercel WAF bypass payload variant
  --path <path>                Custom path to test (can be used multiple times)
  --path-file <file>            File containing list of paths to test (one per line)
  --check-source-exposure      Check for source code exposure via ACTION_ID extraction from HTML
  --double-encode              Apply double URL encoding to bypass WAFs
  --semicolon-bypass           Add semicolons in strategic places to bypass WAFs
  --discord-webhook <url>      Discord webhook URL for real-time vulnerability notifications
  --dos-test                   Test for Denial of Service by sending multiple requests
  --dos-requests <num>         Number of requests to send for DoS test (default: 100)

출력 형식

JSON 출력 구조:

{
  "scan_time": "2025-12-13T03:35:53Z",
  "total_results": 1,
  "results": [
    {
      "host": "https://example.com",
      "vulnerable": true,
      "status_code": 303,
      "final_url": "https://example.com/",
      "tested_url": "https://example.com/",
      "timestamp": "2025-12-13T03:35:51Z"
    }
  ]
}

AutoAR 통합

이 도구는 AutoAR 프로젝트에 통합되어 있으며 다음을 통해 사용할 수 있습니다:

# Via AutoAR main script
./main.sh react2shell_scan run -d example.com

# Via Discord bot
/react2shell_scan domain:example.com

Docker

이 도구는 AutoAR Docker 이미지에 자동으로 빌드되어 설치됩니다:

RUN go install github.com/h0tak88r/next88@latest

성능

  • 동시 스캔: 병렬 호스트 스캔에 goroutine 사용
  • 최적화된 HTTP 클라이언트: 효율적인 연결 풀링 및 타임아웃
  • 낮은 메모리 사용량: 최소한의 의존성을 가진 컴파일된 바이너리
  • 빠른 실행: 일반적으로 Python 구현보다 5~10배 빠름

크레딧

Assetnote 보안 연구팀의 연구를 기반으로 합니다.

라이선스

자세한 내용은 LICENSE 파일을 참조하십시오.

도구 다운로드