Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-55182-checker — React/Next.js 애플리케이션의 CVE-2025-55182용 다중 기술 취약점 탐지기입니다. 가젯 체인, RCE 페이로드 및 WAF 우회 변형을 테스트하여 취약한 Server Actions 엔드포인트를 식별합니다. | Kitploit
도구/GitHubGitHub/harness-security-labs/cve-2025-55182-checker
Vulnerability ScannersExploitationWeb Application ExploitationWAF BypassPenetration TestingPayload Development
GitHubharness-security-labs/cve-2025-55182-checker

CVE-2025-55182-checker

React/Next.js 애플리케이션의 CVE-2025-55182용 다중 기술 취약점 탐지기입니다. 가젯 체인, RCE 페이로드 및 WAF 우회 변형을 테스트하여 취약한 Server Actions 엔드포인트를 식별합니다.

저장소 보기
1169개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2025-55182 취약점 탐지기 - 향상된 버전

React/Next.js 애플리케이션에서 CVE-2025-55182를 위한 포괄적인 취약점 탐지 도구로, 다양한 탐지 기술을 제공합니다.

⚠️ 법적 고지

승인된 보안 테스트 및 연구 목적으로만 사용하세요

이 도구는 다음을 위해 설계되었습니다:

  • 승인된 침투 테스트 작업
  • 통제된 환경에서의 보안 연구
  • 교육 목적
  • 적절한 승인을 받은 취약성 평가

컴퓨터 시스템에 대한 무단 접근은 불법입니다. 테스트 전에 항상 서면 허가를 받으세요.

기능

  • 다중 탐지 기술: 다양한 접근 방식을 통한 포괄적 테스트
  • 가젯 체인 프로브: 다양한 Node.js 모듈 액세스 경로 테스트
  • 안전한 작업: 무해하고 비파괴적인 테스트 명령만 사용
  • WAF 우회 기술: 보호된 환경을 위한 고급 탐지
  • 배치 테스트: 파일에서 여러 대상 테스트

이 스크립트의 기능

이 탐지기는 여러 기술을 사용하여 대상 애플리케이션이 CVE-2025-55182에 취약한지 포괄적으로 테스트합니다:

✅ 가젯 체인 프로브 (안전, 비파괴)

도구는 무해한 작업으로 Node.js 가젯 체인을 테스트합니다:

  • fs#constructor: 파일시스템 생성자 접근 테스트 (파일 접근 없음)
  • vm#runInThisContext: 안전한 JavaScript 평가 (1+1)
  • child_process#execSync: 무해한 명령 실행 (echo test)
  • module#_load: 안전한 내장 모듈 로드 (path)
  • fs#readFileSync: 안전한 시스템 파일 읽기 (/dev/null)
  • util#promisify: 유틸리티 함수 접근 테스트

✅ 향상된 탐지 기술

  • 안전한 부채널 탐지: 비악용 오류 패턴 탐지
  • RCE 개념 증명: 명령 실행 테스트 (Unix/Linux 및 Windows)
  • WAF 우회 변형: 웹 애플리케이션 방화벽을 우회하는 기술
  • 고급 페이로드: 여러 페이로드 구성 방법

⚠️ 도구의 기능

테스트 작업:

  • 안전하고 무해한 명령 실행 (echo test, 1+1)
  • 안전한 시스템 파일 읽기 (/dev/null)
  • 내장 모듈을 사용한 모듈 로딩 테스트
  • 취약점 탐지를 위한 여러 페이로드 변형 전송

하지 않는 것:

  • 민감한 파일이나 데이터 읽기
  • 파일 쓰기 또는 수정
  • 파괴적인 명령 실행
  • 흔적이나 백도어 남기기
  • 탐지를 넘어서는 취약점 악용

설치

이 도구는 종속성 관리 및 실행을 위해 uv를 사용합니다.

사전 요구 사항

  • Python 3.13 이상
  • uv (https://github.com/astral-sh/uv에서 설치)

빠른 시작

설치가 필요 없습니다! 복제하고 실행하세요:

git clone <repository-url>
cd CVE-2025-55182/poc
uv run check http://target.com:3000

도구는 첫 실행 시 자동으로 종속성을 설치합니다.

사용법

기본 사용법

uv run check <target_url>

예제

# Test a target with default settings (tests /formaction endpoint)
uv run check http://localhost:3002

# Specify custom endpoint
uv run check http://localhost:3002 --endpoint /api/formaction

# Test multiple targets from a file
uv run check --file targets.txt

# Save vulnerable hosts to file
uv run check --file targets.txt -o vulnerable.txt

# Increase timeout for slow connections
uv run check http://localhost:3002 --timeout 15

# Disable SSL verification (for self-signed certificates)
uv run check http://localhost:3002 --no-ssl-verify

# Quiet mode (minimal output)
uv run check http://localhost:3002 --quiet

명령줄 옵션

usage: uv run check [-h] [-f FILE] [-e ENDPOINT] [-t TIMEOUT]
                    [--no-ssl-verify] [-q] [-o OUTPUT] [target]

positional arguments:
  target                Target URL (e.g., http://target.com:3000)

optional arguments:
  -h, --help            Show help message and exit
  -f, --file FILE       File containing target URLs (one per line)
  -e, --endpoint        API endpoint path (default: /formaction)
  -t, --timeout         Request timeout in seconds (default: 10)
  --no-ssl-verify       Disable SSL certificate verification
  -q, --quiet           Quiet mode (minimal output)
  -o, --output OUTPUT   Output file to write vulnerable hosts

종료 코드

  • 0 - 대상이 취약하지 않음
  • 1 - 대상이 취약함
  • 130 - 사용자가 중단 (Ctrl+C)
  • 기타 - 오류 발생

샘플 출력

취약한 대상

# uv run check http://localhost:3002
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================

[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✓ VULNERABLE
  → Gadget: vm#runInThisContext: ✓ VULNERABLE
  → Gadget: child_process#execSync: ✓ VULNERABLE
  → Gadget: module#_load: ✓ VULNERABLE
  → Gadget: fs#readFileSync: ✓ VULNERABLE
  → Gadget: util#promisify: ✗ Not vulnerable
  → Safe Side-Channel Detection: ✗ Not vulnerable
  → RCE PoC (Unix/Linux): ✗ Not vulnerable
  → RCE PoC (Windows): ✗ Not vulnerable
  → RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
  → RCE with WAF Bypass (Windows): ✗ Not vulnerable
  → Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable

======================================================================
DETECTION RESULTS
======================================================================
Target:                  http://localhost:3002
Endpoint:                /formaction
Techniques Tested:       Multiple
Successful Techniques:   5 techniques detected vulnerability

Status:                  ⚠️  VULNERABLE

The target appears to be vulnerable to CVE-2025-55182.

Techniques that detected vulnerability:
 -> Gadget: fs#constructor
 -> Gadget: vm#runInThisContext
 -> Gadget: child_process#execSync
 -> Gadget: module#_load
 -> Gadget: fs#readFileSync

Recommendation: Apply security patches immediately.
======================================================================

취약하지 않은 대상

# uv run check http://localhost:8000
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================

[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✗ Not vulnerable
  → Gadget: vm#runInThisContext: ✗ Not vulnerable
  → Gadget: child_process#execSync: ✗ Not vulnerable
  → Gadget: module#_load: ✗ Not vulnerable
  → Gadget: fs#readFileSync: ✗ Not vulnerable
  → Gadget: util#promisify: ✗ Not vulnerable
  → Safe Side-Channel Detection: ✗ Not vulnerable
  → RCE PoC (Unix/Linux): ✗ Not vulnerable
  → RCE PoC (Windows): ✗ Not vulnerable
  → RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
  → RCE with WAF Bypass (Windows): ✗ Not vulnerable
  → Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable

======================================================================
DETECTION RESULTS
======================================================================
Target:                  http://localhost:8000
Endpoint:                /formaction
Techniques Tested:       Multiple

Status:                  ✓ NOT VULNERABLE

The target does not appear to be vulnerable to CVE-2025-55182.
All detection techniques failed to confirm vulnerability.
======================================================================

배치 테스트

스크립트를 사용하면 여러 호스트를 한 번에 테스트할 수 있습니다.

# Create a file with target URLs (one per line)
echo "http://localhost:3002" > targets.txt
echo "http://localhost:8000" >> targets.txt

# Run batch scan
uv run check --file targets.txt -o vulnerable.txt

출력:

======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================

[*] Loaded 2 target(s) from file

[*] Testing target 1/2
[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✓ VULNERABLE
  → Gadget: vm#runInThisContext: ✓ VULNERABLE
  [... additional techniques ...]

======================================================================
DETECTION RESULTS
======================================================================
Target:                  http://localhost:3002
Endpoint:                /formaction
Techniques Tested:       Multiple
Successful Techniques:   5 techniques detected vulnerability

Status:                  ⚠️  VULNERABLE
[... details ...]
======================================================================

[*] Testing target 2/2
[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✗ Not vulnerable
  [... all techniques fail ...]

----------------------------------------------------------------------
Target:                  http://localhost:8000
Endpoint:                /formaction
Techniques Tested:       Multiple
도구 다운로드