
CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE 취약점)을 위한 AWS 조직 전체 탐지 도구 키트
CVE-2025-55182 및 CVE-2025-66478을 위한 AWS 조직 차원 탐지 툴킷
⚠️ 중요 면책 조항 - 사용 전 반드시 읽어주세요
이 툴킷은 프로덕션 AWS 환경에서 테스트되지 않았습니다.
인프라 제약으로 인해 이 프로젝트는 코드 리뷰, 정적 분석 및 문서 검증을 통해서만 개발 및 검증되었습니다. 실제 GuardDuty, WAF, EventBridge 또는 CloudTrail 서비스가 활성화된 라이브 AWS 환경에 배포되거나 테스트되지 않았습니다.
이것이 의미하는 바:
구성 요소 상태 Python 스캐너 로직 ✅ 코드 리뷰 완료, Snyk 검증 완료 Terraform 구문 ✅ 검증 완료, 적용되지 않음 IAM 정책 ⚠️ 사용자 환경에 맞게 조정 필요 EventBridge 규칙 ⚠️ AWS 문서 기반 탐지 패턴 WAF 규칙 ⚠️ 정규식 패턴이 실제 트래픽에 대해 테스트되지 않음 Athena 쿼리 ⚠️ 스키마 가정이 수정되어야 할 수 있음 권장 사항:
- 먼저 비프로덕션 계정에 배포 - 모든 구성 요소를 샌드박스 환경에서 테스트
- IAM 정책을 주의 깊게 검토 - 조직 요구 사항에 맞게 권한 조정
- Terraform 계획 검증 -
terraform plan실행 후 적용 전 검토- EventBridge 패턴 테스트 - GuardDuty 출력과 일치하는 탐지 유형 문자열 확인
- CloudWatch 로그 모니터링 - 배포 후 오류 확인
책임:
이 소프트웨어는 어떠한 종류의 보증도 없이 "있는 그대로" 제공됩니다. 작성자는 이 툴킷 사용으로 인해 발생하는 손해, 보안 사고 또는 AWS 비용에 대해 책임을 지지 않습니다. 사용에 따른 모든 책임은 본인에게 있습니다.
이 툴킷을 성공적으로 배포하고 테스트하셨다면, 발견 사항을 커뮤니티에 기여하여 개선해 주시기 바랍니다.
AWS 환경 전반에서 React2Shell 악용 시도를 탐지하기 위한 포괄적인 보안 툴킷입니다. 이 툴킷은 중요 React 서버 컴포넌트 RCE 취약점에 대한 실시간 탐지, 위협 사냥 기능 및 자동화된 대응을 제공합니다.
__proto__:then 조작을 통해 process.mainModule.require('child_process').execSync()로 임의 코드 실행 가능## 전제 조건
### 필요한 권한```
# Minimum IAM permissions for the detection script
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"logs:StartQuery",
"logs:GetQueryResults",
"guardduty:ListDetectors",
"guardduty:ListFindings",
"guardduty:GetFindings",
"guardduty:CreateThreatIntelSet",
"guardduty:UpdateThreatIntelSet",
"guardduty:ListThreatIntelSets",
"guardduty:GetThreatIntelSet",
"s3:PutObject",
"s3:GetObject",
"sts:GetCallerIdentity",
"sts:AssumeRole"
],
"Resource": "*"
}
]
}
# For Security Hub integration, add:
"securityhub:BatchImportFindings"
# For SNS alerting, add:
"sns:Publish"
# For organization-wide scanning, add:
"organizations:ListAccounts"
| 소프트웨어 | 버전 | 목적 |
|---|---|---|
| Python | 3.9+ | 탐지 스크립트 런타임 |
| Terraform | 1.0+ | 인프라 배포 |
| AWS CLI | 2.x | AWS 인증 |
| boto3 | 1.34+ | Python용 AWS SDK |
cd React2Shell_Hunter
python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate
pip install -r requirements.txt
### 2단계: AWS 자격 증명 구성```bash
# Option A: Use AWS CLI profile
aws configure --profile security-scanner
# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"
# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource
aws sts get-caller-identity
python -c "import boto3, yaml; print('Dependencies OK')"
python -c " import yaml with open('config/iocs.yaml') as f: iocs = yaml.safe_load(f) print(f'Loaded {len(iocs["network_iocs"]["malicious_ips"])} malicious IPs') "
---
## 빠른 시작
### 현재 계정 스캔 (최근 24시간)```bash
python src/react2shell_detector.py --hours 24
예상 출력:``` 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script 2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan... 2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs... 2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...
Total findings: 0 CRITICAL: 0 HIGH: 0 MEDIUM: 0
### 전체 프로덕션 스캔```bash
python src/react2shell_detector.py \
--organization \
--role-name SecurityAuditRole \
--security-hub \
--guardduty-bucket my-threat-intel-bucket-12345 \
--vpc-log-group /aws/vpc/flowlogs \
--waf-log-group aws-waf-logs-react2shell \
--sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
--output json \
--output-file findings-$(date +%Y%m%d).json \
--hours 72
GuardDuty에서 사용자 정의 탐지 규칙을 생성할 수 없습니다.
GuardDuty는 ML 모델과 위협 인텔리전스를 사용하여 결과를 생성합니다. React2Shell을 탐지하려면: