Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
React2Shell_Hunter — CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE 취약점)을 위한 AWS 조직 전체 탐지 도구 키트 | Kitploit
도구/GitHubGitHub/rocklambros/react2shell_hunter
Defensive ToolsVulnerability ScannersExploitationWeb SecurityCloud SecurityThreat IntelligenceIntrusion DetectionIncident ResponseLog Analysis
GitHubrocklambros/react2shell_hunter

React2Shell_Hunter

CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE 취약점)을 위한 AWS 조직 전체 탐지 도구 키트

1279개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기

React2Shell Hunter

CVE-2025-55182 및 CVE-2025-66478을 위한 AWS 조직 차원 탐지 툴킷


⚠️ 중요 면책 조항 - 사용 전 반드시 읽어주세요

이 툴킷은 프로덕션 AWS 환경에서 테스트되지 않았습니다.

인프라 제약으로 인해 이 프로젝트는 코드 리뷰, 정적 분석 및 문서 검증을 통해서만 개발 및 검증되었습니다. 실제 GuardDuty, WAF, EventBridge 또는 CloudTrail 서비스가 활성화된 라이브 AWS 환경에 배포되거나 테스트되지 않았습니다.

이것이 의미하는 바:

구성 요소상태
Python 스캐너 로직✅ 코드 리뷰 완료, Snyk 검증 완료
Terraform 구문✅ 검증 완료, 적용되지 않음
IAM 정책⚠️ 사용자 환경에 맞게 조정 필요
EventBridge 규칙⚠️ AWS 문서 기반 탐지 패턴
WAF 규칙⚠️ 정규식 패턴이 실제 트래픽에 대해 테스트되지 않음
Athena 쿼리⚠️ 스키마 가정이 수정되어야 할 수 있음

권장 사항:

  1. 먼저 비프로덕션 계정에 배포 - 모든 구성 요소를 샌드박스 환경에서 테스트
  2. IAM 정책을 주의 깊게 검토 - 조직 요구 사항에 맞게 권한 조정
  3. Terraform 계획 검증 - terraform plan 실행 후 적용 전 검토
  4. EventBridge 패턴 테스트 - GuardDuty 출력과 일치하는 탐지 유형 문자열 확인
  5. CloudWatch 로그 모니터링 - 배포 후 오류 확인

책임:

이 소프트웨어는 어떠한 종류의 보증도 없이 "있는 그대로" 제공됩니다. 작성자는 이 툴킷 사용으로 인해 발생하는 손해, 보안 사고 또는 AWS 비용에 대해 책임을 지지 않습니다. 사용에 따른 모든 책임은 본인에게 있습니다.

이 툴킷을 성공적으로 배포하고 테스트하셨다면, 발견 사항을 커뮤니티에 기여하여 개선해 주시기 바랍니다.


AWS 환경 전반에서 React2Shell 악용 시도를 탐지하기 위한 포괄적인 보안 툴킷입니다. 이 툴킷은 중요 React 서버 컴포넌트 RCE 취약점에 대한 실시간 탐지, 위협 사냥 기능 및 자동화된 대응을 제공합니다.


목차

  1. 이 툴킷이 탐지하는 것
  2. 사전 요구 사항
  3. 설치
  4. 빠른 시작
  5. 아키텍처 심층 분석
  6. 구성 요소 참조
  7. 배포 가이드
  8. IOC 참조
  9. 문제 해결
  10. FAQ

이 툴킷이 탐지하는 것

CVE-2025-55182 (React 서버 컴포넌트)

  • CVSS 점수: 10.0 (최대 심각도)
  • 공격 벡터: 네트워크, 인증 불필요
  • 근본 원인: React의 "Flight" 프로토콜에서 안전하지 않은 역직렬화로 인한 프로토타입 오염
  • 악용 방식: __proto__:then 조작을 통해 process.mainModule.require('child_process').execSync()로 임의 코드 실행 가능

CVE-2025-66478 (Next.js)

  • 다운스트림 영향: 취약한 React 버전을 사용하는 Next.js 프레임워크
  • 영향을 받는 버전: Next.js 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6 및 14.3.0-canary.77+

이 툴킷이 탐지하는 공격 체인```

  1. INITIAL ACCESS → WAF detects Next-Action header + prototype pollution payloads
  2. EXECUTION → GuardDuty ThreatIntelSet detects C2 IP connections
  3. CREDENTIAL THEFT → CloudTrail detects GetCallerIdentity from EC2 roles
  4. LATERAL MOVEMENT → EventBridge rules detect SSM SendCommand/StartSession
  5. EXFILTRATION → DNS exfiltration to ceye.io/dnslog.cn detected
  6. CRYPTOMINING → GuardDuty detects cryptocurrency mining activity
## 전제 조건

### 필요한 권한```
# Minimum IAM permissions for the detection script
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cloudtrail:LookupEvents",
        "logs:StartQuery",
        "logs:GetQueryResults",
        "guardduty:ListDetectors",
        "guardduty:ListFindings",
        "guardduty:GetFindings",
        "guardduty:CreateThreatIntelSet",
        "guardduty:UpdateThreatIntelSet",
        "guardduty:ListThreatIntelSets",
        "guardduty:GetThreatIntelSet",
        "s3:PutObject",
        "s3:GetObject",
        "sts:GetCallerIdentity",
        "sts:AssumeRole"
      ],
      "Resource": "*"
    }
  ]
}

# For Security Hub integration, add:
"securityhub:BatchImportFindings"

# For SNS alerting, add:
"sns:Publish"

# For organization-wide scanning, add:
"organizations:ListAccounts"

소프트웨어 요구 사항

소프트웨어버전목적
Python3.9+탐지 스크립트 런타임
Terraform1.0+인프라 배포
AWS CLI2.xAWS 인증
boto31.34+Python용 AWS SDK

설치

1단계: 리포지토리 복제 및 종속성 설치```bash

Navigate to project

cd React2Shell_Hunter

Create virtual environment (RECOMMENDED)

python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate

Install dependencies

pip install -r requirements.txt

### 2단계: AWS 자격 증명 구성```bash
# Option A: Use AWS CLI profile
aws configure --profile security-scanner

# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"

# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource

3단계: 설치 확인```bash

Test AWS connectivity

aws sts get-caller-identity

Test Python dependencies

python -c "import boto3, yaml; print('Dependencies OK')"

Test IOC loading

python -c " import yaml with open('config/iocs.yaml') as f: iocs = yaml.safe_load(f) print(f'Loaded {len(iocs["network_iocs"]["malicious_ips"])} malicious IPs') "

---

## 빠른 시작

### 현재 계정 스캔 (최근 24시간)```bash
python src/react2shell_detector.py --hours 24

예상 출력:``` 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script 2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan... 2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs... 2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...

Total findings: 0 CRITICAL: 0 HIGH: 0 MEDIUM: 0

### 전체 프로덕션 스캔```bash
python src/react2shell_detector.py \
    --organization \
    --role-name SecurityAuditRole \
    --security-hub \
    --guardduty-bucket my-threat-intel-bucket-12345 \
    --vpc-log-group /aws/vpc/flowlogs \
    --waf-log-group aws-waf-logs-react2shell \
    --sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
    --output json \
    --output-file findings-$(date +%Y%m%d).json \
    --hours 72

아키텍처 심층 분석

핵심 개념: GuardDuty 탐지 작동 방식

GuardDuty에서 사용자 정의 탐지 규칙을 생성할 수 없습니다.

GuardDuty는 ML 모델과 위협 인텔리전스를 사용하여 결과를 생성합니다. React2Shell을 탐지하려면:

도구 다운로드