Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ore_react2shell_scanner — CVE-2025-55182 (React2Shell) 扫描器 | Kitploit
工具/GitHubGitHub/rapticore/ore_react2shell_scanner
侦察漏洞扫描器漏洞利用Web应用程序漏洞利用WAF绕过渗透测试子域名枚举
GitHubrapticore/ore_react2shell_scanner

ore_react2shell_scanner

CVE-2025-55182 (React2Shell) 扫描器

查看仓库
2146个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Rapticore Security Research - React2Shell 扫描器

由 Rapticore Security Research Team 开发的安全评估工具包,用于检测 React Server Components (RSC) 漏洞,包括 CVE-2025-55182 (React2Shell) - 一个严重的远程代码执行漏洞。

概述

本工具包提供两种专用工具:

工具描述
ore_rsc.py快速 RSC 端点扫描器,用于快速评估
ore_react2shell.py完整的评估套件,包含子域名枚举和报告生成

演示

https://github.com/user-attachments/assets/5be7661b-515c-46b4-ade4-8e88fdff6528

扫描器检测测试 Next.js 应用程序中的 CVE-2025-55182 (React2Shell) 漏洞。

漏洞背景

CVE-2025-55182 (React2Shell) 是一个影响 React Server Components 的严重 RCE 漏洞:

受影响的包受影响版本修复版本
react-server-dom-webpack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1+
react-server-dom-parcel19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1+
react-server-dom-turbopack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1+

参考: GHSA-fv66-9v8q-g76r

功能特性

快速扫描器 (ore_rsc.py)

  • 异步并发扫描
  • RSC 端点路径发现
  • 多种输出格式(控制台、CSV、JSON)
  • 风险分级(严重、高、中、低)
  • 框架检测(Next.js、Remix、Waku)
  • Server Action 检测
  • Flight 协议模式匹配
  • 深度扫描模式
  • WAF 绕过技术

完整评估套件 (ore_react2shell.py)

  • 子域名枚举(subfinder 集成)
  • 在线主机探测
  • Next.js/RSC 应用识别
  • 执行报告生成(HTML、JSON、CSV、TXT)
  • 风险分层与修复指导
  • 按域名和时间戳组织输出

安装

# 克隆仓库
git clone https://github.com/rapticore/ore_react2shell_scanner.git
cd ore_react2shell_scanner

# 创建虚拟环境
python3 -m venv env
source env/bin/activate  # 在 Windows 上:env\Scripts\activate

# 安装依赖
pip install aiohttp jinja2

# 可选:安装 subfinder 用于子域名枚举
go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest

快速开始

使用 ore_rsc.py 快速扫描

# 单域名扫描
python ore_rsc.py example.com

# 多个域名
python ore_rsc.py example.com api.example.com

# 从文件扫描
python ore_rsc.py -f subdomains.txt

# 深度扫描(扩展路径)
python ore_rsc.py example.com --deep

# 主动验证(发送 PoC 载荷)
python ore_rsc.py example.com --verify

# 安全侧信道检查(非利用性)
python ore_rsc.py example.com --safe-check

# JSON 输出
python ore_rsc.py example.com --format json -o results.json

使用 ore_react2shell.py 完整评估

# 完整评估,包含子域名枚举
# 结果保存至:results/example_com_{timestamp}/
python ore_react2shell.py --domain example.com

# 使用现有子域名列表
python ore_react2shell.py --domain example.com -f subdomains.txt

# 多个根域名
python ore_react2shell.py --domain example.com --domain example.org

# 带主动验证
python ore_react2shell.py --domain example.com --verify

# 安全侧信道检查
python ore_react2shell.py --domain example.com --safe-check

# 跳过子域名枚举
python ore_react2shell.py --domain example.com --skip-enum

# 自定义输出目录
python ore_react2shell.py --domain example.com -o ./reports

输出结构

报告按域名和时间戳自动组织:

results/
└── example_com_20250106_143052/
    ├── rsc_assessment.html              # 交互式 HTML 报告
    ├── rsc_assessment.json              # 机器可读的 JSON
    ├── rsc_assessment.csv               # 电子表格格式
    └── rsc_assessment_executive_summary.txt  # 文本摘要

命令行选项

ore_rsc.py

选项描述
domains要扫描的域名
-f, --file包含域名的文件(每行一个)
-c, --concurrency并发请求数(默认:20)
-t, --timeout请求超时秒数(默认:25)
--deep深度扫描,使用扩展路径
--verify主动验证 - 发送 RCE PoC 载荷
--safe-check安全侧信道验证
--waf-bypassWAF 绕过模式,使用垃圾数据
-o, --output输出文件路径
--format输出格式:console、json、csv

ore_react2shell.py

选项描述
-d, --domain要评估的目标域名(必需)
-f, --file包含子域名的文件
--skip-enum跳过子域名枚举
-c, --concurrency并发请求数(默认:30)
--deep深度扫描,使用扩展路径
--verify主动验证模式
--safe-check安全侧信道验证
-o, --output输出基目录(默认:results)
--format输出格式:html、json、csv、txt、all

检测方法

改进的验证逻辑(v1.1)

扫描器实现了健壮的验证逻辑以处理不稳定的服务器:

  • 服务器崩溃检测:自动识别带有特定 RSC 堆栈跟踪的 HTTP 500 错误,确认为已确认漏洞。
  • 连接断开:在载荷执行期间,立即断开服务器连接标记为“可能容易受攻击”(表示进程崩溃)。
  • 安全载荷:使用专门的非破坏性 JSON 载荷触发侧信道错误,而不执行系统命令。

RSC 端点检测

扫描器通过以下方式检测 RSC 端点:

  1. Content-Type 头:text/x-component、text/x-rsc、text/x-flight
  2. 响应头:x-nextjs-cache、rsc、next-action 等
  3. Flight 协议模式:流块(0:、1:)、React 引用($)
  4. Server Action 标记:$ACTION_ID、formAction 属性

风险分级

风险等级标准
严重通过 --verify 确认可利用
高通过 --safe-check 可能容易受攻击
中具有 server actions 的 RSC 端点
低检测到 RSC 端点
信息存在 RSC 指示器

修复指导

如果检测到易受攻击的端点:

  1. 立即:将 react-server-dom-* 升级到修复版本(19.0.1、19.1.2、19.2.1+)
  2. 短期:部署 WAF 规则,启用日志记录
  3. 长期:审查 Server Actions,实施 CSP

要求

  • Python 3.8+
  • aiohttp
  • jinja2(用于 HTML 报告)
  • subfinder(可选,用于子域名枚举)

安全声明

本工具仅用于已授权的安全评估。仅在你拥有或已获得明确书面授权的域名上使用。

Rapticore Security Research Team 不对滥用行为承担任何责任。

致谢

  • Rapticore Security Research Team - 工具开发与维护
  • Lachlan Davidson - 原始 PoC 和漏洞研究(CVE-2025-55182)
  • Assetnote - 原始 CVE-2025-55182 (React2Shell) 漏洞研究
  • ProjectDiscovery - subfinder 子域名枚举工具
  • React 安全团队 关于负责任的披露协调

由 Rapticore Security Research Team 开发

下载工具