针对 CVE-2025-55182 与 CVE-2025-66478 的 AWS 组织级检测工具包
⚠️ 重要声明 - 使用前请阅读
本工具包尚未在生产 AWS 环境中经过测试。
由于基础设施限制,本项目仅通过代码审查、静态分析和文档验证进行验证。未曾部署到或针对包含活跃 GuardDuty、WAF、EventBridge 或 CloudTrail 服务的真实 AWS 环境进行测试。
对您意味着什么:
组件 状态 Python 扫描器逻辑 ✅ 代码审查,Snyk 验证 Terraform 语法 ✅ 已验证,未实际应用 IAM 策略 ⚠️ 可能需要根据您的环境进行调整 EventBridge 规则 ⚠️ 基于 AWS 文档的发现模式 WAF 规则 ⚠️ 正则表达式模式未针对真实流量测试 Athena 查询 ⚠️ 架构假设可能需要修改 建议:
- 首先部署到非生产账户 - 在沙盒环境中测试所有组件
- 仔细审查 IAM 策略 - 根据您的组织要求调整权限
- 验证 Terraform 计划 - 运行
terraform plan并在应用前审查- 测试 EventBridge 模式 - 验证发现类型字符串是否与您的 GuardDuty 输出匹配
- 监控 CloudWatch 日志 - 部署后检查错误
责任声明:
本软件按“原样”提供,不作任何形式的保证。作者不对因使用本工具包造成的任何损害、安全事件或 AWS 费用承担责任。使用风险自负。
如果您成功部署并测试了本工具包,请考虑将您的发现反馈回来以改进社区。
一个全面的安全工具包,用于在 AWS 环境中检测 React2Shell 利用尝试。该工具包提供针对 React Server Components 关键 RCE 漏洞的实时检测、威胁狩猎能力和自动响应。
__proto__:then 操作通过 process.mainModule.require('child_process').execSync() 实现任意代码执行---
## 先决条件
### 所需权限```
# Minimum IAM permissions for the detection script
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"logs:StartQuery",
"logs:GetQueryResults",
"guardduty:ListDetectors",
"guardduty:ListFindings",
"guardduty:GetFindings",
"guardduty:CreateThreatIntelSet",
"guardduty:UpdateThreatIntelSet",
"guardduty:ListThreatIntelSets",
"guardduty:GetThreatIntelSet",
"s3:PutObject",
"s3:GetObject",
"sts:GetCallerIdentity",
"sts:AssumeRole"
],
"Resource": "*"
}
]
}
# For Security Hub integration, add:
"securityhub:BatchImportFindings"
# For SNS alerting, add:
"sns:Publish"
# For organization-wide scanning, add:
"organizations:ListAccounts"
| 软件 | 版本 | 用途 |
|---|---|---|
| Python | 3.9+ | 检测脚本运行时 |
| Terraform | 1.0+ | 基础设施部署 |
| AWS CLI | 2.x | AWS 认证 |
| boto3 | 1.34+ | AWS SDK for Python |
cd React2Shell_Hunter
python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate
pip install -r requirements.txt
### 第2步:配置 AWS 凭证```bash
# Option A: Use AWS CLI profile
aws configure --profile security-scanner
# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"
# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource
aws sts get-caller-identity
python -c "import boto3, yaml; print('Dependencies OK')"
python -c " import yaml with open('config/iocs.yaml') as f: iocs = yaml.safe_load(f) print(f'Loaded {len(iocs["network_iocs"]["malicious_ips"])} malicious IPs') "
## 快速开始
### 扫描当前账户(最近24小时)```bash
python src/react2shell_detector.py --hours 24
预期输出:``` 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script 2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan... 2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs... 2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...
Total findings: 0 CRITICAL: 0 HIGH: 0 MEDIUM: 0
### 完整生产扫描```bash
python src/react2shell_detector.py \
--organization \
--role-name SecurityAuditRole \
--security-hub \
--guardduty-bucket my-threat-intel-bucket-12345 \
--vpc-log-group /aws/vpc/flowlogs \
--waf-log-group aws-waf-logs-react2shell \
--sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
--output json \
--output-file findings-$(date +%Y%m%d).json \
--hours 72
您不能在 GuardDuty 中创建自定义检测规则。
GuardDuty 使用机器学习模型和威胁情报来生成发现结果。要检测 React2Shell: