Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
React2Shell_Hunter — AWS 组织级检测工具集,用于 CVE-2025-55182 和 CVE-2025-66478(React Server Components / Next.js RCE 漏洞) | Kitploit
工具/GitHubGitHub/rocklambros/react2shell_hunter
防御工具漏洞扫描器漏洞利用Web安全云安全威胁情报入侵检测事件响应日志分析
GitHubrocklambros/react2shell_hunter

React2Shell_Hunter

AWS 组织级检测工具集,用于 CVE-2025-55182 和 CVE-2025-66478(React Server Components / Next.js RCE 漏洞)

1269个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库

React2Shell Hunter

针对 CVE-2025-55182 与 CVE-2025-66478 的 AWS 组织级检测工具包


⚠️ 重要声明 - 使用前请阅读

本工具包尚未在生产 AWS 环境中经过测试。

由于基础设施限制,本项目仅通过代码审查、静态分析和文档验证进行验证。未曾部署到或针对包含活跃 GuardDuty、WAF、EventBridge 或 CloudTrail 服务的真实 AWS 环境进行测试。

对您意味着什么:

组件状态
Python 扫描器逻辑✅ 代码审查,Snyk 验证
Terraform 语法✅ 已验证,未实际应用
IAM 策略⚠️ 可能需要根据您的环境进行调整
EventBridge 规则⚠️ 基于 AWS 文档的发现模式
WAF 规则⚠️ 正则表达式模式未针对真实流量测试
Athena 查询⚠️ 架构假设可能需要修改

建议:

  1. 首先部署到非生产账户 - 在沙盒环境中测试所有组件
  2. 仔细审查 IAM 策略 - 根据您的组织要求调整权限
  3. 验证 Terraform 计划 - 运行 terraform plan 并在应用前审查
  4. 测试 EventBridge 模式 - 验证发现类型字符串是否与您的 GuardDuty 输出匹配
  5. 监控 CloudWatch 日志 - 部署后检查错误

责任声明:

本软件按“原样”提供,不作任何形式的保证。作者不对因使用本工具包造成的任何损害、安全事件或 AWS 费用承担责任。使用风险自负。

如果您成功部署并测试了本工具包,请考虑将您的发现反馈回来以改进社区。


一个全面的安全工具包,用于在 AWS 环境中检测 React2Shell 利用尝试。该工具包提供针对 React Server Components 关键 RCE 漏洞的实时检测、威胁狩猎能力和自动响应。


目录

  1. 此工具包检测的内容
  2. 前提条件
  3. 安装
  4. 快速开始
  5. 架构深入解析
  6. 组件参考
  7. 部署指南
  8. IOC 参考
  9. 故障排除
  10. 常见问题

此工具包检测的内容

CVE-2025-55182 (React Server Components)

  • CVSS 评分: 10.0 (最高严重性)
  • 攻击向量: 网络,无需认证
  • 根本原因: 通过 React "Flight" 协议中的不安全反序列化导致的原型污染
  • 利用方式: __proto__:then 操作通过 process.mainModule.require('child_process').execSync() 实现任意代码执行

CVE-2025-66478 (Next.js)

  • 下游影响: 使用存在漏洞的 React 版本的 Next.js 框架
  • 受影响版本: Next.js 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6 及 14.3.0-canary.77+

此工具包检测的攻击链```

  1. INITIAL ACCESS → WAF detects Next-Action header + prototype pollution payloads
  2. EXECUTION → GuardDuty ThreatIntelSet detects C2 IP connections
  3. CREDENTIAL THEFT → CloudTrail detects GetCallerIdentity from EC2 roles
  4. LATERAL MOVEMENT → EventBridge rules detect SSM SendCommand/StartSession
  5. EXFILTRATION → DNS exfiltration to ceye.io/dnslog.cn detected
  6. CRYPTOMINING → GuardDuty detects cryptocurrency mining activity
---

## 先决条件

### 所需权限```
# Minimum IAM permissions for the detection script
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cloudtrail:LookupEvents",
        "logs:StartQuery",
        "logs:GetQueryResults",
        "guardduty:ListDetectors",
        "guardduty:ListFindings",
        "guardduty:GetFindings",
        "guardduty:CreateThreatIntelSet",
        "guardduty:UpdateThreatIntelSet",
        "guardduty:ListThreatIntelSets",
        "guardduty:GetThreatIntelSet",
        "s3:PutObject",
        "s3:GetObject",
        "sts:GetCallerIdentity",
        "sts:AssumeRole"
      ],
      "Resource": "*"
    }
  ]
}

# For Security Hub integration, add:
"securityhub:BatchImportFindings"

# For SNS alerting, add:
"sns:Publish"

# For organization-wide scanning, add:
"organizations:ListAccounts"

软件要求

软件版本用途
Python3.9+检测脚本运行时
Terraform1.0+基础设施部署
AWS CLI2.xAWS 认证
boto31.34+AWS SDK for Python

安装

步骤 1:克隆并安装依赖```bash

Navigate to project

cd React2Shell_Hunter

Create virtual environment (RECOMMENDED)

python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate

Install dependencies

pip install -r requirements.txt

### 第2步:配置 AWS 凭证```bash
# Option A: Use AWS CLI profile
aws configure --profile security-scanner

# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"

# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource

第三步:验证安装```bash

Test AWS connectivity

aws sts get-caller-identity

Test Python dependencies

python -c "import boto3, yaml; print('Dependencies OK')"

Test IOC loading

python -c " import yaml with open('config/iocs.yaml') as f: iocs = yaml.safe_load(f) print(f'Loaded {len(iocs["network_iocs"]["malicious_ips"])} malicious IPs') "

## 快速开始

### 扫描当前账户(最近24小时)```bash
python src/react2shell_detector.py --hours 24

预期输出:``` 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script 2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478 2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================ 2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan... 2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs... 2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...

Total findings: 0 CRITICAL: 0 HIGH: 0 MEDIUM: 0

### 完整生产扫描```bash
python src/react2shell_detector.py \
    --organization \
    --role-name SecurityAuditRole \
    --security-hub \
    --guardduty-bucket my-threat-intel-bucket-12345 \
    --vpc-log-group /aws/vpc/flowlogs \
    --waf-log-group aws-waf-logs-react2shell \
    --sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
    --output json \
    --output-file findings-$(date +%Y%m%d).json \
    --hours 72

架构深度剖析

核心概念:GuardDuty 检测如何工作

您不能在 GuardDuty 中创建自定义检测规则。

GuardDuty 使用机器学习模型和威胁情报来生成发现结果。要检测 React2Shell:

下载工具