Загрузка видео...

Не удалось загрузить видео

На главную

A POC for CVE-2025-55182

552,596 просмотров • 9 месяцев назад •via X (Twitter)

Комментарии: 31

Фото профиля maple3142
maple31429 месяцев назад

It is like a fun node.js (or whatever server JS runtime) jail challenge that you would see in a CTF.

Фото профиля Peter Girnus 🦅
Peter Girnus 🦅9 месяцев назад

CTF in prod. The best kind. The worst kind.

Фото профиля Tears
Tears9 месяцев назад

The original poc by Lachlan Davidson is available btw

Фото профиля thomas🌦
thomas🌦9 месяцев назад

write-up someday of your technique?

Фото профиля maple3142
maple31429 месяцев назад

Just added a short writeup for the trick to the gist

Фото профиля thomas🌦
thomas🌦9 месяцев назад

thank you!

Фото профиля Sylvie
Sylvie9 месяцев назад

ayyyyyyyy nice job <3

Фото профиля Basix
Basix9 месяцев назад

clean and easy to understand, amazing!

Фото профиля MartinZugec
MartinZugec9 месяцев назад

Heya, I see you're passing the child_process exploit string inside the _prefix property. How is this string being passed as an argument to the function? My understanding of the Flight protocol is that the parser doesn't automatically eval() strings in JSON values 🤔

Фото профиля Lexter
Lexter9 месяцев назад

good work I am working on that since the last night and I don't have found a good way to pollute to bypass proxy bundlerConfig. So big gg

Фото профиля Lucien
Lucien9 месяцев назад

Insane poc ! gg

Фото профиля Ivan Garcia
Ivan Garcia9 месяцев назад

This is insane.

Фото профиля Jimmy
Jimmy9 месяцев назад

what a gadget :O congrats! seems like first poc

Фото профиля IRIS C2
IRIS C29 месяцев назад

Good work

Фото профиля Chia
Chia9 месяцев назад

It appears to work on a fresh created next project, but fails when a middleware (proxy.ts/middleware.ts) redirects unauthenticated users.

Фото профиля Y4GUAR3TE
Y4GUAR3TE9 месяцев назад

@sushicomabacate

Фото профиля Turing@penligent.ai
[email protected]9 месяцев назад

hi why not trying Penligent's one-click PoC? @penligent

Фото профиля ponti
ponti9 месяцев назад

Incredible work on the gadget chain, thanks for sharing

Фото профиля BENRICH
BENRICH9 месяцев назад

Good stuff 👏

Фото профиля D.
D.9 месяцев назад

😅

Фото профиля Alex
Alex9 месяцев назад

Can you share the payload? Also a simple explanation of the _prefix thing 😀

Фото профиля Just_Clive
Just_Clive9 месяцев назад

PoC is live. If you haven't patched yet, stop scrolling and run this: npx @neurolint/cli security:cve-2025-55182 . --fix Free. Open source. Takes 30 seconds.

Фото профиля Cyberexploit💀🧘
Cyberexploit💀🧘9 месяцев назад

Noted

Фото профиля Night_Dive_C
Night_Dive_C9 месяцев назад

做得好👍

Фото профиля Gabriel Bigardi
Gabriel Bigardi9 месяцев назад

Thanks, i tried it today on my website, to my surprise it worked out, when i checked the /tmp/ it was full o xmrigs already... they are scanning the whole ip range

Фото профиля 🧊
🧊9 месяцев назад

@h4x0r_dz How much vulnerable servers with this exploit out there?

Фото профиля CallMeWhy
CallMeWhy9 месяцев назад

优雅

Фото профиля MissionPossible
MissionPossible9 месяцев назад

@grok о чем видео?

Фото профиля Hackers4Right- let us all weep
Hackers4Right- let us all weep9 месяцев назад

any1 using this for sans?

Фото профиля ElleuchX1
ElleuchX19 месяцев назад

🐐

Фото профиля l2 p0ir3
l2 p0ir39 месяцев назад

To Explain & PoC

Похожие видео