Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

🚨CVE-2025-25257: Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector PoC: Write-up:

13,749 Aufrufe • vor 1 Jahr •via X (Twitter)

0 Kommentare

Keine Kommentare verfügbar

Kommentare vom Original-Post werden hier angezeigt

Ähnliche Videos

🚨 PP Krit's Final Call! This is your absolute last chance to grab the 'PP Krit Undress Zoetrope & Picture Disc Vinyl' #PPKritUndressVinyl #ZoetropeVinyl #PictureDisc #PPKritEntertainment #PPKritt ----- 2 SIDED VINYL ZOETROPE & PICTURE DISC 1 LP VINYL 180 GRAM / 33⅓ RPM POSTER TRACKLIST Side A เสนอตัว (Ooh!) FIRE BOY เส้นเรื่องเดิม (RERUN) Side B ลังเล (Hesitate) ขอโทษละกัน (friend to friend) BONUS TRACK - FIRE BOY (SpatChies Remix) Price: THB 2,450 🛒 Start Pre-order from 21st September 2025 (12:00 PM | GMT+7) to 31st October 2025 (11:59 PM | GMT+7) at Made to order products will be shipped within 90 days after the pre-order period ends 🌟 เงื่อนไขการ Pre-order - เปิด Pre-order สินค้าตั้งแต่วันนี้ - 31 ตุลาคม 2568 (11:59 น. l GMT+7) ผ่านช่องทาง - การสั่งซื้อสินค้าบนเว็บไซต์ สามารถซื้อสินค้าได้ครั้งละ 2 ชิ้น / คำสั่งซื้อ (ราคายังไม่รวมค่าขนส่งสินค้า) 🌟 Pre-order Conditions - Pre-order starts from now - 31st October 2025 (11:59 PM l GMT+7), through the website - Each order placed on the website can include up to 2 items (Shipping costs are not included).

PP Krit Entertainment

111,190 Aufrufe • vor 9 Monaten

🚨 POC for CVE-2025-55182 that works on Next.js 16.0.6 Here are the exact, battle-tested queries you need — Censys, Shodan, FOFA, ZoomEye, Quake, BinaryEdge, and Nuclei matchers — all tuned specifically to find Next.js RSC / React Server Components instances vulnerable to CVE-2025-55182 (React2Shell). ⸻ ✅ 1. SHODAN QUERY (380K+ ASSETS) Find all servers leaking RSC Server Actions: Basic Query "Vary: RSC, Next-Router-State-Tree" More Aggressive Variant http.headers.vary:"RSC" AND http.headers.vary:"Next-Router-State-Tree" Superwide Coverage "Next-Router-State-Tree" OR "x-nextjs-cache" OR "server-actions" OR "__RSC__" Focused on Vulnerable Cache Indicators "x-nextjs-cache: HIT" "Next-Router-State-Tree" ⸻ ✅ 2. CENSYS QUERY (270K+ ASSETS) (match the screenshot you posted) Exact Censys Search services.http.response.headers.vary: "RSC, Next-Router-State-Tree" Safer Multi-Matcher services.http.response.headers.vary: "RSC" AND services.http.response.headers.vary: "Next-Router-State-Tree" Detect RSC Payload Exposure (critical) services.http.response.body: "__RSC__" Detect Flight Data Leaks services.http.response.body: "server-reference-manifest" ⸻ ✅ 3. FOFA QUERY (CHINA’S OSINT GIANT) (VERY POWERFUL for RSC/Next.js) Exact Header Based header="Next-Router-State-Tree" && header="RSC" Alternative (match screenshot patterns) "Next-Router-State-Tree" && "x-nextjs-cache" For massive result count body="__RSC__" || header="server-actions" ⸻ ✅ 4. ZOOMEYE QUERY ZoomEye scans often catch Node.js apps Shodan misses. Exact Unicode-Ready Query "Next-Router-State-Tree" && "RSC" Advanced app:"Next.js" && header:"RSC" ⸻ ✅ 5. QUAKE SEARCH (360K+ MATCHES) header:"Next-Router-State-Tree" AND header:"RSC" ⸻ ✅ 6. BINARYEDGE QUERY http.response.headers.vary:"Next-Router-State-Tree" ⸻ ✅ 7. QUERY headers:"Next-Router-State-Tree" && headers:"RSC" ⸻ 🎯 8. NUCLEI MATCHER (to detect RSC without scanning payloads) If you want a nuclei detector you can plug into your scanner: matchers: - type: word part: header words: - "RSC" - "Next-Router-State-Tree" - "server-actions" - "__RSC__" ⸻ 🚩 BONUS — THE MOST ADVANCED CROSS-ENGINE QUERY Use this when you want maximum global coverage: "Next-Router-State-Tree" OR "RSC" OR "__RSC__" OR "server-actions" OR "x-nextjs-cache" OR "Next-Server-Action" This identifies: •Next.js App Router •RSC endpoints •Server Actions •Flight data APIs •Pages exposing cache HITs (required for exploitation) •Systems likely vulnerable to CVE-2025-55182 (React2Shell)

X

10,544 Aufrufe • vor 7 Monaten