- Notifications
You must be signed in to change notification settings - Fork49
dr0op/shiro-550-with-NoCC
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
Shiro550 无Commons-collections依赖利用工具:
使用Shiro自身利用链,不依赖Commons-collections库
命令回显,依赖tomcat,支持tomcat7
无限制命令执行,去除java命令执行不能使用管道和重定向符号的限制,如:
cat /etc/passwd| grep root;echo 8416e1521a05a271074df8417177d090> /tmp/1; cat 1
root:x:0:0:root:/root:/bin/bash8416e1521a05a271074df8417177d090 命令执行成功
该工具仅用于安全研究、企业安全自查使用,请勿用于非法用途。
https://www.leavesongs.com/PENETRATION/commons-beanutils-without-commons-collections.html
About
Shiro-550 不依赖CC链利用工具
Resources
License
Uh oh!
There was an error while loading.Please reload this page.
Stars
Watchers
Forks
Packages0
No packages published