Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Shiro-550 不依赖CC链利用工具

License

NotificationsYou must be signed in to change notification settings

dr0op/shiro-550-with-NoCC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 

Repository files navigation

Shiro550 无Commons-collections依赖利用工具:

  1. 使用Shiro自身利用链,不依赖Commons-collections库

  2. 命令回显,依赖tomcat,支持tomcat7

  3. 无限制命令执行,去除java命令执行不能使用管道和重定向符号的限制,如:

    cat /etc/passwd| grep root;echo 8416e1521a05a271074df8417177d090> /tmp/1; cat 1
    root:x:0:0:root:/root:/bin/bash8416e1521a05a271074df8417177d090 命令执行成功

免责声明

该工具仅用于安全研究、企业安全自查使用,请勿用于非法用途。

REFERENCE

https://www.leavesongs.com/PENETRATION/commons-beanutils-without-commons-collections.html

About

Shiro-550 不依赖CC链利用工具

Resources

License

Stars

Watchers

Forks

Packages

No packages published

[8]ページ先頭

©2009-2025 Movatter.jp