Giter Club home page Giter Club logo

memoryshelllearn's Introduction

0x00 动机

仓库主要分享一下学习内存马以来的成果:

  • 几个jsp文件,可以直接注入tomcat的listener、filter、servlet内存马
  • spring mvc 结合JNDI注入可以使用的java代码,通过java恶意类可以注入litener、filter、servlet、controller和interceptor内存马(tomcat环境下)

看了大佬们的无私技术分享文章,学到很多东西,所以把收集的文章列举在后面,respect !

0x01 文章汇总

在学习的过程中,又想到了内存马结合菜刀和冰蝎的使用,所以研究了一下写了一篇文章(联动冰蝎的具体代码可以见仓库内的controller内存马)

针对spring mvc的controller内存马-学习和实验(注入菜刀和冰蝎可用的马

跟着landgrey大佬的文章走了一遍spring mvc的拦截器添加和调用过程,记录了一下

针对Spring MVC的Interceptor内存马

然后是学习阶段看的文章:

filter内存马

servlet内存马

listener型

Spring controller内存马

Spring Interceptor内存马

其它前提研究-获取request对象

Weblogic注入内存马

java agent内存马

内存马查杀

memoryshelllearn's People

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

memoryshelllearn's Issues

缺环境

大佬有空能把环境提供一下就好了,我试了一下,可能是环境不对,不能成功,Spring
版本,Spring mvc版本,Spring的配置文件……

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.