Giter Club home page Giter Club logo

confluencememshell's Introduction

ConfluenceMemshell

Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入

  • 支持 Confluence 版本:CVE-2021-26084,CVE-2022-26134,CVE_2023_22515,CVE-2023-22527
  • (如果对您有帮助,感觉不错的话,请您给个大大的 ⭐️❗️)
  • 哥斯拉默认密码:pass ,默认key:key
  • 冰蝎默认密码:rebeyond,默认UA:Accept-Language:zh-CN,zh;q=0.95,n-AS,fr-RF
  • 只有 CVE-2022-26134 版本支持哥斯拉,冰蝎自定义密码,其他版本都是默认密码

V1.1版本

  • 新增 CVE_2023_22515,用户创建,内存马注入,基于 CmdShell 的命令执行
  • table 双击复制当前行,shell路径,key,ua
  • 哥斯拉 memshell 地址:url+/plugins/servlet/com/atlassian/TeamManageServlet
  • 哥斯拉默认密码:pass ,默认key:key
  • CmdShell 地址:url+/plugins/servlet/com/atlassian/TeamManageServlet?team=whoami
  1. 创建用户
image
  • 成功创建
image
  1. 生成恶意插件 Jar 包(包含哥斯拉,和CmdShell)
image
  • 显示内存马地址,和pass:key(双击复制,shell路径,key,ua)
image
  1. 用创建的用户进后台,插件功能地址: url+/plugins/servlet/upm,上传插件(不用等传完,直接刷新就有了。)
image
  1. 哥斯拉连接
image
  1. 基于插件 CmdShell 命令执行
image

V1.0

  1. 命令执行(其他 CVE 版本同理)
image
  1. 内存马注入(其他 CVE 版本同理)
  • 哥斯拉
image image
  • 冰蝎
image image

参考

https://github.com/BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL https://github.com/aaaademo/Confluence-EvilJar

免责声明

本工具仅能在取得足够合法授权的企业安全建设中使用,在使用本工具过程中,您应确保自己所有行为符合当地的法律法规。

如您在使用本工具的过程中存在任何非法行为,您将自行承担所有后果,本工具所有开发者和所有贡献者不承担任何法律及连带责任。

confluencememshell's People

Contributors

lotus6 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.