Security "Re-searcher"
Blog: Y4er.com
Team: ChaBug
Twitter: @Y4er_ChaBug
Weblogic IIOP CVE-2020-2551
Security "Re-searcher"
Blog: Y4er.com
Team: ChaBug
Twitter: @Y4er_ChaBug
This PR #2 attempts to solve this issue by allowing people to build the code via ant (for instance on a remote server with no graphical access)
On Ubuntu for instance:
sudo apt install ant
make
You'll find the jar in build/jar/weblogic_CVE_2020_2551.jar
Cheers,
-- Mathieu
师傅,我这个命令一直无法利用成功,能帮忙看看是什么原因吗?
虚拟机:
192.168.0.101
Weblogic 10.3.6
Jdk:6u45
主机:
192.168.0.105
Jdk: jdk14和6u45(编译时使用的6u45)
EXP:
package payload;
import java.io.IOException;
public class exp {
public exp() {
String cmd = "calc";
try {
Runtime.getRuntime().exec(cmd).getInputStream();
} catch (IOException e) {
e.printStackTrace();
}
}
}
Weblogic 12c not work?
看了
https://xz.aliyun.com/t/7498
还是不知道为什么我的weblogic 12c没有成功的原因
你好,本地WebLogic Server 版本: 10.3.6.0提示无回显自行检测是什么情况?
dnslog也没有呀
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.