Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/webraybtl/ysoserialbtl

基于ysoserial扩展命令执行结果回显,生成冰蝎内存马
https://github.com/webraybtl/ysoserialbtl

Last synced: 21 days ago
JSON representation

基于ysoserial扩展命令执行结果回显,生成冰蝎内存马

Awesome Lists containing this project

README

        

# ysoserialbtl

用法与原生ysoserial完全一致,原生ysoserial生成的payload只能实现命令执行的效果,不能输出命令执行的结果,不能生成内存马。

ysoserialbtl针对原生的CommonBeanutils1等链,新增了回显与内存马实现的思路。

1. CommonBeanutils1Echo, 回显命令执行的输出结果。

​ 利用方式是在header中增加btl,用于输入命令。

![image-20230317162513473](imgs/1.png)

2. CommonBeanutils1TomcatMemshell

利用方式是使用冰蝎进行链接/btltest,密码是123,增加header头X-Options-Bi: xxx,值可以随意

![image-20230317162513473](imgs/2.png)

3. CommonBeanutils1SpringMemshell

利用方式是使用冰蝎进行链接/xxx(任意地址),密码是123,增加header头X-Options-Bi: xxx,值可以随意

## 免责声明:

本篇文章仅用于技术交流学习和研究的目的,严禁使用文章中的技术用于非法目的和破坏,否则造成一切后果与发表本文章的作者无关。

### 中文版本:

本免责声明旨在明确指出,本文仅为技术交流、学习和研究之用,不得将文章中的技术用于任何非法目的或破坏行为。发表本文章的作者对于任何非法使用技术或对他人或系统造成的损害概不负责。

阅读和参考本文章时,您必须明确并承诺,不会利用文章中提供的技术来实施非法活动、侵犯他人的权益或对系统进行攻击。任何使用本文中的技术所导致的任何意外、损失或损害,包括但不限于数据损失、财产损失、法律责任等问题,都与发表本文章的作者无关。

本文提供的技术信息仅供学习和参考之用,不构成任何形式的担保或保证。发表本文章的作者不对技术的准确性、有效性或适用性做任何声明或保证。

### 英文版本:

This disclaimer is intended to clearly state that this article is solely for the purpose of technical exchange, learning, and research, and the use of the techniques mentioned in the article for any illegal purposes or destructive actions is strictly prohibited. The author of this article shall not be held responsible for any consequences resulting from the misuse of the techniques mentioned.

By reading and referring to this article, you must acknowledge and commit that you will not exploit the techniques provided in the article for any illegal activities, infringement of rights of others, or attacks on systems. The author of this article bears no responsibility for any accidents, losses, or damages caused by the use of the techniques mentioned in this article, including but not limited to data loss, property damage, legal liabilities, etc.

The technical information provided in this article is for learning and reference purposes only and does not constitute any form of warranty or guarantee. The author of this article makes no representations or warranties regarding the accuracy, effectiveness, or applicability of the techniques mentioned.