yaml反序化漏洞本地环境复现

上传者: u013224189 | 上传时间: 2021-08-28 18:48:37 | 文件大小: 2.57MB | 文件类型: RAR
yaml反序化漏洞本地环境复现 CTF 比赛中yaml反序劣化payloads有个!!的限制,当时没搞出来,事后大神透露需要借助tag, 于是就有了这个资源文件

文件下载

资源详情

[{"title":"( 57 个子文件 2.57MB ) yaml反序化漏洞本地环境复现","children":[{"title":"yaml_IDEA_project","children":[{"title":"src","children":[{"title":"META-INF","children":[{"title":"MANIFEST.MF <span style='color:#111;'> 56B </span>","children":null,"spread":false}],"spread":true},{"title":"com","children":[{"title":"his","children":[{"title":"Main.java <span style='color:#111;'> 1.45KB </span>","children":null,"spread":false}],"spread":true}],"spread":true}],"spread":true},{"title":"out","children":[{"title":"production","children":[{"title":"yamlpayloads","children":[{"title":"META-INF","children":[{"title":"MANIFEST.MF <span style='color:#111;'> 56B </span>","children":null,"spread":false},{"title":"yamlpayloads.kotlin_module <span style='color:#111;'> 16B </span>","children":null,"spread":false}],"spread":true},{"title":"com","children":[{"title":"his","children":[{"title":"Main.class <span style='color:#111;'> 2.00KB </span>","children":null,"spread":false}],"spread":true}],"spread":true}],"spread":true}],"spread":true},{"title":"artifacts","children":[{"title":"yamlpayloads_jar","children":[{"title":"yamlpayloads.jar <span style='color:#111;'> 543.82KB </span>","children":null,"spread":false}],"spread":true}],"spread":true}],"spread":true},{"title":".idea","children":[{"title":"misc.xml <span style='color:#111;'> 504B </span>","children":null,"spread":false},{"title":"encodings.xml <span style='color:#111;'> 164B </span>","children":null,"spread":false},{"title":"libraries","children":[{"title":"commons_codec_1_10.xml <span style='color:#111;'> 234B </span>","children":null,"spread":false},{"title":"snakeyaml_1_12.xml <span style='color:#111;'> 226B </span>","children":null,"spread":false}],"spread":true},{"title":"workspace.xml <span style='color:#111;'> 8.24KB </span>","children":null,"spread":false},{"title":"artifacts","children":[{"title":"yamlpayloads_jar.xml <span style='color:#111;'> 509B </span>","children":null,"spread":false}],"spread":true},{"title":"project-template.xml <span style='color:#111;'> 91B </span>","children":null,"spread":false},{"title":"description.html <span style='color:#111;'> 97B </span>","children":null,"spread":false},{"title":"modules.xml <span style='color:#111;'> 271B </span>","children":null,"spread":false}],"spread":true},{"title":"lib","children":[{"title":"snakeyaml-1.12.jar <span style='color:#111;'> 264.43KB </span>","children":null,"spread":false},{"title":"commons-codec-1.10.jar <span style='color:#111;'> 277.52KB </span>","children":null,"spread":false}],"spread":true},{"title":"yamlpayloads.iml <span style='color:#111;'> 583B </span>","children":null,"spread":false}],"spread":true},{"title":"漏洞原理","children":[{"title":"Java SnakeYaml反序列化漏洞 [ Mi1k7ea ].html <span style='color:#111;'> 100.53KB </span>","children":null,"spread":false},{"title":"Java SnakeYaml反序列化漏洞 [ Mi1k7ea ]_files","children":[{"title":"2.png <span style='color:#111;'> 45.12KB </span>","children":null,"spread":false},{"title":"9.png <span style='color:#111;'> 49.78KB </span>","children":null,"spread":false},{"title":"push.js.下载 <span style='color:#111;'> 308B </span>","children":null,"spread":false},{"title":"3.png <span style='color:#111;'> 62.92KB </span>","children":null,"spread":false},{"title":"23.png <span style='color:#111;'> 64.43KB </span>","children":null,"spread":false},{"title":"22.png <span style='color:#111;'> 76.96KB </span>","children":null,"spread":false},{"title":"18.png <span style='color:#111;'> 79.41KB </span>","children":null,"spread":false},{"title":"5.png <span style='color:#111;'> 27.82KB </span>","children":null,"spread":false},{"title":"8.png <span style='color:#111;'> 68.42KB </span>","children":null,"spread":false},{"title":"6.png <span style='color:#111;'> 32.17KB </span>","children":null,"spread":false},{"title":"busuanzi.pure.mini.js.下载 <span style='color:#111;'> 1.89KB </span>","children":null,"spread":false},{"title":"11.png <span style='color:#111;'> 45.45KB </span>","children":null,"spread":false},{"title":"1.png <span style='color:#111;'> 24.32KB </span>","children":null,"spread":false},{"title":"26.png <span style='color:#111;'> 72.92KB </span>","children":null,"spread":false},{"title":"12.png <span style='color:#111;'> 10.34KB </span>","children":null,"spread":false},{"title":"16.png <span style='color:#111;'> 63.46KB </span>","children":null,"spread":false},{"title":"13.png <span style='color:#111;'> 46.54KB </span>","children":null,"spread":false},{"title":"pure-min.css <span style='color:#111;'> 16.06KB </span>","children":null,"spread":false},{"title":"19.png <span style='color:#111;'> 148.62KB </span>","children":null,"spread":false},{"title":"15.png <span style='color:#111;'> 85.51KB </span>","children":null,"spread":false},{"title":"4.png <span style='color:#111;'> 70.31KB </span>","children":null,"spread":false},{"title":"17.png <span style='color:#111;'> 71.36KB </span>","children":null,"spread":false},{"title":"24.png <span style='color:#111;'> 64.91KB </span>","children":null,"spread":false},{"title":"21.png <span style='color:#111;'> 220.06KB </span>","children":null,"spread":false},{"title":"10.png <span style='color:#111;'> 19.03KB </span>","children":null,"spread":false},{"title":"25.png <span style='color:#111;'> 119.35KB </span>","children":null,"spread":false},{"title":"7.png <span style='color:#111;'> 41.22KB </span>","children":null,"spread":false},{"title":"14.png <span style='color:#111;'> 40.49KB </span>","children":null,"spread":false},{"title":"xoxo.css <span style='color:#111;'> 18.58KB </span>","children":null,"spread":false},{"title":"20.png <span style='color:#111;'> 62.90KB </span>","children":null,"spread":false}],"spread":false}],"spread":true},{"title":"远程jar文件payload","children":[{"title":"yaml-payload-master","children":[{"title":".gitignore <span style='color:#111;'> 53B </span>","children":null,"spread":false},{"title":"src","children":[{"title":"META-INF","children":[{"title":"services","children":[{"title":"javax.script.ScriptEngineFactory <span style='color:#111;'> 36B </span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"artsploit","children":[{"title":"AwesomeScriptEngineFactory.java <span style='color:#111;'> 1.48KB </span>","children":null,"spread":false},{"title":"AwesomeScriptEngineFactory.class <span style='color:#111;'> 1.59KB </span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"README.md <span style='color:#111;'> 623B </span>","children":null,"spread":false},{"title":"yaml-payload.jar <span style='color:#111;'> 2.14KB </span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"Yaml反序列化.assets","children":[{"title":"image-20201122234739829.png <span style='color:#111;'> 171.52KB </span>","children":null,"spread":false}],"spread":true},{"title":"Yaml反序列化.md <span style='color:#111;'> 1.22KB </span>","children":null,"spread":false}],"spread":true}]

评论信息

免责申明

【只为小站】的资源来自网友分享,仅供学习研究,请务必在下载后24小时内给予删除,不得用于其他任何用途,否则后果自负。基于互联网的特殊性,【只为小站】 无法对用户传输的作品、信息、内容的权属或合法性、合规性、真实性、科学性、完整权、有效性等进行实质审查;无论 【只为小站】 经营者是否已进行审查,用户均应自行承担因其传输的作品、信息、内容而可能或已经产生的侵权或权属纠纷等法律责任。
本站所有资源不代表本站的观点或立场,基于网友分享,根据中国法律《信息网络传播权保护条例》第二十二条之规定,若资源存在侵权或相关问题请联系本站客服人员,zhiweidada#qq.com,请把#换成@,本站将给予最大的支持与配合,做到及时反馈和处理。关于更多版权及免责申明参见 版权及免责申明