
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
CVE-2024-36401 Graphical Exploitation Tool, supports exploitation across various JDK versions, as well as echo and memory shell implementation.
Affected versions:
GeoServer < 2.23.6
2.24.0 <= GeoServer < 2.24.4
2.25.0 <= GeoServer < 2.25.2
Recently during HW (Red/Blue team exercises), this vulnerability was found to be quite common, but there hasn't been a handy tool. Here, by referencing the approach of https://github.com/whitebear-ch/GeoServerExploit, this tool was rewritten.

Just build the artifact.
Launch with JDK8: java -jar GeoServer-Tools.jar

dnslog (JDK version independent):


Echo:


Memory Shell:


My test environment uses vulhub (JDK17) and the Windows version (JDK8) from: https://master.dl.sourceforge.net/project/geoserver/GeoServer/2.15.0/geoserver-2.15.0.exe?viasf=1
Actual environments may vary; please test on your own.
The Godzilla memory shell on JDK17 is likely too long to be successfully injected; it is recommended to use Behinder or AntSword.
For technical research and authorized offensive/defensive projects only. Users must comply with the "Cybersecurity Law of the People's Republic of China". Do not use for any illegal activities. If the tool is used for other purposes, the user shall bear all legal and joint liabilities. The author and publisher assume no legal or joint liability!