
역직렬화를 통한 Apache Tomcat RCE 익스플로잇 스크립트(CVE-2020-9484)로, ysoserial 페이로드를 활용하여 원격 코드 실행을 달성합니다.
CVE-2020-9484-exploit Apache Tomcat 원격 코드 실행
스크립트를 실행하기 전에 ysoserial 경로를 파일 경로에 맞게 변경하십시오.
ysoserial : https://github.com/frohoff/ysoserial
더 많은 참고 자료 : https://www.redtimmy.com/java-hacking/apache-tomcat-rce-by-deserialization-cve-2020-9484-write-up-and-exploit/