Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SpringBreakPoC — SpringBreak(CVE-2017-8046)용 PoC | Kitploit
도구/GitHubGitHub/fixyourface/springbreakpoc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubfixyourface/springbreakpoc

SpringBreakPoC

SpringBreak(CVE-2017-8046)용 PoC

저장소 보기
18년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SpringBreakPoC

최근 공개된 SpringBreak 취약점(CVE-2017-8046)에 대해 여러 엔드포인트를 테스트할 도구가 필요했지만, 마땅한 도구를 찾지 못해 이걸 급조했습니다.

사용법

root@kitploit:~
_______  _______  _______ _________ _        _______  ______   _______  _______  _______  _
(  ____ \(  ____ )(  ____ )\__   __/( (    /|(  ____ \(  ___ \ (  ____ )(  ____ \(  ___  )| \    /\
| (    \/| (    )|| (    )|   ) (   |  \  ( || (    \/| (   ) )| (    )|| (    \/| (   ) ||  \  / /
| (_____ | (____)|| (____)|   | |   |   \ | || |      | (__/ / | (____)|| (__    | (___) ||  (_/ /
(_____  )|  _____)|     __)   | |   | (\ \) || | ____ |  __ (  |     __)|  __)   |  ___  ||   _ (
     ) || (      | (\ (      | |   | | \   || | \_  )| (  \ \ | (\ (   | (      | (   ) ||  ( \ \
/\____) || )      | ) \ \_____) (___| )  \  || (___) || )___) )| ) \ \__| (____/\| )   ( ||  /  \
\_______)|/       |/   \__/\_______/|/    )_)(_______)|/ \___/ |/   \__/(_______/|/     \||_/    \/

PoC for CVE-2017-8046. Available commands:
 target <https://host/app/path>
 exec <command to execute on target>
 base64 <on|off> (Toggles base64 encoding of commands (uses bash), default: on)
 verify <on|off> (Toggles SSL verification, default: on)
 exit
Note: This is blind RCE, commands executed will not return output.

SpringBreak>

이 명령들은 자명하지만, base64에 대해 좀 더 설명하자면:

base64는 기본적으로 활성화되어 있으며, 명령어를 base64로 변환한 다음 bash -c {echo,BASE64_COMMAND}|{base64,-d}|{bash,-i}로 감쌉니다. 비활성화하면 (바이트 배열로 변환한 후) 원시 명령어를 그대로 전송합니다.

참고 자료

  • https://lgtm.com/blog/spring_data_rest_CVE-2017-8046_ql
도구 다운로드