Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

回显方式跟JRMP方式之间的联系 #2

Open
haoliu0027 opened this issue Jan 21, 2022 · 2 comments
Open

回显方式跟JRMP方式之间的联系 #2

haoliu0027 opened this issue Jan 21, 2022 · 2 comments

Comments

@haoliu0027
Copy link

作者您好,

我是一名刚接触shiro反序列化的学生。 然后最近我有一个疑惑,不知您可以给些指导么?

问题: 我按照JRMP Client 生成payload然后让服务器去连接 JRMP Listener,然后JRMP listener会传过自己的反弹shell获取root权限。 但我最近在使用其他攻击软件的时候,发现有tomcat 回显、 spring 回显、 回显攻击方式。 这让我很疑惑,我不知道这两者之间的联系是什么, 您可以给些指导么

@fanyibo2009
Copy link

fanyibo2009 commented Jan 21, 2022 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants
@fanyibo2009 @haoliu0027 and others