D0g3-8Bit / OFBiz-Attack

A Tool For CVE-2023-49070/CVE-2023-51467 Attack
17 stars 1 forks source link

Not Executed for Security Reasons #2

Open Aledangelo opened 5 months ago

Aledangelo commented 5 months ago

I can no longer execute any command, the tool always gives me the same message.

Not Executed for Security Reasons

This is the message that appears in the logs

┌──(kali㉿kali)-[~/…/OFBiz-Attack/out/artifacts/OFBiz_Attack_jar]
└─$ java -jar OFBiz-Attack.jar
Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true
Feb 29, 2024 8:56:59 AM okhttp3.internal.platform.Platform log
WARNING: A connection to https://bizness.htb/ was leaked. Did you forget to close a response body? To see where this was allocated, set the OkHttpClient logger level to FINE: Logger.getLogger(OkHttpClient.class.getName()).setLevel(Level.FINE);
N1vi4 commented 5 months ago

Thank you for raising the issue.First of all, this is a GUI tool, so you should run it on your own computer.The second is to try manual injection to ensure that the vulnerability exists.If possible, could you please provide the vulnerability environment?Sorry to bring you a bad experience.If there are bugs in the tool, we will step up updates.Thank you