wh1t3p1g / ysomap

A helpful Java Deserialization exploit framework.
Apache License 2.0
1.18k stars 150 forks source link

add payload RMIConnectUnicastRef #41

Closed cokeBeer closed 2 years ago

cokeBeer commented 2 years ago

改动内容

添加了一个绕过JEP290的RMIConnect类型的payload。

适用场景

适用场景为过滤了RemoteObejct但是未过滤UnicastRef的场合

实际测试

image

测试图片中返回了远端的类型异常,但是反连已经发生了

wh1t3p1g commented 2 years ago

感谢提交,后面会merge上去

wh1t3p1g commented 2 years ago

pr里的功能之前就有了,暂不merge