zilong3033 / fastjsonScan

fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。
106 stars 73 forks source link

请问一下为什么连p牛的靶场都扫不出来fastjson #13

Open ThestaRY7 opened 2 years ago

ThestaRY7 commented 2 years ago

靶场环境:https://vulhub.org/#/environments/fastjson/1.2.47-rce/ 没有扫出来,send to fastjsonscan也一样

SecureKaiser commented 2 years ago

是的靶场扫不出来

zilong3033 commented 2 years ago

是的靶场扫不出来 那玩意dnslog有问题呢