Skip to content
This repository has been archived by the owner on Aug 10, 2024. It is now read-only.

注入suo5内存马失败 #1

Open
dirchen-admin opened this issue Aug 15, 2023 · 5 comments
Open

注入suo5内存马失败 #1

dirchen-admin opened this issue Aug 15, 2023 · 5 comments

Comments

@dirchen-admin
Copy link

按照作者的步骤自行编译的jar
evalClass is null
图片

@X1r0z
Copy link
Owner

X1r0z commented Aug 15, 2023

能发一下你编译好的jar吗

@X1r0z
Copy link
Owner

X1r0z commented Aug 20, 2023

看了下应该是 spring 网站直接使用 Suo5TomcatFilter 注入会报错, 最新 0.5 版本加入了 Suo5SpringController 内存马, 师傅再试试看呢?

@BeingEasy
Copy link

注入内存马成功,pass和key在哪里设置

@Treasurez
Copy link

漏洞环境为JeecgBoot JimuReport 模板注入导致命令执行漏洞(CVE-2023-4450)也会出现 evalClass is null
Godzilla-Suo5MemShell version 0.5injecting Suo5SpringController, urlPattern: /favicon.ico, result: evalClass is null
user-agent: Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.1.2.3

@hi-unc1e
Copy link

反馈:不支持 tomcat10,报错如下:

Godzilla-Suo5MemShell version 0.5, author: X1r0z
injecting Suo5TomcatFilter, urlPattern: /favicon.ico, result: Cannot invoke "String.isEmpty()" because "this.filterName" is null

tomcat 版本:apache-tomcat-10.1.15/

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants