b1gc8v 发表于 2024-10-3 07:02:15

Exp-Tools!高危漏洞利用工具1.2.5


    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><strong style="color: blue;"><span style="color: black;">本工具仅供安全测试人员运用于授权测试, 禁止用于未授权测试, 违者责任自负。</span></strong></p>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">简介</h1>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">该工具<span style="color: black;">运用</span>了ExpDemo-JavaFX项目,<span style="color: black;">保存</span>了核心的数据包请求接口,<span style="color: black;">运用</span>jdk1.8环境<span style="color: black;">研发</span>。<span style="color: black;">日前</span>只编写了oa系列,对<span style="color: black;">关联</span>漏洞进行复现和分析,极力避免exp的误报和有效性。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">截止到<span style="color: black;">日前</span>为止,已实现了用友、泛微、通达、致远、帆软报表、万户、蓝凌、红帆、金和、华天动力总共10个OA。 <span style="color: black;">所有</span>是命令执行、文件上传类的漏洞,<span style="color: black;">包含</span>前台和后台,未编写log4j、fastjson<span style="color: black;">关联</span>漏洞。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">用友已完成:</span></p><span style="color: black;">用友NC-BshServlet 远程命令执行</span><span style="color: black;">用友NC-BshServlet-bypass 远程命令执行</span><span style="color: black;">用友NC accept 文件上传</span><span style="color: black;">用友NC uapim 文件上传</span><span style="color: black;">用友NC mp 文件上传</span><span style="color: black;">用友U8CRM swfupload 文件上传</span><span style="color: black;">用友U8CRM getemaildata 文件上传</span><span style="color: black;">用有GRP-U8 UploadFileData 文件上传</span><span style="color: black;">用有GRP-U8 U8AppProxy 文件上传</span><span style="color: black;">用友GRP-U8 services 文件写入</span><span style="color: black;">用友U8 cloud文件上传</span><span style="color: black;">用友反序列化-1</span><span style="color: black;">用友反序列化-2</span><span style="color: black;">用友反序列化-3</span><span style="color: black;">用友畅捷通T+文件上传</span><span style="color: black;">用友KSOA ImageUpload 文件上传</span><span style="color: black;">用友KSOA Attachment 文件写入</span><span style="color: black;">用友NC Cloud 文件写入</span><span style="color: black;">用友NC Cloud 文件上传</span><span style="color: black;">用友移动管理平台Apk文件上传</span><span style="color: black;">用友移动管理平台Icon文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">泛微已完成:</span></p><span style="color: black;">泛微OA KtreeUploadAction 文件上传</span><span style="color: black;">泛微OA uploaderOperate 文件上传</span><span style="color: black;">泛微OA weaver.common.Ctrl 文件上传</span><span style="color: black;">泛微eoffice OfficeServer 文件上传</span><span style="color: black;">泛微eoffice UploadFile 文件上传</span><span style="color: black;">泛微eoffice uploadify 文件上传</span><span style="color: black;">泛微eoffice ajax 文件上传</span><span style="color: black;">泛微BshServlet 远程命令执行</span><span style="color: black;">泛微ecology前台sql注入-1</span><span style="color: black;">泛微ecology前台sql注入-2</span><span style="color: black;">泛微ecology前台sql注入-3</span><span style="color: black;">泛微ecology WorkflowServiceXml命令执行</span><span style="color: black;">泛微ecology FileClient 文件上传</span><span style="color: black;">泛微ecology后台风格文件上传</span><span style="color: black;">泛微ecology后台流程命令执行</span><span style="color: black;">泛微emobile client命令执行</span><span style="color: black;">泛微emobile messageType命令执行</span><span style="color: black;">泛微emobile lang2sql文件覆盖</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">蓝凌已完成:</span></p><span style="color: black;">蓝凌OA 任意用户登录</span><span style="color: black;">蓝凌OA SSRF</span><span style="color: black;">蓝凌OA SSRF BeanShell 文件上传</span><span style="color: black;">蓝凌OA SSRF XmlDecoder 文件上传</span><span style="color: black;">蓝凌OA treexml 命令执行</span><span style="color: black;">蓝凌OA界面文件上传</span><span style="color: black;">蓝凌OA主题文件上传</span><span style="color: black;">蓝凌OA jg_service文件上传</span><span style="color: black;">蓝凌OA后台模板文件上传</span><span style="color: black;">蓝凌EIS api文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">万户已完成:</span></p><span style="color: black;">万户OA用户<span style="color: black;">秘码</span><span style="color: black;">泄密</span></span><span style="color: black;">万户OA fileUpload 文件上传</span><span style="color: black;">万户OA officeserverservlet 文件上传</span><span style="color: black;">万户OA smartUpload 文件上传</span><span style="color: black;">万户OA OfficeServer 文件上传</span><span style="color: black;">万户OA senddocument 文件导入</span><span style="color: black;">万户OA wpsservlet 文件上传</span><span style="color: black;">万户OA SOAP 文件写入</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">帆软已完成:</span></p><span style="color: black;">帆软报表任意文件读取</span><span style="color: black;">帆软报表任意文件读取-bypass</span><span style="color: black;">帆软报表任意文件覆盖</span><span style="color: black;">帆软报表未授权命令执行</span><span style="color: black;">帆软报表channel命令执行</span><span style="color: black;">帆软报表后台插件文件上传</span><span style="color: black;">帆软报表后台主题文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">致远已完成:</span></p><span style="color: black;">致远session<span style="color: black;">泄密</span>processUpload文件上传</span><span style="color: black;">致远uploadMenuIcon文件上传</span><span style="color: black;">致远ajax文件上传</span><span style="color: black;">致远ajax文件上传-bypass</span><span style="color: black;">致远wpsAssistServlet文件上传</span><span style="color: black;">致远htmlofficeservlet文件上传</span><span style="color: black;">致远任意用户<span style="color: black;">秘码</span>重置</span><span style="color: black;">致远后台模板文件上传</span><span style="color: black;">致远后台模板管理器文件上传</span><span style="color: black;">致远后台表格文件写入</span><span style="color: black;">致远帆软报表文件读取</span><span style="color: black;">致远帆软报表文件读取-bypass</span><span style="color: black;">致远帆软报表后台插件文件上传</span><span style="color: black;">致远帆软报表后台主题文件上传</span><span style="color: black;">致远M1命令执行</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">通达已完成:</span></p><span style="color: black;">通达任意用户登录-1</span><span style="color: black;">通达任意用户登录-2</span><span style="color: black;">通达任意用户登录-3</span><span style="color: black;">通达任意用户登录-4</span><span style="color: black;">通达Ispirit文件上传</span><span style="color: black;">通达ueditor文件上传</span><span style="color: black;">通达gateway反序列化</span><span style="color: black;">通达后台附件文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">红帆已完成:</span></p><span style="color: black;">红帆OA任意文件上传</span><span style="color: black;">红帆OA任意文件写入</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">金和已完成:</span></p><span style="color: black;">金和OA命令执行</span><span style="color: black;">金和OA editeprint文件写入</span><span style="color: black;">金和OA saveAsOtherFormatServlet文件上传</span><span style="color: black;">金和OA OfficeServer文件上传</span><span style="color: black;">金和OA jcsUploadServlet文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">金蝶已完成:</span></p><span style="color: black;">金蝶云星空反序列化</span><span style="color: black;">金蝶云星空文件上传</span><span style="color: black;">金蝶EAS file文件上传</span><span style="color: black;">金蝶EAS logo文件上传</span><span style="color: black;">金蝶Apusic 文件上传</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">华天动力已完成:</span></p><span style="color: black;">华天动力OA ntkoupload 文件上传</span><span style="color: black;">华天动力OA Servlet文件上传</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;"><span style="color: black;">运用</span>说明</h1>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">直接下载releases版本<span style="color: black;">就可</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">运用</span>JDK8<span style="color: black;">起步</span>,命令如下:</span></strong></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">java -javaagent:Exp-Tools-1.2.5-encrypted.jar -jar Exp-Tools-1.2.5-encrypted.jar</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-axegupay5k/17ca81db7e6c402f990552c0a4d86f4c~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728088890&amp;x-signature=qbgHncgbtZ%2FJWMi2yMX%2BDrgSPOI%3D" style="width: 50%; margin-bottom: 20px;"></div>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">更新日志</h1>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/1/2</h1><span style="color: black;">新增红帆OA任意文件上传</span><span style="color: black;">新增华天动力OA任意文件上传</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/2/1</h1><span style="color: black;">新增泛微ecology FileClient 文件上传</span><span style="color: black;">新增泛微ecology后台流程命令执行</span><span style="color: black;">默认上传文件修改为json.txt</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/2/28</h1><span style="color: black;">修复通达oa后台附件文件上传一处bug</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/3/1</h1><span style="color: black;">新增YongyouNC反序列化</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/3/17</h1><span style="color: black;">新增Yongyou-U8 AppProxy 文件上传</span><span style="color: black;">新增用友KSOA Attachment 文件写入</span><span style="color: black;">新增致远后台模板管理器文件上传</span><span style="color: black;">修复多个bug</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/4/6</h1><span style="color: black;">新增蓝凌oa后台模板上传</span><span style="color: black;">新增用友CRM swfupload 文件上传</span><span style="color: black;">修复cookie 更新</span><span style="color: black;">优化部分代码</span><span style="color: black;">修复多个bug</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/4/27</h1><span style="color: black;">新增泛微ecology前台sql注入-2</span><span style="color: black;">新增红帆OA任意文件写入</span><span style="color: black;">修复泛微emobile一处bug</span><span style="color: black;">删除泛微ecology后台皮肤文件上传</span><span style="color: black;">删除conf文件夹,修改为<span style="color: black;">起步</span>时创建</span><span style="color: black;">删除cookie提示</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/6/28</h1><span style="color: black;">新增用友畅捷通T+SQL注入</span><span style="color: black;">新增致远帆软报表文件读取-bypass</span><span style="color: black;">新增泛微eoffice uploadify上传</span><span style="color: black;">新增php-framework和java-framework</span><span style="color: black;">新增nacos任意用户添加</span><span style="color: black;">新增金蝶云星空反序列化</span><span style="color: black;">优化部分代码</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/8/8</h1><span style="color: black;">新增用友反序列化-3</span><span style="color: black;">新增泛微ecology WorkflowServiceXml命令执行</span><span style="color: black;">新增用友U8 cloud文件上传</span><span style="color: black;">新增用友NC 文件上传</span><span style="color: black;">新增帆软报表文件读取-bypass</span><span style="color: black;">新增帆软报表未授权命令执行</span><span style="color: black;">新增用友移动管理平台文件上传</span><span style="color: black;">优化部分代码</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/9/6</h1><span style="color: black;">删除用友畅捷通T+sql注入</span><span style="color: black;">新增致远M1反序列化</span><span style="color: black;">新增用友移动管理平台Icon文件上传</span><span style="color: black;">新增大华、海康、宏景漏洞利用</span><span style="color: black;">优化部分代码</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/10/11</h1><span style="color: black;">新增蓝凌、用友、万户部分漏洞</span><span style="color: black;">修复部分漏洞误报</span><span style="color: black;">优化部分代码</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/11/24</h1><span style="color: black;">新增蓝凌、nacos、用友部分漏洞</span>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;">2023/12/08</h1><span style="color: black;">修复asp上传内容</span><span style="color: black;">新增部分漏洞</span>




7wu1wm0 发表于 2024-10-4 10:00:53

你的见解真是独到,让我受益良多。

7wu1wm0 发表于 2024-10-5 23:10:17

你的留言真是温暖如春,让我感受到了无尽的支持与鼓励。

b1gc8v 发表于 2024-10-8 10:07:23

你字句如珍珠,我珍藏这份情。

qzmjef 发表于 2024-10-31 10:30:50

交流如星光璀璨,点亮思想夜空。

1fy07h 发表于 2024-11-11 04:08:07

这篇文章真的让我受益匪浅,外链发布感谢分享!
页: [1]
查看完整版本: Exp-Tools!高危漏洞利用工具1.2.5