Spring4Shell-POC
Spring4Shell-Detection
Spring4Shell-POC | Spring4Shell-Detection | |
---|---|---|
6 | 2 | |
348 | 12 | |
- | - | |
0.0 | 0.0 | |
over 1 year ago | almost 2 years ago | |
Python | ||
- | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Spring4Shell-POC
-
help needed
Hey guys, I'm rewriting this poc for spring4shell in c .
- A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
-
Spring4Shell Details and Exploit code leaked
It's quite trivial to build a working POC using the steps at https://github.com/BobTheShoplifter/Spring4Shell-POC
-
Spring4Shell: 0-day RCE on Spring Core
I have tried all the steps in the referenced PDF and lunasec link. I also went to https://github.com/BobTheShoplifter/Spring4Shell-POC and tried poc.py - no success. I am not able to reproduce it on Spring Boot 2.6.4 with java 11.
-
SpringShell: Spring Core RCE 0-day Vulnerability
Created a repo for the issue, https://github.com/BobTheShoplifter/Spring4Shell-POC ill update it as we explore the issue
Spring4Shell-Detection
What are some alternatives?
Spring - Spring Framework
SplunkDashboards - Collection of Dashboards for Threat Hunting and more!
Spring4Shell-POC - This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).
threathunting-spl - Splunk code (SPL) for serious threat hunters and detection engineers.
SpringShell - Spring4Shell - Spring Core RCE - CVE-2022-22965
ansible-role-splunkbase - Ansible role for downloading and installing apps from splunkbase.com
spring-rce-vulnerable-app - Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228) and the possible Spring RCE vulnerability.
awesome-detection-engineering - Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
SpringCore0day - SpringCore0day from https://share.vx-underground.org/ & some additional links
CVE-2022-22965 - 🚀 Exploit for Spring core RCE in C [ wip ]
TA-UserWatchlist - User Watchlist App for Splunk