Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ncc_JNDI #30

Open
0902lin opened this issue Mar 4, 2023 · 3 comments
Open

ncc_JNDI #30

0902lin opened this issue Mar 4, 2023 · 3 comments

Comments

@0902lin
Copy link

0902lin commented Mar 4, 2023

师傅你好,我看工具里面有个ncc的jndi注入,我想看下原始请求是什么,请问可以单独出一个POC或者说下大概是怎样一个思路的吗

@0902lin 0902lin changed the title 1 ncc_JNDI Mar 4, 2023
@achuna33
Copy link
Owner

achuna33 commented Mar 4, 2023

ncc 的jndi 注入 和 NC6.5 的login_jndi 原理是一样的, 但是再ncc中加了一个header 的判断

@0902lin
Copy link
Author

0902lin commented Mar 4, 2023

师傅你好,但是好像我抓包看请求的时候没见到有加header判断,而且POST请求也乱码了。所以我就想着如果要手工利用的话,请求包内容如何去构造呢

@achuna33
Copy link
Owner

achuna33 commented Mar 6, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants