Comments (4)
Is the exploited target also using the same Java version? This is the relevant version, not the one you run the server with. Also add a trailing slash to the classpath URL, otherwise this will try to load a JAR file at that location.
from marshalsec.
Yes, same version running on the same host. Attached jstack on the rmiClient: jstack.txt
from marshalsec.
Ah, I did not closely look at the client code the first time. Directly performing a Registry lookup will not trigger resolving the Reference, only if you do the lookup through JNDI. E.g. something like `new InitialContext().lookup("rmi://127.0.0.1/test"). Also no need
to a add .class to the fragment when starting RMIRefServer, that should just be the classname.
from marshalsec.
Indeed. I've created another java app and confirmed it. Thanks!
from marshalsec.
Related Issues (20)
- kali HOT 1
- HTTP request not sent HOT 18
- Jackson not found HOT 8
- where is marshalsec.jar HOT 1
- 谁能帮我看看,我这是编译的有问题还是什么原因? HOT 4
- Could not find or load main class HOT 5
- Missing Dependencies
- Exception in thread "main" java.lang.NoClassDefFoundError: javassist/ClassPath HOT 1
- Marshalsec and webserver do not communicate HOT 56
- Cast Exception on server HOT 2
- No connection between Marshalsec and HTTP server HOT 1
- cant build HOT 3
- Marshalsec server not even launching HOT 1
- Docker support HOT 1
- Unable to contact the http server / RMI Payload debug HOT 3
- Some Errors HOT 2
- Exception in thread "main" java.lang.IllegalAccessError HOT 3
- Exception in thread "main" java.lang.IllegalAccessError HOT 3
- MIT License Please
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from marshalsec.