Skip to content

Releases: cckuailong/JNDI-Injection-Exploit-Plus

JNDI-Injection-Exploit-Plus-2.5

24 Jun 11:43
Compare
Choose a tag to compare

JNDI-Injection-Exploit-Plus-2.4

08 Mar 01:43
Compare
Choose a tag to compare
  1. Add DirtyWrap: Insert a lot of dirty data to bypass WAF
  2. optimize UTF-Fusion Function

JNDI-Injection-Exploit-Plus-2.3

27 Feb 11:38
Compare
Choose a tag to compare
  1. New Function: new flag "-F" to fusion the class name in the bytes to bypass WAF.
  2. Remove sensitive info to bypass WAF.

JNDI-Injection-Exploit-Plus-2.2

09 Jun 14:34
Compare
Choose a tag to compare
  1. fix bug which give empty output when use Deserialize Gadget
  2. add Jackson Gadget to exploit nacos jraft rce

JNDI-Injection-Exploit-Plus-2.1

28 Mar 12:50
Compare
Choose a tag to compare

JNDI-Injection-Exploit-Plus-2.0

02 Mar 03:02
Compare
Choose a tag to compare

Add Some Weblogic Gadgets

JNDI-Injection-Exploit-Plus-1.9

22 Feb 09:24
Compare
Choose a tag to compare

JNDI-Injection-Exploit-Plus-1.8

20 Oct 07:11
Compare
Choose a tag to compare

add apereo wrapper

JNDI-Injection-Exploit-Plus-1.7

26 Sep 12:32
Compare
Choose a tag to compare
  1. optimize CommonDeseial
  2. add wrapper Function
  3. add Xstream wrapper
  4. fix bin output bug
  5. add new type Output -- hex
  6. add Web to return Deserial Data

JNDI-Injection-Exploit-Plus-1.6

03 Sep 06:59
Compare
Choose a tag to compare
  1. add 3 new coherence gadgets
  2. fix coherence1's bug