Code Monkey home page Code Monkey logo

smartbiattacktool's Introduction

SmartBIAttackTool

SmartBI 登录代码逻辑漏洞导致的远程代码执行利用工具,所有请求与响应均使用RMICoder进行编解码,规避常规流量设备检测。

支持功能

登录代码逻辑漏洞检测

登录代码逻辑漏洞检测

命令执行

命令执行

文件上传

文件上传

内存马注入

内存马注入

用户管理

支持表格筛选,实战中可以筛选管理员、admin关键字,登录管理员权限账户。

用户管理

用户管理

用户管理

RMICoder编解码

RMICoder编解码

数据源管理

支持自动解密连接密码。

数据源管理

配置文件信息获取

主要用于获取SmartBI配置文件中的数据库信息,支持自动解密连接密码。

配置文件信息获取

smartbiattacktool's People

Contributors

yggo avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

smartbiattacktool's Issues

师傅,可以获取联系方式吗,有一些问题想要咨询

我看到您有写关于 smartbi 的编码解码部分
我写了一个简单的 demo 来进行解码操作

import smartbi.framework.rmi.RMICoder;

public class decode {
    public static void main(String[] args) throws Exception {
        String encode = "zDp4Wp4gRip+-pkWQ~xQ6ikRw6D+/JV/uutjaO*a3a!/uu/JT";
        String[] decode = RMICoder.decode(encode);
        System.out.println(decode[0]);
        System.out.println(decode[1]);
        System.out.println(decode[2]);
    }
}

这是没有问题的
但是在编码操作部分,利用 RMICoder.encode( 生成的字符串无法顺利解码,应该是生成错误了,想知道具体的原因,以及解决办法

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.