Skip to content

Releases: cckuailong/JNDI-Injection-Exploit-Plus

JNDI-Injection-Exploit-Plus-2.5

24 Jun 11:43

Choose a tag to compare

JNDI-Injection-Exploit-Plus-2.4

08 Mar 01:43

Choose a tag to compare

  1. Add DirtyWrap: Insert a lot of dirty data to bypass WAF
  2. optimize UTF-Fusion Function

JNDI-Injection-Exploit-Plus-2.3

27 Feb 11:38

Choose a tag to compare

  1. New Function: new flag "-F" to fusion the class name in the bytes to bypass WAF.
  2. Remove sensitive info to bypass WAF.

JNDI-Injection-Exploit-Plus-2.2

09 Jun 14:34

Choose a tag to compare

  1. fix bug which give empty output when use Deserialize Gadget
  2. add Jackson Gadget to exploit nacos jraft rce

JNDI-Injection-Exploit-Plus-2.1

28 Mar 12:50

Choose a tag to compare

JNDI-Injection-Exploit-Plus-2.0

02 Mar 03:02

Choose a tag to compare

Add Some Weblogic Gadgets

JNDI-Injection-Exploit-Plus-1.9

22 Feb 09:24

Choose a tag to compare

JNDI-Injection-Exploit-Plus-1.8

20 Oct 07:11

Choose a tag to compare

add apereo wrapper

JNDI-Injection-Exploit-Plus-1.7

26 Sep 12:32

Choose a tag to compare

  1. optimize CommonDeseial
  2. add wrapper Function
  3. add Xstream wrapper
  4. fix bin output bug
  5. add new type Output -- hex
  6. add Web to return Deserial Data

JNDI-Injection-Exploit-Plus-1.6

03 Sep 06:59

Choose a tag to compare

  1. add 3 new coherence gadgets
  2. fix coherence1's bug