Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入
- 支持 Confluence 版本:CVE-2021-26084,CVE-2022-26134,CVE_2023_22515,CVE-2023-22527
- (如果对您有帮助,感觉不错的话,请您给个大大的 ⭐️❗️)
- 哥斯拉默认密码:pass ,默认key:key ,请求配置 - 协议头 需加上
Connection: close
- 冰蝎默认密码:rebeyond,默认UA:Accept-Language:zh-CN,zh;q=0.95,n-AS,fr-RF
- 只有 CVE-2022-26134 版本支持哥斯拉,冰蝎自定义密码,其他版本都是默认密码
V1.1版本
- 新增 CVE_2023_22515,用户创建,内存马注入,基于 CmdShell 的命令执行
- table 双击复制当前行,shell路径,key,ua
- 哥斯拉 memshell 地址:url+/plugins/servlet/com/atlassian/TeamManageServlet
- 哥斯拉默认密码:pass ,默认key:key ,请求配置 - 协议头 需加上
Connection: close
- CmdShell 地址:url+/plugins/servlet/com/atlassian/TeamManageServlet?team=whoami
- 创建用户
![image](https://private-user-images.githubusercontent.com/63742814/300168439-ced702d4-c8bf-4b97-bc2c-00e298b69d20.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjg0MzktY2VkNzAyZDQtYzhiZi00Yjk3LWJjMmMtMDBlMjk4YjY5ZDIwLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTgyNzU3MTlmMTg3OTczYjdhODIzNzIyMzM4ZjNmOWQ1N2MwZDAzNjQ5NTc3MDNjNTkzMTgyMGFiMTFmNzc3ZGQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.iMOXIlcEf6IgQ-oMWuTSqnhCkEQ2tiMsuGcI-FTHOW8)
- 成功创建
![image](https://private-user-images.githubusercontent.com/63742814/300167255-ae4d1a0c-bd45-49aa-9107-563898954c4f.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjcyNTUtYWU0ZDFhMGMtYmQ0NS00OWFhLTkxMDctNTYzODk4OTU0YzRmLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTQ1OWYxMjM4MzdlYzM4OGY4NzQxMWY4NWJjZGFiYmIyNTVhZWI5MjgzMDllZGIwMTU1MTI2OTFlYTJmNDBmMWUmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.mWqRC2naM3dd0eMaHxgMicLuMKyPdBrWQjLaPAGABf8)
- 生成恶意插件 Jar 包(包含哥斯拉,和CmdShell)
![image](https://private-user-images.githubusercontent.com/63742814/300168491-72774447-7fd1-4a75-81a2-fbc3bfa214b0.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjg0OTEtNzI3NzQ0NDctN2ZkMS00YTc1LTgxYTItZmJjM2JmYTIxNGIwLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTUyYzQxMGI4MTI1MWM3NmQ2MDUwMmVlMTkwMDNjZmJlNDQzMTZjMWQzNmQ2OTgzM2JkZGU4NWQ1YzAwMzFhMWQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.9GdkIeYoWZ9TI4Gh1avNXufKkfI6cZ6lOQMslS1gBlA)
- 显示内存马地址,和pass:key(双击复制,shell路径,key,ua)
![image](https://private-user-images.githubusercontent.com/63742814/300167378-621f2e34-4055-48d8-995e-559fdb056ebf.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjczNzgtNjIxZjJlMzQtNDA1NS00OGQ4LTk5NWUtNTU5ZmRiMDU2ZWJmLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWM2YTBhZDU2OWUxZWM1MzIwNmMxNWIxMTYwNjY4ZWNhZjZjYjIwZDk4YzYwZjI4YzNiMWQzNDRlMWYyZjM3ZTgmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.gG0HHzvraB8IX_S3a0Bfe1uKsWmjSyYk6-vi2EALJdM)
- 用创建的用户进后台,插件功能地址: url+/plugins/servlet/upm,上传插件(不用等传完,直接刷新就有了。)
![image](https://private-user-images.githubusercontent.com/63742814/300167589-694e70af-cd88-4bac-958e-fe4c55d2e414.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjc1ODktNjk0ZTcwYWYtY2Q4OC00YmFjLTk1OGUtZmU0YzU1ZDJlNDE0LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWFlNjdiOGJkOGFmMzUwZTVkMzRmMTRhYzk0NTcwYmMzN2ViODUzYTg0YWY3NGRiN2IxZDQ1OTg2Yjg5MzI3Y2UmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.vhuiN7BluCok6sxr8QzKnJixlDeV9n9-X2GdD7NJOiY)
- 哥斯拉连接
![image](https://private-user-images.githubusercontent.com/63742814/300167658-55bbc76a-33cc-466c-b84f-331fa5de6bbd.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjc2NTgtNTViYmM3NmEtMzNjYy00NjZjLWI4NGYtMzMxZmE1ZGU2YmJkLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTZhMzlkYzRkNWVhZTAzYzZmNjkyMmZmNmRkNWM0ZTUzOGY3NDdiMmM3NjU5Y2E0Y2JjMmZkNzNjYjRiY2NkYjQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.QUCcSU3POG3XCiyUzzogX7hfpISdUNd59qsljTr5aqI)
- 基于插件 CmdShell 命令执行
![image](https://private-user-images.githubusercontent.com/63742814/300167750-654ca5a9-85a3-4fdf-b994-06fffc8d10f8.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAxNjc3NTAtNjU0Y2E1YTktODVhMy00ZmRmLWI5OTQtMDZmZmZjOGQxMGY4LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWI5YTVjNzFhOWY2NjE5NDkxMTBmMmVlZGJhMzNlYWFkZDJmNWQwYmE2MWNlYWEzODBiMDFkMjI4OWQyZTgyOGEmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.tqATJk5eLnast97SWSxdTqXOoIFumc-7vJWk7GpkGnk)
V1.0
- 命令执行(其他 CVE 版本同理)
![image](https://private-user-images.githubusercontent.com/63742814/299994269-ebbad08a-994c-4717-818a-721f24250119.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8yOTk5OTQyNjktZWJiYWQwOGEtOTk0Yy00NzE3LTgxOGEtNzIxZjI0MjUwMTE5LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWZhMDE5YWVkOGQ5NjhiMTZjNDExNWIyNzlkZjhmZjZiZmQyMTYwMThhNDc1YWYwYjI2ZWY1ODdhM2E4MGY1MjImWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.g8SMfTvMwTfVgy9RDkvg4pXTxdMiQlDCPwkmnm62Ndo)
- 内存马注入(其他 CVE 版本同理)
- 哥斯拉
![image](https://private-user-images.githubusercontent.com/63742814/299998019-b7221eaa-d7d5-4fce-ba77-d3f1969b492a.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8yOTk5OTgwMTktYjcyMjFlYWEtZDdkNS00ZmNlLWJhNzctZDNmMTk2OWI0OTJhLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTk0NTdmOTYwYjdkZDNiYjZkZTRjMTZkZjI3ZTM3ZTc1M2QxMWJhYjVjOWNkNGRjOWM4ZDk2NDZhNGQyMDdiMzkmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.sZuL-Y8uPpfkm4QMD_hJ7JCDx_42yIkwb38TnkrX0NE)
![image](https://private-user-images.githubusercontent.com/63742814/299994952-0cc1c2cf-b0b8-43f0-8b18-9d3333824cef.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8yOTk5OTQ5NTItMGNjMWMyY2YtYjBiOC00M2YwLThiMTgtOWQzMzMzODI0Y2VmLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTlhMDc0MTVmODM0N2U2OWQwNWQ5MGJiYWZiNWVlYmM5ODZkMDJmODEwYzA2MDVhMjQ3YWFjYTRjZGI5YTRlZTAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.HXm86b20w38cG9RCvZODELglT6xrK1kYR0BVeB9L9kQ)
- 冰蝎
![image](https://private-user-images.githubusercontent.com/63742814/300004229-21861463-c3ba-41f5-a7a7-9249758eb8e3.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8zMDAwMDQyMjktMjE4NjE0NjMtYzNiYS00MWY1LWE3YTctOTI0OTc1OGViOGUzLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWM3OWVjYjQyYmRhMTc0ZjQzNmFiZjk3YzNhZjJkZTU5OTA4NTVmOGJhOGMxMTNlOWRlNTI1MzA5MjEyNzRjNzQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.l2CNrQIeWb3UBQpl8k69gpWagmZDNRsDtY7mVkubhXI)
![image](https://private-user-images.githubusercontent.com/63742814/299998513-d95dd5c7-6843-4c3c-aac7-bb3147e32005.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk3MjQyNTUsIm5iZiI6MTczOTcyMzk1NSwicGF0aCI6Ii82Mzc0MjgxNC8yOTk5OTg1MTMtZDk1ZGQ1YzctNjg0My00YzNjLWFhYzctYmIzMTQ3ZTMyMDA1LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTYlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE2VDE2MzkxNVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTU2Yjk3YzczMTEyMmNlMTkzOTkzNTEzOTYzOTBiODQ4YzM4NWM5OWU5M2U4YmQ2ZTM3YWM0ZTM0NDk1M2VlZWMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.IJOrUsuof8y1iGWykv1o4mDUjbkpUCf8H-nBxMweeSw)
参考
https://github.com/BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL https://github.com/aaaademo/Confluence-EvilJar
免责声明
本工具仅能在取得足够合法授权的企业安全建设中使用,在使用本工具过程中,您应确保自己所有行为符合当地的法律法规。
如您在使用本工具的过程中存在任何非法行为,您将自行承担所有后果,本工具所有开发者和所有贡献者不承担任何法律及连带责任。