java 代码审计学习靶场,边学边完善
- spring actuator (web 和 jmx 方式)
http://127.0.0.1:8999/actuatorhttp://127.0.0.1:8999/actuator/envhttp://127.0.0.1:8999/actuator/heapdumphttp://127.0.0.1:8999/actuator/mappingshttp://127.0.0.1:8999/actuator/prometheus
- swagger
http://127.0.0.1:8999/swagger-resourceshttp://127.0.0.1:8999/swagger-ui.htmlhttp://127.0.0.1:8999/v2/api-docs
- druid
http://127.0.0.1:8999/druid/login.htmladmin/admin
- spel注入
http://127.0.0.1:8999/spel?exec=1无过滤
- mysql注入
http://127.0.0.1:8999/sqlinj/mysql/getbyid/1无过滤
- postgresql注入
http://127.0.0.1:8999/sqlinj/postgre/getbyid/1无过滤
- url跳转漏洞
http://127.0.0.1:8999/redirect/1?url=无过滤http://127.0.0.1:8999/redirect/2?url=可以被绕过的白名单案例http://127.0.0.1:8999/redirect/3?url=反斜杠绕过http://127.0.0.1:8999/redirect/safe?url=安全案例
- 文件上传
http://127.0.0.1:8999/upload无过滤/黑名单过滤/白名单过滤/安全案例
- ssrf
http://127.0.0.1:8999/ssrf/1?url=无过滤http://127.0.0.1:8999/ssrf/2?url=重定向bypasshttp://127.0.0.1:8999/ssrf/safe?url=安全案例
- ssti(Thymeleaf)
http://127.0.0.1:8999/ssti/1?name=&name2=return可控(预处理)http://127.0.0.1:8999/ssti/2?name=视图名称可控
- log4j
todo