Apache JMeter 3.3 running as a jmeter-server, vulnerable to CVE-2018-1297: its RMI registry on port 1099 deserializes objects from any client, and the BeanShell gadget chain bundled with JMeter runs commands.
Pas commencéDockercommit 20281b8x86_64 · aarch64Secret
Exploit CVE-2018-1297 through the JMeter RMI registry to run commands and get a shell.
Le brief de ce lab se trouve dans son dépôt.