Skip to content

Commit bea7883

Browse files
author
“threedr3am”
committed
op:sync-session-bug README.md
1 parent 8506ee4 commit bea7883

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

tomcat/sync-session-bug/README.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,6 @@
1+
### exp
2+
利用工具:[tomcat-cluster-session-sync-exp](https://github.com/threedr3am/tomcat-cluster-session-sync-exp)
3+
14
### sync-session-bug
25

36
这是一个tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包,

0 commit comments

Comments
 (0)