Decodificador de injeção OGNL
Cole uma carga OGNL encontrada num log de WAF ou de aplicação e leia o que ela pretendia fazer. Separa a fuga do sandbox da chamada de execução, nomeia a família de boletim compatível com o formato e sempre declara o que não determinou. Só decodifica - nunca avalia a carga e não guarda modelos.
Segurança e WAFRead locally in your browser. Nothing is sent anywhere, and nothing in the payload is evaluated — the tool recognises syntax and describes it.
Referências
- Apache Struts security bulletin S2-045 (CVE-2017-5638): remote code execution via the Jakarta multipart parser
- Apache Struts security bulletin S2-057 (CVE-2018-11776): possible RCE when namespace and result values are evaluated
- Apache Commons OGNL language guide: expression syntax and static method access