Skip to content

Commit 5e53cb2

Browse files
committed
Updated new gedgets and payloads
1 parent 37447b8 commit 5e53cb2

File tree

7 files changed

+722
-128
lines changed

7 files changed

+722
-128
lines changed

.gitignore

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,3 +39,8 @@ Resource/java/*
3939
Resource/python/*
4040
Resource/ysoserialnet/*
4141
Resource/ysoserial.jar
42+
obj/*
43+
bin/*
44+
packages/*
45+
.vs/*
46+
Properties/PublishProfiles/*

Models/PhpGGC.cs

Lines changed: 71 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,26 +38,46 @@ public class PhpGGC
3838

3939
public enum Gadget
4040
{
41+
Bitrix_RCE1,
4142
CakePHP_RCE1,
4243
CakePHP_RCE2,
44+
CodeIgniter4_FD1,
45+
CodeIgniter4_FD2,
46+
CodeIgniter4_FR1,
4347
CodeIgniter4_RCE1,
4448
CodeIgniter4_RCE2,
4549
CodeIgniter4_RCE3,
50+
CodeIgniter4_RCE4,
51+
CodeIgniter4_RCE5,
52+
CodeIgniter4_RCE6,
4653
Doctrine_FW1,
4754
Doctrine_FW2,
55+
Doctrine_RCE1,
56+
Doctrine_RCE2,
4857
Dompdf_FD1,
4958
Dompdf_FD2,
59+
Drupal_AT1,
60+
Drupal_FD1,
61+
Drupal_PsySH_INFO1,
62+
Drupal_SQLI1,
63+
Drupal_SSRF1,
64+
Drupal_XXE1,
5065
Drupal7_FD1,
5166
Drupal7_RCE1,
67+
Drupal7_SQLI1,
68+
Drupal7_SSRF1,
69+
Drupal9_RCE1,
70+
Grav_FD1,
5271
Guzzle_FW1,
5372
Guzzle_INFO1,
5473
Guzzle_RCE1,
5574
Horde_RCE1,
75+
Joomla_FW1,
5676
Kohana_FR1,
5777
Laminas_FD1,
5878
Laminas_FW1,
79+
Laravel_FD1,
5980
Laravel_RCE1,
60-
Laravel_RCE10,
6181
Laravel_RCE2,
6282
Laravel_RCE3,
6383
Laravel_RCE4,
@@ -66,9 +86,23 @@ public enum Gadget
6686
Laravel_RCE7,
6787
Laravel_RCE8,
6888
Laravel_RCE9,
89+
Laravel_RCE10,
90+
Laravel_RCE11,
91+
Laravel_RCE12,
92+
Laravel_RCE13,
93+
Laravel_RCE14,
94+
Laravel_RCE15,
95+
Laravel_RCE16,
96+
Laravel_RCE17,
97+
Laravel_RCE18,
98+
Laravel_RCE19,
99+
Laravel_RCE20,
100+
Laravel_RCE21,
101+
Laravel_RCE22,
69102
Magento_FW1,
70103
Magento_SQLI1,
71104
Magento2_FD1,
105+
Magento2_FD2,
72106
Monolog_FW1,
73107
Monolog_RCE1,
74108
Monolog_RCE2,
@@ -79,36 +113,66 @@ public enum Gadget
79113
Monolog_RCE7,
80114
Monolog_RCE8,
81115
Monolog_RCE9,
116+
OpenCart_FW1,
117+
OpenCart_FW2,
118+
OpenCart_FW3,
119+
OpenCart_RCE1,
120+
OpenCart_RCE2,
82121
Phalcon_RCE1,
122+
Phing_FD1,
83123
PHPCSFixer_FD1,
84124
PHPCSFixer_FD2,
85125
PHPExcel_FD1,
86126
PHPExcel_FD2,
87127
PHPExcel_FD3,
88128
PHPExcel_FD4,
89129
PHPSecLib_RCE1,
130+
phpThumb_FD1,
131+
PHPWord_FD1,
132+
Plates_RCE1,
90133
Pydio_Guzzle_RCE1,
134+
Silverstripe_FD1,
91135
Slim_RCE1,
92136
Smarty_FD1,
93137
Smarty_SSRF1,
138+
Snappy_FD1,
139+
Spiral_RCE1,
140+
Spiral_RCE2,
94141
SwiftMailer_FD1,
142+
SwiftMailer_FD2,
143+
SwiftMailer_FR1,
95144
SwiftMailer_FW1,
96145
SwiftMailer_FW2,
97146
SwiftMailer_FW3,
98147
SwiftMailer_FW4,
148+
Symfony_FD1,
99149
Symfony_FW1,
100150
Symfony_FW2,
101151
Symfony_RCE1,
102152
Symfony_RCE2,
103153
Symfony_RCE3,
104154
Symfony_RCE4,
105155
Symfony_RCE5,
156+
Symfony_RCE6,
157+
Symfony_RCE7,
158+
Symfony_RCE8,
159+
Symfony_RCE9,
160+
Symfony_RCE10,
161+
Symfony_RCE11,
162+
Symfony_RCE12,
163+
Symfony_RCE13,
164+
Symfony_RCE14,
165+
Symfony_RCE15,
166+
Symfony_RCE16,
106167
TCPDF_FD1,
107168
ThinkPHP_FW1,
108169
ThinkPHP_FW2,
109170
ThinkPHP_RCE1,
110171
ThinkPHP_RCE2,
172+
ThinkPHP_RCE3,
173+
ThinkPHP_RCE4,
111174
Typo3_FD1,
175+
vBulletin_RCE1,
112176
WordPress_Dompdf_RCE1,
113177
WordPress_Dompdf_RCE2,
114178
WordPress_Guzzle_RCE1,
@@ -118,20 +182,25 @@ public enum Gadget
118182
WordPress_P_WooCommerce_RCE1,
119183
WordPress_P_WooCommerce_RCE2,
120184
WordPress_P_YetAnotherStarsRating_RCE1,
185+
WordPress_P_YoastSEO_FW1,
121186
WordPress_PHPExcel_RCE1,
122187
WordPress_PHPExcel_RCE2,
123188
WordPress_PHPExcel_RCE3,
124189
WordPress_PHPExcel_RCE4,
125190
WordPress_PHPExcel_RCE5,
126191
WordPress_PHPExcel_RCE6,
192+
WordPress_RCE1,
193+
WordPress_RCE2,
127194
Yii_RCE1,
195+
Yii_RCE2,
128196
Yii2_RCE1,
129197
Yii2_RCE2,
130198
ZendFramework_FD1,
131199
ZendFramework_RCE1,
132200
ZendFramework_RCE2,
133201
ZendFramework_RCE3,
134-
ZendFramework_RCE4
202+
ZendFramework_RCE4,
203+
ZendFramework_RCE5
135204
}
136205

137206
public enum Encoding

Models/YSoSerialNET.cs

Lines changed: 21 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,12 @@ public enum Plugin
6262
ApplicationTrust,
6363
Clipboard,
6464
DotNetNuke,
65+
GetterCallGadgets,
66+
NetNonRceGadgets,
6567
Resx,
6668
SessionSecurityTokenHandler,
6769
SharePoint,
70+
ThirdPartyGadgets,
6871
TransactionManagerReenlist,
6972
ViewState
7073
}
@@ -75,20 +78,32 @@ public enum NetGadget
7578
ActivitySurrogateDisableTypeCheck,
7679
ActivitySurrogateSelectorFromFile,
7780
AxHostState,
81+
BaseActivationFactory,
7882
ClaimsIdentity,
83+
ClaimsPrincipal,
7984
DataSet,
85+
DataSetOldBehaviour,
86+
DataSetOldBehaviourFromFile,
87+
DataSetTypeSpoof,
88+
GenericPrincipal,
89+
GetterCompilerResults,
90+
GetterSecurityException,
91+
GetterSettingsPropertyValue,
8092
ObjectDataProvider,
93+
ObjRef,
8194
PSObject,
8295
RolePrincipal,
83-
ResourceSet,
8496
SessionSecurityToken,
8597
SessionViewStateHistoryItem,
8698
TextFormattingRunProperties,
99+
ToolboxItemContainer,
87100
TypeConfuseDelegate,
88101
TypeConfuseDelegateMono,
89102
WindowsClaimsIdentity,
90103
WindowsIdentity,
91-
WindowsPrincipal
104+
WindowsPrincipal,
105+
XamlAssemblyLoadFromFile,
106+
XamlImageInfo
92107
}
93108

94109
public enum Formatter
@@ -107,7 +122,10 @@ public enum Formatter
107122
SharpSerializerXml,
108123
Xaml,
109124
XmlSerializer,
110-
YamlDotNet
125+
YamlDotNet,
126+
MessagePackTypeless,
127+
MessagePackTypelessLz4,
128+
ObjectStateFormatter
111129
}
112130

113131
public enum NetOutput

0 commit comments

Comments
 (0)