Skip to content

Commit 14db112

Browse files
committed
Add logging to show executed Java and result
1 parent 4c240e8 commit 14db112

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

modules/exploits/multi/elasticsearch/script_mvel_rce.rb

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -105,12 +105,16 @@ def vulnerable?
105105
sum = addend_one + addend_two
106106

107107
java = java_sum([addend_one, addend_two])
108+
109+
vprint_status("#{peer} attempting to execute '#{java}' in Java")
108110
res = execute(java)
109111
result = parse_result(res)
110112

111113
if result.nil?
114+
vprint_status("#{peer} no response to executed Java")
112115
return false
113116
else
117+
vprint_status("#{peer} response to executed Java: #{result}")
114118
result.to_i == sum
115119
end
116120
end
@@ -136,11 +140,7 @@ def parse_result(res)
136140
end
137141

138142
def java_sum(summands)
139-
source = <<-EOF
140-
#{summands.join(" + ")}
141-
EOF
142-
143-
source
143+
summands.join(' + ')
144144
end
145145

146146
def to_java_byte_array(str)

0 commit comments

Comments
 (0)