Comments (17)
更换一下Extender
→Options
→Java Environment
下的JDK版本试试
from log4j2burpscanner.
同样的错误,试了切换JDK版本还是一样。JDK8 9 11 7 6都试过了
from log4j2burpscanner.
我给出我的jdk配置参考一下,感觉可能是小版本的问题
实在不行下载源码本地编译一下
from log4j2burpscanner.
#8 这位师傅换的1.8_202成功了
from log4j2burpscanner.
还是一样报错
from log4j2burpscanner.
下载源码自编译还是一样,release下载也是一样。
from log4j2burpscanner.
你好,请问你启动burp的java版本是不是超过了8?提供的tag里面都是使用java1.8进行编译的,所以在高版本的情况下,可能导致导入失败,你可以下载源码使用你同burp的java版本进行编译即可
from log4j2burpscanner.
看下pmiaowu大佬的解答
pmiaowu/BurpFastJsonScan#6
from log4j2burpscanner.
我这里windows低版本bp、低版本windows也可以加载
from log4j2burpscanner.
都不行,害。难受
from log4j2burpscanner.
编译的时候修改下pom.xml里的
<source>1.8</source>
<target>1.8</target>
改为自有的版本呢,比如mvn的jdk10就是1.10,google了一下感觉都是高版本jdk对低版本jdk编译的jar不兼容的问题
from log4j2burpscanner.
试试看新的releases下的jdk11的jar,我切换了mvn的jdk版本进行打包了
from log4j2burpscanner.
我跟他一样的问题,1.8.0_161,自己编译和下载release的都不行,报这个错
java.lang.NullPointerException
at burp.ind.b(Unknown Source)
at burp.p0g.getHttpService(Unknown Source)
at burp.lxg.getHttpService(Unknown Source)
at burp.BurpExtender$MarkInfoTab.isEnabled(BurpExtender.java:151)
at burp.a1g.b(Unknown Source)
at burp.q5e.a(Unknown Source)
at burp.q5e.a(Unknown Source)
at burp.ycf.b(Unknown Source)
at burp.abb.a(Unknown Source)
at burp.q5e.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addImpl(Unknown Source)
at javax.swing.JTabbedPane.insertTab(Unknown Source)
at burp.p5e.a(Unknown Source)
at burp.p5e.insertTab(Unknown Source)
at javax.swing.JTabbedPane.addTab(Unknown Source)
at burp.z6e.a(Unknown Source)
at burp.ycf.b(Unknown Source)
at burp.ycf.a(Unknown Source)
at burp.izc.a(Unknown Source)
at burp.xcf.addSuiteTab(Unknown Source)
at burp.z3f.addSuiteTab(Unknown Source)
at burp.BurpExtender$1.run(BurpExtender.java:1004)
at java.awt.event.InvocationEvent.dispatch(Unknown Source)
at java.awt.EventQueue.dispatchEventImpl(Unknown Source)
at java.awt.EventQueue.access$500(Unknown Source)
at java.awt.EventQueue$3.run(Unknown Source)
at java.awt.EventQueue$3.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at java.security.ProtectionDomain$JavaSecurityAccessImpl.doIntersectionPrivilege(Unknown Source)
at java.awt.EventQueue.dispatchEvent(Unknown Source)
at java.awt.EventDispatchThread.pumpOneEventForFilters(Unknown Source)
at java.awt.EventDispatchThread.pumpEventsForFilter(Unknown Source)
at java.awt.EventDispatchThread.pumpEventsForHierarchy(Unknown Source)
at java.awt.EventDispatchThread.pumpEvents(Unknown Source)
at java.awt.EventDispatchThread.pumpEvents(Unknown Source)
at java.awt.EventDispatchThread.run(Unknown Source)
java.lang.NullPointerException
at burp.ind.b(Unknown Source)
at burp.p0g.getHttpService(Unknown Source)
at burp.lxg.getHttpService(Unknown Source)
at burp.BurpExtender$MarkInfoTab.isEnabled(BurpExtender.java:151)
at burp.a1g.b(Unknown Source)
at burp.q5e.a(Unknown Source)
at burp.q5e.a(Unknown Source)
at burp.ycf.b(Unknown Source)
at burp.abb.a(Unknown Source)
at burp.q5e.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addNotify(Unknown Source)
at javax.swing.JComponent.addNotify(Unknown Source)
at java.awt.Container.addImpl(Unknown Source)
at javax.swing.JTabbedPane.insertTab(Unknown Source)
at burp.p5e.a(Unknown Source)
at burp.p5e.insertTab(Unknown Source)
at javax.swing.JTabbedPane.addTab(Unknown Source)
at burp.z6e.a(Unknown Source)
at burp.ycf.b(Unknown Source)
at burp.ycf.a(Unknown Source)
at burp.izc.a(Unknown Source)
at burp.xcf.addSuiteTab(Unknown Source)
at burp.z3f.addSuiteTab(Unknown Source)
at burp.BurpExtender$1.run(BurpExtender.java:1004)
at java.awt.event.InvocationEvent.dispatch(Unknown Source)
at java.awt.EventQueue.dispatchEventImpl(Unknown Source)
at java.awt.EventQueue.access$500(Unknown Source)
at java.awt.EventQueue$3.run(Unknown Source)
at java.awt.EventQueue$3.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at java.security.ProtectionDomain$JavaSecurityAccessImpl.doIntersectionPrivilege(Unknown Source)
at java.awt.EventQueue.dispatchEvent(Unknown Source)
at java.awt.EventDispatchThread.pumpOneEventForFilters(Unknown Source)
at java.awt.EventDispatchThread.pumpEventsForFilter(Unknown Source)
at java.awt.EventDispatchThread.pumpEventsForHierarchy(Unknown Source)
at java.awt.EventDispatchThread.pumpEvents(Unknown Source)
at java.awt.EventDispatchThread.pumpEvents(Unknown Source)
at java.awt.EventDispatchThread.run(Unknown Source)
from log4j2burpscanner.
用高版本的jdk8试试,实测1.8_251
、1.8_231
都可以正常加载
具体和启动burp的jdk也有关系
from log4j2burpscanner.
上面报错不影响使用,但运行报错这个,感觉是多线程处理问题?
from log4j2burpscanner.
工具还有几点建议,这个漏洞点不宜区分呀。不知道具体漏洞点是哪个,建议搞个编号。
from log4j2burpscanner.
0.17.2
版本已添加漏洞参数点报告
from log4j2burpscanner.
Related Issues (20)
- 添加自定义poc扫描 HOT 1
- 右键发送log4j2问题 HOT 4
- 大佬 请教下有办法取消默认的url吗?还有为啥payload会多个冒号呢? HOT 7
- 大佬可否出个白名单功能啊,现在只要一开启插件就什么网站都打
- 大佬可否出个白名单功能啊,现在只要一开启插件就什么网站都打 HOT 2
- 有报错信息 HOT 1
- 内存泄漏问题 HOT 1
- 插件进行了扫描,ceye也可以看到记录,但是在显示界面没有回显 HOT 1
- 作者你好,jdk版本是1.8_231但是无法导入插件。请问您用的是那个版本的bp呢?(我用的是2.0.11) HOT 1
- 0.20.1版本bug HOT 7
- Just a question HOT 2
- 使用完整的域名做标识符会将冒号“:”带入导致域名出现错误 HOT 2
- 可以用于内网测试吗 HOT 1
- 建议同步下release中24.0的代码 HOT 1
- 关于DNSLOG的问题 HOT 1
- 更换自定义dnslog问题 HOT 1
- bug,设置自定义dns未生效,右键菜单Send to log4j2 Scanner 没反应 HOT 1
- Extender里发现漏洞命中有记录,但是在插件面板中为空 HOT 2
- send log4j 无效 HOT 3
- dnslog平台失效 HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from log4j2burpscanner.