# KimJun1010/WeblogicTool

WeblogicTool，GUI漏洞利用工具，支持漏洞检测、命令执行、内存马注入、密码解密等（深信服深蓝实验室天威战队强力驱动）

Repository: https://github.com/KimJun1010/WeblogicTool
Canonical: https://ross.abutalabs.com/products/weblogictool
License Family: other
Last push: 2023-11-01T03:30:09+00:00

## Health v2 (maintenance only)
Score: 20/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 88
- inputs: {"age_days": 1235, "days_push": 1036, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1804, forks 107 (observed 2026-08-28T04:05:38.923452+00:00)

## What it is
A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs via T3, IIOP, JNDI, and JRMP protocols. It also offers command execution, memory shell injection (Godzilla, Behinder, AntSword), WebLogic password decryption, and batch protocol probing.

## Use cases
- detect weblogic vulnerabilities across many CVEs
- exploit CVE-2023-21839 JNDI injection
- execute commands on vulnerable weblogic servers
- inject memory shells like Godzilla or Behinder filters
- decrypt weblogic 3DES and AES credentials
- batch scan T3 and IIOP protocol exposure

## When to choose
- you need an all-in-one GUI tool for authorized WebLogic penetration testing
- existing WebLogic tools are outdated or have JDK compatibility issues
- you need memory shell injection or credential decryption alongside exploitation

## When to avoid
- you lack explicit legal authorization to test the target
- you need a maintained tool with active development and a license
- target is not Oracle WebLogic

## Facets
- artifact type: application
- maturity: maintenance
- function: penetration-testing, security, vulnerability-scanning
- domain: security, penetration-testing
- platform: cross-platform, cli
- tags: weblogic, exploitation, gui-tool, memory-shell, jndi, jrmp, deserialization, password-decryption, red-team

## Member repositories
- KimJun1010/WeblogicTool (main) score 20

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:38.923452+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:47.955038+00:00, confidence not recorded.
  - readme: https://github.com/KimJun1010/WeblogicTool (fetched 2026-08-28T04:05:38.923452+00:00, sha 117b06f35a27)
- Data as of 2026-08-30T08:39:29.467469+00:00.
