Skip to content

如果反序列化过程中使用resolveClass拉黑了TemplatesImpl如何绕过

Notifications You must be signed in to change notification settings

Y4Sec-Team/no-templates

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

no-templates

文章链接:使用JDK类绕过TemplatesImpl黑名单

这是一个靶场,用于测试TemplatesImpl被拉黑的情况:

  • spring-boot-env 一个包含了前端的测试靶场
  • gadget-generator 生成各种测试payload
  • evil-ldap-server 用于绕过黑名单的ldap服务端

About

如果反序列化过程中使用resolveClass拉黑了TemplatesImpl如何绕过

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published