Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
在 Java 源代码字符串中隐藏 payload
portswigger.net
| 研究 |
#rce
|
#burp-suite
|
#java
|
#bambdas
|
#code-execution
|
#unicode-escapes
摘要
在 Java 源代码字符串中隐藏 payload:Java 先处理 Unicode 转义再解析语法,\u0022 可提前闭合字符串,让看似无害的 Bambda 实际执行任意代码——使用来源不明的 Bambda 前务必审查。
发布时间
2024-01-24 12:27
收录时间
2026-07-22 04:47
原文 ↗
相关内容
用 bambdas 重塑你的 HTTP 视角
(portswigger.net)
用 Bambdas 找到那个古怪的端点
(portswigger.net)
CVE-2022-22947:Spring Cloud Gateway 代码注入漏洞
(blog.viettelcybersecurity.com)
实用的 Web 缓存投毒
(portswigger.net)
利用Unicode溢出绕过字符黑名单
(portswigger.net)
URL验证绕过速查表中的全新疯狂Payload
(portswigger.net)
返回