mirror of
https://github.com/frohoff/ysoserial.git
synced 2026-09-21 22:50:46 +08:00
tests for scala payloads
This commit is contained in:
@@ -7,6 +7,7 @@ import scala.math.Ordering$;
|
||||
import scala.sys.process.processInternal$;
|
||||
import ysoserial.payloads.annotation.Authors;
|
||||
import ysoserial.payloads.annotation.Dependencies;
|
||||
import ysoserial.payloads.annotation.PayloadTest;
|
||||
import ysoserial.payloads.util.PayloadRunner;
|
||||
import ysoserial.payloads.util.Reflections;
|
||||
|
||||
@@ -65,6 +66,7 @@ public class Scala {
|
||||
scala.sys.process.ProcessBuilderImpl$FileOutput$$anonfun$$lessinit$greater$3.apply()
|
||||
java.io.FileOutputStream.<init>()
|
||||
*/
|
||||
@PayloadTest(harness="ysoserial.test.payloads.EmptyFileWriteTest")
|
||||
@Dependencies({"org.scala-lang:scala-library:2.12.6"})
|
||||
@Authors({ Authors.JACKOFMOSTTRADES })
|
||||
public static class ScalaCreateZeroFile extends PayloadRunner implements ObjectPayload<PriorityQueue<Throwable>> {
|
||||
@@ -88,6 +90,7 @@ public class Scala {
|
||||
scala.sys.process.ProcessBuilderImpl$URLInput$$anonfun$$lessinit$greater$1.apply()
|
||||
java.net.URL.openStream()
|
||||
*/
|
||||
@PayloadTest(harness="ysoserial.test.payloads.SsrfTest")
|
||||
@Dependencies({"org.scala-lang:scala-library:2.12.6"})
|
||||
@Authors({ Authors.JACKOFMOSTTRADES })
|
||||
public static class ScalaSsrf extends PayloadRunner implements ObjectPayload<PriorityQueue<Throwable>> {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
package ysoserial.test.payloads;
|
||||
|
||||
import org.apache.commons.codec.binary.Base64;
|
||||
import org.junit.Assert;
|
||||
import ysoserial.Strings;
|
||||
import ysoserial.payloads.Scala;
|
||||
import ysoserial.test.CustomTest;
|
||||
import ysoserial.test.util.Files;
|
||||
import ysoserial.test.util.OS;
|
||||
|
||||
import java.io.BufferedReader;
|
||||
import java.io.File;
|
||||
import java.io.FileReader;
|
||||
import java.util.concurrent.Callable;
|
||||
|
||||
public class EmptyFileWriteTest implements CustomTest {
|
||||
private final File testFile = new File(OS.getTmpDir(), "ysoserial-test-" + Strings.randUUID());
|
||||
private final String testContent = Strings.randUUID();
|
||||
|
||||
@Override
|
||||
public void run(Callable<Object> payload) throws Exception {
|
||||
Assert.assertFalse("test file should not exist", testFile.exists());
|
||||
try {
|
||||
payload.call();
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
Files.waitForFile(testFile, 5000);
|
||||
Assert.assertTrue("test file should exist", testFile.exists());
|
||||
Assert.assertEquals(0, testFile.length());
|
||||
testFile.deleteOnExit();
|
||||
}
|
||||
|
||||
@Override
|
||||
public String getPayloadArgs() {
|
||||
return testFile.toString();
|
||||
}
|
||||
|
||||
public static void main(String[] args) throws Exception {
|
||||
PayloadsTest.testPayload(Scala.ScalaCreateZeroFile.class, new Class[0]);
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,57 @@
|
||||
package ysoserial.test.payloads;
|
||||
|
||||
import com.sun.net.httpserver.HttpExchange;
|
||||
import com.sun.net.httpserver.HttpHandler;
|
||||
import com.sun.net.httpserver.HttpServer;
|
||||
import org.junit.Assert;
|
||||
import ysoserial.Strings;
|
||||
import ysoserial.payloads.Scala;
|
||||
import ysoserial.test.CustomTest;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.net.InetSocketAddress;
|
||||
import java.util.LinkedList;
|
||||
import java.util.List;
|
||||
import java.util.Random;
|
||||
import java.util.concurrent.Callable;
|
||||
|
||||
public class SsrfTest implements CustomTest {
|
||||
int port = 16000 + new Random().nextInt(16000);
|
||||
String authority = "http://localhost:" + port;
|
||||
String uri = "/?" + Strings.randUUID();
|
||||
|
||||
@Override
|
||||
public String getPayloadArgs() {
|
||||
return authority + uri;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void run(Callable<Object> payload) throws Exception {
|
||||
final List<String> uris = new LinkedList<String>();
|
||||
HttpServer server = HttpServer.create(new InetSocketAddress("127.0.0.1", port), 0);
|
||||
server.createContext("/", new HttpHandler() {
|
||||
@Override
|
||||
public void handle(HttpExchange exchange) throws IOException {
|
||||
System.out.println(exchange.getRequestURI());
|
||||
uris.add(exchange.getRequestURI().toString());
|
||||
exchange.sendResponseHeaders(200, 0);
|
||||
exchange.close();
|
||||
}
|
||||
});
|
||||
server.start();
|
||||
try {
|
||||
try {
|
||||
payload.call();
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
Assert.assertTrue(uris.contains(uri));
|
||||
} finally {
|
||||
server.stop(0);
|
||||
}
|
||||
}
|
||||
|
||||
public static void main(String[] args) throws Exception {
|
||||
PayloadsTest.testPayload(Scala.ScalaSsrf.class, new Class[0]);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user