13.07.2015 Views

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-<strong>2010</strong>-1871 exploitHow to execute OS commands via JBoss EL?can’t reference java.<strong>lang</strong>.Runtime directly, sinceresolvers won’t know how to resolve ‘java’Reflection!!!Every Object has Class <strong>getClass</strong>()And Class has Class <strong>forName</strong>(String), whichreturns class based on supplied name:<strong>view</strong>.<strong>getClass</strong>.<strong>forName</strong>(<strong>'java</strong>.<strong>lang</strong>.<strong>Runtime'</strong>)Thursday, November 25, <strong>2010</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!