You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As Jupiter's deserialization protocol is dictated by the sender's request configuration, attackers can induce the Provider side to employ the Native JDK protocol for deserializing carefully crafted serialized data, thereby accomplishing an RCE attack.
Reproduce
Provider
We employed the built-in module "jupiter-example" of the project to set up the test environment for the attack. The JDK version used is 8u65.
POC
At line 66, change the deserialization protocol to Native JAVA, and at line 70, replace the malicious injection object (there are several known candidate injection objects, one is selected here as an example, and this chain depends on the following JAR files).
Problem Description
As Jupiter's deserialization protocol is dictated by the sender's request configuration, attackers can induce the Provider side to employ the Native JDK protocol for deserializing carefully crafted serialized data, thereby accomplishing an RCE attack.
Reproduce
Provider
We employed the built-in module "jupiter-example" of the project to set up the test environment for the attack. The JDK version used is 8u65.
data:image/s3,"s3://crabby-images/bc866/bc86616b9b68bfc1558102934c9419ec6f19e659" alt="截屏2023-11-02 22 54 28"
POC
At line 66, change the deserialization protocol to Native JAVA, and at line 70, replace the malicious injection object (there are several known candidate injection objects, one is selected here as an example, and this chain depends on the following JAR files).
Attack Impact
Capable of executing an RCE attack, in this attack test, it is demonstrated through the launch of the calculator application.
data:image/s3,"s3://crabby-images/aff0a/aff0a8e51f84e38352fb7d73fc8116f88ef5fd8d" alt="截屏2023-11-02 22 51 49"
data:image/s3,"s3://crabby-images/35d70/35d7006a4f8c8b98fe1e4fde752362ed3dc1a0d8" alt="截屏2023-11-02 22 52 28"
data:image/s3,"s3://crabby-images/d44e9/d44e9550b4c0d485ecff2bbd7f40073f34bfc256" alt="截屏2023-11-02 22 52 50"
The text was updated successfully, but these errors were encountered: