0x01 前言
《java反序列化利用链自动挖掘工具gadgetinspector源码浅析》
我的上一篇文章,详细地讲述了gadgetinspector挖掘java反序列化利用链的原理,在明白了gadgetinspector的原理细节后,我们其实会发现它还存在着一部分的缺点:
- 对于运行时确定的实现,也就是多态性,没办法做到污点分析:
https://github.com/baidu/openrasp
Unlike perimeter control solutions like WAF, OpenRASP directly integrates its protection engine into the application server by instrumentation. It can monitor various events including database queries, file operations and network requests etc.