0x03反射-补充零散知识点
文章目录
向大佬致敬: https://drun1baby.top
Runtime
类中有 exec
方法,可以用来命令执行。
一般情况下,我们使用反射机制不能对类的私有 private
字段进行操作,绕过私有权限的访问
package IOStream;
import java.io.ByteArrayOutputStream;
import java.io.IOException;
import java.io.InputStream;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.Map;
public class FileStreamTest {
public static void main(String[] args){
InputStream inputStream = null;
try {
//命令执行方法1
// inputStream = Runtime.getRuntime().exec("whoami").getInputStream();
//命令执行方法2
// inputStream = new ProcessBuilder("calc").start().getInputStream();
//命令执行方法3 反射间接调用
String[] cmds = new String[]{
"calc"};
Class clazz = Class.forName("java.lang.ProcessImpl");
Method method = clazz.getDeclaredMethod("start", String[].class, Map.class, String.class, ProcessBuilder.Redirect[].class, boolean.class);
method.setAccessible(true);
Process e = (Process) method.invoke(null, cmds, null, ".", null, true);
inputStream = e.getInputStream();
} catch (ClassNotFoundException | NoSuchMethodException e) {
e.printStackTrace();
} cat