Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#java# 规范 1.6 OS命令执行 修订建议 #43

Open
k4n5ha0 opened this issue May 31, 2021 · 0 comments
Open

#java# 规范 1.6 OS命令执行 修订建议 #43

k4n5ha0 opened this issue May 31, 2021 · 0 comments

Comments

@k4n5ha0
Copy link

k4n5ha0 commented May 31, 2021

1、问题描述
java 代码安全规范的【1.6 】 OS命令执行 需修改

2、解决建议
应修改下列编码建议:
或过滤转义以下符号:|;&$><(反引号)!
修改为
或过滤转义以下符号: & | ; $ > < ` ' " ! ? #

主要增加一些ctf里,命令执行绕过的技巧中用到的特殊符号

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant