Commons-Collections 篇 --CC链总结

CC1

核心要点:

  • 利用 InvokerTransformer 调用 Runtime.getRuntime().exec()
  • LazyMap 懒加载触发 Transformer
  • 反序列化入口:AnnotationInvocationHandler.readObject()

关键节点链:

1
2
3
4
5
6
readObject()
invoke()
LazyMap.get()
ChainedTransformer.transform()
InvokerTransformer.transform()
Runtime.exec()

CC2

核心要点:

  • 利用 TemplatesImpl 执行恶意字节码(而不是直接 Runtime.exec)
  • 触发 defineTransletClasses() -> newInstance()
  • 反序列化入口:PriorityQueue

关键节点链:

1
2
3
4
5
6
readObject()
PriorityQueue.heapify()
Comparable.compare()
TrAXFilter.newTransformer()
TemplatesImpl.getTransletInstance()
<恶意类初始化执行>

CC3

核心要点:

  • 核心依旧是 TemplatesImpl
  • 入口由 CC1 的 LazyMap 换成了 BadAttributeValueExpException
  • toString() 触发

关键链:

1
2
3
4
5
6
7
readObject()
BadAttributeValueExpException.readObject()
toString()
TiedMapEntry.getValue()
LazyMap.get()
InvokerTransformer(TemplatesImpl.newTransformer)
payload 执行

CC4

核心要点:

  • 利用 PriorityQueue + TransformingComparator
  • 不再使用 AnnotationInvocationHandler
  • 仍然是 Runtime.exec()

关键链:

1
2
3
4
5
readObject()
PriorityQueue.heapify()
TransformingComparator.compare()
Transformer.transform()
Runtime.exec()

CC5

核心要点:

  • 利用 BadAttributeValueExpException.toString()
  • 利用 TiedMapEntry.getValue()
  • LazyMap 触发 transformer 链

关键链:

1
2
3
4
5
6
7
readObject()
BadAttributeValueExpException.readObject()
toString()
TiedMapEntry.getValue()
LazyMap.get()
Transformer.transform()
Runtime.exec()

与 CC3 的差别:CC3 使用 TemplatesImpl,CC5 使用 Runtime.exec

CC6

核心要点:

  • 入口:Method.invoke()
  • 利用 HashMap 反序列化过程中调用 hashCode()
  • TiedMapEntry.hashCode() 触发 LazyMap

关键链:

1
2
3
4
5
6
7
readObject()
HashMap.readObject()
HashMap.hash()
TiedMapEntry.hashCode()
LazyMap.get()
Transformer.transform()
Runtime.exec()

CC7

核心要点:

  • Hashtable 的 readObject() 触发
  • 利用 equals() → LazyMap.get() 执行链
  • 执行 Runtime.exec()

关键链:

1
2
3
4
5
6
7
8
readObject()
Hashtable.readObject()
rehash()
equals()
TiedMapEntry.getValue()
LazyMap.get()
Transformer.transform()
Runtime.exec()

CC11

核心要点:

  • 利用 PriorityQueue 反序列化时 必然触发比较器
  • 通过 TransformingComparator 将 compare() 行为转换为 Transformer.transform()
  • 不依赖 TemplatesImpl
  • 执行方式通常为 Runtime.exec()(或等价方法调用)

关键链:

1
2
3
4
5
6
7
readObject()
PriorityQueue.readObject()
heapify()
TransformingComparator.compare()
ChainedTransformer.transform()
InvokerTransformer.transform()
Runtime.exec()

对比

链 执行来源 反序列化触发点 执行方式 常见利用 Payload
CC1 LazyMap AnnotationInvocationHandler InvokerTransformer Runtime.exec
CC2 PriorityQueue heapify() - compare() TemplatesImpl 恶意字节码执行
CC3 BadAttributeValueExpException.toString TiedMapEntry TemplatesImpl 恶意类构造执行
CC4 PriorityQueue TransformingComparator.compare InvokerTransformer Runtime.exec
CC5 BadAttributeValueExpException.toString LazyMap InvokerTransformer Runtime.exec
CC6 HashMap.hash() TiedMapEntry.hashCode InvokerTransformer Runtime.exec
CC7 Hashtable.equals TiedMapEntry.equals/getValue InvokerTransformer Runtime.exec
CC11 PriorityQueue TransformingComparator.compare nvokerTransformer Runtime.exec

主要触发:

  1. CC1 LazyMap + AnnotationInvocationHandler
  2. CC2 PriorityQueue + TemplatesImpl
  3. CC3 BadAttrExpException + TemplatesImpl
  4. CC4 PriorityQueue + TransformingComparator
  5. CC5 BadAttrExpException + LazyMap
  6. CC6 HashMap.hash() + LazyMap
  7. CC7 Hashtable.equals() + LazyMap
  8. CC11 PriorityQueue + TransformingComparator

流程图:

image-20251217162804674


Commons-Collections 篇 --CC链总结
http://example.com/2025/12/17/CC链总结/
作者
Piggy Sprint
发布于
2025年12月17日
许可协议