Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
perwendel__spark_CVE-2018-9159_2-7-1 — 라우팅, 필터 및 정적 파일 서비스를 지원하는 경량 Java 8 웹 프레임워크입니다. 이전 버전에 대한 보안 권고 및 CRUD API 예제를 포함합니다. | Kitploit
도구/GitHubGitHub/shoucheng3/perwendel__spark_cve-2018-9159_2-7-1
General Purpose UtilitiesVulnerability AnalysisAPI Security TestingWeb SecurityPenetration TestingLearning & Education
GitHubshoucheng3/perwendel__spark_cve-2018-9159_2-7-1

perwendel__spark_CVE-2018-9159_2-7-1

라우팅, 필터 및 정적 파일 서비스를 지원하는 경량 Java 8 웹 프레임워크입니다. 이전 버전에 대한 보안 권고 및 CRUD API 예제를 포함합니다.

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
저장소 보기
161년 전아직 검토되지 않음
공유

Spark - Java 8을 위한 소형 웹 프레임워크

소식: Spark 2.7.0이 출시되었습니다. 사용해보시고 버그를 신고해주세요.

<dependency>
    <groupId>com.sparkjava</groupId>
    <artifactId>spark-core</artifactId>
    <version>2.7.0</version>
</dependency>

중요 - 이전 버전의 Spark(2.5.2 미만 버전)에는 취약점이 있습니다. 최신 버전으로 업그레이드하세요.

문서는 다음에서 확인하세요: http://sparkjava.com/documentation

사용 질문은 “spark-java” 태그가 있는 stack overflow를 이용해주세요.

Javadoc: http://javadoc.io/doc/com.sparkjava/spark-core

시작하기

<dependency>
    <groupId>com.sparkjava</groupId>
    <artifactId>spark-core</artifactId>
    <version>2.7.0</version>
</dependency>
import static spark.Spark.*;

public class HelloWorld {
    public static void main(String[] args) {
        get("/hello", (request, response) -> "Hello World!");
    }
}

다음에서 확인: http://localhost:4567/hello

소스 코드의 예제를 확인하고 시도해보세요. 또한 javadoc을 확인할 수 있습니다. github에서 소스를 받은 후 다음을 실행하세요:

mvn javadoc:javadoc

결과는 /target/site/apidocs에 저장됩니다.

예제

기본 기능을 보여주는 간단한 예제

import static spark.Spark.*;

/**
 * A simple example just showing some basic functionality
 */
public class SimpleExample {

    public static void main(String[] args) {

        //  port(5678); <- Uncomment this if you want spark to listen to port 5678 instead of the default 4567

        get("/hello", (request, response) -> "Hello World!");

        post("/hello", (request, response) ->
            "Hello World: " + request.body()
        );

        get("/private", (request, response) -> {
            response.status(401);
            return "Go Away!!!";
        });

        get("/users/:name", (request, response) -> "Selected user: " + request.params(":name"));

        get("/news/:section", (request, response) -> {
            response.type("text/xml");
            return "<?xml version=\"1.0\" encoding=\"UTF-8\"?><news>" + request.params("section") + "</news>";
        });

        get("/protected", (request, response) -> {
            halt(403, "I don't think so!!!");
            return null;
        });

        get("/redirect", (request, response) -> {
            response.redirect("/news/world");
            return null;
        });

        get("/", (request, response) -> "root");
    }
}


책 리소스를 생성, 조회, 업데이트, 삭제하는 방법을 보여주는 간단한 CRUD 예제

import static spark.Spark.*;

import java.util.HashMap;
import java.util.Map;
import java.util.Random;

/**
 * A simple CRUD example showing how to create, get, update and delete book resources.
 */
public class Books {

    /**
     * Map holding the books
     */
    private static Map<String, Book> books = new HashMap<String, Book>();

    public static void main(String[] args) {
        final Random random = new Random();

        // Creates a new book resource, will return the ID to the created resource
        // author and title are sent in the post body as x-www-urlencoded values e.g. author=Foo&title=Bar
        // you get them by using request.queryParams("valuename")
        post("/books", (request, response) -> {
            String author = request.queryParams("author");
            String title = request.queryParams("title");
            Book book = new Book(author, title);

            int id = random.nextInt(Integer.MAX_VALUE);
            books.put(String.valueOf(id), book);

            response.status(201); // 201 Created
            return id;
        });

        // Gets the book resource for the provided id
        get("/books/:id", (request, response) -> {
            Book book = books.get(request.params(":id"));
            if (book != null) {
                return "Title: " + book.getTitle() + ", Author: " + book.getAuthor();
            } else {
                response.status(404); // 404 Not found
                return "Book not found";
            }
        });

        // Updates the book resource for the provided id with new information
        // author and title are sent in the request body as x-www-urlencoded values e.g. author=Foo&title=Bar
        // you get them by using request.queryParams("valuename")
        put("/books/:id", (request, response) -> {
            String id = request.params(":id");
            Book book = books.get(id);
            if (book != null) {
                String newAuthor = request.queryParams("author");
                String newTitle = request.queryParams("title");
                if (newAuthor != null) {
                    book.setAuthor(newAuthor);
                }
                if (newTitle != null) {
                    book.setTitle(newTitle);
                }
                return "Book with id '" + id + "' updated";
            } else {
                response.status(404); // 404 Not found
                return "Book not found";
            }
        });

        // Deletes the book resource for the provided id
        delete("/books/:id", (request, response) -> {
            String id = request.params(":id");
            Book book = books.remove(id);
            if (book != null) {
                return "Book with id '" + id + "' deleted";
            } else {
                response.status(404); // 404 Not found
                return "Book not found";
            }
        });

        // Gets all available book resources (ids)
        get("/books", (request, response) -> {
            String ids = "";
            for (String id : books.keySet()) {
                ids += id + " ";
            }
            return ids;
        });
    }

    public static class Book {

        public String author, title;

        public Book(String author, String title) {
            this.author = author;
            this.title = title;
        }

        public String getAuthor() {
            return author;
        }

        public void setAuthor(String author) {
            this.author = author;
        }

        public String getTitle() {
            return title;
        }

        public void setTitle(String title) {
            this.title = title;
        }
    }
}

모든 다른 리소스보다 먼저 실행되는 매우 간단한 (그리고 바보 같은) 인증 필터를 보여주는 예제

리소스를 요청할 때, 예를 들어 http://localhost:4567/hello?user=some&password=guy 필터가 실행을 중단하고 클라이언트는 'You are not welcome here' 내용과 함께 401 UNAUTHORIZED를 받게 됩니다.

리소스를 요청할 때, 예를 들어 http://localhost:4567/hello?user=foo&password=bar 필터가 요청을 수락하고 요청은 /hello 라우트로 계속 진행됩니다.

참고: 두 번째 "before filter"가 있으며 응답에 헤더를 추가합니다. 참고: 응답에 헤더를 추가하는 "after filter"도 있습니다.

import static spark.Spark.*;

import java.util.HashMap;
import java.util.Map;

/**
 * Example showing a very simple (and stupid) authentication filter that is
 * executed before all other resources.
 *
 * When requesting the resource with e.g.
 *     http://localhost:4567/hello?user=some&password=guy
 * the filter will stop the execution and the client will get a 401 UNAUTHORIZED with the content 'You are not welcome here'
 *
 * When requesting the resource with e.g.
 *     http://localhost:4567/hello?user=foo&password=bar
 * the filter will accept the request and the request will continue to the /hello route.
 *
 * Note: There is a second "before filter" that adds a header to the response
 * Note: There is also an "after filter" that adds a header to the response
 */
public class FilterExample {

    private static Map<String, String> usernamePasswords = new HashMap<String, String>();

    public static void main(String[] args) {

        usernamePasswords.put("foo", "bar");
        usernamePasswords.put("admin", "admin");
도구 다운로드