该项目使用 Python 内置的 http.server 模块模拟防火墙,检测并阻止利用 Spring4Shell (CVE-2022-22965) 漏洞的恶意请求。
Spring4Shell 是一个影响 Spring Core 框架的严重远程代码执行 (RCE) 漏洞。攻击者使用恶意有效载荷在服务器上部署 Web Shell。本仓库演示如何使用轻量级的自定义 Python HTTP 防火墙来阻止这些攻击。
/tomcatwar.jspclass.module.classLoader.resources.context.parent.pipeline%7Bc1%7D、%7Bc2%7D403 Forbidden