Xuing

Results 6 issues of Xuing

FileHook拦截了java.io.File中的list函数用于检测File.listFiles方法导致的目录遍历攻击。 ![image](https://user-images.githubusercontent.com/11143269/117414753-16ce6d80-af4a-11eb-8372-7c81956f08ec.png) 但**至少**在windows的jdk11当中,listFiles是直接调用的normalizedList方法。对`normalizedList`方法的hook缺失,导致了无法正常拦截。 如图为linux jdk11的listFiles实现。是调用的list方法。 ![image](https://user-images.githubusercontent.com/11143269/117414606-eab2ec80-af49-11eb-9993-552e75d0e716.png) 下图为windows下jdk11的listFiles实现。是调用的normalizedList方法。 ![image](https://user-images.githubusercontent.com/11143269/117414688-05856100-af4a-11eb-8570-146d36bd71ed.png)

jdk16 XSS 漏洞无法检测。 触发点在,dispatchCheckEvent方法中,CheckParameter的toString方法。 原因应该是params中的buffer(类型nio.HeapByteBuffer),引起的InaccessibleObjectException异常

The reason is that the /proof page does not check the wallet connection status.

![image](https://user-images.githubusercontent.com/11143269/46054638-c5975400-c17a-11e8-9bc5-ba4421acf0cb.png) Is this a compatibility issue? maybe need sdk7.0 to compile? Thanks

Adjusted the function signature to strictly match runtime behavior, allowing the return type to be either a 2-tuple or a 3-tuple, stopping the IDE from complaining when only two values...