Method, apparatus, system, device, and medium for injecting in-memory webshell into jdk

The method enables in-memory webshell injection into JDK 17 and above by using Java APIs to locate and inject webshells into memory, addressing the challenge of strong module encapsulation and improving server control efficiency.

WO2026044722A1PCT designated stage Publication Date: 2026-03-05SIEMENS AG +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

In-memory webshell injection is difficult in high versions of JDK runtime environments such as JDK 17 and above due to strong module encapsulation, which prevents the use of traditional class loading APIs, and determining the package of the vulnerable class is challenging in black-box scenarios.

Method used

A method is proposed to generate a request with an injection script and webshell payload, executed in the JDK environment to locate an object managing web component lifecycles and inject the webshell into memory, utilizing Java APIs like MethodHandles.defineClass for JDK 17 and above.

Benefits of technology

This method allows convenient injection of webshells into JDK 17 and above environments, enhancing control efficiency over target servers by exploiting vulnerabilities in web applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024116040_05032026_PF_FP_ABST
    Figure CN2024116040_05032026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a method, apparatus, system, device, and medium for injecting in-memory webshell into JDK. The method comprises: generating a first request, wherein payload of the first request comprises an injection script and a webshell; sending the first request to a web application via an interface provided by the web application; wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory. Conveniently injecting a webshell into the memory of JDK runtime environment improves control efficiency for target server, especially suitable for JDK17 and above operating environments.
Need to check novelty before this filing date? Find Prior Art

Description

Method, apparatus, system, device, and medium for injecting in-memory webshell into JDKFIELD

[0001] The present disclosure relates to the technical field of network security, in particular to a method, apparatus, system, device, and medium for injecting in-memory webshell into JDK.BACKGROUND

[0002] In-memory webshell is a commonly used technique for file-free attacks. With the increasing popularity of attack and defense exercises, professional security devices such as traffic analysis and EDR are widely used in the game between the two sides. Traditional webshell files are becoming easier to detect, while the use of in-memory webshell is becoming common.

[0003] At present, it is difficult to inject in-memory webshell in high versions of JDK runtime environments (such as JDK 17 or higher) .SUMMARY

[0004] Embodiments of the present disclosure propose a method, apparatus, system, device, and medium for injecting in-memory webshell into JDK.

[0005] In a first aspect, a method for injecting in-memory webshell into JDK is provided. The method includes:

[0006] generating a first request, wherein payload of the first request comprises an injection script and a webshell;

[0007] sending the first request to a web application via an interface provided by the web application;

[0008] wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0009] In a second aspect, an apparatus for injecting in-memory webshell into JDK is provided. The apparatus includes:

[0010] a generating module, configured to generate a first request, wherein payload of the first request comprises an injection script and a webshell; and

[0011] a sending module, configured to send the first request to a web application via an interface provided by the web application;

[0012] wherein the injection script is executed in a JDK running environment of the web application to locate an  object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0013] In a third aspect, a system for injecting in-memory webshell into JDK is provided. The system comprises a client and a server containing a web application; wherein the client is configured to generate a first request, payload of the first request comprises an injection script and a webshell; send the first request to a web application via an interface provided by the web application; the server is configured to execute the injection script in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0014] In a fourth aspect, an electronic device is provided. The electronic device comprising a processor and a memory, wherein an application program executable by the processor is stored in the memory for causing the processor to execute a method for injecting in-memory webshell into JDK as described in any of the above.

[0015] In a fifth aspect, a computer-readable medium comprising computer-readable instructions stored thereon is provided, wherein the computer-readable instructions for executing a method for injecting in-memory webshell into JDK as described in any of the above.

[0016] In a sixth aspect, a computer program product comprising a computer program, when the computer program is executed by a processor for executing a method for injecting in-memory webshell into JDK as described in any of the above.

[0017] According to the above technical solutions, generating a first request, wherein payload of the first request comprises an injection script and a webshell; sending the first request to a web application via an interface provided by the web application; wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory. Therefore, conveniently injecting a webshell into the memory of JDK runtime environment improves control efficiency for target server.BRIEF DESCRIPTION OF THE DRAWINGS

[0018] To make technical solutions of examples of the present disclosure clearer, accompanying drawings to be used in description of the examples will be simply introduced hereinafter. Obviously, the accompanying drawings to be described hereinafter are only some examples of the present disclosure. Those skilled in the art may obtain other drawings according to these accompanying drawings without creative labor.

[0019] Fig. 1 is an exemplary flowchart of a method for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure.

[0020] Fig. 2 is an exemplary structural diagram of the first request according to an embodiment of the present disclosure.

[0021] Fig. 3 is an exemplary flowchart of a method for implementing remote control according to an embodiment of the present disclosure.

[0022] Fig. 4 is an exemplary structural diagram of a system for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure.

[0023] Fig. 5 is an exemplary structural diagram of an apparatus for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure.

[0024] Fig. 6 is an exemplary structural diagram of an electronic device according to an embodiment of the present disclosure.

[0025] List of reference numbers: DETAILED DESCRIPTION

[0026] To make the purpose, technical scheme, and advantages of the disclosure clearer, the following examples are given to further explain the disclosure in detail. Nouns and pronouns related to people in this patent application are not limited to specific gender.

[0027] To be concise and intuitive in description, the scheme of the disclosure is described below by describing several representative embodiments. Many details in the embodiments are only used to help understand the scheme of the disclosure. However, it is obvious that the technical scheme of the disclosure can be realized without being limited to these details. To avoid unnecessarily blurring the scheme of the disclosure, some embodiments are not described in detail, but only the framework is given. Hereinafter, "including" refers to "including but not limited to" , "according to... " refers to "at least according to..., but not limited to... " . When the number of an element is not specifically indicated below, it means that the element can be one or more, or can be understood as at least one.

[0028] Firstly, provide an exemplary description of the relevant terms and background technology of embodiments of the present disclosure.

[0029] JDK (Java Development Kit) is a toolkit for Java program development, which includes all the basic components and tools required for Java application development. JDK is the core of Java program development, providing tools such as Java compiler (JavaC) , document generator (Javadoc) , debugger (JDB) , as well as all the libraries and tools required for Java runtime environment (JRE) . Through JDK, developers can write, compile, debug, and run Java programs. JDK not only includes the Java Runtime Environment (JRE) , but also provides various tools for developing Java applications, making it an essential toolkit for Java developers.

[0030] For example, the main components of JDK include: (1) Compiler (JavaC) : used to compile Java source code into bytecode. (2) Document Generator (Javadoc) : Extract documentation from source code comments and generate API documentation. (3) Debugger (jdb) : used to debug Java programs and identify errors in the program. (4) Runtime Java Library (JRE) : It includes the Java Virtual Machine (JVM) and Java Core Library, allowing compiled Java bytecode to run on any platform that supports Java. By installing and configuring JDK, developers can fully utilize the tools provided by JDK for Java program development and debugging, ensuring the correctness and performance of the program.

[0031] The Java Runtime Environment (JRE) is the basic software environment required to run Java programs. It mainly includes Java Virtual Machine (JVM) and Java Class Library. JRE provides the necessary capabilities for running Java programs, including the ability to interpret and execute Java bytecode, as well as offering many commonly used features and tools such as input / output, network communication, database connections, etc. The Java Virtual Machine (JVM) is the execution engine for Java applications, responsible for interpreting and executing Java bytecode. JVM is cross platform because it can convert bytecode into machine code specific to a particular operating system, allowing Java programs to run on different operating systems. A Java class library is a collection of pre written Java classes and methods, provided through the Java Standard Library. These libraries  contain various functions and tools required to run Java programs, such as file manipulation, network communication, etc. For end users of Java applications, they only need to install JRE to run Java applications, without the need to install the complete JDK, which includes all the tools needed for Java program development and debugging. JRE is the runtime environment required by Java developers to write and test Java applications, and is also a necessary condition for users to run Java programs.

[0032] Webshell is a code execution environment that exists in the form of web files such as ASP, PHP, JSP, or CGI. It is mainly used for website management, server management, permission management, and other operations, making it convenient for users to manage websites and servers. As a result, some people modify the code and use it as a backdoor program to control website servers. As the name suggests, "web" means that the server needs to open up web services; The meaning of 'shell' is to obtain some degree of operational command on the server. On the one hand, Webshell is used by webmasters for website management, server management, and more. Depending on the FSO permissions, it includes online editing of web scripts, uploading and downloading files, viewing databases, executing arbitrary program commands, and more. On the other hand, webshells are exploited by intruders to control website servers. These web scripts are often referred to as web script Trojans, including popular ASP or PHP Trojans NET script Trojan and JSP script Trojan.

[0033] Traditional file based webshells, such as JSP, are easy to detect and eliminate, while in-memory webshells do not involve file writing, making them relatively difficult to detect. At present, there are situations where JSP files cannot be uploaded or uploaded files cannot be parsed. Moreover, in JDK 17 and above versions, due to the strong encapsulation of modules, it is not possible to call key APIs for memory webshell injection (such as java. lang. ClassLoader#definaClass) , making in-memory webshell injection difficult.

[0034] Considering that the existing and widely used in-memory webshell injection techniques were mainly designed for versions prior to JDK17. In environments using JDK17 and higher versions, the powerful encapsulation function of modules has been introduced, but there is a lack of effective injection solutions. The critical technology for in-memory webshell injection involves using java. lang. ClassLoader#defineClass or sun. misc. Unsafe#defineClass / defineAnonymousClass API to load malicious classes. The introduction of strong module encapsulation in JDK 17 and beyond disables this capability.

[0035] To implement the class loading functionality, the java. lang. invoke. MethodHandles. lookup () . defineClass introduced in JDK 9 and above is used to load malicious classes. However, this interface has a usage restriction: the package of the class calling this interface must be the same as the package of the malicious class being loaded. In various vulnerability scenarios, the specific package of the class where the vulnerability that allows code execution resides can differ, such as with expression injections (EL / JUEL / SpEL) , code injections, template  injections, deserialization, JNDI injections, etc. In most penetration testing scenarios, which are predominantly black-box, it is not possible to know the exact package of the class that triggers the vulnerability. This presents a challenge for the loading of malicious classes during in-memory webshell injections.

[0036] In JDK 17 and above versions, due to the presence of strong module encapsulation, there is no universal method (across various code execution scenarios) for loading malicious classes. This invention provides such a method. Since the malicious class is passed from the client in base64 form, there is no need to connect to other networks / hosts to retrieve the malicious class. The exploitation process only requires the communication channel between the client and the server.

[0037] Embodiments of the present disclosure propose a method for injecting a webshell into a memory in the JDK runtime environment, which can be applied to JDK 17 and above versions. Embodiments of the present disclosure solve the problem of determining the package by normalizing various types of attacks that allow code execution into a certain attack type.

[0038] Fig. 1 is an exemplary flowchart of a method for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure. As shown in Figure 1, the method includes:

[0039] Step 101: generating a first request, wherein payload of the first request comprises an injection script and a webshell.

[0040] Fig. 2 is an exemplary structural diagram of the first request according to an embodiment of the present disclosure. As can be seen, the first request 20 includes a request header 21, an injection script 22 and a webshell23, where the injection script 22 and webshell23 are included in the payload of the first request 20. The payload may further contain other contents, and embodiments of the present disclosure are not limited to this.

[0041] Specifically, the first request 20 can be implemented as any of the following requests:

[0042] (1) Input URL request: The user enters the URL in the browser and then presses Enter.

[0043] (2) DNS resolution request: The browser sends the domain name in the URL to the DNS server for resolution, obtaining the corresponding IP address.

[0044] (3) Establish TCP connection request: The browser establishes a TCP connection with the server, which typically involves a process called a three-way handshake.

[0045] (4) Sending HTTP request: The browser sends an HTTP request to the server through a TCP connection. Requests typically include the request method (such as GET or POST) , the resource path of the request, the HTTP version, the request header (such as User Agent, Accept, etc. ) , and possible request bodies.

[0046] The above exemplary description provides typical examples of the first request 20. Those skilled in the art  will appreciate that this description is only exemplary and not intended to limit the scope of protection of embodiments of the present disclosure.

[0047] Step 102: sending the first request to a web application via an interface provided by the web application. The injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0048] For example, injection script contains codes for implementing the following functions: (1) locating an object that governs lifecycles of all web components in the memory of web application; (2) Call a method of the object to inject the webshell into the memory of the web application.

[0049] Under normal circumstances, web applications should not have the ability to execute code. That is to say, under normal circumstances, web applications should not execute the injection script to perform the above functions. However, when a web application has a vulnerability, that is, when it has code execution capability, it can be injected into a script to exploit the vulnerability and perform the above functions. In embodiments of the present invention, memory injection is implemented for web applications that have code execution capabilities (i.e. vulnerabilities) .

[0050] In one embodiment, the web application has at least one of the following vulnerabilities: deserialization vulnerability; code execution vulnerability; expression injection vulnerability; template injection vulnerability.

[0051] The following is an exemplary example of the first request 30.

[0052] POST  / el HTTP / 1.1

[0053] Connection: close

[0054] Content-Type: application / x-www-form-urlencoded

[0055] expression=” . getClass () . forName ( 'java. lang. invoke. MethodHandles' ) . getMethod ( 'lookup' ) . invoke (null ) . defineClass (” . getClass () . forName ( 'java. util. Base64' ) . getMethod ( 'getDecoder' ) . invoke (null) . decode ( 'yv66. .. < base64 form of webshell content >' ) ) . newInstance () .

[0056] Therefore, EL expressions can be used to inject into the webshell. In the first request 30, use java. lang. voice MethodHandles. lookup () . fineClass (java. til. Base64. getDecor () . decode to implement injection script. The part after "yv66" is webshell. webshells typically exist in encoded form and are decoded into Java bytecode. The essence is to exploit EL expression vulnerabilities to execute on the target web server: java. lang. voice MethodHandles. lookup () . fineClass (java. til. Base64. getDecoder () . decode ( 'yv66... <base64 form of webshell content>' ) . newInstance () .

[0057] In one embodiment, the web application is Spring web application or Tomcat web application. In one  embodiment, the object that is in charge of respective life cycles of web components of the web application is StandardContext. StandardContext is responsible for managing the deployment and operation of web applications. StandardContext is a part of the Catalina container used to handle requests from web applications. For example, in Tomcat, a web application typically has multiple servlet instances, each corresponding to a Wrapper container instance. StandardContext, as a Context instance, manages these Wrapper instances, which are the "sub containers" of the Context. When the Context receives a servlet request, it needs to map the request to which Wrapper to specifically handle it. StandardContext implements this mapping logic by maintaining two sets of maps, servant mappings and children, making it easy to find the corresponding wrapper instance based on the requested URL. The StandardContextMapper in StandardContext is the standard implementation of a mapper, through which the corresponding Wrapper instance can be found based on the request and processed accordingly.

[0058] In one embodiment, the method of StandardContext is addApplicationEventListener. AddAppliceEventListener is a mechanism used to add event listeners to Spring Framework applications. It allows developers to define listeners to respond to specific events in the application, such as application startup, service startup, etc. These events can be custom or standard events provided by the Spring framework. By adding listeners, developers can perform specific logic or operations in response to these events.

[0059] (1) Spring is an open-source Java platform that provides a comprehensive programming and configuration model for developing enterprise level applications. The Spring framework aims to solve the problems encountered by developers in J2EE development. It provides powerful features such as Dependency Injection (IOC) , Aspect Oriented Programming (AOP) , and Web MVC. Spring can not only be used alone to build applications, but also combined with web frameworks such as Struts, Webwork, Tapestry, and even with desktop application frameworks such as Swing. Therefore, Spring is not limited to J2EE applications, but can also be applied to desktop applications and small applications.

[0060] (2) Tomcat is an open-source web server that implements the Java Servlet and JavaServer Pages (JSP) technical specifications. Tomcat provides a container environment for running Servlet and JSP, which listens on specific ports (such as port 8080) , receives HTTP requests from clients, and decides to call the corresponding Servlet based on the requested information to process the request, and then returns the result to the client. Tomcat supports the latest Servlet and JSP specifications and is the preferred runtime environment for many Java web applications.

[0061] In short, Spring is a lightweight Java development framework that provides a comprehensive programming model and configuration options, while Tomcat is a web server and Servlet container used to run Java based web applications. These two are usually used together, with Spring used for developing complex business logic and  Tomcat providing support for runtime environments and service endpoints.

[0062] The purpose of locating the object in charge of lifecycles of web components here is essentially that the truly persistent memory Trojan is the web component that exposes its interface to the user (attacker) . To find the object in charge of lifecycles of web components, it is necessary to have a deep understanding of the layout of the target application service in memory. Due to the fact that both Spring web applications and Tomcat web applications are open source, it is possible to precisely locate the object that govern the lifecycles of web components by repeatedly debugging the code. Moreover, after locating the object that governs the lifecycles of the web components, a method provided by that object (functions in Java) can be called to add the webshell as a web component to the web component list of the object. At this point, the injection of memory webshell is completed. Afterwards, when it is desired to control the target server of the application program, the client can initiate a request to the target server to provide the operation command to be executed. The target server executes the operation command and then returns the command execution result to the client. At this point, the function of the in-memory webshell is completed. In one implementation, the JDK runtime environment is either JDK17 version or higher than JDK17 version.

[0063] In one embodiment, the method comprises: comprising: generating a second request, wherein payload of the second request comprises an operation command; sending the second request to the web application via the interface, wherein the webshell in the memory executes the operation command; receiving a response message of the operation command. Among them, the operation commands can be implemented as browsing files, deleting files, writing files, creating new directories, deleting directories, copying files, changing file properties, moving files or renaming files, and so on.

[0064] The above exemplary descriptions illustrate typical examples of operation commands, and those skilled in the art will appreciate that such descriptions are only exemplary and not intended to limit the scope of protection of the embodiments of the present invention.

[0065] Fig. 4 is an exemplary structural diagram of a system for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure. As shown in Figure 4, the method comprises:

[0066] Step 201: generating a first request. Payload of the first request comprises an injection script and a webshell.

[0067] Step 202: sending the first request to a web application via an interface provided by the web application. The injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0068] Step 203: generating a second request. Payload of the second request comprises an operation command.

[0069] Step 204: sending the second request to the web application via the interface, the webshell in the memory executes the operation command.

[0070] Step 205: receiving a response message of the operation command.

[0071] Fig. 5 is an exemplary structural diagram of an apparatus for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure. The system comprises a client 300 and a server 400 containing a web application. The client 300 is configured to generate a first request, payload of the first request comprises an injection script and a webshell; send the first request to a web application via an interface provided by the web application. The server 400 is configured to execute the injection script in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0072] In one embodiment, the client 300 is configured to generate a second request, payload of the second request comprises an operation command; send the second request to the web application via the interface. The server400 is configured to enable the webshell in the memory to execute the operation command and generate a response message of the operation command. The client 300 is further configured to receive the response message.

[0073] In summary, embodiments of the present disclosure comprise: generating a first request, wherein payload of the first request comprises an injection script and a webshell; sending the first request to a web application via an interface provided by the web application; wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory. Conveniently injecting a webshell into the memory of JDK runtime environment improves control efficiency for target server, especially suitable for in JDK17 and above operating environments.

[0074] Fig. 5 is an exemplary structural diagram of an apparatus for injecting webshell into JDK runtime environment according to an embodiment of the present disclosure. The apparatus 600 comprising: a generating module 601, configured to generate a first request, wherein payload of the first request comprises an injection script and a webshell; and a sending module 602, configured to send the first request to a web application via an interface provided by the web application. The injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.

[0075] In one embodiment, the generating module 601 is configured to generate a second request, wherein payload of the second request comprises an operation command; the sending module 602 is configured to send the second  request to the web application via the interface. The webshell in the memory executes the operation command; the apparatus comprises: a receiving module 603, configured to receive a response message of the operation command.

[0076] Embodiments of the present disclosure also propose an electronic device with a processor memory architecture. Fig. 6 is an exemplary structural diagram of an electronic device according to an embodiment of the present disclosure. As shown in Figure 6, electronic device 700 includes a processor 701, a memory 702, and a computer program stored on memory 702 that can run on processor 701. When the computer program is executed by processor 701, the method for injecting in-memory webshell into JDK as described in either of the above is implemented. Among them, memory 702 can be implemented as various storage media such as electrically erasable programmable read-only memory (EEPROM) , flash memory, programmable program read-only memory (PROM) , etc. Processor 701 can be implemented to include one or more central processors or one or more field programmable gate arrays, wherein the field programmable gate array integrates one or more central processor cores. Specifically, the central processing unit or core can be implemented as a CPU, MCU, DSP, and so on.

[0077] It should be noted that not all steps and modules in the above processes and structural diagrams are necessary, and some steps or modules can be ignored according to actual needs. The execution sequence of each step is not fixed and can be adjusted as needed. The division of each module is only for the convenience of describing the functional division used. In actual implementation, a module can be divided into multiple modules, and the functions of multiple modules can also be implemented by the same module. These modules can be in the same device or different devices.

[0078] The hardware modules in each implementation can be implemented mechanically or electronically. For example, a hardware module can include specially designed permanent circuits or logic devices (such as dedicated processors, such as FPGA or ASIC) to complete specific operations. Hardware modules can also include programmable logic devices or circuits temporarily configured by software (such as general-purpose processors or other programmable processors) for performing specific operations. As for the specific use of mechanical methods, either dedicated permanent circuits or temporarily configured circuits (such as software configuration) to implement hardware modules, it can be determined based on cost and time considerations.

[0079] The above is only a preferred embodiment of the present disclosure and is not intended to limit the scope of protection of the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1.A method for injecting in-memory webshell into JDK, comprising:generating (101) a first request, wherein payload of the first request comprises an injection script and a webshell;sending (102) the first request to a web application via an interface provided by the web application;wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.2.The method according to claim 1, wherein the object is StandardContext.3.The method according to claim 2, wherein the method of StandardContext is addApplicationEventListener.4.The method according to claim 1, comprising:generating a second request, wherein payload of the second request comprises an operation command;sending the second request to the web application via the interface, wherein the webshell in the memory executes the operation command;receiving a response message of the operation command.5.The method according to any one of claims 1-4, wherein the web application has at least one of the following vulnerabilities:deserialization vulnerability;code execution vulnerability;expression injection vulnerability;template injection vulnerability.6.The method according to any one of claims 1-4, wherein the web application is Spring web application or Tomcat web application.7.The method according to any one of claims 1-4, wherein the JDK running environment is running environment of JDK 17 or versions higher than JDK 17.8.An apparatus for injecting in-memory webshell into JDK, comprising:a generating module (601) , configured to generate a first request, wherein payload of the first request comprises an injection script and a webshell; anda sending module (602) , configured to send the first request to a web application via an interface provided by the web application;wherein the injection script is executed in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.9.The apparatus according to claim 8, wherein the generating module (601) is configured to generate a second request, wherein payload of the second request comprises an operation command; the sending module (602) is configured to send the second request to the web application via the interface, wherein the webshell in the memory executes the operation command; the apparatus comprises:a receiving module (603) , configured to receive a response message of the operation command.10.A system for injecting in-memory webshell into JDK, comprises a client (300) and a server (400) containing a web application;wherein the client (300) is configured to generate a first request, payload of the first request comprises an injection script and a webshell; send the first request to a web application via an interface provided by the web application; the server (400) is configured to execute the injection script in a JDK running environment of the web application to locate an object that is in charge of respective life cycles of web components of the web application in a memory, and call a method of the object to inject the webshell into the memory.11.The system of claim 10, wherein the client (300) is configured to generate a second request, payload of the second request comprises an operation command; send the second request to the web application via the interface; the server (400) is configured to enable the webshell in the memory to execute the operation command and generate a response message of the operation command; the client (300) is further configured to receive the response message.12.An electronic device, comprising a processor (701) and a memory (702) , wherein an application program executable by the processor (701) is stored in the memory (702) for causing the processor (701) to execute a method for injecting in-memory webshell into JDK according to any one of claims 1-7.13.A computer-readable medium comprising computer-readable instructions stored thereon, wherein the computer-readable instructions for executing a method for injecting in-memory webshell into JDK according to any one of claims 1-7.14.A computer program product comprising a computer program, upon the computer program is executed by a processor for executing a method for injecting in-memory webshell into JDK according to any one of claims 1-7.

Citation Information

Patent Citations

  • Script injection attack detection method and system

    CN101459548A

  • Systems and methods for remote detection of software through browser webinjects

    US10521583B1

  • Detecting malicious code received from malicious client side injection vectors

    US20200358818A1