frohoff / ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
http://frohoff.github.io/appseccali-marshalling-pickles/
MIT License
7.77k stars 1.76k forks source link

getting error while executing the command #214

Closed cotone1807 closed 9 months ago

cotone1807 commented 9 months ago

java -jar ysoserial-0.0.4.jar Spring1 'command' Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true Error while generating or serializing payload java.lang.IllegalAccessError: class ysoserial.payloads.util.Gadgets (in unnamed module @0x5a9ae579) cannot access class com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl (in module java.xml) because module java.xml does not export com.sun.org.apache.xalan.internal.xsltc.trax to unnamed module @0x5a9ae579 at ysoserial.payloads.util.Gadgets.createTemplatesImpl(Gadgets.java:102) at ysoserial.payloads.Spring1.getObject(Spring1.java:57) at ysoserial.GeneratePayload.main(GeneratePayload.java:34)

frohoff commented 9 months ago

Duplicate of #176. See the thread there about --add-opens.