Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

太狠了,还做了持久化.. #9

Open
fa1c0n1 opened this issue Sep 5, 2023 · 3 comments
Open

太狠了,还做了持久化.. #9

fa1c0n1 opened this issue Sep 5, 2023 · 3 comments

Comments

@fa1c0n1
Copy link

fa1c0n1 commented Sep 5, 2023

太狠了,还做了持久化..重启Nacos后还是会自动加载内存马

@fa1c0n1
Copy link
Author

fa1c0n1 commented Sep 7, 2023

请问这里Nacos重启后内存马依旧存活的原理是啥,是不是对其它具有代码执行漏洞的springboot的应用同样适用?还是说Nacos JRaft这个比较特殊所以可以实现.

@c0olw
Copy link
Owner

c0olw commented Sep 7, 2023

是这个漏洞比较特殊的原因

@fa1c0n1
Copy link
Author

fa1c0n1 commented Sep 7, 2023

确实很特殊,,跟它的jraft的机制有关,会把发过去的数据在 nacos目录nacos/data/protocol/raft/保存一份,比如这里用到的groupo是naming_service_metadata,就会在 nacos\data\protocol\raft\naming_service_metadata\log目录下的某个 .log 文件保存一份序列化数据. 重启后,会从 .log文件读出来然后又再次读出来并反序列化...

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants