Skip to content

[Java] Find lookup interface #769

Answered by MathiasVP
zxcv0221 asked this question in Q&A
Discussion options

You must be logged in to vote

Thanks for all the details 🙂. So it looks like the lookup method on javax.naming.Context isn't included the database. That's why JNDIMethod doesn't have any results when you quick-eval it's "characteristic predicate" (i.e., the thing in the JNDIMethod class that looks like a constructor). So call.getMethod() instanceof JNDIMethod will never be satisfied. Can you point me to the line in https://github.com/l4yn3/micro_service_seclab that you tried to capture with your definition of isSink (i.e., the call to lookup on an object of type javax.naming.Context)?

Replies: 1 comment 8 replies

Comment options

You must be logged in to vote
8 replies
@zxcv0221
Comment options

@MathiasVP
Comment options

@zxcv0221
Comment options

@MathiasVP
Comment options

Answer selected by zxcv0221
@zxcv0221
Comment options

@MathiasVP
Comment options

@zxcv0221
Comment options

@MathiasVP
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants