Don’t hack the platform? β˜ οΈπŸ’£πŸ’₯

Jan Ouwens
2 July 2021

ΰ² _ΰ² 

About me πŸ€“

Jan Ouwens

jqno

EqualsVerifier


EqualsVerifier.forClass(Foo.class)
              .verify();

About this talk

Things you shouldn’t mess with:

  • Language β€˜features’
  • Reflection
  • Annotations
  • External libraries

Ratings

  • ☠️
  • β˜ οΈπŸ’£
  • β˜ οΈπŸ’£πŸ’₯

☠️ Language β€˜features’

True Lambda

Demo

True Lambda

Java 11!

In fact… Java 17!

Demo

Generics

Demo

Unicode symbols

  • Hard to type
  • Hard to read
  • Rating: ☠️

False is True

Demo

False is True

Scala demo

False is True

Kotlin demo

False is True

Rating: β˜ οΈπŸ’£

Unicode converter

Demo

Unicode escapes

  • Harder to type and read
  • Maven says Β―\_(ツ)_/Β―
  • Rating: β˜ οΈπŸ’£

Emoji

Demo

Emoji

Rating: πŸŽ‰

Hash-code

Demo

Hash-code

  • Fun when coworkers insist on hashCode as key
  • Rating: ☠️

Hash-code

However…

☠️ Reflection

Introducing: Reflector

Loopy

Demo

Oh man πŸ˜’

Exception in thread "main" java.lang.reflect.InaccessibleObjectException: Unable to make field private final int java.lang.Integer.value accessible: module java.base does not "opens java.lang" to unnamed module @2a0a80c0

--add-opens java.base/java.lang=ALL-UNNAMED --

Loopy

Demo

Loopy

Was this hack evil? βœ‹

Are Calendars and arrays evil? βœ‹

Are JPA entities evil? πŸ‘Ή

Loopy

Rating: β˜ οΈπŸ’£πŸ’₯

Interning

Demo

Interning

  • Fun way to mess up unit tests!
  • Rating: β˜ οΈπŸ’£

dirty_CLASS

Demo

You should probably

  • Call close() on URLClassLoader
  • Report compilation errors with CompilationTask
  • Handle exceptions


Β―\_(ツ)_/Β―

Multi-release JAR file

EqualsVerifier

@Test
public void equalsverifierSucceeds_whenOneOfTheFieldsIsSynthetic() {
    if (!isJava8Available()) {
        return;
    }

    Class<?> java8ClassWithSyntheticField = compile(JAVA_8_CLASS_WITH_SYNTHETIC_FIELD_NAME, JAVA_8_CLASS_WITH_SYNTHETIC_FIELD);
    EqualsVerifier.forClass(java8ClassWithSyntheticField)
            .verify();
}

private static final String JAVA_8_CLASS_WITH_SYNTHETIC_FIELD_NAME = "Java8ClassWithSyntheticField";
private static final String JAVA_8_CLASS_WITH_SYNTHETIC_FIELD =
        "\nimport java.util.Comparator;" +
        "\nimport java.util.Objects;" +
        "\n" +
        "\npublic final class Java8ClassWithSyntheticField {" +
        "\n    private static final Comparator<Java8ClassWithSyntheticField> COMPARATOR =" +
        "\n            (c1, c2) -> 0;   // A lambda is a synthetic class" +
        "\n" +
        "\n    private final String s;" +
        "\n    " +
        "\n    public Java8ClassWithSyntheticField(String s) {" +
        "\n        this.s = s;" +
        "\n    }" +
        "\n    " +
        "\n    @Override" +
        "\n    public boolean equals(Object obj) {" +
        "\n        if (!(obj instanceof Java8ClassWithSyntheticField)) {" +
        "\n            return false;" +
        "\n        }" +
        "\n        return Objects.equals(s, ((Java8ClassWithSyntheticField)obj).s);" +
        "\n    }" +
        "\n    " +
        "\n    @Override" +
        "\n    public int hashCode() {" +
        "\n        return Objects.hash(s);" +
        "\n    }" +
        "\n}";

JavaCompiler

Rating: β˜ οΈπŸ’£πŸ’₯

☠️ Annotations

Lombok 🌢

use annotations

to trick the Java compiler

into generating bytecode

that does something else

Spring & Hibernate

use annotations

to trick the Java runtime

into generating bytecode

that does something else






Boring

☠️ External libraries

Objenesis

Constructors are tedious

Demo

Constructors are tedious

Rating: ☠️

Singletons

β€œ[An enum] provides an ironclad guarantee against multiple instantiation, even in the face of sophisticated serialization or reflection attacks. […] A single-element enum type is often the best way to implement a singleton.”

– Joshua Bloch, Effective Java 2nd Edition

Singletons

β€œ[An enum] provides an ironclad guarantee against multiple instantiation, even in the face of sophisticated serialization or reflection attacks. […] A single-element enum type is often the best way to implement a singleton.”

– Joshua Bloch, Effective Java 3rd Edition

πŸ˜‡

Singletons

Demo

Singletons

Rating: β˜ οΈπŸ’£

Confusing card game

Confusing card game

Demo

Confusing card game

Rating:

Java 11: β˜ οΈπŸ’£πŸ’₯
Java 12+: πŸ₯³

Confusing card game

External libraries

ByteBuddy

&

ByteBuddy Agent

Disclaimer

Use cases for agents

  • there are many
  • they’re legitimate

Confusing card game - revisited

Demo

Confusing card game - revisited

Rating: β˜ οΈπŸ’£πŸ’₯

Time Traveling πŸ•™πŸ•š

Demo





Idea shamelessly stolen from
/TOPdesk/time-transformer-agent

Time Traveling πŸ•™πŸ•š

  • Unit testing legacy code
  • Messing up any code
  • Rating: β˜ οΈπŸ’£πŸ’₯

But wait

There’s more

Victim / Attack

Demo



mvn clean package

runjava -r src/main/java/demos/libraries/remote/Attack.java target/dont-hack-the-platform-0.1-SNAPSHOT.jar ???

Victim / Attack

Rating:

😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱😱

</>

Awareness

Emoji & unicode

  • Checkstyle
  • SonarQube

Security manager

Demo



System.setSecurityManager(new SecurityManager());

Security manager

Security manager

Java 17: Deprecated

FOR REMOVAL

Modularisation

WARNING: An illegal reflective access operation has occurred
WARNING: Illegal reflective access by demos.reflection.Reflector (file:/Users/jqno/w/personal/dont-hack-the-platform-talk/target/classes/) to field java.lang.String.value
WARNING: Please consider reporting this to the maintainers of demos.reflection.Reflector
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations
WARNING: All illegal access operations will be denied in a future release

--illegal-access=deny

Just be careful

Who has access to PROD?

Do try this at home!

Maybe not at work though?

Questions?



slides & code at
https://jqno.nl/talks/dont-hack-the-platform/

I’m at
jqno