第 85 条:其他序列化优先于 Java 序列化
作者:
综合楼 | 来源:发表于
2022-06-27 13:13 被阅读0次
![](https://img.haomeiwen.com/i7484530/599ff9adb76ba852.jpeg)
其他序列化优先于 Java 序列化.jpeg
// Deserialization bomb - deserializing this stream takes forever
static byte[] bomb() {
Set<Object> root = new HashSet<>();
Set<Object> s1 = root;
Set<Object> s2 = new HashSet<>();
for (int i = 0; i < 100; i++) {
Set<Object> t1 = new HashSet<>();
Set<Object> t2 = new HashSet<>();
t1.add("foo"); // Make t1 unequal to t2
s1.add(t1); s1.add(t2);
s2.add(t1); s2.add(t2);
s1 = t1;
s2 = t2;
}
return serialize(root); // Method omitted for brevity
}
本文标题:第 85 条:其他序列化优先于 Java 序列化
本文链接:https://www.haomeiwen.com/subject/dclesltx.html
网友评论