svn commit: r1732876 - in /ofbiz/branches/release15.12/tools/security: check.bat notsoserial/deserialize-trace.txt notsoserial/is-deserialized.txt

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

svn commit: r1732876 - in /ofbiz/branches/release15.12/tools/security: check.bat notsoserial/deserialize-trace.txt notsoserial/is-deserialized.txt

jleroux@apache.org
Author: jleroux
Date: Mon Feb 29 12:02:13 2016
New Revision: 1732876

URL: http://svn.apache.org/viewvc?rev=1732876&view=rev
Log:
No functional change, somehow things were slightly different here than in trunk

Added:
    ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt   (with props)
    ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt   (with props)
Removed:
    ofbiz/branches/release15.12/tools/security/check.bat

Added: ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt
URL: http://svn.apache.org/viewvc/ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt?rev=1732876&view=auto
==============================================================================
--- ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt (added)
+++ ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt Mon Feb 29 12:02:13 2016
@@ -0,0 +1,290 @@
+Deserialization of class [Z (on Wed Feb 17 18:22:22 CET 2016)
+ at org.apache.derby.iapi.services.io.FormatIdInputStream.readObject
+ at org.apache.derby.iapi.services.io.ArrayUtil.readArrayItems
+ at org.apache.derby.impl.sql.GenericStorablePreparedStatement.readExternal
+ at org.apache.derby.iapi.services.io.FormatIdInputStream.readObject
+ at org.apache.derby.iapi.types.UserType.readExternal
+ at org.apache.derby.impl.store.raw.data.StoredPage.readRecordFromArray
+ at org.apache.derby.impl.store.raw.data.StoredPage.restoreRecordFromSlot
+ at org.apache.derby.impl.store.raw.data.BasePage.fetchFromSlot
+ at org.apache.derby.impl.store.raw.data.CachedPage.fetchFromSlot
+ at org.apache.derby.impl.store.access.conglomerate.GenericConglomerateController.fetch
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getDescriptorViaIndexMinion
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getDescriptorViaIndex
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getSPSDescriptorIndex1Scan
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getUncachedSPSDescriptor
+ at org.apache.derby.impl.sql.catalog.SPSNameCacheable.setIdentity
+ at org.apache.derby.impl.services.cache.ConcurrentCache.find
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getSPSDescriptor
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.prepareSPS
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQueryUsingSystemTables
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQuery
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQuery
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getTables
+ at org.apache.commons.dbcp2.DelegatingDatabaseMetaData.getTables
+ at org.apache.commons.dbcp2.DelegatingDatabaseMetaData.getTables
+ at org.ofbiz.entity.jdbc.DatabaseUtil.getTableNames
+ at org.ofbiz.entity.jdbc.DatabaseUtil.checkDb
+ at org.ofbiz.entity.jdbc.DatabaseUtil.checkDb
+ at org.ofbiz.entity.datasource.GenericDAO.checkDb
+ at org.ofbiz.entity.datasource.GenericHelperDAO.checkDataSource
+ at org.ofbiz.entity.GenericDelegator.initializeOneGenericHelper
+ at org.ofbiz.entity.GenericDelegator.access$000
+ at org.ofbiz.entity.GenericDelegator$1.call
+ at org.ofbiz.entity.GenericDelegator$1.call
+ at java.util.concurrent.FutureTask.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class [I (on Wed Feb 17 18:22:22 CET 2016)
+ at org.apache.derby.iapi.services.io.FormatIdInputStream.readObject
+ at org.apache.derby.iapi.sql.execute.ExecRowBuilder.readExternal
+ at org.apache.derby.iapi.services.io.FormatIdInputStream.readObject
+ at org.apache.derby.iapi.services.io.ArrayUtil.readArrayItems
+ at org.apache.derby.impl.sql.GenericStorablePreparedStatement.readExternal
+ at org.apache.derby.iapi.services.io.FormatIdInputStream.readObject
+ at org.apache.derby.iapi.types.UserType.readExternal
+ at org.apache.derby.impl.store.raw.data.StoredPage.readRecordFromArray
+ at org.apache.derby.impl.store.raw.data.StoredPage.restoreRecordFromSlot
+ at org.apache.derby.impl.store.raw.data.BasePage.fetchFromSlot
+ at org.apache.derby.impl.store.raw.data.CachedPage.fetchFromSlot
+ at org.apache.derby.impl.store.access.conglomerate.GenericConglomerateController.fetch
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getDescriptorViaIndexMinion
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getDescriptorViaIndex
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getSPSDescriptorIndex1Scan
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getUncachedSPSDescriptor
+ at org.apache.derby.impl.sql.catalog.SPSNameCacheable.setIdentity
+ at org.apache.derby.impl.services.cache.ConcurrentCache.find
+ at org.apache.derby.impl.sql.catalog.DataDictionaryImpl.getSPSDescriptor
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.prepareSPS
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQueryUsingSystemTables
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQuery
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getPreparedQuery
+ at org.apache.derby.impl.jdbc.EmbedDatabaseMetaData.getTables
+ at org.apache.commons.dbcp2.DelegatingDatabaseMetaData.getTables
+ at org.apache.commons.dbcp2.DelegatingDatabaseMetaData.getTables
+ at org.ofbiz.entity.jdbc.DatabaseUtil.getTableNames
+ at org.ofbiz.entity.jdbc.DatabaseUtil.checkDb
+ at org.ofbiz.entity.jdbc.DatabaseUtil.checkDb
+ at org.ofbiz.entity.datasource.GenericDAO.checkDb
+ at org.ofbiz.entity.datasource.GenericHelperDAO.checkDataSource
+ at org.ofbiz.entity.GenericDelegator.initializeOneGenericHelper
+ at org.ofbiz.entity.GenericDelegator.access$000
+ at org.ofbiz.entity.GenericDelegator$1.call
+ at org.ofbiz.entity.GenericDelegator$1.call
+ at java.util.concurrent.FutureTask.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class org.ofbiz.service.rmi.RemoteDispatcherImpl_Stub (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.registry.RegistryImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.server.RemoteStub (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.registry.RegistryImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.server.RemoteObject (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.registry.RegistryImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class org.ofbiz.service.rmi.socket.ssl.SSLClientSocketFactory (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.tcp.TCPEndpoint.read
+ at sun.rmi.transport.LiveRef.read
+ at sun.rmi.server.UnicastRef2.readExternal
+ at java.rmi.server.RemoteObject.readObject
+ at sun.reflect.NativeMethodAccessorImpl.invoke0
+ at sun.reflect.NativeMethodAccessorImpl.invoke
+ at sun.reflect.DelegatingMethodAccessorImpl.invoke
+ at java.lang.reflect.Method.invoke
+ at java.io.ObjectStreamClass.invokeReadObject
+ at java.io.ObjectInputStream.readSerialData
+ at java.io.ObjectInputStream.readOrdinaryObject
+ at java.io.ObjectInputStream.readObject0
+ at java.io.ObjectInputStream.readObject
+ at sun.rmi.registry.RegistryImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class [Ljava.rmi.server.ObjID; (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.server.ObjID (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.server.UID (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.dgc.Lease (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.dgc.VMID (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class [B (on Wed Feb 17 18:22:28 CET 2016)
+ at sun.rmi.transport.DGCImpl_Skel.dispatch
+ at sun.rmi.server.UnicastServerRef.oldDispatch
+ at sun.rmi.server.UnicastServerRef.dispatch
+ at sun.rmi.transport.Transport$1.run
+ at sun.rmi.transport.Transport$1.run
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.Transport.serviceCall
+ at sun.rmi.transport.tcp.TCPTransport.handleMessages
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0
+ at java.security.AccessController.doPrivileged
+ at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.rmi.NotBoundException (on Wed Feb 17 18:22:35 CET 2016)
+ at sun.rmi.transport.StreamRemoteCall.executeCall
+ at sun.rmi.server.UnicastRef.invoke
+ at sun.rmi.registry.RegistryImpl_Stub.lookup
+ at com.sun.jndi.rmi.registry.RegistryContext.lookup
+ at com.sun.jndi.rmi.registry.RegistryContext.lookup
+ at javax.naming.InitialContext.lookup
+ at org.apache.solr.core.SolrResourceLoader.locateSolrHome
+ at org.apache.solr.servlet.SolrDispatchFilter.init
+ at org.ofbiz.solr.webapp.OFBizSolrContextFilter.init
+ at org.apache.catalina.core.ApplicationFilterConfig.initFilter
+ at org.apache.catalina.core.ApplicationFilterConfig.getFilter
+ at org.apache.catalina.core.ApplicationFilterConfig.<init>
+ at org.apache.catalina.core.StandardContext.filterStart
+ at org.apache.catalina.core.StandardContext.startInternal
+ at org.apache.catalina.util.LifecycleBase.start
+ at org.apache.catalina.core.ContainerBase$StartChild.call
+ at org.apache.catalina.core.ContainerBase$StartChild.call
+ at java.util.concurrent.FutureTask.run
+ at java.util.concurrent.ThreadPoolExecutor.runWorker
+ at java.util.concurrent.ThreadPoolExecutor$Worker.run
+ at java.lang.Thread.run
+Deserialization of class java.lang.Exception (on Wed Feb 17 18:22:35 CET 2016)
+ at sun.rmi.transport.StreamRemoteCall.executeCall
+ at sun.rmi.server.UnicastRef.invoke
+ at sun.rmi.registry.RegistryImpl_Stub.lookup
+ at com.sun.jndi.rmi.registry.RegistryContext.lookup
+ at com.sun.jndi.rmi.registry.RegistryContext.lookup
+ at javax.naming.InitialContext.lookup
+ at org.apache.solr.core.SolrResourceLoader.locateSolrHome
+ at org.apache.solr.servlet.SolrDispatchFilter.init
+ at org.ofbiz.solr.webapp.OFBizSolrContextFilter.init
+ at org.apache.catalina.core.ApplicationFilterConfig.initFilter
+ at org.apache.catalina.core.ApplicationFilterConfig.getFilter
+ at org.apache.catalina.core.ApplicationFilterConfig.<init>
+ at org.apache.catalina.core.StandardContext.filterStart
+ at org.apache.catalina.core.StandardContext.startInternal
+ at org.apache.catalina.util.LifecycleBase.start
+ at org.apach
\ No newline at end of file

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt
------------------------------------------------------------------------------
    svn:eol-style = native

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt
------------------------------------------------------------------------------
    svn:keywords = Date Rev Author URL Id

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/deserialize-trace.txt
------------------------------------------------------------------------------
    svn:mime-type = text/plain

Added: ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt
URL: http://svn.apache.org/viewvc/ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt?rev=1732876&view=auto
==============================================================================
--- ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt (added)
+++ ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt Mon Feb 29 12:02:13 2016
@@ -0,0 +1,20 @@
+[Z
+[I
+org.ofbiz.service.rmi.RemoteDispatcherImpl_Stub
+java.rmi.server.RemoteStub
+java.rmi.server.RemoteObject
+org.ofbiz.service.rmi.socket.ssl.SSLClientSocketFactory
+[Ljava.rmi.server.ObjID;
+java.rmi.server.ObjID
+java.rmi.server.UID
+java.rmi.dgc.Lease
+java.rmi.dgc.VMID
+[B
+java.rmi.NotBoundException
+java.lang.Exception
+java.lang.Throwable
+[Ljava.lang.StackTraceElement;
+java.lang.StackTraceElement
+java.util.Collections$UnmodifiableList
+java.util.Collections$UnmodifiableCollection
+java.util.ArrayList

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt
------------------------------------------------------------------------------
    svn:eol-style = native

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt
------------------------------------------------------------------------------
    svn:keywords = Date Rev Author URL Id

Propchange: ofbiz/branches/release15.12/tools/security/notsoserial/is-deserialized.txt
------------------------------------------------------------------------------
    svn:mime-type = text/plain