Module:版本对比 v1 → v2
v1(2026-10-04 03:44,mcst12345)→ v2(2026-10-04 03:46,mcst12345)
共 6 行变更 · 新增 1 行 · 删除 1 行(左右分栏:左为旧版本,右为新版本)
| ⋯ 省略 5 行未变内容 ⋯ | |||
| 6 | We won't talk about shits like "--add-opens" here. That's not how we do ms. The easiest way to trick module system, is to replace the java.lang.Class.module field, to replace your class's module field to the module of the class you want to access. To replace the module field you need Unsafe. sun.misc.Unsafe is enough for this. Note that you should recover the module field of your class afterward otherwise that class will fail to access your other classes. | 6 | We won't talk about shits like "--add-opens" here. That's not how we do ms. The easiest way to trick module system, is to replace the java.lang.Class.module field, to replace your class's module field to the module of the class you want to access. To replace the module field you need Unsafe. sun.misc.Unsafe is enough for this. Note that you should recover the module field of your class afterward otherwise that class will fail to access your other classes. |
| 7 | Using the method we discussed above, we can construct (or get) a trusted Lookup. After that, nothing can stop us from accessing all the shits inside JVM. | 7 | Using the method we discussed above, we can construct (or get) a trusted Lookup. After that, nothing can stop us from accessing all the shits inside JVM. |
| 8 | If you hate invoking everything using a MethodHandle, there's also workaround: You can find native methods named addReads0,addExports0,addExportsToAll0,addExportsToAllUnnamed0 inside java.lang.Module. Invoke addExportsToAll0 and addExportsToAllUnnamed0 on every packages a module contains, then invoke addReads0 on the module your module, you can bypass the runtime module access check. However you still need to fight with the compiler's access check. | ||
| 8 | If you hate invoking everything using a MethodHandle, there's also a workaround: You can find native methods named addReads0,addExports0,addExportsToAll0,addExportsToAllUnnamed0 inside java.lang.Module. Invoke addExportsToAll0 and addExportsToAllUnnamed0 on every packages a module contains, then invoke addReads0 on the module your module, you can bypass the runtime module access check. However you still need to fight with the compiler's access check. | ||
| 9 | [https://github.com/Rongmario/ImagineBreaker This] is a helper library aims to break out of the module system's access control. However the Github repo doesn't contain its actual source that you need to decompile the distributed jar. | 9 | [https://github.com/Rongmario/ImagineBreaker This] is a helper library aims to break out of the module system's access control. However the Github repo doesn't contain its actual source that you need to decompile the distributed jar. |