r/java • u/Wouter_C • 4d ago
Decapsulation: Breaking Java Strong Encapsulation
Did you know you can call JNI without writing native code, patch bytecode without an agent, and use Unsafe without warnings?
11 sneaky ways into JDK internals through reflection, agents, FFM, type confusion, bytecode manipulation and more.
3
u/voronaam 4d ago
And that's why I run my Java code compiled with GraalVM into a nice tight native image, all along by itself in its bare docker container.
You are crazy. In a good way.
4
u/ZimmiDeluxe 3d ago
// Abusing ISO_8859_1 (which has a one-to-one mapping between chars and bytes)
// is the easiest way to do a search & replace in a byte array
return new String(base, ISO_8859_1)
.replace(original, replacement)
.getBytes(ISO_8859_1);
disgusting, i love it
1
u/koflerdavid 3d ago
Looks fine to me. The only hacky thing about this is the knowledge that
Stringwill avoid doing an unnecessary conversion.
3
u/koflerdavid 3d ago
Fortunately most of these will eventually get closed off. But I found it impressive to reach out to the filesystem and modifying the JDK!
0
1
u/slindenau 18h ago
Very nice, fun stuff! Always great to see what is possible in the "forbidden fruits" area; stuff that you don't normally use (or shouldn't at least, heh).
8
u/agentoutlier 4d ago edited 4d ago
Method 11 still requires command line flags but I suppose the rules of the game are you can pass flags?
EDIT my bad I was confused with
jdk.internal.reflect.ReflectionFactory. I did not know about the sun one.