springboot heapdump含有数据库账户密码,利用memoryAnalyzer内存分析工具即可提取口令信息,步骤详情如下
MemoryAnalyzer
1、打开heapdump包后点击QQL输入查询语句,点击红色叹号搜索password字段
select * from java.util.Hashtable$Entry x WHERE (toString(x.key).contains("password"))
2、点击path to gc roots——>with all references,可查看jdbc详情