mirror of
https://github.com/ReaJason/MemShellParty.git
synced 2026-09-22 07:00:43 +08:00
test: add CB4 multi version gadgets integration test
This commit is contained in:
@@ -15,6 +15,7 @@ import java.nio.file.Paths;
|
|||||||
public class ContainerTool {
|
public class ContainerTool {
|
||||||
public static final MountableFile warJakartaFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp-jakarta/build/libs/vul-webapp-jakarta.war").toAbsolutePath());
|
public static final MountableFile warJakartaFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp-jakarta/build/libs/vul-webapp-jakarta.war").toAbsolutePath());
|
||||||
public static final MountableFile warExpressionFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp-expression/build/libs/vul-webapp-expression.war").toAbsolutePath());
|
public static final MountableFile warExpressionFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp-expression/build/libs/vul-webapp-expression.war").toAbsolutePath());
|
||||||
|
public static final MountableFile warDeserializeFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp-deserialize/build/libs/vul-webapp-deserialize.war").toAbsolutePath());
|
||||||
public static final MountableFile warFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp/build/libs/vul-webapp.war").toAbsolutePath());
|
public static final MountableFile warFile = MountableFile.forHostPath(Paths.get("../vul/vul-webapp/build/libs/vul-webapp.war").toAbsolutePath());
|
||||||
public static final MountableFile springBoot2WarFile = MountableFile.forHostPath(Paths.get("../vul/vul-springboot2/build/libs/vul-springboot2.war").toAbsolutePath());
|
public static final MountableFile springBoot2WarFile = MountableFile.forHostPath(Paths.get("../vul/vul-springboot2/build/libs/vul-springboot2.war").toAbsolutePath());
|
||||||
public static final Path springBoot2Dockerfile = Paths.get("../vul/vul-springboot2/Dockerfile").toAbsolutePath();
|
public static final Path springBoot2Dockerfile = Paths.get("../vul/vul-springboot2/Dockerfile").toAbsolutePath();
|
||||||
|
|||||||
+5
@@ -242,6 +242,11 @@ public class ShellAssertionTool {
|
|||||||
case Freemarker -> VulTool.postData(url + "/freemarker", content);
|
case Freemarker -> VulTool.postData(url + "/freemarker", content);
|
||||||
case Velocity -> VulTool.postData(url + "/velocity", content);
|
case Velocity -> VulTool.postData(url + "/velocity", content);
|
||||||
case JavaDeserialize -> VulTool.postData(url + "/java_deserialize", content);
|
case JavaDeserialize -> VulTool.postData(url + "/java_deserialize", content);
|
||||||
|
case JavaCommonsBeanutils16 -> VulTool.postData(url + "/java_deserialize/cb161", content);
|
||||||
|
case JavaCommonsBeanutils17 -> VulTool.postData(url + "/java_deserialize/cb170", content);
|
||||||
|
case JavaCommonsBeanutils18 -> VulTool.postData(url + "/java_deserialize/cb183", content);
|
||||||
|
case JavaCommonsBeanutils19 -> VulTool.postData(url + "/java_deserialize/cb194", content);
|
||||||
|
case JavaCommonsBeanutils110 -> VulTool.postData(url + "/java_deserialize/cb110", content);
|
||||||
case Base64 -> VulTool.postData(url + "/b64", content);
|
case Base64 -> VulTool.postData(url + "/b64", content);
|
||||||
case XxlJob -> VulTool.xxlJobExecutor(url + "/run", content);
|
case XxlJob -> VulTool.xxlJobExecutor(url + "/run", content);
|
||||||
default -> throw new IllegalStateException("Unexpected value: " + packer);
|
default -> throw new IllegalStateException("Unexpected value: " + packer);
|
||||||
|
|||||||
+64
@@ -0,0 +1,64 @@
|
|||||||
|
package com.reajason.javaweb.integration.tomcat;
|
||||||
|
|
||||||
|
import com.reajason.javaweb.memshell.config.Constants;
|
||||||
|
import com.reajason.javaweb.memshell.config.Server;
|
||||||
|
import com.reajason.javaweb.memshell.config.ShellTool;
|
||||||
|
import com.reajason.javaweb.memshell.packer.Packers;
|
||||||
|
import lombok.extern.slf4j.Slf4j;
|
||||||
|
import net.bytebuddy.jar.asm.Opcodes;
|
||||||
|
import org.junit.jupiter.api.AfterAll;
|
||||||
|
import org.junit.jupiter.params.ParameterizedTest;
|
||||||
|
import org.junit.jupiter.params.provider.Arguments;
|
||||||
|
import org.junit.jupiter.params.provider.MethodSource;
|
||||||
|
import org.testcontainers.containers.GenericContainer;
|
||||||
|
import org.testcontainers.containers.wait.strategy.Wait;
|
||||||
|
import org.testcontainers.junit.jupiter.Container;
|
||||||
|
import org.testcontainers.junit.jupiter.Testcontainers;
|
||||||
|
|
||||||
|
import java.util.stream.Stream;
|
||||||
|
|
||||||
|
import static com.reajason.javaweb.integration.ContainerTool.*;
|
||||||
|
import static com.reajason.javaweb.integration.DoesNotContainExceptionMatcher.doesNotContainException;
|
||||||
|
import static com.reajason.javaweb.integration.ShellAssertionTool.testShellInjectAssertOk;
|
||||||
|
import static org.hamcrest.MatcherAssert.assertThat;
|
||||||
|
import static org.junit.jupiter.params.provider.Arguments.arguments;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/4
|
||||||
|
*/
|
||||||
|
@Slf4j
|
||||||
|
@Testcontainers
|
||||||
|
public class Tomcat8DeserializeContainerTest {
|
||||||
|
public static final String imageName = "tomcat:8-jre8";
|
||||||
|
|
||||||
|
@Container
|
||||||
|
public final static GenericContainer<?> container = new GenericContainer<>(imageName)
|
||||||
|
.withCopyToContainer(warDeserializeFile, "/usr/local/tomcat/webapps/app.war")
|
||||||
|
.withCopyToContainer(jattachFile, "/jattach")
|
||||||
|
.withCopyToContainer(tomcatPid, "/fetch_pid.sh")
|
||||||
|
.waitingFor(Wait.forHttp("/app"))
|
||||||
|
.withExposedPorts(8080);
|
||||||
|
|
||||||
|
static Stream<Arguments> casesProvider() {
|
||||||
|
return Stream.of(
|
||||||
|
arguments(imageName, Constants.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils16),
|
||||||
|
arguments(imageName, Constants.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils17),
|
||||||
|
arguments(imageName, Constants.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils18),
|
||||||
|
arguments(imageName, Constants.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils19),
|
||||||
|
arguments(imageName, Constants.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils110)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
@AfterAll
|
||||||
|
static void tearDown() {
|
||||||
|
String logs = container.getLogs();
|
||||||
|
assertThat("Logs should not contain any exceptions", logs, doesNotContainException());
|
||||||
|
}
|
||||||
|
|
||||||
|
@ParameterizedTest(name = "{0}-expression|{1}{2}|{3}")
|
||||||
|
@MethodSource("casesProvider")
|
||||||
|
void test(String imageName, String shellType, ShellTool shellTool, Packers packer) {
|
||||||
|
testShellInjectAssertOk(getUrl(container), Server.Tomcat, shellType, shellTool, Opcodes.V1_8, packer, container);
|
||||||
|
}
|
||||||
|
}
|
||||||
-1
@@ -61,7 +61,6 @@ public class Tomcat8ExpressionContainerTest {
|
|||||||
@AfterAll
|
@AfterAll
|
||||||
static void tearDown() {
|
static void tearDown() {
|
||||||
String logs = container.getLogs();
|
String logs = container.getLogs();
|
||||||
log.info(logs);
|
|
||||||
assertThat("Logs should not contain any exceptions", logs, doesNotContainException());
|
assertThat("Logs should not contain any exceptions", logs, doesNotContainException());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ include 'vul'
|
|||||||
include 'vul:vul-webapp'
|
include 'vul:vul-webapp'
|
||||||
include 'vul:vul-webapp-jakarta'
|
include 'vul:vul-webapp-jakarta'
|
||||||
include 'vul:vul-webapp-expression'
|
include 'vul:vul-webapp-expression'
|
||||||
|
include 'vul:vul-webapp-deserialize'
|
||||||
include 'vul:vul-springboot2'
|
include 'vul:vul-springboot2'
|
||||||
include 'vul:vul-springboot3'
|
include 'vul:vul-springboot3'
|
||||||
include 'vul:vul-springboot2-webflux'
|
include 'vul:vul-springboot2-webflux'
|
||||||
|
|||||||
@@ -0,0 +1,54 @@
|
|||||||
|
plugins {
|
||||||
|
id 'war'
|
||||||
|
}
|
||||||
|
|
||||||
|
group = 'com.reajason.javaweb.vul'
|
||||||
|
version = ''
|
||||||
|
|
||||||
|
java {
|
||||||
|
toolchain {
|
||||||
|
languageVersion = JavaLanguageVersion.of(8)
|
||||||
|
}
|
||||||
|
sourceCompatibility = JavaVersion.VERSION_1_8
|
||||||
|
targetCompatibility = JavaVersion.VERSION_1_8
|
||||||
|
}
|
||||||
|
|
||||||
|
configurations {
|
||||||
|
cb110
|
||||||
|
cb194
|
||||||
|
cb183
|
||||||
|
cb170
|
||||||
|
cb161
|
||||||
|
}
|
||||||
|
|
||||||
|
dependencies {
|
||||||
|
cb110 'commons-beanutils:commons-beanutils:1.10.0'
|
||||||
|
cb194 'commons-beanutils:commons-beanutils:1.9.4'
|
||||||
|
cb183 'commons-beanutils:commons-beanutils:1.8.3'
|
||||||
|
cb170 'commons-beanutils:commons-beanutils:1.7.0'
|
||||||
|
cb161 'commons-beanutils:commons-beanutils:1.6.1'
|
||||||
|
|
||||||
|
providedCompile 'javax.servlet:javax.servlet-api:3.1.0'
|
||||||
|
}
|
||||||
|
|
||||||
|
war {
|
||||||
|
duplicatesStrategy = DuplicatesStrategy.EXCLUDE
|
||||||
|
|
||||||
|
doFirst {
|
||||||
|
delete "${webAppDir}/WEB-INF/dep"
|
||||||
|
|
||||||
|
copy { from configurations.cb110 into "${webAppDir}/WEB-INF/dep" }
|
||||||
|
copy { from configurations.cb194 into "${webAppDir}/WEB-INF/dep" }
|
||||||
|
copy { from configurations.cb183 into "${webAppDir}/WEB-INF/dep" }
|
||||||
|
copy { from configurations.cb170 into "${webAppDir}/WEB-INF/dep" }
|
||||||
|
copy { from configurations.cb161 into "${webAppDir}/WEB-INF/dep" }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
clean {
|
||||||
|
delete "${webAppDir}/WEB-INF/dep"
|
||||||
|
}
|
||||||
|
|
||||||
|
test {
|
||||||
|
useJUnitPlatform()
|
||||||
|
}
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
import javax.servlet.ServletException;
|
||||||
|
import javax.servlet.http.HttpServlet;
|
||||||
|
import javax.servlet.http.HttpServletRequest;
|
||||||
|
import javax.servlet.http.HttpServletResponse;
|
||||||
|
import java.io.*;
|
||||||
|
import java.net.MalformedURLException;
|
||||||
|
import java.net.URL;
|
||||||
|
import java.net.URLClassLoader;
|
||||||
|
import java.util.Base64;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2025/2/19
|
||||||
|
*/
|
||||||
|
public abstract class BaseDeserializeServlet extends HttpServlet {
|
||||||
|
|
||||||
|
abstract List<String> getDependentPaths();
|
||||||
|
|
||||||
|
@Override
|
||||||
|
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
|
||||||
|
try {
|
||||||
|
String libPath = getServletContext().getRealPath("/WEB-INF/dep");
|
||||||
|
URL[] urls = getDependentPaths().stream().map(path -> {
|
||||||
|
try {
|
||||||
|
return new File(libPath + File.separator + path).toURI().toURL();
|
||||||
|
} catch (MalformedURLException e) {
|
||||||
|
throw new RuntimeException(e);
|
||||||
|
}
|
||||||
|
}).toArray(URL[]::new);
|
||||||
|
|
||||||
|
final URLClassLoader classLoader = new URLClassLoader(urls);
|
||||||
|
|
||||||
|
String data = req.getParameter("data");
|
||||||
|
ByteArrayInputStream inputStream = new ByteArrayInputStream(Base64.getDecoder().decode(data));
|
||||||
|
ObjectInputStream bis = new ObjectInputStream(inputStream) {
|
||||||
|
@Override
|
||||||
|
protected Class<?> resolveClass(ObjectStreamClass desc) throws IOException, ClassNotFoundException {
|
||||||
|
return Class.forName(desc.getName(), false, classLoader);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
bis.readObject();
|
||||||
|
bis.close();
|
||||||
|
} catch (Exception e) {
|
||||||
|
if (e.getMessage().contains("InvocationTargetException")) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
throw new RuntimeException(e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import java.util.Arrays;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/10
|
||||||
|
*/
|
||||||
|
@WebServlet("/java_deserialize/cb110")
|
||||||
|
public class JavaReadObCB110jServlet extends BaseDeserializeServlet {
|
||||||
|
|
||||||
|
@Override
|
||||||
|
List<String> getDependentPaths() {
|
||||||
|
return Arrays.asList("commons-beanutils-1.10.0.jar", "commons-collections-3.2.2.jar", "commons-logging-1.3.4.jar");
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import java.util.Arrays;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/10
|
||||||
|
*/
|
||||||
|
@WebServlet("/java_deserialize/cb161")
|
||||||
|
public class JavaReadObCB161jServlet extends BaseDeserializeServlet {
|
||||||
|
|
||||||
|
@Override
|
||||||
|
List<String> getDependentPaths() {
|
||||||
|
return Arrays.asList("commons-beanutils-1.6.1.jar", "commons-collections-2.0.jar", "commons-logging-1.0.jar");
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import java.util.Arrays;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/10
|
||||||
|
*/
|
||||||
|
@WebServlet("/java_deserialize/cb170")
|
||||||
|
public class JavaReadObCB170jServlet extends BaseDeserializeServlet {
|
||||||
|
|
||||||
|
@Override
|
||||||
|
List<String> getDependentPaths() {
|
||||||
|
return Arrays.asList("commons-beanutils-1.7.0.jar", "commons-logging-1.0.3.jar");
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import java.util.Arrays;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/10
|
||||||
|
*/
|
||||||
|
@WebServlet("/java_deserialize/cb183")
|
||||||
|
public class JavaReadObCB183jServlet extends BaseDeserializeServlet {
|
||||||
|
|
||||||
|
@Override
|
||||||
|
List<String> getDependentPaths() {
|
||||||
|
return Arrays.asList("commons-beanutils-1.8.3.jar", "commons-logging-1.1.1.jar");
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
import javax.servlet.ServletException;
|
||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import javax.servlet.http.HttpServlet;
|
||||||
|
import javax.servlet.http.HttpServletRequest;
|
||||||
|
import javax.servlet.http.HttpServletResponse;
|
||||||
|
import java.io.ByteArrayInputStream;
|
||||||
|
import java.io.IOException;
|
||||||
|
import java.io.ObjectInputStream;
|
||||||
|
import java.util.Arrays;
|
||||||
|
import java.util.Collections;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2024/12/10
|
||||||
|
*/
|
||||||
|
@WebServlet("/java_deserialize/cb194")
|
||||||
|
public class JavaReadObjCB194Servlet extends BaseDeserializeServlet {
|
||||||
|
|
||||||
|
@Override
|
||||||
|
List<String> getDependentPaths() {
|
||||||
|
return Arrays.asList("commons-beanutils-1.9.4.jar", "commons-logging-1.2.jar");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
import javax.servlet.ServletException;
|
||||||
|
import javax.servlet.annotation.WebServlet;
|
||||||
|
import javax.servlet.http.HttpServlet;
|
||||||
|
import javax.servlet.http.HttpServletRequest;
|
||||||
|
import javax.servlet.http.HttpServletResponse;
|
||||||
|
import java.io.IOException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2025/2/19
|
||||||
|
*/
|
||||||
|
@WebServlet("/test")
|
||||||
|
public class TestServlet extends HttpServlet {
|
||||||
|
@Override
|
||||||
|
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
<web-app xmlns="http://xmlns.jcp.org/xml/ns/javaee"
|
||||||
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||||
|
xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee
|
||||||
|
http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd"
|
||||||
|
version="3.1">
|
||||||
|
<welcome-file-list>
|
||||||
|
<welcome-file>index.html</welcome-file>
|
||||||
|
</welcome-file-list>
|
||||||
|
</web-app>
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
<h1>hello</h1>
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import com.googlecode.aviator.AviatorEvaluator;
|
||||||
|
import com.googlecode.aviator.AviatorEvaluatorInstance;
|
||||||
|
import org.junit.jupiter.api.Test;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2025/1/29
|
||||||
|
*/
|
||||||
|
class AviatorServletTest {
|
||||||
|
|
||||||
|
@Test
|
||||||
|
void test() {
|
||||||
|
String exp = "use org.springframework.cglib.core.*;use org.springframework.util.*;ReflectionUtils.invokeMethod(ClassUtils.getMethod(Class.forName('java.lang.Thread'), 'getContextClassLoader', nil), Thread.currentThread())";
|
||||||
|
AviatorEvaluatorInstance evaluator = AviatorEvaluator.newInstance();
|
||||||
|
System.out.println(evaluator.execute(exp));
|
||||||
|
}
|
||||||
|
}
|
||||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -0,0 +1,18 @@
|
|||||||
|
import org.apache.commons.jexl2.Expression;
|
||||||
|
import org.junit.jupiter.api.Test;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2025/1/29
|
||||||
|
*/
|
||||||
|
class JEXL2ServletTest {
|
||||||
|
|
||||||
|
@Test
|
||||||
|
void test() {
|
||||||
|
System.out.println(System.getProperty("java.version"));
|
||||||
|
org.apache.commons.jexl2.JexlEngine jexl = new org.apache.commons.jexl2.JexlEngine();
|
||||||
|
Expression e = jexl.createExpression("''.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('js')");
|
||||||
|
org.apache.commons.jexl2.MapContext jc = new org.apache.commons.jexl2.MapContext();
|
||||||
|
System.out.println(e.evaluate(jc));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
import org.apache.commons.jexl3.*;
|
||||||
|
import org.junit.jupiter.api.Test;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @author ReaJason
|
||||||
|
* @since 2025/1/29
|
||||||
|
*/
|
||||||
|
class JEXL3ServletTest {
|
||||||
|
|
||||||
|
@Test
|
||||||
|
void test() {
|
||||||
|
System.out.println(System.getProperty("java.version"));
|
||||||
|
JexlEngine jexl = new JexlBuilder().create();
|
||||||
|
JexlExpression e = jexl.createExpression("''.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('js')");
|
||||||
|
JexlContext jc = new MapContext();
|
||||||
|
System.out.println(e.evaluate(jc));
|
||||||
|
}
|
||||||
|
}
|
||||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user