From b357e50303f5a982edfe884db88488fb6871a560 Mon Sep 17 00:00:00 2001 From: ReaJason Date: Mon, 1 Sep 2025 23:19:43 +0800 Subject: [PATCH] docs: update CHANGELOG --- CHANGELOG.md | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 948d65ed..bcef3985 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,7 +10,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Added 1. 添加 BigInteger 打包方式(#86 by @wanswu) -2. 添加 SpELSpringIOUtilsGzipJDK17 打包方式(#83 by @xcxmiku and @ReaJason) +2. 添加 SpELSpringGzipJDK17 打包方式(#83 by @xcxmiku and @ReaJason) +3. 添加 JXPathSpringGzipPacker、JXPathSpringGzipPackerJDK17 打包方式(GeoServer 漏洞注入) ### Fixed @@ -18,12 +19,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 2. 修复使用 Dockerfile 进行自定义构建时,自定义路由无法正常工作 3. 修复探测内存马中 Sleep 和 DNSLog 自定义类名失效(#89 Thanks @yinsel) 4. 修复自定义内存马中,不会自动调用 listener 添加 getResponseFromRequest 实现代码和 valve 修改包名的逻辑(使用自定义内存马请参考:[如何使用自定义内存马功能](/docs/WriteCustomShell.md) 进行实现,否则会出现不可用的问题) +5. 修复使用 Agent Packer 在 jar-with-dependencies(fatjar) 中会出现打包整个 jar 的问题 ### Changed 1. 去除 logback(java11)和 okhttp 无用依赖,解决使用 SDK 打包部分场景会出现类版本不支持的问题 2. 实现 @SuperBuilder 自定义 Builder 简化配置类的创建代码(#9f8f3baa) -3. 依赖更新 +3. 优化命令执行内存马,改为和回显马逻辑一致,使用 ProcessBuilder.redirectErrorStream 简化流读取 +4. 修改 packer 中脚本存放添加 memshell-party 一级,防止打包成 fatjar 时文件全在根目录,可能会被覆盖导致功能破坏 +5. 优化资源读取,通过工具类 loadTemplateFromResource 统一实现 +6. 优化 Agent Attacher JDK11 异常处理 +7. 依赖更新 **Full Changelog:** [v2.0.0...v2.1.0](https://github.com/ReaJason/MemShellParty/compare/v2.0.0...v2.1.0)