JBoss Exploitation.pdf
(
455 KB
)
Pobierz
WHITEPAPER – Jboss Exploitation
WWW.SECFENCE.COM
JBoss Exploitation
By
Whitepaper on
Prashant Uniyal
prashant.u@secfence.com
www.secfence.com
WHITEPAPER – Jboss Exploitation
WWW.SECFENCE.COM
INTRODUCTION
JBoss Application Server is an open-source Java EE-based
application server. An important distinction for this class of software
is that it not only implements a server that runs on Java, but it
actually implements the Java EE part of Java. Because it is Java-
based, the JBoss application server operates cross-platform: usable
on any operating system that supports Java. JBoss AS was
developed by JBoss, now a division of Red Hat.
JBoss Web Server provides organizations with a single deployment
platform for Java Server Pages (JSP) and Java Servlet technologies,
PHP, and CGI. It uses a genuine high performance hybrid technology
that incorporates the best of the most recent OS technologies for
processing high volume data, while keeping all the reference Java
specifications.
WHITEPAPER – Jboss Exploitation
WWW.SECFENCE.COM
VULNERABILITY
JBoss is widely used today and is deployed by many organizations on
their respective web servers. Being a useful application, it must have
been under target of hackers and malicious users. Though many
vulnerabilities and bugs have been found on JBoss and many CVE’s
have been issued. But today we will look at one of the most critical
bug in the JBoss application that can be used widely by cyber
criminals. Let’s have a look at the default JBoss server
WHITEPAPER – Jboss Exploitation
WWW.SECFENCE.COM
Fig: A default jmx-console
The default state, if not configured properly, can allow attackers to
create havoc. As the jmx console can be accessed remotely usually
on port 8080, hackers and malicious users can deploy their on WAR
(web archive) file or shells on the server using the
DeploymentScanner function in the JBoss console. In the next
section, we will have a look on the exploitation in action.
WHITEPAPER – Jboss Exploitation
WWW.SECFENCE.COM
EXPLOITATION IN ACTION!
Most of us will start looking for tools like meatsploit, nmap, nessus
etc! You won’t need them here. Yes, you heard it right ! For hacking
JBoss server, you don’t need much application. All you need is a jsp
shell and a browser. We formed a Google dork to search jmx
consoles: inurl:jmx-console/HtmlAdaptor . And here is the result:
Most of the JBoss server have default authentication to the jmx-
console. The default configuration of JBoss does not restrict access
to the console and web management interfaces, which allow remote
attackers to bypass authentication and gain administrative access
via direct requests. We just choose one of the random URL and
bingo ! We got the access to the jmx-console.
Next, we need a JSP Shell. Jsp shells can be easily obtained by
searching over the internet. So now, we have a jsp shell to move on.
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
StegoSploit - Exploiting the Browser using only Images.pdf
(33848 KB)
Access Denied - Guide for Code Breakers.pdf
(5201 KB)
Exploiting Software - How To Break Code.pdf
(7765 KB)
Linux Kernel Crash Book - Everything you need to know.pdf
(4992 KB)
Runtime Attacks - Buffer Overflow and Return-Oriented-Programming.pdf
(6793 KB)
Inne foldery tego chomika:
Reversing
Tools
Zgłoś jeśli
naruszono regulamin