From LOW to PWNED [3] JBoss/Tomcat server-status

简介: http://carnal0wnage.attackresearch.com/2012/04/from-low-to-pwned-3-jbosstomcat-server.

http://carnal0wnage.attackresearch.com/2012/04/from-low-to-pwned-3-jbosstomcat-server.html

Several (tm) months back I did my talk on "From LOW to PWNED" at hashdays and BSides Atlanta.

The slides were published here and the video from hashdays is here, no video for BSides ATL.

I consistently violate presentation zen and I try to make my slides usable after the talk but I decided to do a few blog posts covering the topics I put in the talk anyway.

Post [3] JBoss/Tomcat server-status

There have been some posts/exploits/modules on hitting up unprotected jboss and tomcat servers.

http://www.nruns.com/_downloads/Whitepaper-Hacking-jBoss-using-a-Browser.pdf 
http://carnal0wnage.attackresearch.com/2009/11/hacking-unprotected-jboss-jmx-console.html 
http://www.notsosecure.com/folder2/2009/10/27/hacking-jboss-with-jmx-console/ 
http://goohackle.com/jboss-security-vulnerability-jmx-management-console/ 

http://www.metasploit.com/modules/exploit/multi/http/jboss_maindeployer 
http://www.metasploit.com/modules/exploit/multi/http/tomcat_mgr_deploy 

Sometimes even though the deployer functionality is password protected the sever-status may not be.

/web-console/status?full=true




/manager/status/all



LOW?

This can be useful to find:


  • Lists of applications
  • Recent URL's accessed
    • sometimes with sessionids 
  • Find hidden services/apps
  • Enabled servlets
  • owned stuff :-)
Finding 0wned stuff is always fun let's see

Looking at the list of applications list one that doesnt look normal (zecmd)

Following that down leads us to zecmd.jsp that is a jsp shell


If you are interested in zecmd.jsp and jboss worm it comes from -->   this is a good write up as well as this OWASP preso  https://www.owasp.org/images/a/a9/OWASP3011_Luca.pdf

thoughts?

-CG

目录
相关文章
|
算法 应用服务中间件 网络安全
|
应用服务中间件 容器
Angular 自动编译部署 Tomcat Jboss
版权声明:本文为博主原创文章,未经博主允许不得转载。 https://blog.
1424 0
|
Java 应用服务中间件
|
关系型数据库 Java 应用服务中间件
|
消息中间件 XML 应用服务中间件
|
JavaScript 应用服务中间件 安全
|
应用服务中间件 网络协议 Java