当前位置:网站首页>JMX Console 未授权访问漏洞
JMX Console 未授权访问漏洞
2022-07-24 08:16:00 【曲折上升】
漏洞详情
Jboss的webUI界面 http://ip:port/jmx-console 未授权访问(或默认密码admin/admin ),可导致JBoss的部署管理的信息泄露,攻击者也可以直接上传木马获取 webshell。
影响范围
所有低版本
Docker搭建靶场环境
docker search testjboss
docker pull testjboss/jobss
docker run -p 8080:8080 -d testjboss/jboss
漏洞复现
访问靶场地址。如图搭建成功。

访问http://ip:8080/jmx-console/如果能直接进入或者通过默认账号密码登录则代表存在漏洞。

远程部署war包。
找到 jboss.deployment 选项flavor=URL,type=DeploymentScanner 点进去。
进入页面后找到 void addURL()

此时部署我们远程的war木马。(需要jdk环境)


在浏览器访问地址,获得war包路径。


然后点击 Invoke 部署

随后来到 URLList 中查看 Value 值是否已经部署好,并且为我们的远程war木马地址。


- 找到 jboss.web.deployment 查看是否存在我们部署的war木马。

- 此时可以看到已经部署成功。

- 访问地址:http://ip/cmd/shell.jsp(eg:aaa.war ;cmd=aaa)
防护建议
1、对jmx-console和web-console界面访问增加强认证。
2、关闭jmx-console和web-console,提高安全性。
边栏推荐
- [Beijiao] image processing: basic concepts, image enhancement, morphological processing, image segmentation
- [matlab] (IV) application of MATLAB in linear algebra
- Implementation of unity hub free version
- *Code understanding *numpy basic (plus code) that must be understood
- Project practice - document scanning OCR recognition
- [wechat applet development] (II) wechat native bottom tabbar configuration
- Go: Gin basicauth Middleware
- Assembly | screen display numbers
- Decision tree - ID3, C4.5, cart
- 【JDBC】JDBC经典面试题,持续更新中......
猜你喜欢

FPGA integrated project - image edge detection system

【MATLAB】(四)MATLAB在线性代数中的应用

The vision group of Hegong University Sky team trained day3 - machine learning, strengthened the use of Yolo models, and learned pumpkin books and watermelon books

VIDAR team team exclusive interview: as we do, as you know
![[technical interview] how to introduce yourself](/img/2e/775e4ba577098f7465309f772ee591.png)
[technical interview] how to introduce yourself

Learning dynamic Siamese network for visual object tracking full text translation

Figure New Earth: how to import CAD files with modified elevation datum (ellipsoid)

My six months at Microsoft
![[wechat applet development] (I) development environment and applet official account application](/img/94/b93d5fb6d9e3515a1f218cc4ec6eef.png)
[wechat applet development] (I) development environment and applet official account application

About the big hole of wechat applet promise
随机推荐
Zhouzhihua machine learning watermelon book chapter 2 model evaluation and selection - accuracy and model generalization evaluation method, self-help method and integrated learning
P1305 new binary tree solution
Error reported by Nacos: error Nacos failed to start, please see d:\nacos\logs\nacos log for more details.
Cmake binary installation
[database] complete SQL statement
赛宁TechTalk丨攻防演练:攻击组合拳 “稳准狠”渗透
FPGA综合项目——图像边缘检测系统
55. Jumping game
The difference between online learning and offline learning
Kotlin coprocess analysis (III) -- understanding the context of coprocess
13. Unity2d horizontal version of two-way platform that can move up, down, left and right (two-way walking + movable + independent judgment) + random platform generation
Wechat payment V3 version of openresty implementation and pit avoidance Guide (service side)
【MATLAB】(三)MATLAB在高等数学中的应用
You can't access this shared folder because your organization's security policies prevent unauthenticated guests from accessing it. These policies can help protect your computer from unsafe or malicio
Stack / heap / queue question brushing (Part 2)
Opencv project practice - credit card recognition
Summary of study notes (I)
Introduction of some functions or methods in DGL Library
[wechat applet development (III)] realize the stacking and sliding of cards
The code is tired. Stop and enjoy the top color matching~