daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

jboss.md (2814B)


      1 ---
      2 title: "JBoss"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/jboss.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jboss.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # JBoss
     14 
     15 ## Enumeration and Exploitation Techniques
     16 
     17 Check for exposed legacy and current management endpoints, including `/admin-console/`, `/jmx-console/`, `/management/`, `/web-console/`, `/web-console/ServerInfo.jsp`, and `/status?full=true`. The available paths vary by JBoss generation and configuration. Legacy JBoss deployments may expose an HTML JMX console or invoker servlets; Red Hat's security guidance recommends restricting these administrative access points.<sup>[[1]](#references)</sup>
     18 
     19 - Test authentication rather than assuming a default password. If a management interface is exposed, enumerate its version, enabled roles, and accessible operations before attempting any authenticated checks.
     20 - On legacy installations, also check `/web-console/Invoker`, `/invoker/JMXInvokerServlet`, `/restricted/JMXInvokerServlet`, and `/invoker/EJBInvokerServlet`. These invokers can transport serialized invocations to MBeans or EJB/JNDI services, so an exposed or weakly protected endpoint may provide powerful management operations.<sup>[[1]](#references)</sup>
     21 
     22 The **clusterd** toolkit and Metasploit's `auxiliary/scanner/http/jboss_vulnscan` module automate checks for exposed JBoss interfaces and known deployment weaknesses.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     23 
     24 ### Exploitation Resources
     25 
     26 **JexBoss** can identify and validate several known JBoss and Java deserialization issues. Use active exploitation only with explicit authorization and verify the detected product/version before selecting a check.<sup>[[4]](#references)</sup>
     27 
     28 ### Finding Vulnerable Targets
     29 
     30 Search engines may reveal inadvertently indexed management endpoints. For assets within the authorized scope, one possible query is `inurl:status EJBInvokerServlet`.
     31 
     32 ## References
     33 
     34 - [1] [Red Hat - JBoss Enterprise Application Platform 5 Security Guide](https://docs.redhat.com/en-us/documentation/jboss_enterprise_application_platform_common_criteria_certification/5/pdf/security_guide/JBoss_Enterprise_Application_Platform_Common_Criteria_Certification-5-Security_Guide-en-US.pdf)
     35 - [2] [GitHub - hatRiot/clusterd](https://github.com/hatRiot/clusterd)
     36 - [3] [Rapid7 Vulnerability & Exploit Database - JBoss vulnerability scanner](https://www.rapid7.com/db/modules/auxiliary/scanner/http/jboss_vulnscan/)
     37 - [4] [GitHub - joaomatosf/jexboss](https://github.com/joaomatosf/jexboss)