jboss.md (2814B)
1 --- 2 title: "JBoss" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/jboss.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jboss.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # JBoss 14 15 ## Enumeration and Exploitation Techniques 16 17 Check for exposed legacy and current management endpoints, including `/admin-console/`, `/jmx-console/`, `/management/`, `/web-console/`, `/web-console/ServerInfo.jsp`, and `/status?full=true`. The available paths vary by JBoss generation and configuration. Legacy JBoss deployments may expose an HTML JMX console or invoker servlets; Red Hat's security guidance recommends restricting these administrative access points.<sup>[[1]](#references)</sup> 18 19 - Test authentication rather than assuming a default password. If a management interface is exposed, enumerate its version, enabled roles, and accessible operations before attempting any authenticated checks. 20 - On legacy installations, also check `/web-console/Invoker`, `/invoker/JMXInvokerServlet`, `/restricted/JMXInvokerServlet`, and `/invoker/EJBInvokerServlet`. These invokers can transport serialized invocations to MBeans or EJB/JNDI services, so an exposed or weakly protected endpoint may provide powerful management operations.<sup>[[1]](#references)</sup> 21 22 The **clusterd** toolkit and Metasploit's `auxiliary/scanner/http/jboss_vulnscan` module automate checks for exposed JBoss interfaces and known deployment weaknesses.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 23 24 ### Exploitation Resources 25 26 **JexBoss** can identify and validate several known JBoss and Java deserialization issues. Use active exploitation only with explicit authorization and verify the detected product/version before selecting a check.<sup>[[4]](#references)</sup> 27 28 ### Finding Vulnerable Targets 29 30 Search engines may reveal inadvertently indexed management endpoints. For assets within the authorized scope, one possible query is `inurl:status EJBInvokerServlet`. 31 32 ## References 33 34 - [1] [Red Hat - JBoss Enterprise Application Platform 5 Security Guide](https://docs.redhat.com/en-us/documentation/jboss_enterprise_application_platform_common_criteria_certification/5/pdf/security_guide/JBoss_Enterprise_Application_Platform_Common_Criteria_Certification-5-Security_Guide-en-US.pdf) 35 - [2] [GitHub - hatRiot/clusterd](https://github.com/hatRiot/clusterd) 36 - [3] [Rapid7 Vulnerability & Exploit Database - JBoss vulnerability scanner](https://www.rapid7.com/db/modules/auxiliary/scanner/http/jboss_vulnscan/) 37 - [4] [GitHub - joaomatosf/jexboss](https://github.com/joaomatosf/jexboss)