daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (3046B)


      1 ---
      2 title: "Google Web Toolkit"
      3 topic: "Google Web Toolkit"
      4 topicSlug: "google-web-toolkit"
      5 sourcePath: "Google Web Toolkit/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Google%20Web%20Toolkit/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Google Web Toolkit
     12 
     13 > Google Web Toolkit (GWT), also known as GWT Web Toolkit, is an open-source set of tools that allows web developers to create and maintain JavaScript front-end applications using Java. It was originally developed by Google and had its initial release on May 16, 2006.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [References](#references)
     20 
     21 ## Tools
     22 
     23 * [FSecureLABS/GWTMap](https://github.com/FSecureLABS/GWTMap) - GWTMap is a tool to help map the attack surface of Google Web Toolkit (GWT) based applications.
     24 * [GDSSecurity/GWT-Penetration-Testing-Toolset](https://github.com/GDSSecurity/GWT-Penetration-Testing-Toolset) - A set of tools made to assist in penetration testing GWT applications.
     25 
     26 ## Methodology
     27 
     28 * Enumerate the methods of a remote application via it's bootstrap file and create a local backup of the code (selects permutation at random):
     29 
     30     ```ps1
     31     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --backup
     32     ```
     33 
     34 * Enumerate the methods of a remote application via a specific code permutation
     35 
     36     ```ps1
     37     ./gwtmap.py -u http://10.10.10.10/olympian/C39AB19B83398A76A21E0CD04EC9B14C.cache.js
     38     ```
     39 
     40 * Enumerate the methods whilst routing traffic through an HTTP proxy:
     41 
     42     ```ps1
     43     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --backup -p http://127.0.0.1:8080
     44     ```
     45 
     46 * Enumerate the methods of a local copy (a file) of any given permutation:
     47 
     48     ```ps1
     49     ./gwtmap.py -F test_data/olympian/C39AB19B83398A76A21E0CD04EC9B14C.cache.js
     50     ```
     51 
     52 * Filter output to a specific service or method:
     53 
     54     ```ps1
     55     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --filter AuthenticationService.login
     56     ```
     57 
     58 * Generate RPC payloads for all methods of the filtered service, with coloured output
     59 
     60     ```ps1
     61     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --filter AuthenticationService --rpc --color
     62     ```
     63 
     64 * Automatically test (probe) the generate RPC request for the filtered service method
     65 
     66     ```ps1
     67     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --filter AuthenticationService.login --rpc --probe
     68     ./gwtmap.py -u http://10.10.10.10/olympian/olympian.nocache.js --filter TestService.testDetails --rpc --probe
     69     ```
     70 
     71 ## References
     72 
     73 * [From Serialized to Shell :: Exploiting Google Web Toolkit with EL Injection - Stevent Seeley - May 22, 2017](https://web.archive.org/web/20260220100658/https://srcincite.io/blog/2017/05/22/from-serialized-to-shell-auditing-google-web-toolkit-with-el-injection.html)
     74 * [Hacking a Google Web Toolkit application - thehackerish - April 22, 2021](https://web.archive.org/web/20210227222455/https://thehackerish.com/hacking-a-google-web-toolkit-application/)