Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
beanshooter — Strumento di enumerazione e attacco JMX. | Kitploit
Strumenti/GitHubGitHub/qtc-de/beanshooter
Analisi delle VulnerabilitàExploitPenetration Testing
GitHubqtc-de/beanshooter

beanshooter

Strumento di enumerazione e attacco JMX.

Vedi Repository
50955513 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

beanshooter


beanshooter è uno strumento di enumerazione e attacco JMX, che aiuta a identificare vulnerabilità comuni sugli endpoint JMX.

https://user-images.githubusercontent.com/49147108/183278179-4a5566a7-5af8-4ce8-a73d-1016876a36d5.mp4

Installazione


beanshooter è un progetto maven e l'installazione dovrebbe essere semplice. Con maven installato, basta eseguire i seguenti comandi per creare un file .jar eseguibile:```console [qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter [qtc@devbox ~]$ cd beanshooter [qtc@devbox ~]$ mvn package

Puoi anche utilizzare i pacchetti precompilati creati per [ogni release](https://github.com/qtc-de/beanshooter/releases). I pacchetti precompilati per il ramo di sviluppo vengono creati automaticamente e si trovano sulla [pagina delle azioni](https://github.com/qtc-de/beanshooter/actions) di *GitHub*. È inoltre disponibile un'immagine Docker precompilata per eseguire *beanshooter* [disponibile](#docker-image).

*beanshooter* non include *ysoserial* come dipendenza. Per abilitare il supporto a *ysoserial*, è necessario specificare il percorso del file ``ysoserial.jar`` come argomento aggiuntivo (ad esempio ``--yso /opt/ysoserial.jar``) oppure modificare il percorso predefinito all'interno del [file di configurazione di beanshooter](https://github.com/qtc-de/beanshooter/blob/master/beanshooter/config.properties) prima di compilare il progetto.

*beanshooter* supporta l'autocompletamento per *bash*. Per sfruttare l'autocompletamento, è necessario avere installato il progetto [completion-helpers](https://github.com/qtc-de/completion-helpers). Se configurato correttamente, è sufficiente copiare lo [script di completamento](https://github.com/qtc-de/beanshooter/blob/master/resources/bash_completion.d/beanshooter) nella cartella ``~/.bash_completion.d`` per abilitare l'autocompletamento.```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/

Indice


  • Operazioni Supportate
    • Operazioni Base
      • attr
      • brute
      • deploy
      • enum
      • info
      • invoke
      • jolokia
      • list
      • model
      • serial
      • stager
      • standard
      • undeploy
    • Operazioni MBean
      • generic
        • attr
        • info
        • invoke
        • stats
        • status
        • export
        • deploy
        • undeploy
      • diagnostic
        • read
        • load
        • logfile
        • nolog
        • cmdline
        • props
      • hotspot
        • dump
        • list
        • get
        • set
      • mlet
        • load
      • recorder
        • new
        • start
        • stop
        • read
        • dump
      • tomcat
        • dump
        • list
        • write
      • tonka
        • exec
        • execarray
        • shell
        • upload
        • download
  • JMXMP
  • Supporto Jolokia
  • Immagine Docker
  • Server di Esempio

Operazioni Supportate


Le diverse operazioni di beanshooter possono essere suddivise in due gruppi: operazioni base e operazioni MBean. Mentre le operazioni base vengono utilizzate per eseguire operazioni generali su un endpoint JMX, le operazioni MBean mirano a interagire con uno specifico MBean. Per maggiori dettagli, consulta gli esempi di utilizzo nelle sezioni seguenti.```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...

beanshooter v3.0.0 - a JMX enumeration and attacking tool

positional arguments:

Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server

MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files

named arguments: -h, --help show this help message and exit

### Operazioni di base

---

Le operazioni di base sono operazioni di uso generale che possono essere eseguite su un servizio JMX. Di solito si tratta di
operazioni che non hanno come target un MBean specifico o che hanno come target un MBean senza supporto integrato da beanshooter.

#### Attr

L'azione `attr` può essere utilizzata per ottenere o impostare attributi su un *MBean* specificato. Per ottenere gli attributi disponibili,
si dovrebbe utilizzare l'azione `info`:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+]     Attributes:
[+]         Verbose (type: boolean , writable: true)
[+]         ObjectPendingFinalizationCount (type: int , writable: false)
[+]         HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+]     Operations:
[+]         void gc()

Quando viene specificato solo il nome dell'attributo, beanshooter ottiene e visualizza il valore corrente dell'attributo:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false

Quando viene specificato un valore aggiuntivo, *beanshooter* tenta di impostare l'attributo corrispondente. Per attributi che hanno un tipo diverso da *String*, è necessario specificare il tipo di attributo usando l'opzione `--type`:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true

Brute

Scarica lo strumento