
beanshooter は、JMX エンドポイントの一般的な脆弱性を特定するのに役立つ、JMX 列挙および攻撃ツールです。
beanshooter は maven プロジェクトであり、インストールは簡単です。maven がインストールされている状態で、以下のコマンドを実行して実行可能な .jar ファイルを作成してください:```console
[qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter
[qtc@devbox ~]$ cd beanshooter
[qtc@devbox ~]$ mvn package
各リリース向けに作成されたビルド済みパッケージを利用することもできます。
開発ブランチ向けのビルド済みパッケージは自動的に作成され、*GitHub* の [アクションページ](https://github.com/qtc-de/beanshooter/actions) で入手できます。また、*beanshooter* を実行するためのビルド済みDockerイメージも [利用可能です](#docker-image)。
*beanshooter* は *ysoserial* を依存関係として含んでいません。*ysoserial* サポートを有効にするには、``ysoserial.jar`` ファイルへのパスを追加引数として指定するか(例: ``--yso /opt/ysoserial.jar``)、プロジェクトをビルドする前に [beanshooter 設定ファイル](https://github.com/qtc-de/beanshooter/blob/master/beanshooter/config.properties) 内のデフォルトパスを変更する必要があります。
*beanshooter* は *bash* でのオートコンプリートをサポートしています。オートコンプリートを利用するには、[completion-helpers](https://github.com/qtc-de/completion-helpers) プロジェクトがインストールされている必要があります。正しくセットアップされていれば、[completion script](https://github.com/qtc-de/beanshooter/blob/master/resources/bash_completion.d/beanshooter) を ``~/.bash_completion.d`` フォルダにコピーするだけでオートコンプリートが有効になります。```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/
さまざまな beanshooter 操作は、基本操作 と MBean操作 の2つのグループに分類できます。基本操作 は JMX エンドポイントで一般的な操作を実行するために使用されるのに対し、MBean操作 は特定の MBean を対象として操作を行います。詳細については、以下のセクションの使用例を参照してください。```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...
beanshooter v3.0.0 - a JMX enumeration and attacking tool
positional arguments:
Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server
MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files
named arguments: -h, --help show this help message and exit
### 基本操作
---
基本操作は、JMXサービスに対して実行できる汎用的な操作です。これらは通常、特定のMBeanを対象としない操作、またはbeanshooterによる組み込みサポートがないMBeanを対象とする操作です。
#### Attr
`attr`アクションは、指定された*MBean*の属性を取得または設定するために使用できます。利用可能な属性を取得するには、`info`アクションを使用する必要があります:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+] Attributes:
[+] Verbose (type: boolean , writable: true)
[+] ObjectPendingFinalizationCount (type: int , writable: false)
[+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+] Operations:
[+] void gc()
属性名のみが指定された場合、beanshooter は現在の属性値を取得して表示します。```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false
追加の値が指定された場合、*beanshooter* は対応する属性を設定しようとします。*String* とは異なる型を持つ属性の場合、`--type` オプションを使用して属性の型を指定する必要があります。```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true
brute アクションは、パスワードで保護された JMX サービスに対してブルートフォース攻撃を実行します。追加のオプション引数なしで実行した場合、beanshooter は一般的なユーザー名とパスワードの組み合わせを含む組み込みのワードリストを使用します。より本格的な攻撃には、--username-file および --password-file オプションを使用して、より網羅的なワードリストを指定してください。```console
[qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090
[+] Reading wordlists for the brute action.
[+] Reading credentials from internal wordlist.
[+]
[+] Starting bruteforce attack with 10 credentials.
[+]
[+] Found valid credentials: admin:admin
[+] [10 / 10] [########################################] 100%
[+]
[+] done.
#### Deploy
`deploy` アクションは、*JMX* サービス上に *MBean* をデプロイするために使用できます。このアクションは、例えば *TonkaBean* のようなデフォルトサポートを持つ *MBean* をデプロイするために**使用すべきではありません**。デフォルトサポートを持つ *MBean* のデプロイは、対応する [MBean 操作](#mbean-operations) を通じて行う必要があります。