
JMX 열거 및 공격 도구.
beanshooter는 JMX 엔드포인트에서 일반적인 취약점을 식별하는 데 도움이 되는 JMX 열거 및 공격 도구입니다.
beanshooter는 maven 프로젝트이며 설치가 간단합니다. maven이 설치되어 있으면 다음 명령을 실행하여 실행 가능한 .jar 파일을 생성할 수 있습니다:```console
[qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter
[qtc@devbox ~]$ cd beanshooter
[qtc@devbox ~]$ mvn package
또한 [각 릴리스](https://github.com/qtc-de/beanshooter/releases)에 대해 생성된 사전 빌드 패키지를 사용할 수 있습니다.
개발 브랜치용 사전 빌드 패키지는 자동으로 생성되며 *GitHub* [actions 페이지](https://github.com/qtc-de/beanshooter/actions)에서 찾을 수 있습니다.
또한 *beanshooter*를 실행하기 위한 사전 빌드 도커 이미지도 [이용 가능](#docker-image)합니다.
*beanshooter*는 *ysoserial*을 종속성으로 포함하지 않습니다.
*ysoserial* 지원을 활성화하려면 ``ysoserial.jar`` 파일의 경로를 추가 인수로 지정하거나(예: ``--yso /opt/ysoserial.jar``) 프로젝트를 빌드하기 전에 [beanshooter 구성 파일](https://github.com/qtc-de/beanshooter/blob/master/beanshooter/config.properties) 내의 기본 경로를 변경해야 합니다.
*beanshooter*는 *bash*에 대한 자동 완성을 지원합니다. 자동 완성을 사용하려면 [completion-helpers](https://github.com/qtc-de/completion-helpers) 프로젝트가 설치되어 있어야 합니다. 올바르게 설정된 경우 [완성 스크립트](https://github.com/qtc-de/beanshooter/blob/master/resources/bash_completion.d/beanshooter)를 ``~/.bash_completion.d`` 폴더에 복사하기만 하면 자동 완성이 활성화됩니다.```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/
다양한 beanshooter 작업은 두 그룹으로 나눌 수 있습니다: *기본 작업(basic operations)*과 *MBean 작업(MBean operations)*입니다. 기본 작업은 JMX 엔드포인트에 대한 일반 작업을 수행하는 데 사용되는 반면, MBean 작업은 특정 MBean과 상호 작용합니다. 자세한 내용은 다음 섹션의 사용 예제를 확인하십시오.```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...
beanshooter v3.0.0 - a JMX enumeration and attacking tool
positional arguments:
Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server
MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files
named arguments: -h, --help show this help message and exit
### Basic Operations
---
기본 작업은 JMX 서비스에서 수행할 수 있는 범용 작업입니다. 이는 일반적으로 특정 MBean을 대상으로 하지 않거나 beanshooter에 내장 지원이 없는 MBean을 대상으로 하는 작업입니다.
#### Attr
`attr` 작업을 사용하여 지정된 *MBean*의 속성을 가져오거나 설정할 수 있습니다. 사용 가능한 속성을 얻으려면 `info` 작업을 사용해야 합니다.```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+] Attributes:
[+] Verbose (type: boolean , writable: true)
[+] ObjectPendingFinalizationCount (type: int , writable: false)
[+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+] Operations:
[+] void gc()
속성 이름만 지정되면 beanshooter는 현재 속성 값을 가져와서 표시합니다:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false
추가 값이 지정되면, *beanshooter*는 해당 속성을 설정하려고 시도합니다. *String*과 다른 유형의 속성의 경우 `--type` 옵션을 사용하여 속성 유형을 지정해야 합니다:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true
brute 작업은 비밀번호로 보호된 JMX 서비스에 대해 무차별 대입 공격을 수행합니다. 추가 선택적 인수 없이 실행하면 beanshooter는 몇 가지 일반적인 사용자 이름-비밀번호 조합이 포함된 내장 단어 목록을 사용합니다. 더 전용적인 공격을 위해서는 --username-file 및 --password-file 옵션을 사용하여 더 포괄적인 단어 목록을 지정해야 합니다.```console
[qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090
[+] Reading wordlists for the brute action.
[+] Reading credentials from internal wordlist.
[+]
[+] Starting bruteforce attack with 10 credentials.
[+]
[+] Found valid credentials: admin:admin
[+] [10 / 10] [########################################] 100%
[+]
[+] done.
#### 배포
`deploy` 액션은 *JMX* 서비스에 *MBean*을 배포하는 데 사용할 수 있습니다. 이 액션은 기본 지원을 제공하는 예를 들어 *TonkaBean*과 같은 *MBeans*을 배포하는 데
**사용해서는 안 됩니다**. 기본 지원이 있는 *MBean*은 해당 [MBean 작업](#mbean-operations)을 통해 배포해야 합니다.