beanshooter 是一个 JMX 枚举和攻击工具,用于识别 JMX 端点上的常见漏洞。
beanshooter 是一个 maven 项目,安装过程应该很简单。在安装了 maven 之后,只需执行以下命令即可创建一个可执行的 .jar 文件:```console
[qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter
[qtc@devbox ~]$ cd beanshooter
[qtc@devbox ~]$ mvn package
你也可以使用为[每个版本](https://github.com/qtc-de/beanshooter/releases)创建的预构建包。
开发分支的预构建包会自动创建,可在 *GitHub* 的[操作页面](https://github.com/qtc-de/beanshooter/actions)找到。同时,也有一个用于运行 *beanshooter* 的预构建 Docker 镜像[可用](#docker-image)。
*beanshooter* 不包含 *ysoserial* 作为依赖项。要启用 *ysoserial* 支持,你需要指定 ``ysoserial.jar`` 文件的路径作为额外参数(例如 ``--yso /opt/ysoserial.jar``),或者在构建项目之前更改 [beanshooter 配置文件](https://github.com/qtc-de/beanshooter/blob/master/beanshooter/config.properties) 中的默认路径。
*beanshooter* 支持 *bash* 的自动补全功能。要利用自动补全,你需要安装 [completion-helpers](https://github.com/qtc-de/completion-helpers) 项目。如果设置正确,只需将[补全脚本](https://github.com/qtc-de/beanshooter/blob/master/resources/bash_completion.d/beanshooter)复制到你的 ``~/.bash_completion.d`` 文件夹即可启用自动补全。```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/
不同 beanshooter 操作可分为两组:基本操作 和 MBean 操作。其中,基本操作 用于对 JMX 端点执行常规操作,而 MBean 操作 则针对特定的 MBean 进行交互。有关更多详细信息,请参阅以下部分的使用示例。```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...
beanshooter v3.0.0 - a JMX enumeration and attacking tool
positional arguments:
Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server
MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files
named arguments: -h, --help show this help message and exit
### Basic Operations
---
基本操作是可对 JMX 服务执行的通用操作。这些通常是不针对特定 MBean 或针对 beanshooter 没有内置支持的 MBean 的操作。
#### Attr
`attr` 操作用于获取或设置指定 *MBean* 上的属性。要获取可用属性,应使用 `info` 操作:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+] Attributes:
[+] Verbose (type: boolean , writable: true)
[+] ObjectPendingFinalizationCount (type: int , writable: false)
[+] HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+] ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+] Operations:
[+] void gc()
当仅指定属性名称时,beanshooter 会获取并显示当前属性值:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false
当指定了额外的值时,*beanshooter* 会尝试设置相应的属性。对于类型不同于 *String* 的属性,需要使用 `--type` 选项指定属性类型:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true
brute动作对受密码保护的JMX服务执行暴力破解攻击。当不附带额外可选参数运行时,beanshooter使用内置的少量常见用户名-密码组合词表。对于更专注的攻击,应使用--username-file和--password-file选项指定更全面的词表。```console
[qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090
[+] Reading wordlists for the brute action.
[+] Reading credentials from internal wordlist.
[+]
[+] Starting bruteforce attack with 10 credentials.
[+]
[+] Found valid credentials: admin:admin
[+] [10 / 10] [########################################] 100%
[+]
[+] done.
#### 部署
`deploy` 动作可用于在 *JMX* 服务上部署 *MBean*。此操作**不应**用于部署具有默认支持的 *MBeans*,例如 *TonkaBean*。部署具有默认支持的 *MBeans* 应通过相应的 [MBean 操作](#mbean-operations) 进行。