Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
beanshooter — JMX枚举与攻击工具。 | Kitploit
工具/GitHubGitHub/qtc-de/beanshooter
漏洞分析漏洞利用渗透测试
GitHubqtc-de/beanshooter

beanshooter

JMX枚举与攻击工具。

查看仓库
50955513年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

beanshooter


beanshooter 是一个 JMX 枚举和攻击工具,用于识别 JMX 端点上的常见漏洞。

https://user-images.githubusercontent.com/49147108/183278179-4a5566a7-5af8-4ce8-a73d-1016876a36d5.mp4

安装


beanshooter 是一个 maven 项目,安装过程应该很简单。在安装了 maven 之后,只需执行以下命令即可创建一个可执行的 .jar 文件:```console [qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter [qtc@devbox ~]$ cd beanshooter [qtc@devbox ~]$ mvn package

你也可以使用为[每个版本](https://github.com/qtc-de/beanshooter/releases)创建的预构建包。
开发分支的预构建包会自动创建,可在 *GitHub* 的[操作页面](https://github.com/qtc-de/beanshooter/actions)找到。同时,也有一个用于运行 *beanshooter* 的预构建 Docker 镜像[可用](#docker-image)。

*beanshooter* 不包含 *ysoserial* 作为依赖项。要启用 *ysoserial* 支持,你需要指定 ``ysoserial.jar`` 文件的路径作为额外参数(例如 ``--yso /opt/ysoserial.jar``),或者在构建项目之前更改 [beanshooter 配置文件](https://github.com/qtc-de/beanshooter/blob/master/beanshooter/config.properties) 中的默认路径。

*beanshooter* 支持 *bash* 的自动补全功能。要利用自动补全,你需要安装 [completion-helpers](https://github.com/qtc-de/completion-helpers) 项目。如果设置正确,只需将[补全脚本](https://github.com/qtc-de/beanshooter/blob/master/resources/bash_completion.d/beanshooter)复制到你的 ``~/.bash_completion.d`` 文件夹即可启用自动补全。```console
[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/

目录


  • 支持的操作
    • 基本操作
      • attr
      • brute
      • deploy
      • enum
      • info
      • invoke
      • jolokia
      • list
      • model
      • serial
      • stager
      • standard
      • undeploy
    • MBean 操作
      • 通用
        • attr
        • info
        • invoke
        • stats
        • status
        • export
        • deploy
        • undeploy
      • 诊断
        • read
        • load
        • logfile
        • nolog
        • cmdline
        • props
      • HotSpot
        • dump
        • list
        • get
        • set
      • MLet
        • load
      • 记录器
        • new
        • start
        • stop
        • read
        • dump
      • Tomcat
        • dump
        • list
        • write
      • Tonka
        • exec
        • execarray
        • shell
        • upload
        • download
  • JMXMP
  • Jolokia 支持
  • Docker 镜像
  • 示例服务器

支持的操作


不同 beanshooter 操作可分为两组:基本操作 和 MBean 操作。其中,基本操作 用于对 JMX 端点执行常规操作,而 MBean 操作 则针对特定的 MBean 进行交互。有关更多详细信息,请参阅以下部分的使用示例。```console [qtc@devbox ~]$ beanshooter -h usage: beanshooter [-h] ...

beanshooter v3.0.0 - a JMX enumeration and attacking tool

positional arguments:

Basic Operations attr set or get MBean attributes brute bruteforce JMX credentials deploy deploys the specified MBean on the JMX server enum enumerate the JMX service for common vulnerabilities info display method and attribute information on an MBean invoke invoke the specified method on the specified MBean list list available MBEans on the remote MBean server serial perform a deserialization attack stager start a stager server to deliver MBeans undeploy undeploys the specified MBEAN from the JMX server

MBean Operations diagnostic Diagnostic Command MBean hotspot HotSpot Diagnostic MBean mlet default JMX bean that can be used to load additional beans dynamically recorder jfr Flight Recorder MBean tomcat tomcat MemoryUserDatabaseMBean used for user management tonka general purpose bean for executing commands and uploading or download files

named arguments: -h, --help show this help message and exit

### Basic Operations

---

基本操作是可对 JMX 服务执行的通用操作。这些通常是不针对特定 MBean 或针对 beanshooter 没有内置支持的 MBean 的操作。

#### Attr

`attr` 操作用于获取或设置指定 *MBean* 上的属性。要获取可用属性,应使用 `info` 操作:```console
[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+]     Attributes:
[+]         Verbose (type: boolean , writable: true)
[+]         ObjectPendingFinalizationCount (type: int , writable: false)
[+]         HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+]     Operations:
[+]         void gc()

当仅指定属性名称时,beanshooter 会获取并显示当前属性值:```console [qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose false

当指定了额外的值时,*beanshooter* 会尝试设置相应的属性。对于类型不同于 *String* 的属性,需要使用 `--type` 选项指定属性类型:```console
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true

Brute

brute动作对受密码保护的JMX服务执行暴力破解攻击。当不附带额外可选参数运行时,beanshooter使用内置的少量常见用户名-密码组合词表。对于更专注的攻击,应使用--username-file和--password-file选项指定更全面的词表。```console [qtc@devbox ~]$ beanshooter brute 172.17.0.2 1090 [+] Reading wordlists for the brute action. [+] Reading credentials from internal wordlist. [+] [+] Starting bruteforce attack with 10 credentials. [+] [+] Found valid credentials: admin:admin [+] [10 / 10] [########################################] 100% [+] [+] done.

#### 部署

`deploy` 动作可用于在 *JMX* 服务上部署 *MBean*。此操作**不应**用于部署具有默认支持的 *MBeans*,例如 *TonkaBean*。部署具有默认支持的 *MBeans* 应通过相应的 [MBean 操作](#mbean-operations) 进行。
下载工具