Skip to content
This repository has been archived by the owner on Jul 25, 2024. It is now read-only.

jolokia Realm JNDI RCE 利用失败 #13

Closed
TryA9ain opened this issue Nov 12, 2021 · 3 comments
Closed

jolokia Realm JNDI RCE 利用失败 #13

TryA9ain opened this issue Nov 12, 2021 · 3 comments

Comments

@TryA9ain
Copy link

jolokia Realm JNDI RCE 利用失败

1、输入目标地址和配置服务器地址,点击连接,验证成功

image

2、检测利用链失败

image

3、访问 https://x2.2x0.x4.xx5/actuator/jolokia/list 查看存在 createJNDIRealm 关键词

image

4、查看存在 type=MBeanFactory 关键词

image

5、手工设置监听,使用py 打成功

image

@SummerSec
Copy link
Member

涉密嘛?能否发给我邮箱[email protected],我看看具体情况原因?这种情况还是第一次遇见

@SummerSec
Copy link
Member

查明原因了,RegistryContextFactory是rmi协议,但JNDI漏洞利用工具只能是ldap协议。如果使用ldap协议得用LdapCtxFactory,但这个类是不支持自定义端口和引用对象,故报错了。目前只能发现是否存在漏洞,漏洞利用只能手工打了。后期尝试其他方法,感谢!

@SummerSec SummerSec pinned this issue Nov 22, 2021
@xiaoming-king
Copy link

漏洞如何复现的呢 我打了一遍也打不通

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants