akde/infosec

Information security is ultimately about managing risk


Enumeration

Mandatory

  1. Check con­fig­u­ra­tion:
    nmap -sSVC --script rmi-dumpregistry -p 1100 $target

Optional

  • Try msf> use scanner/misc/java_rmi_server if class upload is pos­si­ble; if yes, try msf> use multi/misc/java_rmi_server.
  • Try to exploit with BaRMIe.

Leave a Reply

About

Personal collection of some infosec stuff. Primary purpose of this site is to collect and organize for myself.

Note: Some content is not publicly visible due to copyright issues. Therefore, some links could be broken.

Checklists

Categories

Checklists: Ports

python -c 'import pty;pty.spawn("/bin/bash")';

python3 -c 'import pty;pty.spawn("/bin/bash")';