Enumeration
Mandatory
- Check configuration:
nmap -sSVC --script rmi-dumpregistry -p 1100 $target
Optional
- Try
msf> use scanner/misc/java_rmi_serverif class upload is possible; if yes, trymsf> use multi/misc/java_rmi_server. - Try to exploit with BaRMIe.
Leave a Reply
You must be logged in to post a comment.