Web Hack List

Collected research

JMX Exploitation Revisited

Two default JMX MBean classes give instant remote code execution on any reachable JMX endpoint, needing no application-specific MBeans and no callback connection. StandardMBean wraps an arbitrary serializable object such as TemplatesImpl so reading its OutputProperties attribute loads attacker bytecode, and RequiredModelMBean can invoke arbitrary instance methods or any public static method.

Record

Published by
codewhitesec.blogspot.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of codewhitesec.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .