00:00
377
Deploy a JSP reverse or bind shell (Metasploit one) using the JMX exposed deploymentFileRepository MBean of JBoss. The first request made is a HEAD one to bypass auth and deploy the malicious JSP, the second request is a GET one that triggers the reverse connection to the specified MSF listener.

Originally presented at CONFidence 2011: 2011.confidence.org.pl/prelegenci/michele-orru
This conversation is missing your voice. Take five seconds to join Vimeo or log in.

Advertisement

About this video

MP4
00:06:17
  • 640x400, 27.19MB
  • Uploaded Mon May 30, 2011
  • Please join or log in to download

Statistics

Date Plays Comments
Totals 330 1 0
Feb 24th 0 0 0
Feb 23rd 0 0 0
Feb 22nd 3 0 0
Feb 21st 2 0 0
Feb 20th 0 0 0
Feb 19th 1 0 0
Feb 18th 0 0 0