28 February 2011 | 10,417 views

JBoss Autopwn – JSP Hacking Tool For JBoss AS Server

Want to Learn Penetration Testing

This JBoss script deploys a JSP shell on the target JBoss AS server. Once deployed, the script uses its upload and command execution capability to provide an interactive session.

Features

  • Multiplatform support – tested on Windows, Linux and Mac targets
  • Support for bind and reverse bind shells
  • Meterpreter shells and VNC support for Windows targets

Installation

Dependencies include

  • Netcat
  • Curl
  • Metasploit v3, installed in the current path as “framework3″

You can download JBoss Autopwn here:

jboss-autopwn.zip

Or read more here.

Post to Twitter Post to Facebook Post to Google Buzz Post to Delicious Post to Digg Post to Reddit Post to StumbleUpon






Recent in Exploits/Vulnerabilities:
- US Subway Stores POS Hacked For $3Million Dollars
- No BEAST Fix From Microsoft In December Patch Tuesday – But They Fixed Duqu Bug
- Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit

Related Posts:
- winAUTOPWN v2.8 Released For Download – Windows Auto-Hacking Toolkit
- Metasploit 3.4.0 Hacking Framework Released – Over 100 New Exploits Added
- Gooscan – Automated Google Hacking Tool

Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 192,527 views
- AJAX: Is your application secure enough? - 115,792 views
- eEye Launches 0-Day Exploit Tracker - 81,954 views

Advertise on Darknet


3 Responses to “JBoss Autopwn – JSP Hacking Tool For JBoss AS Server”

  1. secret 4 March 2011 at 9:33 pm Permalink

    Hey, man! Link don’t work, plz update! Tnx! )

  2. STRSHR 5 March 2011 at 10:20 am Permalink

    The whole github profile of spiderlabs is not available, any mirror will be appreciated.

  3. jbossLover 7 March 2011 at 6:38 pm Permalink

    This exploit is the same to http://www.nruns.com/_downloads/Whitepaper-Hacking-jBoss-using-a-Browser.pdf or am i wrong?