diff --git a/modules/vulnerabilities/unix/misc/jboss/jboss.pp b/modules/vulnerabilities/unix/misc/jboss/jboss.pp deleted file mode 100644 index 5b949adfb..000000000 --- a/modules/vulnerabilities/unix/misc/jboss/jboss.pp +++ /dev/null @@ -1,2 +0,0 @@ -include jboss::install -include jboss::flags diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_00 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_00 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_00 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_00 diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_01 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_01 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_01 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_01 diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_02 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_02 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_02 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_02 diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_03 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_03 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_03 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jboss-archive-files/jboss-as-distribution-6.1.0.Final.zip_03 diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_00 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_00 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_00 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_00 diff --git a/modules/vulnerabilities/unix/misc/jboss/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_01 b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_01 similarity index 100% rename from modules/vulnerabilities/unix/misc/jboss/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_01 rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/files/jre-archive-files/jre-8u351-linux-x64.tar.gz_01 diff --git a/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/jboss.pp b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/jboss.pp new file mode 100644 index 000000000..4193b01ab --- /dev/null +++ b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/jboss.pp @@ -0,0 +1,2 @@ +include jboss_remoting_unified_invoker_rce::install +include jboss_remoting_unified_invoker_rce::flags diff --git a/modules/vulnerabilities/unix/misc/jboss/manifests/flags.pp b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/flags.pp similarity index 89% rename from modules/vulnerabilities/unix/misc/jboss/manifests/flags.pp rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/flags.pp index f866485ac..b2e9c2b87 100644 --- a/modules/vulnerabilities/unix/misc/jboss/manifests/flags.pp +++ b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/flags.pp @@ -1,4 +1,4 @@ -class jboss::flags { +class jboss_remoting_unified_invoker_rce::flags { $secgen_parameters = secgen_functions::get_parameters($::base64_inputs_file) $leaked_filenames = $secgen_parameters['leaked_filenames'] $strings_to_leak = $secgen_parameters['strings_to_leak'] diff --git a/modules/vulnerabilities/unix/misc/jboss/manifests/install.pp b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/install.pp similarity index 98% rename from modules/vulnerabilities/unix/misc/jboss/manifests/install.pp rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/install.pp index 7cdedea68..91b555d52 100644 --- a/modules/vulnerabilities/unix/misc/jboss/manifests/install.pp +++ b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/manifests/install.pp @@ -1,4 +1,4 @@ -class jboss::install { +class jboss_remoting_unified_invoker_rce::install { Exec { path => ['/bin', '/usr/bin', '/usr/local/bin', '/sbin', '/usr/sbin'], environment => ['JAVA_HOME="/usr/lib/jvm/adoptopenjdk-8-hotspot-amd64/bin/java"']} diff --git a/modules/vulnerabilities/unix/misc/jboss/secgen_metadata.xml b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/secgen_metadata.xml similarity index 50% rename from modules/vulnerabilities/unix/misc/jboss/secgen_metadata.xml rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/secgen_metadata.xml index b7a02a311..acbddc234 100644 --- a/modules/vulnerabilities/unix/misc/jboss/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/secgen_metadata.xml @@ -19,7 +19,7 @@ strings_to_leak leaked_filenames - leaked_username + unix_username @@ -29,8 +29,35 @@ - + - \ No newline at end of file + https://s3.amazonaws.com/files.joaomatosf.com/slides/alligator_slides.pdf + jboss + LGPL v2.1 + + exploits/multi/misc/jboss_remoting_unified_invoker_rce + JBoss is vulnerable. + + + update + + + + EXPLOITATION + EXPLOITATION FRAMEWORKS + + + CVEs and CWEs + + + PENETRATION TESTING - SOFTWARE TOOLS + PENETRATION TESTING - ACTIVE PENETRATION + + + server-side misconfiguration and vulnerable components + Serialized objects + + + diff --git a/modules/vulnerabilities/unix/misc/jboss/templates/jboss.service.erb b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/templates/jboss.service.erb similarity index 86% rename from modules/vulnerabilities/unix/misc/jboss/templates/jboss.service.erb rename to modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/templates/jboss.service.erb index 5b709e62f..a6c2dcef7 100644 --- a/modules/vulnerabilities/unix/misc/jboss/templates/jboss.service.erb +++ b/modules/vulnerabilities/unix/misc/jboss_remoting_unified_invoker_rce/templates/jboss.service.erb @@ -9,4 +9,4 @@ Restart=on-abort RestartSec=1 [Install] -WantedBy=multi-user.target \ No newline at end of file +WantedBy=multi-user.target