Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to abuse the loophole of Java remote protocol in IBM WebSphere platform

Shulou Source: shulou.com Published: 2022-05-31 23:38:01 10月03日 Update

This article focuses on "how to abuse the Java remote protocol loophole in the IBM WebSphere platform". Interested friends may wish to take a look. The method introduced in this paper is simple, fast and practical. Let's let the editor take you to learn how to abuse the Java remote protocol loophole in IBM WebSphere platform.

CORBA, the common object request broker architecture, is a standardized specification defined by the object Management Organization (OMG). It is a platform-independent RPC framework and predates standards such as SOAP and gRPC. In a distributed environment, CORBA uses Internet InterORB Protocol (IIOP) to communicate between endpoints. In the default installation configuration of IBM WebSphere, the CORBA service can run on TCP ports 2809, 9100, 9402, and 9403. The Interceptor class will intercept the invocation request before invoking the service method. What we need to note here is the TxServerInterceptor class.

CVE-2020-4450-snippet-1.java:public void receive_request (ServerRequestInfo sri) {/ /... snip... If (TxProperties.SINGLE_PROCESS) {propagationContext = TxInterceptorHelper.demarshalContext (serviceContext.context_data, (ORB) ((LocalObject) sri). _ orb (); / /

Tags: Vulnerabilities methods objects code sequences services platforms can be passed through proxies attacks content scenarios measures attackers schemes standards frameworks learning queries running Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi Shulou Technology MySQL MariaDB macOS