Java-monitor RSS bot
04-08-2011, 21:12
This Metasploit module logs in to an GlassFish Server 3.1 (Open Source or Commercial) instance using a default credential, uploads, and executes commands via deploying a malicious WAR. On Glassfish 2.x, 3.0 and Sun Java System Application Server 9.x this module will try to bypass authentication instead by sending lowercase HTTP verbs.
More... (http://packetstormsecurity.org/files/view/103714/glassfish_deployer.rb.txt)
More... (http://packetstormsecurity.org/files/view/103714/glassfish_deployer.rb.txt)