2023-02-07 20:23:49 +00:00
id : jboss-web-service
info :
2023-02-09 04:46:34 +00:00
name : JBoss Web Service Console - Detect
2023-02-07 20:23:49 +00:00
author : DhiyaneshDK
severity : low
description : |
The JBoss Web Service console discloses the details of the remote system, The console displays all the web services and exposed by the system leading to a potential information disclosure.
remediation : Restrict access to the ws service
reference :
- https://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/JBossWS.java
metadata :
2023-06-04 08:13:42 +00:00
verified : true
2023-10-14 11:27:55 +00:00
max-request : 1
2023-02-07 20:23:49 +00:00
shodan-query : html:"JBossWS"
tags : jboss,misconfig
2023-04-27 04:28:59 +00:00
http :
2023-02-07 20:23:49 +00:00
- method : GET
path :
- '{{BaseURL}}/jbossws/services'
matchers-condition : and
matchers :
- type : word
part : body
words :
- 'JBossWS/Services</div>'
case-insensitive : true
2023-02-09 04:46:34 +00:00
- type : word
part : body
words :
- 'no endpoints deployed'
negative : true
2023-02-07 20:23:49 +00:00
- type : status
status :
- 200
2023-10-20 11:41:13 +00:00
# digest: 4b0a00483046022100994adf83a52cb8bd4770c61f637e2241ffeadb647753e98d052ffe1f9cdaf6ac0221009c057b596f129446405368b4e767f418aa430a384e67bed42ae44e1ced638fb4:922c64590222798bb761d5b6d8e72950