Skip to content

LazyTitan33/Openfire_Plugin_Upload

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 

Repository files navigation

Openfire plugin upload

Should you find yourself in an engagement with access to the Openfire Admin console, you could upload a malicious plugin (.jar file) to get RCE.

I was in such a situation and because of a shaky connection to their network, I wanted to make my life easier.

The script below doesn't have any error handling because I'm lazy. If you have issues, modify the script to go through your proxy, ensure you are hitting the correct IP, on the correct port, correct user etc. My script assumes port 9090.

image

I'll leave creating the malicious .jar plugin to your imagination and exercise.

NOTE: On the plus side, Openfire, by default, runs as NT Authority\System:

image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages