Blog do Seba

DBA, Consultor, Instrutor, [aprendiz de] Ninja e metido a Chef nas horas vagas!

Como tratar a vulnerabilidade do JBoss ao WORM 'pnscan'

Created in Oct 24, 2011

100 Words. Read in about 1 Min.
Categories: JBoss
Tags: jboss pnscan Rapidinhas vulnerabilidade worm

Altere o arquivo deploy/jmx-console.war/WEB-INF/web.xml, removendo as tags abaixo da sessão security-constraint:

<http-method>GET</http-method>
<http-method>POST</http-method>

Deve ficar parecido com isso:

<security-constraint>
  <web-resource-collection>
    <web-resource-name>HtmlAdaptor</web-resource-name>
    <description>
       An example security config that only allows users with the role
       JBossAdmin to access the HTML JMX console web application
    </description>
    <url-pattern>/*</url-pattern>
  </web-resource-collection>
  <auth-constraint>
    <role-name>JBossAdmin</role-name>
  </auth-constraint>
</security-constraint>

Agora reinicie sua instância.

Mais detalhes/Referências:

Comentários

comments powered by Disqus