> For the complete documentation index, see [llms.txt](https://sec.skill.or.kr/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sec.skill.or.kr/hacking/jboss-exploit.md).

# Exploiting JBOSS with JexBoss

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Exploiting JBOSS with JexBoss

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> JexBoss는 JBoss Application Server 및 기타 Java 플랫폼, 프레임 워크, 응용 프로그램 등에서 취약점을 테스트하고 악용하기 위한 도구입니다.
>
> JBOSS 를 사용하고 있는 관리자 분들은 테스트를 해 보시기 바랍니다.

### Description :&#x20;

> Simple JBOSS exploiting. See more deserialization exploitations in:

### Infomation : &#x20;

> GitHub : <https://github.com/joaomatosf/jexboss>

{% embed url="<https://youtu.be/yI54sRqFOyI>" %}
영상 시연    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}
