Apache ActiveMQ
Discovery
Port
Service
# Nmap detection
nmap -sC -sV -p 8161,61616,61613,61614,5672,1883 $ip
# Look for
ActiveMQ OpenWire transport
basic realm=ActiveMQRealm
Jetty(9.4.x)Default Credentials
Username
Password
CVE-2023-46604 - RCE (OpenWire Deserialization)
Exploit Repositories
Malicious XML Payload
Exploitation Steps
Verify Vulnerability
Post-Exploitation
References
Last updated