Files
nuclei-templates/network/detection/unauth-java-message-broker-detect.yaml

32 lines
1.0 KiB
YAML
Raw Normal View History

2025-11-12 12:49:10 +04:00
id: unauth-java-message-broker-detect
info:
2025-11-12 12:49:10 +04:00
name: Unauthenticated Java Message Broker - Detect
author: matejsmycka
severity: low
description: |
2025-11-12 12:49:10 +04:00
Detection of a Java Message Service (JMS) broker, typically used by Oracle GlassFish Message Queue and Payara Application Server. This port should remain closed to the internet, as it enables unauthenticated access to messaging services.
metadata:
verified: true
2025-11-12 12:49:10 +04:00
shodan-query: product:"Java Message Service"
tags: network,tcp,jms,openmq,unauth
network:
- inputs:
2025-11-12 12:49:10 +04:00
- data: "\n"
host:
- "{{Host}}:7676"
matchers:
- type: word
words:
- "101 imqbroker"
2025-11-12 12:49:10 +04:00
- "cluster_discovery"
condition: and
extractors:
- type: regex
regex:
2025-11-14 07:53:44 +00:00
- "imqbroker ([0-9.]+)"
2025-11-18 17:36:36 +00:00
# digest: 4a0a00473045022075614143ec7cc9455ec482f799e95d08c33a9c0bb899e3b3bdd88cb2af221dde02210087504db5b831614be7ec9c32aa844215ef6a87915f7c853675edde86b8c1e9b7:922c64590222798bb761d5b6d8e72950