Files
nuclei-templates/network/detection/unauth-java-message-broker-detect.yaml
2025-12-25 23:05:08 +00:00

32 lines
1.0 KiB
YAML

id: unauth-java-message-broker-detect
info:
name: Unauthenticated Java Message Broker - Detect
author: matejsmycka
severity: low
description: |
Detection of a Java Message Service (JMS) broker, typically used by Oracle GlassFish Message Queue and Payara Application Server. This port should remain closed to the internet, as it enables unauthenticated access to messaging services.
metadata:
verified: true
shodan-query: product:"Java Message Service"
tags: network,tcp,jms,openmq,unauth
tcp:
- inputs:
- data: "\n"
host:
- "{{Host}}:7676"
matchers:
- type: word
words:
- "101 imqbroker"
- "cluster_discovery"
condition: and
extractors:
- type: regex
regex:
- "imqbroker ([0-9.]+)"
# digest: 4b0a00483046022100bfb4a182fe57615720cb4419e0ef7268c7a4207e42ea70a4f9903766dbbfc1a7022100ab717d0e1c7386617f3e5f6a36023f6742db1ee66ccf78619a0d0c2232d0759e:922c64590222798bb761d5b6d8e72950