Solved

Is there a WIndows patch for the JBOSS exploits

Posted on 2016-07-26
4
84 Views
Last Modified: 2016-08-22
Has anyone found if there is a patch for a JBOSS exploit for Windows.  I know they are available for RedHat but I couldn't find anything other that a reference to JBOSS in that patches that MS put out on April 2016.
0
Comment
Question by:Member_2_7969384
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 20

Assisted Solution

by:Russ Suter
Russ Suter earned 250 total points (awarded by participants)
ID: 41729594
JBOSS is a RedHat product. RedHat would be responsible for releasing patches. Microsoft would have nothing to do with it.
0
 

Author Comment

by:Member_2_7969384
ID: 41729618
Thanks, that is what I thought but since there were references out there to windows I thought it best to ask the question.  Thank you for the quick feed back.
0
 
LVL 64

Accepted Solution

by:
btan earned 250 total points (awarded by participants)
ID: 41729640
It is not to patch Windows as Russ Suter has shared. The concern is more of surfacing webshell backdoor in vulnerable machines. Generally, servers systems running web services and mostly those exposed to public internet accesss should be scanned if there is such indicator of compromise existence

jbossass.jsp      jbossass_jsp.class
shellinvoker.jsp      shellinvoker_jsp.class
mela.jsp      mela_jsp.class
zecmd.jsp      zecmd_jsp.class
cmd.jsp      cmd_jsp.class
wstats.jsp      wstats_jsp.class
idssvc.jsp      idssvc_jsp.class
iesvc.jsp      iesvc_jsp.class
http://blog.talosintel.com/2016/04/jboss-backdoor.html
See also US-CERT part advisory on webshell - https://www.us-cert.gov/ncas/alerts/TA15-314A

Just make sure your server system is readily patched to the latest security patch for business running

To share there is also another recent Jboss security advisory to address the Red Hat JBoss JGroups security bypass vulnerability.- https://tools.cisco.com/security/center/viewAlert.x?alertId=46834
0
 
LVL 64

Expert Comment

by:btan
ID: 41755355
It is explained on the exploit is not readily applicable but however, the threats lies in other type
0

Featured Post

Schedule a Tour of the ATEN booth at InfoComm 2017

Tour the ATEN booth to see the the Latest Addition to the Modular Matrix Switch Series, New 4K HDMI Over IP Extender and more! Enter ATEN's Ultimate Giveaway Sweepstakes for a chance to win one of several great prizes, including an ATEN US7220 2-Port Thunderbolt 2 Sharing Switch!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question