Path: blob/master/documentation/modules/post/multi/gather/maven_creds.md
24405 views
Vulnerable Application
Maven a software project management. This module seeks all settings.xml (Maven configuration file) on the target file system to extract credentials from them. Credentials are store in the tag ; the module also tries to cross the identifier found with the or tag in order to find the full realm the credentials belong to.
This module was successfully tested against:
Ubuntu 14.04 and Maven 3.0.5 with shell and meterpreter as session type
Debian 9 and Maven 3.0.5 with shell and meterpreter as session type
Verification Steps
Get a
shellormeterpretersession on some host.Do:
use post/multi/gather/maven_credsDo:
set SESSION [SESSION_ID]Do:
runIf the system has readable configuration files (settings.xml) containing username and passwords, they will be printed out.