[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdwg98USL7ahhC-GnD7NNVckAkomB13CgW5pZSAJaA2o":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},442,"How can I enable remote debugging for the Jetty web server in Sophos XG?","To enable Jetty remote debugging, first locate the startup script at \u002Fusr\u002Fbin\u002Fjetty and remount the filesystem with `mount -o rw,remount \u002F`. Add the JVM debugging parameter `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000` to the exec line. Since the built-in OpenJDK lacks the debug library, replace it with a complete JDK (e.g., jdk-11.0.15) by backing up \u002Flib\u002Fjvm\u002Fjava-11-openjdk and extracting the new JDK there. Restart the service with `service tomcat:restart -ds nosync` and ensure the firewall allows port 8000 using `iptables -I INPUT -p tcp --dport 8000 -j ACCEPT`. You can then attach a remote debugger in an IDE like IntelliJ IDEA.","\u003Cp>To enable Jetty remote debugging, first locate the startup script at \u002Fusr\u002Fbin\u002Fjetty and remount the filesystem with `mount -o rw,remount \u002F`. Add the JVM debugging parameter `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000` to the exec line. Since the built-in OpenJDK lacks the debug library, replace it with a complete JDK (e.g., jdk-11.0.15) by backing up \u002Flib\u002Fjvm\u002Fjava-11-openjdk and extracting the new JDK there. Restart the service with `service tomcat:restart -ds nosync` and ensure the firewall allows port 8000 using `iptables -I INPUT -p tcp --dport 8000 -j ACCEPT`. You can then attach a remote debugger in an IDE like IntelliJ IDEA.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsophos-xg-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-enable-remote-debugging-for-the-jetty-web-server-in-sophos-xg-1777483611096","Jetty, remote debugging, JDWP, JDK replacement, Sophos XG, tomcat",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},111,"Sophos XG Vulnerability Debugging Environment Setup","sophos-xg-vulnerability-debugging-environment-setup","Learn to set up a Sophos XG vulnerability debugging environment, including Jetty debugging, CSC file decryption, and PostgreSQL database access.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Sophos UTM and Sophos XG are two distinct products; the former leans towards general threat management, while the latter focuses on hardware firewalls. This article will introduce the method for setting up a Sophos XG vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Jetty Debugging Environment Setup\u003C\u002Fli>\u003Cli>CSC Configuration File Decryption\u003C\u002Fli>\u003Cli>PostgreSQL Database Query\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Fundamentals\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Architecture as shown in the diagram below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017315579_0_4808194c6d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fcodewhitesec.blogspot.com\u002F2020\u002F07\u002Fsophos-xg-tale-of-unfortunate-re.html\u003C\u002Fp>\u003Cp>Overall, it is divided into the following three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Processes web data and forwards it to csc for further processing\u003C\u002Fli>\u003Cli>csc: Main program: Loads Perl Packages and implements core functionalities\u003C\u002Fli>\u003Cli>Postgresql: Used for data storage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my actual research, I encountered the following issues with these three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Unable to start Java after adding debugging information\u003C\u002Fli>\u003Cli>csc: csc automatically deletes after loading Perl Packages, making it impossible to obtain implementation details of the Perl Packages\u003C\u002Fli>\u003Cli>Postgresql: Low user privileges prevent querying database tables\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The following will introduce solutions to these three problems one by one\u003C\u002Fp>\u003Ch2>0x03 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.sophos.com\u002Fnsg\u002Fsophos-firewall\u002F18.5\u002FHelp\u002Fen-us\u002Fwebhelp\u002Fonlinehelp\u002FVirtualAndSoftwareAppliancesHelp\u002FVMware\u002FVMwareInstall\u002Findex.html\u003C\u002Fp>\u003Ch3>1. Download the installation package\u003C\u002Fh3>\u003Cp>The official website only provides downloads for the latest version by default, but older versions can be downloaded by guessing the correct version number\u003C\u002Fp>\u003Cp>For example, 18.5.3 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.3_MR-3.VMW-408.zip\u003C\u002Fp>\u003Cp>18.5.2 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.2_MR-2.VMW-380.zip\u003C\u002Fp>\u003Ch3>2. Import to VMware Workstation\u003C\u002Fh3>\u003Cp>After downloading the zip file, extract it and run sf_virtual.ovf\u003C\u002Fp>\u003Ch3>3. VMware Workstation network adapter configuration\u003C\u002Fh3>\u003Cp>Two network adapters, VMnet7 and VMnet8, need to be added. Set VMnet7 to Host-only with 172.16.16.0, and VMnet8 to NAT. The specific steps are as follows:\u003C\u002Fp>\u003Ch4>(1) VMnet7\u003C\u002Fh4>\u003Cp>Open VMware Workstation, then select Edit -&gt; Virtual Network Editor...\u003C\u002Fp>\u003Cp>Add Network... -&gt; VMnet7\u003C\u002Fp>\u003Cp>Set VMnet7 as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type: Host-only\u003C\u002Fli>\u003Cli>Subnet Address: 172.16.16.0\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) VMnet8\u003C\u002Fh4>\u003Cp>VMnet8 is set to:\u003C\u002Fp>\u003Cul>\u003Cli>Type: NAT\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Sophos XG Network Card Configuration\u003C\u002Fh3>\u003Cp>Network Adapter set to VMnet7\u003C\u002Fp>\u003Cp>Network Adapter 2 set to VMnet8\u003C\u002Fp>\u003Cp>Network Adapter 3 set to VMnet8\u003C\u002Fp>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017356017_1_6c75cdb1f2.png\">\u003C\u002Fp>\u003Ch3>5. Start Sophos XG\u003C\u002Fh3>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Ch3>6. View IP Address\u003C\u002Fh3>\u003Cp>Enter in sequence: 1. Network Configuration -&gt; 1. Interface Configuration\u003C\u002Fp>\u003Cp>Obtain LAN IP as 172.16.16.16\u003C\u002Fp>\u003Ch3>7. Access the web configuration page for activation\u003C\u002Fh3>\u003Cp>Access https:\u002F\u002F172.16.16.16:4444 via browser\u003C\u002Fp>\u003Cp>On the registration page, select: I don't have a serial number (start a trial)\u003C\u002Fp>\u003Cp>Proceed with registration as prompted\u003C\u002Fp>\u003Cp>After successful registration, re-access https:\u002F\u002F172.16.16.16:4444 for configuration\u003C\u002Fp>\u003Ch2>0x04 Jetty debugging environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Java process related information\u003C\u002Fh3>\u003Cp>Execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             3238   923 root     1393m  264m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the output, obtain Java version as java-11-openjdk\u003C\u002Fp>\u003Ch3>2. Locate configuration file\u003C\u002Fh3>\u003Cp>Configuration file path is \u002Fusr\u002Fbin\u002Fjetty, with content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>\u003Cbr>if   [ \"${RAM}\" == \"2GB\" ]; then\u003Cbr>        heap_size=256\u003Cbr>elif [ \"${RAM}\" == \"4GB\" ]; then\u003Cbr>        heap_size=384\u003Cbr>else\u003Cbr>        heap_size=512\u003Cbr>fi\u003Cbr>\u003Cbr>HYBRID_ENABLED=false\u003Cbr>\u003Cbr>if [ $HYBRID_ENABLED = true ]; then\u003Cbr>    HYBRID_ENABLED=`opcode gethainfo -s nosync | grep -q \"hamode=1\" &amp;&amp; echo \"true\" || echo \"false\"`\u003Cbr>fi\u003Cbr>if [ ! -d \u002Ftmp\u002Fjava ]; then\u003Cbr>    mkdir \u002Ftmp\u002Fjava\u003Cbr>fi\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\" \"mount\"\u003Cbr>\u003Cbr>##\u003Cbr># sun.jnu.encoding=UTF-8 - System property is required with file.encoding otherwise some java APIs unable to read file having double byte characters in file name.\u003Cbr>##\u003Cbr>exec \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx${heap_size}m -Xms12m -Xss256k \"-XX:MaxMetaspaceSize=100m\" \"-Dhybrid.enabled=${HYBRID_ENABLED}\" \"-Djna.tmpdir=\u002Ftmp\u002Fjava\" \"-Djava.io.tmpdir=\u002Ftmp\u002Fjava\" \"-Dsun.jnu.encoding=UTF-8\" \"-Dfile.encoding=UTF-8\" \"-Djava.awt.headless=true\" \"-Djetty.home=\u002Fusr\u002Fshare\u002Fjetty\" \"-Djetty.base=\u002Fusr\u002Fshare\u002Fjetty\" -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar \"--lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\"\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\"\u003Cbr>exit $?\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Add debugging parameters\u003C\u002Fh3>\u003Cp>Modify file attributes: mount -o rw,remount \u002F\u003C\u002Fp>\u003Cp>Add debugging parameters on the exec line: \"-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000\"\u003C\u002Fp>\u003Ch3>4. Restart service\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status is STOPPED\u003C\u002Fp>\u003Cp>To obtain detailed error information, directly run \u002Fusr\u002Fbin\u002Fjetty\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error occurred during initialization of VM\u003Cbr>Could not find agent library jdwp on the library path, with error: libjdwp.so: cannot open shared object file: No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Identified as a JDK issue, opting to replace with a complete JDK here\u003C\u002Fp>\u003Ch3>5. Replace JDK\u003C\u002Fh3>\u003Cp>Download jdk-11.0.15_linux-x64_bin.tar.gz and upload to Sophos XG\u003C\u002Fp>\u003Cp>Backup original folder: cp -r \u002Flib\u002Fjvm\u002Fjava-11-openjdk \u002Flib\u002Fjvm\u002Fjava-11-openjdk_backup\u003C\u002Fp>\u003Cp>Extract jdk-11.0.15_linux-x64_bin.tar.gz: tar zxvf \u002Ftmp\u002Fjdk-11.0.15_linux-x64_bin.tar.gz\u003C\u002Fp>\u003Cp>Replace \u002Flib\u002Fjvm\u002Fjava-11-openjdk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003Cbr>cp -r \u002Ftmp\u002Fjdk-11.0.15 \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Restart service again\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status as RUNNING\u003C\u002Fp>\u003Cp>Confirm parameters were modified, execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             1827   923 root     1454m  158m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000 -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Modify firewall rules\u003C\u002Fh3>\u003Cp>Execute command: iptables -I INPUT -p tcp --dport 8000 -j ACCEPT\u003C\u002Fp>\u003Ch3>8. Use IDEA for remote debugging\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017388600_2_54b8287203.png\">\u003C\u002Fp>\u003Cp>During debugging, if you encounter a situation where breakpoints cannot be set, restart the Java service: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Ch2>0x05 CSC configuration file decryption\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View CSC process related information\u003C\u002Fp>\u003Cp>Execute command: ps ww|grep csc\u003C\u002Fp>\u003Cp>Partial output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csc               859     1 root     25916 23600 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>csc               869   859 root      8628   452 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>cfs               870   859 root     34736 29380 S    {cfs} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>listener          871   859 root     21752 15088 S    {listener} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>lcdd              889   871 root     21108 13556 S    {lcdd} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>postgres          890   871 root     29712 25040 S    {postgres} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>sigdb             891   871 root     26756 23208 S    {sigdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>reportdb          892   871 root     26756 23104 S    {reportdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>awarrensmtp       893   871 root     25916 22296 S    {awarrensmtp} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The csc process reads \u002F_conf\u002Fcscconf.bin as the configuration file, and \u002F_conf\u002Fcscconf.bin is an encrypted file, so it is necessary to decrypt \u002F_conf\u002Fcscconf.bin here.\u003C\u002Fp>\u003Cp>The method I adopted here is to modify the program code through IDA, change the implementation logic, and export the decrypted configuration file.\u003C\u002Fp>\u003Cp>Load csc using IDA, examine the implementation logic of the main() function, partial code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signed int __cdecl csc_main(int a1, char *const *a2)\u003Cbr>{\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>  if ( strlen(v14) &gt; 4 )\u003Cbr>  {\u003Cbr>    v4 = strlen(v14);\u003Cbr>    if ( !strcmp(&amp;v14[v4 - 4], \".bin\") )\u003Cbr>    {\u003Cbr>      extract_conf((int)v14);\u003Cbr>      v17 = 1;\u003Cbr>      v14 = \"\u002F_conf\u002Fcsc\u002Fcsc.conf\";\u003Cbr>    }\u003Cbr>  }\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>    if ( v17 )\u003Cbr>      system(\u003Cbr>        \"rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.g\"\u003Cbr>        \"z \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list\");\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analyzing the above code, csc first calls the extract_conf() function to export configurations, and finally executes the system command rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list to delete configuration files, preventing us from directly obtaining the relevant configuration files.\u003C\u002Fp>\u003Cp>Examining the implementation code of the extract_conf() function:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int __cdecl extract_conf(int a1)\u003Cbr>{\u003Cbr>  int v2; \u002F\u002F [esp+18h] [ebp-10h]\u003Cbr>  unsigned int v3; \u002F\u002F [esp+1Ch] [ebp-Ch]\u003Cbr>\u003Cbr>  v3 = __readgsdword(0x14u);\u003Cbr>  system(\"mount --make-private \u002F_conf\u002Fcsc\");\u003Cbr>  if ( mount(\"none\", \"\u002F_conf\u002Fcsc\", \"tmpfs\", 0, 0) )\u003Cbr>  {\u003Cbr>    puts(\"mount tmpfs failed\");\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  v2 = sub_8052494(a1, \"\u002F_conf\u002Fcsc\u002Fcscconf.tar.gz\");\u003Cbr>  if ( v2 == -1 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  if ( v2 == -2 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file2  %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  system(\"tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc\");\u003Cbr>  return __readgsdword(0x14u) ^ v3;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on the analysis of the above code, csc first calls the sub_8052494() function to decrypt \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz, then executes the system command tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc to extract the configuration files to the folder \u002F_conf\u002Fcsc.\u003C\u002Fp>\u003Cp>Based on the comprehensive analysis above, we can adopt the following method to export the configuration files: modify the csc program to change the extraction path from \u002F_conf\u002Fcsc to another path, such as \u002Fvar\u002Faaaaa. Then, when csc attempts to delete the configuration files, it will fail because it specifies a fixed absolute path, preventing it from deleting the new folder. This allows us to obtain the complete configuration files.\u003C\u002Fp>\u003Cp>The specific implementation method is as follows:\u003C\u002Fp>\u003Ch4>(1) Modify csc\u003C\u002Fh4>\u003Cp>Load csc using IDA, view Exports, find extract_conf, double-click to enter IDA View, locate the string tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017416850_3_bffc7a633b.png\">\u003C\u002Fp>\u003Cp>Switch to Hex View, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017462276_4_96d5079147.png\">\u003C\u002Fp>\u003Cp>Change \u002F_conf\u002Fcsc to \u002Fvar\u002Faaaaa, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017478223_5_297a8b93ce.png\">\u003C\u002Fp>\u003Cp>Right-click and select Apply changes\u003C\u002Fp>\u003Cp>Select Edit-&gt;Patch program-&gt;Apply patches to input file...-&gt;OK in sequence to generate the new file csc\u003C\u002Fp>\u003Ch4>(2) Replace csc\u003C\u002Fh4>\u003Cp>Log in via SSH, upload the new file csc, save to \u002Ftmp\u002Fcsc\u003C\u002Fp>\u003Cp>Back up csc and replace it, execute the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc_original\u003Cbr>mkdir \u002Fvar\u002Faaaaa\u003Cbr>cp \u002Ftmp\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>chmod 755 \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>ll \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Confirm whether the configuration file was exported successfully\u003C\u002Fh4>\u003Cp>Wait for the system to reboot, enter the underlying shell, and sequentially input 5.Device Management-&gt;3.Advanced Shell\u003C\u002Fp>\u003Cp>Check the folder \u002Fvar\u002Faaaaa, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017488148_6_0a43185f68.png\">\u003C\u002Fp>\u003Cp>Configuration file exported successfully\u003C\u002Fp>\u003Ch4>(4) Restore csc\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc_original \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Download the configuration file\u003C\u002Fh4>\u003Cp>Log in via SSH and download the contents from the folder \u002Fvar\u002Faaaaa\u003C\u002Fp>\u003Ch2>0x06 PostgreSQL Database Query\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check port information by executing the command: netstat -tulpen | grep postgres\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      65534      3800       1087\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5433          0.0.0.0:*               LISTEN      65534      5846       1182\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5434          0.0.0.0:*               LISTEN      65534      5813       1161\u002Fpostgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Through investigation, it was found that the connection information for the above three databases corresponds to the following three files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPool.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForReports.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForSignature.cfg\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The configuration information in the files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5432\u002Fcorporate?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5433\u002Fiviewdb?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5434\u002Fsignature?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test command 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>corporate=&gt; \\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:  permission denied for relation pg_class\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates insufficient permissions\u003C\u002Fp>\u003Cp>Test command 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>select * from tbluser;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Able to retrieve user information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>User pgrouser has identical permissions as nobody\u003C\u002Fp>\u003Cp>From the above information, both users pgrouser and nobody are non-root users with limited functionality. Next, attempt to locate the root user\u003C\u002Fp>\u003Cp>Examine the decrypted csc configuration file, locate \\service\\postgres.csc. Key file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblhavmac -f \u002Ftmp\u002Fcorphavmac\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblinterface -t tblipaddress -f \u002Ftmp\u002Fcorpifdb\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -n config -T tbllivesslvpnusers -T tblhbcloudcredential -f \u002Ftmp\u002Fcorpdb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Locate the key user pgroot\u003C\u002Fp>\u003Cp>Test command 3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -U pgroot -d corporate\u003Cbr>\\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces solutions to some problems encountered during the setup of the Sophos XG debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Sophos UTM and Sophos XG are two distinct products; the former leans towards general threat management, while the latter focuses on hardware firewalls. This article will introduce the method for setting up a Sophos XG vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Jetty Debugging Environment Setup\u003C\u002Fli>\u003Cli>CSC Configuration File Decryption\u003C\u002Fli>\u003Cli>PostgreSQL Database Query\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Fundamentals\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Architecture as shown in the diagram below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017315579_0_4808194c6d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fcodewhitesec.blogspot.com\u002F2020\u002F07\u002Fsophos-xg-tale-of-unfortunate-re.html\u003C\u002Fp>\u003Cp>Overall, it is divided into the following three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Processes web data and forwards it to csc for further processing\u003C\u002Fli>\u003Cli>csc: Main program: Loads Perl Packages and implements core functionalities\u003C\u002Fli>\u003Cli>Postgresql: Used for data storage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my actual research, I encountered the following issues with these three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Unable to start Java after adding debugging information\u003C\u002Fli>\u003Cli>csc: csc automatically deletes after loading Perl Packages, making it impossible to obtain implementation details of the Perl Packages\u003C\u002Fli>\u003Cli>Postgresql: Low user privileges prevent querying database tables\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The following will introduce solutions to these three problems one by one\u003C\u002Fp>\u003Ch2>0x03 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.sophos.com\u002Fnsg\u002Fsophos-firewall\u002F18.5\u002FHelp\u002Fen-us\u002Fwebhelp\u002Fonlinehelp\u002FVirtualAndSoftwareAppliancesHelp\u002FVMware\u002FVMwareInstall\u002Findex.html\u003C\u002Fp>\u003Ch3>1. Download the installation package\u003C\u002Fh3>\u003Cp>The official website only provides downloads for the latest version by default, but older versions can be downloaded by guessing the correct version number\u003C\u002Fp>\u003Cp>For example, 18.5.3 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.3_MR-3.VMW-408.zip\u003C\u002Fp>\u003Cp>18.5.2 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.2_MR-2.VMW-380.zip\u003C\u002Fp>\u003Ch3>2. Import to VMware Workstation\u003C\u002Fh3>\u003Cp>After downloading the zip file, extract it and run sf_virtual.ovf\u003C\u002Fp>\u003Ch3>3. VMware Workstation network adapter configuration\u003C\u002Fh3>\u003Cp>Two network adapters, VMnet7 and VMnet8, need to be added. Set VMnet7 to Host-only with 172.16.16.0, and VMnet8 to NAT. The specific steps are as follows:\u003C\u002Fp>\u003Ch4>(1) VMnet7\u003C\u002Fh4>\u003Cp>Open VMware Workstation, then select Edit -&gt; Virtual Network Editor...\u003C\u002Fp>\u003Cp>Add Network... -&gt; VMnet7\u003C\u002Fp>\u003Cp>Set VMnet7 as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type: Host-only\u003C\u002Fli>\u003Cli>Subnet Address: 172.16.16.0\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) VMnet8\u003C\u002Fh4>\u003Cp>VMnet8 is set to:\u003C\u002Fp>\u003Cul>\u003Cli>Type: NAT\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Sophos XG Network Card Configuration\u003C\u002Fh3>\u003Cp>Network Adapter set to VMnet7\u003C\u002Fp>\u003Cp>Network Adapter 2 set to VMnet8\u003C\u002Fp>\u003Cp>Network Adapter 3 set to VMnet8\u003C\u002Fp>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017356017_1_6c75cdb1f2-1.png\">\u003C\u002Fp>\u003Ch3>5. Start Sophos XG\u003C\u002Fh3>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Ch3>6. View IP Address\u003C\u002Fh3>\u003Cp>Enter in sequence: 1. Network Configuration -&gt; 1. Interface Configuration\u003C\u002Fp>\u003Cp>Obtain LAN IP as 172.16.16.16\u003C\u002Fp>\u003Ch3>7. Access the web configuration page for activation\u003C\u002Fh3>\u003Cp>Access https:\u002F\u002F172.16.16.16:4444 via browser\u003C\u002Fp>\u003Cp>On the registration page, select: I don't have a serial number (start a trial)\u003C\u002Fp>\u003Cp>Proceed with registration as prompted\u003C\u002Fp>\u003Cp>After successful registration, re-access https:\u002F\u002F172.16.16.16:4444 for configuration\u003C\u002Fp>\u003Ch2>0x04 Jetty debugging environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Java process related information\u003C\u002Fh3>\u003Cp>Execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             3238   923 root     1393m  264m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the output, obtain Java version as java-11-openjdk\u003C\u002Fp>\u003Ch3>2. Locate configuration file\u003C\u002Fh3>\u003Cp>Configuration file path is \u002Fusr\u002Fbin\u002Fjetty, with content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>\u003Cbr>if   [ \"${RAM}\" == \"2GB\" ]; then\u003Cbr>        heap_size=256\u003Cbr>elif [ \"${RAM}\" == \"4GB\" ]; then\u003Cbr>        heap_size=384\u003Cbr>else\u003Cbr>        heap_size=512\u003Cbr>fi\u003Cbr>\u003Cbr>HYBRID_ENABLED=false\u003Cbr>\u003Cbr>if [ $HYBRID_ENABLED = true ]; then\u003Cbr>    HYBRID_ENABLED=`opcode gethainfo -s nosync | grep -q \"hamode=1\" &amp;&amp; echo \"true\" || echo \"false\"`\u003Cbr>fi\u003Cbr>if [ ! -d \u002Ftmp\u002Fjava ]; then\u003Cbr>    mkdir \u002Ftmp\u002Fjava\u003Cbr>fi\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\" \"mount\"\u003Cbr>\u003Cbr>##\u003Cbr># sun.jnu.encoding=UTF-8 - System property is required with file.encoding otherwise some java APIs unable to read file having double byte characters in file name.\u003Cbr>##\u003Cbr>exec \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx${heap_size}m -Xms12m -Xss256k \"-XX:MaxMetaspaceSize=100m\" \"-Dhybrid.enabled=${HYBRID_ENABLED}\" \"-Djna.tmpdir=\u002Ftmp\u002Fjava\" \"-Djava.io.tmpdir=\u002Ftmp\u002Fjava\" \"-Dsun.jnu.encoding=UTF-8\" \"-Dfile.encoding=UTF-8\" \"-Djava.awt.headless=true\" \"-Djetty.home=\u002Fusr\u002Fshare\u002Fjetty\" \"-Djetty.base=\u002Fusr\u002Fshare\u002Fjetty\" -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar \"--lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\"\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\"\u003Cbr>exit $?\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Add debugging parameters\u003C\u002Fh3>\u003Cp>Modify file attributes: mount -o rw,remount \u002F\u003C\u002Fp>\u003Cp>Add debugging parameters on the exec line: \"-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000\"\u003C\u002Fp>\u003Ch3>4. Restart service\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status is STOPPED\u003C\u002Fp>\u003Cp>To obtain detailed error information, directly run \u002Fusr\u002Fbin\u002Fjetty\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error occurred during initialization of VM\u003Cbr>Could not find agent library jdwp on the library path, with error: libjdwp.so: cannot open shared object file: No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Identified as a JDK issue, opting to replace with a complete JDK here\u003C\u002Fp>\u003Ch3>5. Replace JDK\u003C\u002Fh3>\u003Cp>Download jdk-11.0.15_linux-x64_bin.tar.gz and upload to Sophos XG\u003C\u002Fp>\u003Cp>Backup original folder: cp -r \u002Flib\u002Fjvm\u002Fjava-11-openjdk \u002Flib\u002Fjvm\u002Fjava-11-openjdk_backup\u003C\u002Fp>\u003Cp>Extract jdk-11.0.15_linux-x64_bin.tar.gz: tar zxvf \u002Ftmp\u002Fjdk-11.0.15_linux-x64_bin.tar.gz\u003C\u002Fp>\u003Cp>Replace \u002Flib\u002Fjvm\u002Fjava-11-openjdk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003Cbr>cp -r \u002Ftmp\u002Fjdk-11.0.15 \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Restart service again\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status as RUNNING\u003C\u002Fp>\u003Cp>Confirm parameters were modified, execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             1827   923 root     1454m  158m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000 -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Modify firewall rules\u003C\u002Fh3>\u003Cp>Execute command: iptables -I INPUT -p tcp --dport 8000 -j ACCEPT\u003C\u002Fp>\u003Ch3>8. Use IDEA for remote debugging\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017388600_2_54b8287203-1.png\">\u003C\u002Fp>\u003Cp>During debugging, if you encounter a situation where breakpoints cannot be set, restart the Java service: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Ch2>0x05 CSC configuration file decryption\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View CSC process related information\u003C\u002Fp>\u003Cp>Execute command: ps ww|grep csc\u003C\u002Fp>\u003Cp>Partial output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csc               859     1 root     25916 23600 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>csc               869   859 root      8628   452 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>cfs               870   859 root     34736 29380 S    {cfs} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>listener          871   859 root     21752 15088 S    {listener} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>lcdd              889   871 root     21108 13556 S    {lcdd} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>postgres          890   871 root     29712 25040 S    {postgres} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>sigdb             891   871 root     26756 23208 S    {sigdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>reportdb          892   871 root     26756 23104 S    {reportdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>awarrensmtp       893   871 root     25916 22296 S    {awarrensmtp} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The csc process reads \u002F_conf\u002Fcscconf.bin as the configuration file, and \u002F_conf\u002Fcscconf.bin is an encrypted file, so it is necessary to decrypt \u002F_conf\u002Fcscconf.bin here.\u003C\u002Fp>\u003Cp>The method I adopted here is to modify the program code through IDA, change the implementation logic, and export the decrypted configuration file.\u003C\u002Fp>\u003Cp>Load csc using IDA, examine the implementation logic of the main() function, partial code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signed int __cdecl csc_main(int a1, char *const *a2)\u003Cbr>{\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>  if ( strlen(v14) &gt; 4 )\u003Cbr>  {\u003Cbr>    v4 = strlen(v14);\u003Cbr>    if ( !strcmp(&amp;v14[v4 - 4], \".bin\") )\u003Cbr>    {\u003Cbr>      extract_conf((int)v14);\u003Cbr>      v17 = 1;\u003Cbr>      v14 = \"\u002F_conf\u002Fcsc\u002Fcsc.conf\";\u003Cbr>    }\u003Cbr>  }\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>    if ( v17 )\u003Cbr>      system(\u003Cbr>        \"rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.g\"\u003Cbr>        \"z \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list\");\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analyzing the above code, csc first calls the extract_conf() function to export configurations, and finally executes the system command rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list to delete configuration files, preventing us from directly obtaining the relevant configuration files.\u003C\u002Fp>\u003Cp>Examining the implementation code of the extract_conf() function:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int __cdecl extract_conf(int a1)\u003Cbr>{\u003Cbr>  int v2; \u002F\u002F [esp+18h] [ebp-10h]\u003Cbr>  unsigned int v3; \u002F\u002F [esp+1Ch] [ebp-Ch]\u003Cbr>\u003Cbr>  v3 = __readgsdword(0x14u);\u003Cbr>  system(\"mount --make-private \u002F_conf\u002Fcsc\");\u003Cbr>  if ( mount(\"none\", \"\u002F_conf\u002Fcsc\", \"tmpfs\", 0, 0) )\u003Cbr>  {\u003Cbr>    puts(\"mount tmpfs failed\");\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  v2 = sub_8052494(a1, \"\u002F_conf\u002Fcsc\u002Fcscconf.tar.gz\");\u003Cbr>  if ( v2 == -1 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  if ( v2 == -2 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file2  %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  system(\"tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc\");\u003Cbr>  return __readgsdword(0x14u) ^ v3;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on the analysis of the above code, csc first calls the sub_8052494() function to decrypt \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz, then executes the system command tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc to extract the configuration files to the folder \u002F_conf\u002Fcsc.\u003C\u002Fp>\u003Cp>Based on the comprehensive analysis above, we can adopt the following method to export the configuration files: modify the csc program to change the extraction path from \u002F_conf\u002Fcsc to another path, such as \u002Fvar\u002Faaaaa. Then, when csc attempts to delete the configuration files, it will fail because it specifies a fixed absolute path, preventing it from deleting the new folder. This allows us to obtain the complete configuration files.\u003C\u002Fp>\u003Cp>The specific implementation method is as follows:\u003C\u002Fp>\u003Ch4>(1) Modify csc\u003C\u002Fh4>\u003Cp>Load csc using IDA, view Exports, find extract_conf, double-click to enter IDA View, locate the string tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017416850_3_bffc7a633b-1.png\">\u003C\u002Fp>\u003Cp>Switch to Hex View, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017462276_4_96d5079147-1.png\">\u003C\u002Fp>\u003Cp>Change \u002F_conf\u002Fcsc to \u002Fvar\u002Faaaaa, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017478223_5_297a8b93ce-1.png\">\u003C\u002Fp>\u003Cp>Right-click and select Apply changes\u003C\u002Fp>\u003Cp>Select Edit-&gt;Patch program-&gt;Apply patches to input file...-&gt;OK in sequence to generate the new file csc\u003C\u002Fp>\u003Ch4>(2) Replace csc\u003C\u002Fh4>\u003Cp>Log in via SSH, upload the new file csc, save to \u002Ftmp\u002Fcsc\u003C\u002Fp>\u003Cp>Back up csc and replace it, execute the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc_original\u003Cbr>mkdir \u002Fvar\u002Faaaaa\u003Cbr>cp \u002Ftmp\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>chmod 755 \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>ll \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Confirm whether the configuration file was exported successfully\u003C\u002Fh4>\u003Cp>Wait for the system to reboot, enter the underlying shell, and sequentially input 5.Device Management-&gt;3.Advanced Shell\u003C\u002Fp>\u003Cp>Check the folder \u002Fvar\u002Faaaaa, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017488148_6_0a43185f68-1.png\">\u003C\u002Fp>\u003Cp>Configuration file exported successfully\u003C\u002Fp>\u003Ch4>(4) Restore csc\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc_original \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Download the configuration file\u003C\u002Fh4>\u003Cp>Log in via SSH and download the contents from the folder \u002Fvar\u002Faaaaa\u003C\u002Fp>\u003Ch2>0x06 PostgreSQL Database Query\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check port information by executing the command: netstat -tulpen | grep postgres\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      65534      3800       1087\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5433          0.0.0.0:*               LISTEN      65534      5846       1182\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5434          0.0.0.0:*               LISTEN      65534      5813       1161\u002Fpostgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Through investigation, it was found that the connection information for the above three databases corresponds to the following three files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPool.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForReports.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForSignature.cfg\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The configuration information in the files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5432\u002Fcorporate?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5433\u002Fiviewdb?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5434\u002Fsignature?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test command 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>corporate=&gt; \\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:  permission denied for relation pg_class\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates insufficient permissions\u003C\u002Fp>\u003Cp>Test command 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>select * from tbluser;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Able to retrieve user information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>User pgrouser has identical permissions as nobody\u003C\u002Fp>\u003Cp>From the above information, both users pgrouser and nobody are non-root users with limited functionality. Next, attempt to locate the root user\u003C\u002Fp>\u003Cp>Examine the decrypted csc configuration file, locate \\service\\postgres.csc. Key file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblhavmac -f \u002Ftmp\u002Fcorphavmac\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblinterface -t tblipaddress -f \u002Ftmp\u002Fcorpifdb\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -n config -T tbllivesslvpnusers -T tblhbcloudcredential -f \u002Ftmp\u002Fcorpdb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Locate the key user pgroot\u003C\u002Fp>\u003Cp>Test command 3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -U pgroot -d corporate\u003Cbr>\\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces solutions to some problems encountered during the setup of the Sophos XG debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1157,"Onedaysec",8,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Sophos XG Vulnerability Debugging: Setup Jetty, CSC, PostgreSQL","Sophos XG, vulnerability debugging, Jetty setup, CSC decryption, PostgreSQL query, environment configuration",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],444,443,441,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.310Z","2026-07-23T16:01:35.518Z","draft","2026-07-23T16:06:20.180Z"]