[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMrGPYztNDdlYuoxX7YUjeruOI2yI1IbTUy_Gz4hom3s":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1094,"How can I modify the GoAnywhere database when the service is not running?","When the GoAnywhere service is shut down, you can directly open the Derby database folder using tools like DBSchema or the Apache Derby `ij` command line. For example, to enable the root user, run: `UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';`. To set the root password, use the provided hash value. This method is described in the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup) article.","\u003Cp>When the GoAnywhere service is shut down, you can directly open the Derby database folder using tools like DBSchema or the Apache Derby `ij` command line. For example, to enable the root user, run: `UPDATE APP.DPA_USER SET ENABLED=&#39;1&#39; WHERE USER_NAME=&#39;root&#39;;`. To set the root password, use the provided hash value. This method is described in the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-modify-the-goanywhere-database-when-the-service-is-not-running-1777480526762","GoAnywhere, database modification, Apache Derby, root user, embedded database",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},266,"GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup","goanywhere-managed-file-transfer-vulnerability-debugging-environment-setup","Step-by-step guide to setting up GoAnywhere MFT vulnerability debugging environment: installation, Tomcat debug config, Apache Derby database access & operations.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Overview\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Need to register an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively.\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\tomcat\\\\webapps\\\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging feature\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Achieve this by enabling Tomcat's debugging feature; the method to enable Tomcat's debugging feature is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat's debugging feature is enabled, it listens on the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable the debugging feature is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the web port of GoAnywhere Managed File Transfer, so we choose to modify Tomcat's default debugging port to 8090 here\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>The default database storage location under Windows is: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>The default database storage location under Linux is: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396799505_0_eecd4bb00f.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command Line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere for the Folder\u003C\u002Fp>\u003Cp>Query the user data table as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396803305_1_c621efe1fc.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, not enabled\u003C\u002Fp>\u003Cp>root, not enabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode, which is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to learn about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Overview\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Need to register an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively.\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\tomcat\\\\webapps\\\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging feature\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Achieve this by enabling Tomcat's debugging feature; the method to enable Tomcat's debugging feature is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat's debugging feature is enabled, it listens on the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable the debugging feature is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the web port of GoAnywhere Managed File Transfer, so we choose to modify Tomcat's default debugging port to 8090 here\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>The default database storage location under Windows is: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>The default database storage location under Linux is: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396799505_0_eecd4bb00f-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command Line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere for the Folder\u003C\u002Fp>\u003Cp>Query the user data table as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396803305_1_c621efe1fc-1.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, not enabled\u003C\u002Fp>\u003Cp>root, not enabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode, which is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to learn about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",234,"Onedaysec",3,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"How to Set Up GoAnywhere MFT Vulnerability Debugging Environment","GoAnywhere MFT, vulnerability debugging environment setup, GoAnywhere installation, Tomcat remote debugging, Apache Derby database operations, GoAnywhere debug port, Derby database access",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1093,1092,1091,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.706Z","2026-07-23T16:02:31.429Z","draft","2026-07-23T16:16:38.111Z"]