[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fchzIR728uKDk0vOavuBgG0DgLwzW6BrpdXy0qOHibQo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1096,"How can I obtain the encrypted database password for the 'adap' user in ADAudit Plus?","The encrypted password is stored in `C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\database_params.conf`. Decrypt it using the `CryptoUtil.class` from `framework-tools.jar`, with the encryption key found in `customer-config.xml` under the `CryptTag` attribute. A custom decryption program can yield the plaintext password, which in the example is `Adaudit@123$`.","\u003Cp>The encrypted password is stored in `C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\database_params.conf`. Decrypt it using the `CryptoUtil.class` from `framework-tools.jar`, with the encryption key found in `customer-config.xml` under the `CryptTag` attribute. A custom decryption program can yield the plaintext password, which in the example is `Adaudit@123$`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fadaudit-plus-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-obtain-the-encrypted-database-password-for-the-adap-user-in-adaudit-pl-1777480539979","database password decryption, CryptoUtil, customer-config.xml, database_params.conf, PostgreSQL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},267,"ADAudit Plus Vulnerability Debugging Environment Setup","adaudit-plus-vulnerability-debugging-environment-setup","Learn to set up ADAudit Plus vulnerability debugging environment, configure debug parameters, and get PostgreSQL database user passwords (adap, postgres) with this guide.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>ADAudit Plus Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building an ADAudit Plus vulnerability debugging environment from scratch and introduces the method to obtain database user passwords.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>ADAudit Plus Installation\u003C\u002Fp>\u003Cp>ADAudit Plus Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database User Password Acquisition\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 ADAudit Plus Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Download\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Full version download address: https:\u002F\u002Farchives2.manageengine.com\u002Factive-directory-audit\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation reference: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Factive-directory-audit\u002Fquick-start-\u003Cstrong>guide-overview.html\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access https:\u002F\u002Flocalhost:8081\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 ADAudit Plus Vulnerability Debugging Environment Configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method is basically similar to the configuration of the Password Manager Pro vulnerability debugging environment\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable debugging\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Locate the configuration file\u003C\u002Fp>\u003Cp>Check the Java process information: there are two Java processes here, each corresponding to a different parent process wrapper.exe, as shown in the following figure\u003C\u002Fp>\u003Cp>The process parameters of wrapper.exe are as follows:\u003C\u002Fp>\u003Cp>\"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\Wrapper.exe\" -c \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\..\\conf\\wrapper.conf\"\u003C\u002Fp>\u003Cp>\"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\wrapper.exe\" -s \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\apps\\dataengine-xnode\\conf\\wrapper.conf\"\u003C\u002Fp>\u003Cp>The configuration file to be modified here is C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\wrapper.conf\u003C\u002Fp>\u003Cp>(2) Modify the configuration file to add debugging parameters\u003C\u002Fp>\u003Cp>Find the location to enable debugging:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396803824_0_d7441c77b1.png\">\u003C\u002Fp>\u003Cp>Modify it to:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396809129_1_8f28ead691.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Serial numbers need to be incremented sequentially; here, change wrapper.java.additional.3=-Xdebug to wrapper.java.additional.25=-Xdebug\u003C\u002Fp>\u003Cp>(3) Restart related processes\u003C\u002Fp>\u003Cp>Close the process wrapper.exe and its corresponding child process java.exe\u003C\u002Fp>\u003Cp>Execute the command in the command line:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396810924_2_d8dda0fa7d.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Location of common jar packages\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Path: C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\u003C\u002Fp>\u003Cp>The implementation files for web functions are AdventNetADAPServer.jar and AdventNetADAPClient.jar\u003C\u002Fp>\u003Cp>\u003Cstrong>3. IDEA Settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set to Remote JVM Debug, and the successful remote debugging is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396813576_3_84e99aa1b5.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Obtaining Database User Passwords\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under default configuration, ADAudit Plus uses PostgreSQL to store data, and two login users are configured by default: adap and postgres\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtaining the password for user adap\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Configuration file path: C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\database_params.conf, example content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396818397_4_a5a2599c82.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396822926_5_7dd303c5ed.png\">\u003C\u002Fp>\u003Cp>Here, the password is encrypted; the encryption and decryption algorithm is located at: com.zoho.framework.utils.crypto-&gt;CryptoUtil.class in C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\\framework-tools.jar\u003C\u002Fp>\u003Cp>After code analysis, the following decryption method is derived:\u003C\u002Fp>\u003Cp>The key is fixed in C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\customer-config.xml, example content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396825507_6_a978067166.png\">\u003C\u002Fp>\u003Cp>Obtain the key: CryptTag is 8ElrDgofXtbrMAtNQBqy\u003C\u002Fp>\u003Cp>Based on the ciphertext cb26b920b56fed8d085d71f63bdd79c55ea7b98f8794699562c06ea1bedbec52087b394f and key 8ElrDgofXtbrMAtNQBqy obtained above, write a decryption program. The code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396828715_7_52231157cb.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396832899_8_147e31d09c.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396837544_9_2f9517578d.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396841902_10_d60e4a4dbe.png\">\u003C\u002Fp>\u003Cp>After running the program, the decryption result is: Adaudit@123$\u003C\u002Fp>\u003Cp>Concatenate the database connection command: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=33307 dbname=adap user=adaudit password=Adaudit@123$\"\u003C\u002Fp>\u003Cp>Connection successful, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396843333_11_bb4d4324aa.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Obtaining the password for user postgres\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The password is hard-coded in com.adventnet.sym.adsm.common.server.mssql.tools-&gt;ChangeDBServer.class-&gt;isDBServerRunning() within C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\\AdventnetADAPServer.jar, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396843849_12_dac1ef1ee3.png\">\u003C\u002Fp>\u003Cp>Obtain the password for user postgres as Stonebraker\u003C\u002Fp>\u003Cp>Concatenate the database connection command: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=33307 dbname=adap user=postgres password=Stonebraker\"\u003C\u002Fp>\u003Cp>Connection successful, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396845784_13_121dd3666d.png\">\u003C\u002Fp>\u003Cp>An example command to connect to the database and execute database operations in one line: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" --command=\"SELECT * FROM public.aaapassword ORDER BY password_id ASC;\" postgresql:\u002F\u002Fpostgres:Stonebraker@127.0.0.1:33307\u002Fadap\u003C\u002Fp>\u003Cp>Example of returned result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396846431_14_e4b9ec19f4.png\">\u003C\u002Fp>\u003Cp>It is found that the data content of the password is encrypted\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the ADAudit Plus vulnerability debugging environment, we can then start learning about the vulnerabilities.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>ADAudit Plus Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building an ADAudit Plus vulnerability debugging environment from scratch and introduces the method to obtain database user passwords.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>ADAudit Plus Installation\u003C\u002Fp>\u003Cp>ADAudit Plus Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database User Password Acquisition\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 ADAudit Plus Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Download\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Full version download address: https:\u002F\u002Farchives2.manageengine.com\u002Factive-directory-audit\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation reference: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Factive-directory-audit\u002Fquick-start-\u003Cstrong>guide-overview.html\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access https:\u002F\u002Flocalhost:8081\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 ADAudit Plus Vulnerability Debugging Environment Configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method is basically similar to the configuration of the Password Manager Pro vulnerability debugging environment\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable debugging\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Locate the configuration file\u003C\u002Fp>\u003Cp>Check the Java process information: there are two Java processes here, each corresponding to a different parent process wrapper.exe, as shown in the following figure\u003C\u002Fp>\u003Cp>The process parameters of wrapper.exe are as follows:\u003C\u002Fp>\u003Cp>\"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\Wrapper.exe\" -c \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\..\\conf\\wrapper.conf\"\u003C\u002Fp>\u003Cp>\"C:\\Program Files\\ManageEngine\\ADAudit Plus\\bin\\wrapper.exe\" -s \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\apps\\dataengine-xnode\\conf\\wrapper.conf\"\u003C\u002Fp>\u003Cp>The configuration file to be modified here is C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\wrapper.conf\u003C\u002Fp>\u003Cp>(2) Modify the configuration file to add debugging parameters\u003C\u002Fp>\u003Cp>Find the location to enable debugging:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396803824_0_d7441c77b1-1.png\">\u003C\u002Fp>\u003Cp>Modify it to:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396809129_1_8f28ead691-1.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Serial numbers need to be incremented sequentially; here, change wrapper.java.additional.3=-Xdebug to wrapper.java.additional.25=-Xdebug\u003C\u002Fp>\u003Cp>(3) Restart related processes\u003C\u002Fp>\u003Cp>Close the process wrapper.exe and its corresponding child process java.exe\u003C\u002Fp>\u003Cp>Execute the command in the command line:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396810924_2_d8dda0fa7d-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Location of common jar packages\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Path: C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\u003C\u002Fp>\u003Cp>The implementation files for web functions are AdventNetADAPServer.jar and AdventNetADAPClient.jar\u003C\u002Fp>\u003Cp>\u003Cstrong>3. IDEA Settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set to Remote JVM Debug, and the successful remote debugging is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396813576_3_84e99aa1b5-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Obtaining Database User Passwords\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under default configuration, ADAudit Plus uses PostgreSQL to store data, and two login users are configured by default: adap and postgres\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtaining the password for user adap\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Configuration file path: C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\database_params.conf, example content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396818397_4_a5a2599c82-1.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396822926_5_7dd303c5ed-1.png\">\u003C\u002Fp>\u003Cp>Here, the password is encrypted; the encryption and decryption algorithm is located at: com.zoho.framework.utils.crypto-&gt;CryptoUtil.class in C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\\framework-tools.jar\u003C\u002Fp>\u003Cp>After code analysis, the following decryption method is derived:\u003C\u002Fp>\u003Cp>The key is fixed in C:\\Program Files\\ManageEngine\\ADAudit Plus\\conf\\customer-config.xml, example content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396825507_6_a978067166-1.png\">\u003C\u002Fp>\u003Cp>Obtain the key: CryptTag is 8ElrDgofXtbrMAtNQBqy\u003C\u002Fp>\u003Cp>Based on the ciphertext cb26b920b56fed8d085d71f63bdd79c55ea7b98f8794699562c06ea1bedbec52087b394f and key 8ElrDgofXtbrMAtNQBqy obtained above, write a decryption program. The code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396828715_7_52231157cb-1.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396832899_8_147e31d09c-1.png\">\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396837544_9_2f9517578d-1.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396841902_10_d60e4a4dbe-1.png\">\u003C\u002Fp>\u003Cp>After running the program, the decryption result is: Adaudit@123$\u003C\u002Fp>\u003Cp>Concatenate the database connection command: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=33307 dbname=adap user=adaudit password=Adaudit@123$\"\u003C\u002Fp>\u003Cp>Connection successful, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396843333_11_bb4d4324aa-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Obtaining the password for user postgres\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The password is hard-coded in com.adventnet.sym.adsm.common.server.mssql.tools-&gt;ChangeDBServer.class-&gt;isDBServerRunning() within C:\\Program Files\\ManageEngine\\ADAudit Plus\\lib\\AdventnetADAPServer.jar, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396843849_12_dac1ef1ee3-1.png\">\u003C\u002Fp>\u003Cp>Obtain the password for user postgres as Stonebraker\u003C\u002Fp>\u003Cp>Concatenate the database connection command: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=33307 dbname=adap user=postgres password=Stonebraker\"\u003C\u002Fp>\u003Cp>Connection successful, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396845784_13_121dd3666d-1.png\">\u003C\u002Fp>\u003Cp>An example command to connect to the database and execute database operations in one line: \"C:\\Program Files\\ManageEngine\\ADAudit Plus\\pgsql\\bin\\psql\" --command=\"SELECT * FROM public.aaapassword ORDER BY password_id ASC;\" postgresql:\u002F\u002Fpostgres:Stonebraker@127.0.0.1:33307\u002Fadap\u003C\u002Fp>\u003Cp>Example of returned result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】ADAudit Plus漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396846431_14_e4b9ec19f4-1.png\">\u003C\u002Fp>\u003Cp>It is found that the data content of the password is encrypted\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the ADAudit Plus vulnerability debugging environment, we can then start learning about the vulnerabilities.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",219,"Onedaysec",3,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"ADAudit Plus Vulnerability Debug Env Setup & DB Password Guide","ADAudit Plus, vulnerability debugging environment setup, database password acquisition, remote JVM debug, PostgreSQL password, ManageEngine ADAudit Plus, IDEA remote debug, wrapper.conf configuration",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1098,1097,1095,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.681Z","2026-07-23T16:02:31.601Z","draft","2026-07-23T16:16:38.623Z"]