[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f76kq7Wr2zx6M8tHDvQB78Rzsgnbcia3PJOj-w9PFFBk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},226,"How do I change an administrator password in the GoAnywhere MFT database?","To change a password, you need the hashed value. The article provides a Java code snippet that uses `PasswordHashFactory` to generate a hash (e.g., for `Password@123456`). Once you have the hash, run an SQL update on the database: `UPDATE APP.DPA_USER SET USER_PASS='\u003Chash>' WHERE USER_NAME='root';`. This can be done via Derby command line or DBSchema when GoAnywhere is not running, or through a JSP file when the service is active. Refer to the [database operations](\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment#0x03-database-operations) portion for exact commands.","\u003Cp>To change a password, you need the hashed value. The article provides a Java code snippet that uses `PasswordHashFactory` to generate a hash (e.g., for `Password@123456`). Once you have the hash, run an SQL update on the database: `UPDATE APP.DPA_USER SET USER_PASS=&#39;&lt;hash&gt;&#39; WHERE USER_NAME=&#39;root&#39;;`. This can be done via Derby command line or DBSchema when GoAnywhere is not running, or through a JSP file when the service is active. Refer to the [database operations](\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment#0x03-database-operations) portion for exact commands.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-change-an-administrator-password-in-the-goanywhere-mft-database-1777484611559","password hash, PasswordHashFactory, administrator, database update",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},59,"Setting up GoAnywhere Managed File Transfer Vulnerability Debugging Environment","setting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment","Step-by-step guide to install and configure GoAnywhere Managed File Transfer for vulnerability debugging, including database operations and debugging setup.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>GoAnywhere Managed File Transfer Installation\u003C\u002Fli>\u003Cli>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Operations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download URL: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Registration required to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed separately on Windows and Linux operating systems\u003C\u002Fp>\u003Cp>Default web path on Windows system: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default web path on Linux system: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Ch3>1. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Achieved by enabling Tomcat debugging function. The method to enable Tomcat debugging is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Switch to the bin directory\u003C\u002Fli>\u003Cli>Execute command: catalina jpda start\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After Tomcat debugging function is enabled, it listens on local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Ch4>(1) Debugging on Windows\u003C\u002Fh4>\u003Cp>Modify file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to Java tab, add in Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018736193_0_ace76b8282.png\">\u003C\u002Fp>\u003Cp>Restart GoAnywhere service\u003C\u002Fp>\u003Ch4>(2) Linux debugging\u003C\u002Fh4>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tomcat's default debug port 8000 conflicts with GoAnywhere Managed File Transfer's web port, so here we choose to modify Tomcat's default debug port to 8090\u003C\u002Fp>\u003Cp>Open firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Ch2>0x03 Database Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location on Windows: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location on Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this we can get the implementation details of web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>Extracted Java implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import com.linoma.commons.crypto.PasswordHash;\u003Cbr>import com.linoma.commons.crypto.PasswordHashFactory;\u003Cbr>import com.linoma.dpa.util.SystemInfo;\u003Cbr>public class Main {\u003Cbr>    public static void main(String[] args) throws Exception, Exception {\u003Cbr>        PasswordHash var2 = PasswordHashFactory.getPasswordHash(SystemInfo.getPasswordHashAlgorithm(), \"\");\u003Cbr>        String var3 = var2.hash(\"Password@123456\");\u003Cbr>        System.out.println(var3);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Reading Derby Database\u003C\u002Fh3>\u003Ch4>(1) Command Line Implementation\u003C\u002Fh4>\u003Cp>Using Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Ch4>(2) GUI Implementation\u003C\u002Fh4>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere as the Folder\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018746450_1_5c8f983b92.png\">\u003C\u002Fp>\u003Cp>It can be seen that the default users are the following three:\u003C\u002Fp>\u003Cul>\u003Cli>Administrator, disabled\u003C\u002Fli>\u003Cli>root, disabled\u003C\u002Fli>\u003Cli>admin, default user\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify the Database\u003C\u002Fh3>\u003Cp>GoAnywhere Managed File Transfer's Derby database uses embedded mode, which is not accessible by other applications, so there are two methods to modify the data:\u003C\u002Fp>\u003Ch4>(1) GoAnywhere Managed File Transfer is in a running state\u003C\u002Fh4>\u003Cp>Database modification can be achieved by writing a jsp file\u003C\u002Fp>\u003Ch4>(2) GoAnywhere Managed File Transfer is in a closed state\u003C\u002Fh4>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and directly modify it\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>GoAnywhere Managed File Transfer Installation\u003C\u002Fli>\u003Cli>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Operations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download URL: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Registration required to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed separately on Windows and Linux operating systems\u003C\u002Fp>\u003Cp>Default web path on Windows system: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default web path on Linux system: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Ch3>1. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Achieved by enabling Tomcat debugging function. The method to enable Tomcat debugging is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Switch to the bin directory\u003C\u002Fli>\u003Cli>Execute command: catalina jpda start\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After Tomcat debugging function is enabled, it listens on local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Ch4>(1) Debugging on Windows\u003C\u002Fh4>\u003Cp>Modify file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to Java tab, add in Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018736193_0_ace76b8282-1.png\">\u003C\u002Fp>\u003Cp>Restart GoAnywhere service\u003C\u002Fp>\u003Ch4>(2) Linux debugging\u003C\u002Fh4>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tomcat's default debug port 8000 conflicts with GoAnywhere Managed File Transfer's web port, so here we choose to modify Tomcat's default debug port to 8090\u003C\u002Fp>\u003Cp>Open firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Ch2>0x03 Database Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location on Windows: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location on Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this we can get the implementation details of web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>Extracted Java implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import com.linoma.commons.crypto.PasswordHash;\u003Cbr>import com.linoma.commons.crypto.PasswordHashFactory;\u003Cbr>import com.linoma.dpa.util.SystemInfo;\u003Cbr>public class Main {\u003Cbr>    public static void main(String[] args) throws Exception, Exception {\u003Cbr>        PasswordHash var2 = PasswordHashFactory.getPasswordHash(SystemInfo.getPasswordHashAlgorithm(), \"\");\u003Cbr>        String var3 = var2.hash(\"Password@123456\");\u003Cbr>        System.out.println(var3);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Reading Derby Database\u003C\u002Fh3>\u003Ch4>(1) Command Line Implementation\u003C\u002Fh4>\u003Cp>Using Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Ch4>(2) GUI Implementation\u003C\u002Fh4>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere as the Folder\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018746450_1_5c8f983b92-1.png\">\u003C\u002Fp>\u003Cp>It can be seen that the default users are the following three:\u003C\u002Fp>\u003Cul>\u003Cli>Administrator, disabled\u003C\u002Fli>\u003Cli>root, disabled\u003C\u002Fli>\u003Cli>admin, default user\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify the Database\u003C\u002Fh3>\u003Cp>GoAnywhere Managed File Transfer's Derby database uses embedded mode, which is not accessible by other applications, so there are two methods to modify the data:\u003C\u002Fp>\u003Ch4>(1) GoAnywhere Managed File Transfer is in a running state\u003C\u002Fh4>\u003Cp>Database modification can be achieved by writing a jsp file\u003C\u002Fp>\u003Ch4>(2) GoAnywhere Managed File Transfer is in a closed state\u003C\u002Fh4>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and directly modify it\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1502,"Onedaysec",3,"published","2026-02-02T08:07:54.308Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Setup GoAnywhere MFT Vulnerability Debugging Environment Guide","GoAnywhere MFT, vulnerability debugging, installation, database setup, Tomcat debugging, Derby database",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],227,225,224,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.629Z","2026-07-23T16:01:12.900Z","draft","2026-07-23T16:04:40.020Z"]