[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXEWNiKaKSw7jEebLD7RS25WzcPteGS-jAo-1wEPFPbg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},995,"How do I connect to the PostgreSQL database used by Password Manager Pro?","Use the `psql` client bundled with Password Manager Pro. The connection string from `database_params.conf` uses `localhost` but fails due to SSL mismatch; replace `localhost` with `127.0.0.1`. Example command: `\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv\"`. For single commands, use the URI format: `psql --command=\"SELECT * FROM table;\" postgresql:\u002F\u002Fpmpuser:Eq5XZiQpHv@127.0.0.1:2345\u002FPassTrix`, as shown in the [database connection section](\u002Fnews\u002Fpassword-manager-pro-vulnerability-debugging-environment-setup).","\u003Cp>Use the `psql` client bundled with Password Manager Pro. The connection string from `database_params.conf` uses `localhost` but fails due to SSL mismatch; replace `localhost` with `127.0.0.1`. Example command: `&quot;C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql&quot; &quot;host=127.0.0.1 port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv&quot;`. For single commands, use the URI format: `psql --command=&quot;SELECT * FROM table;&quot; postgresql:\u002F\u002Fpmpuser:Eq5XZiQpHv@127.0.0.1:2345\u002FPassTrix`, as shown in the [database connection section](\u002Fnews\u002Fpassword-manager-pro-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpassword-manager-pro-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-connect-to-the-postgresql-database-used-by-password-manager-pro-1777481078046","PostgreSQL connection, psql, database_params.conf, 127.0.0.1, PassTrix",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},244,"Password Manager Pro Vulnerability Debugging Environment Setup","password-manager-pro-vulnerability-debugging-environment-setup","Step-by-step guide to set up a Password Manager Pro vulnerability debugging environment, covering installation, configuration, and database setup for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a Password Manager Pro vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Password Manager Pro Installation\u003C\u002Fli>\u003Cli>Password Manager Pro Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Connection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Password Manager Pro Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>Latest version download link: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Fpasswordmanagerpro\u002Fdownload.html\u003C\u002Fp>\u003Cp>Older versions download link: https:\u002F\u002Farchives2.manageengine.com\u002Fpasswordmanagerpro\u002F\u003C\u002Fp>\u003Cp>The latest version offers a 30-day free trial by default, while older versions require a valid License for use.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During my testing, I concluded that without a valid License, older versions can only be launched once; a second launch will prompt that there is no valid License.\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>System Requirements: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Fpasswordmanagerpro\u002Fsystem-requirements.html\u003C\u002Fp>\u003Cp>For Windows systems, Windows 7 or above is required; Windows 7 is not supported.\u003C\u002Fp>\u003Cp>Default installation path: C:\\Program Files\\ManageEngine\\PMP\u003C\u002Fp>\u003Ch3>3. Testing\u003C\u002Fh3>\u003Cp>After successful installation, select Start PMP Service.\u003C\u002Fp>\u003Cp>Access https:\u002F\u002Flocalhost:7272\u003C\u002Fp>\u003Cp>Default login username: admin\u003C\u002Fp>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016179499_0_bf444baad3.png\">\u003C\u002Fp>\u003Ch2>0x03 Password Manager Pro Vulnerability Debugging Environment Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses the Windows environment as an example.\u003C\u002Fp>\u003Ch3>1. Password Manager Pro Setup\u003C\u002Fh3>\u003Cp>View the related processes after the service starts, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016182031_1_65be89f6eb.png\">\u003C\u002Fp>\u003Cp>Java process startup parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"..\\jre\\bin\\java\" -Dcatalina.home=.. -Dserver.home=.. -Dserver.stats=1000 -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.util.logging.config.file=..\u002Fconf\u002Flogging.properties -Djava.util.logging.config.class=com.adventnet.logging.LoggingScanner -Dlog.dir=.. -Ddb.home=..\u002Fpgsql -Ddatabaseparams.file=.\u002F..\u002Fconf\u002Fdatabase_params.conf -Dstart.webclient=false -Dgen.db.password=true -Dsplashscreen.progress.color=7515939 -Dsplashscreen.fontforeground.color=7515939 -Dsplashscreen.fontbackground.color=-1 -Dsplash.filename=..\u002Fimages\u002Fpasstrix_splash.png -Dsplashscreen.font.color=black -Djava.io.tmpdir=..\u002Flogs -DcontextDIR=PassTrix -Dcli.debug=false -DADUserNameSyntax=domain.backslash.username -Duser.home=..\u002Flogs\u002F -Dnet.phonefactor.pfsdk.debug=false -server -Dfile.encoding=UTF8 -Duser.language=en -Xms50m -Xmx512m -Djava.library.path=\"..\u002Flib\u002Fnative\" -classpath \"..\u002Flib\u002Fwrapper.jar;..\u002Flib\u002Ftomcat\u002Ftomcat-juli.jar;run.jar;..\u002Ftools.jar;..\u002Flib\u002FAdventNetNPrevalent.jar;..\u002Flib\u002F;..\u002Flib\u002FAdventNetUpdateManagerInstaller.jar;..\u002Flib\u002Fconf.jar\" -Dwrapper.key=\"7ofvurNLTVkDioN9w9Efmug_bEFaMg-M\" -Dwrapper.port=32000 -Dwrapper.jvm.port.min=31000 -Dwrapper.jvm.port.max=31999 -Dwrapper.pid=2744 -Dwrapper.version=\"3.5.25-pro\" -Dwrapper.native_library=\"wrapper\" -Dwrapper.arch=\"x86\" -Dwrapper.service=\"TRUE\" -Dwrapper.cpu.timeout=\"10\" -Dwrapper.jvmid=1 -Dwrapper.lang.domain=wrapper -Dwrapper.lang.folder=..\u002Flang org.tanukisoftware.wrapper.WrapperSimpleApp com.adventnet.mfw.Starter\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parent process of the Java process is wrapper.exe, with startup parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\bin\\wrapper.exe\" -s \"C:\\Program Files\\ManageEngine\\PMP\\conf\\wrapper.conf\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check the file C:\\Program Files\\ManageEngine\\PAM360\\conf\\wrapper.conf to locate where debugging is enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#uncomment the following to enable JPDA debugging\u003Cbr>#wrapper.java.additional.27=-Xdebug\u003Cbr>#wrapper.java.additional.28=-Xnoagent\u003Cbr>#wrapper.java.additional.29=-Xrunjdwp:transport=dt_socket,address=8787,server=y,suspend=n\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After uncommenting, the content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wrapper.java.additional.27=-Xdebug\u003Cbr>wrapper.java.additional.28=-Xnoagent\u003Cbr>wrapper.java.additional.29=-Xrunjdwp:transport=dt_socket,address=8787,server=y,suspend=n\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Do not set the Address configuration as address=*:8787, as it will cause ERROR: transport error 202: gethostbyname: unknown host. Setting address=8787 will enable remote debugging functionality.\u003C\u002Fp>\u003Cp>Restart the service and check the Java process parameters again: wmic process where name=\"java.exe\" get commandline\u003C\u002Fp>\u003Cp>Configuration modified successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016183355_2_b7ae11ac0e.png\">\u003C\u002Fp>\u003Ch3>2. Common JAR Package Locations\u003C\u002Fh3>\u003Cp>Path: C:\\Program Files\\ManageEngine\\PMP\\lib\u003C\u002Fp>\u003Cp>The implementation file for web functionality is AdventNetPassTrix.jar\u003C\u002Fp>\u003Ch3>3. IDEA Settings\u003C\u002Fh3>\u003Cp>Remote debugging settings are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016185424_3_0c3ff80822.png\">\u003C\u002Fp>\u003Cp>Remote debugging successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016186594_4_8ba4703e10.png\">\u003C\u002Fp>\u003Ch2>0x04 Database Connection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By default, Password Manager Pro uses PostgreSQL to store data\u003C\u002Fp>\u003Cp>Configuration file path: C:\\Program Files\\ManageEngine\\PMP\\conf\\database_params.conf\u003C\u002Fp>\u003Cp>Example content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp># $Id$\u003Cbr># driver name\u003Cbr>drivername=org.postgresql.Driver\u003Cbr>\u003Cbr># login username for database if any\u003Cbr>username=pmpuser\u003Cbr>\u003Cbr># password for the db can be specified here\u003Cbr>password=fCYxcAlHx+u\u002FJ+aWJFgCJ3vz+U69Uj4i\u002F9U=\u003Cbr># url is of the form jdbc:subprotocol:DataSourceName for eg.jdbc:odbc:WebNmsDB\u003Cbr>url=jdbc:postgresql:\u002F\u002Flocalhost:2345\u002FPassTrix?ssl=require\u003Cbr>\u003Cbr># Minimum Connection pool size\u003Cbr>minsize=1\u003Cbr>\u003Cbr># Maximum Connection pool size\u003Cbr>maxsize=20\u003Cbr>\u003Cbr># Transaction Isolation level\u003Cbr># Values are constants defined in java.sql.Connection type supported TRANSACTION_NONE    0\u003Cbr># Allowed values are TRANSACTION_READ_COMMITTED, TRANSACTION_READ_UNCOMMITTED, TRANSACTION_REPEATABLE_READ, TRANSACTION_SERIALIZABLE\u003Cbr>transaction_isolation=TRANSACTION_READ_COMMITTED\u003Cbr>exceptionsorterclassname=com.adventnet.db.adapter.postgres.PostgresExceptionSorter\u003Cbr>\u003Cbr># Check if the database password is encrypted or not\u003Cbr>db.password.encrypted=true\u003Cbr>new_superuser_pass=dnKkx6zgLPOsNhc7IpO\u002FXwBo1ZSdrZ7QoNQ=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Password Cracking\u003C\u002Fh3>\u003Cp>The database connection password is encrypted. The encryption\u002Fdecryption algorithm is located in com.adventnet.passtrix.ed.PMPEncryptDecryptImpl.class within C:\\Program Files\\ManageEngine\\PMP\\lib\\AdventNetPassTrix.jar\u003C\u002Fp>\u003Cp>The fixed key is stored in com.adventnet.passtrix.db.PMPDBPasswordGenerator.class, with the content @dv3n7n3tP@55Tri*\u003C\u002Fp>\u003Cp>We can quickly write a decryption program based on the content in PMPEncryptDecryptImpl.class.\u003C\u002Fp>\u003Cp>For the decryption program, refer to: https:\u002F\u002Fwww.shielder.com\u002Fblog\u002F2022\u002F09\u002Fhow-to-decrypt-manage-engine-pmp-passwords-for-fun-and-domain-admin-a-red-teaming-tale\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The decryption of database passwords in the article is correct, but there is a bug in the Master Key decryption. The solution will be introduced in a later article.\u003C\u002Fp>\u003Cp>The decrypted connection password is Eq5XZiQpHv.\u003C\u002Fp>\u003Ch3>2. Database Connection\u003C\u002Fh3>\u003Cp>Construct the database connection command based on the configuration file.\u003C\u002Fp>\u003Ch4>(1) Failed command\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\" \"host=localhost port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connection failed with error: psql: FATAL: no pg_hba.conf entry for host \"::1\", user \"pmpuser\", database \"PassTrix\", SSL on\u003C\u002Fp>\u003Ch4>(2) Successful command\u003C\u002Fh4>\u003Cp>Replace localhost with 127.0.0.1 to connect successfully. The complete command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) A single command to connect to the database and perform database operations\u003C\u002Fh4>\u003Cp>Format: psql --command=\"SELECT * FROM table;\" postgresql:\u002F\u002F\u003Cuser>:\u003Cpassword>@\u003Chost>:\u003Cport>\u002F\u003Cdb>\u003C\u002Fdb>\u003C\u002Fport>\u003C\u002Fhost>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\"  --command=\"select * from DBCredentialsAudit;\" postgresql:\u002F\u002Fpmpuser:Eq5XZiQpHv@127.0.0.1:2345\u002FPassTrix\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> username |                                                                         password                                                                         |   last_modified_time\u003Cbr>----------+----------------------------------------------------------------------------------------------------------------------------------------------------------+-------------------------\u003Cbr> postgres | \\xc30c0409010246e50cc723070408d23b0187325463ff95c0ff5c8f9013e7a37f424b5e0d1f2c11ce97c7184e112cd81536ac90937f99838124dee88239d9444ba8aff26f1a9ff29f22f4b5 | 2022-09-01 11:11:11.111\u003Cbr>(1 row)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found that the password data content is encrypted\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the Password Manager Pro vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a Password Manager Pro vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Password Manager Pro Installation\u003C\u002Fli>\u003Cli>Password Manager Pro Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Connection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Password Manager Pro Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>Latest version download link: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Fpasswordmanagerpro\u002Fdownload.html\u003C\u002Fp>\u003Cp>Older versions download link: https:\u002F\u002Farchives2.manageengine.com\u002Fpasswordmanagerpro\u002F\u003C\u002Fp>\u003Cp>The latest version offers a 30-day free trial by default, while older versions require a valid License for use.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During my testing, I concluded that without a valid License, older versions can only be launched once; a second launch will prompt that there is no valid License.\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>System Requirements: https:\u002F\u002Fwww.manageengine.com\u002Fproducts\u002Fpasswordmanagerpro\u002Fsystem-requirements.html\u003C\u002Fp>\u003Cp>For Windows systems, Windows 7 or above is required; Windows 7 is not supported.\u003C\u002Fp>\u003Cp>Default installation path: C:\\Program Files\\ManageEngine\\PMP\u003C\u002Fp>\u003Ch3>3. Testing\u003C\u002Fh3>\u003Cp>After successful installation, select Start PMP Service.\u003C\u002Fp>\u003Cp>Access https:\u002F\u002Flocalhost:7272\u003C\u002Fp>\u003Cp>Default login username: admin\u003C\u002Fp>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016179499_0_bf444baad3-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Password Manager Pro Vulnerability Debugging Environment Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses the Windows environment as an example.\u003C\u002Fp>\u003Ch3>1. Password Manager Pro Setup\u003C\u002Fh3>\u003Cp>View the related processes after the service starts, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016182031_1_65be89f6eb-1.png\">\u003C\u002Fp>\u003Cp>Java process startup parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"..\\jre\\bin\\java\" -Dcatalina.home=.. -Dserver.home=.. -Dserver.stats=1000 -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.util.logging.config.file=..\u002Fconf\u002Flogging.properties -Djava.util.logging.config.class=com.adventnet.logging.LoggingScanner -Dlog.dir=.. -Ddb.home=..\u002Fpgsql -Ddatabaseparams.file=.\u002F..\u002Fconf\u002Fdatabase_params.conf -Dstart.webclient=false -Dgen.db.password=true -Dsplashscreen.progress.color=7515939 -Dsplashscreen.fontforeground.color=7515939 -Dsplashscreen.fontbackground.color=-1 -Dsplash.filename=..\u002Fimages\u002Fpasstrix_splash.png -Dsplashscreen.font.color=black -Djava.io.tmpdir=..\u002Flogs -DcontextDIR=PassTrix -Dcli.debug=false -DADUserNameSyntax=domain.backslash.username -Duser.home=..\u002Flogs\u002F -Dnet.phonefactor.pfsdk.debug=false -server -Dfile.encoding=UTF8 -Duser.language=en -Xms50m -Xmx512m -Djava.library.path=\"..\u002Flib\u002Fnative\" -classpath \"..\u002Flib\u002Fwrapper.jar;..\u002Flib\u002Ftomcat\u002Ftomcat-juli.jar;run.jar;..\u002Ftools.jar;..\u002Flib\u002FAdventNetNPrevalent.jar;..\u002Flib\u002F;..\u002Flib\u002FAdventNetUpdateManagerInstaller.jar;..\u002Flib\u002Fconf.jar\" -Dwrapper.key=\"7ofvurNLTVkDioN9w9Efmug_bEFaMg-M\" -Dwrapper.port=32000 -Dwrapper.jvm.port.min=31000 -Dwrapper.jvm.port.max=31999 -Dwrapper.pid=2744 -Dwrapper.version=\"3.5.25-pro\" -Dwrapper.native_library=\"wrapper\" -Dwrapper.arch=\"x86\" -Dwrapper.service=\"TRUE\" -Dwrapper.cpu.timeout=\"10\" -Dwrapper.jvmid=1 -Dwrapper.lang.domain=wrapper -Dwrapper.lang.folder=..\u002Flang org.tanukisoftware.wrapper.WrapperSimpleApp com.adventnet.mfw.Starter\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parent process of the Java process is wrapper.exe, with startup parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\bin\\wrapper.exe\" -s \"C:\\Program Files\\ManageEngine\\PMP\\conf\\wrapper.conf\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check the file C:\\Program Files\\ManageEngine\\PAM360\\conf\\wrapper.conf to locate where debugging is enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#uncomment the following to enable JPDA debugging\u003Cbr>#wrapper.java.additional.27=-Xdebug\u003Cbr>#wrapper.java.additional.28=-Xnoagent\u003Cbr>#wrapper.java.additional.29=-Xrunjdwp:transport=dt_socket,address=8787,server=y,suspend=n\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After uncommenting, the content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wrapper.java.additional.27=-Xdebug\u003Cbr>wrapper.java.additional.28=-Xnoagent\u003Cbr>wrapper.java.additional.29=-Xrunjdwp:transport=dt_socket,address=8787,server=y,suspend=n\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Do not set the Address configuration as address=*:8787, as it will cause ERROR: transport error 202: gethostbyname: unknown host. Setting address=8787 will enable remote debugging functionality.\u003C\u002Fp>\u003Cp>Restart the service and check the Java process parameters again: wmic process where name=\"java.exe\" get commandline\u003C\u002Fp>\u003Cp>Configuration modified successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016183355_2_b7ae11ac0e-1.png\">\u003C\u002Fp>\u003Ch3>2. Common JAR Package Locations\u003C\u002Fh3>\u003Cp>Path: C:\\Program Files\\ManageEngine\\PMP\\lib\u003C\u002Fp>\u003Cp>The implementation file for web functionality is AdventNetPassTrix.jar\u003C\u002Fp>\u003Ch3>3. IDEA Settings\u003C\u002Fh3>\u003Cp>Remote debugging settings are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016185424_3_0c3ff80822-1.png\">\u003C\u002Fp>\u003Cp>Remote debugging successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016186594_4_8ba4703e10-1.png\">\u003C\u002Fp>\u003Ch2>0x04 Database Connection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By default, Password Manager Pro uses PostgreSQL to store data\u003C\u002Fp>\u003Cp>Configuration file path: C:\\Program Files\\ManageEngine\\PMP\\conf\\database_params.conf\u003C\u002Fp>\u003Cp>Example content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp># $Id$\u003Cbr># driver name\u003Cbr>drivername=org.postgresql.Driver\u003Cbr>\u003Cbr># login username for database if any\u003Cbr>username=pmpuser\u003Cbr>\u003Cbr># password for the db can be specified here\u003Cbr>password=fCYxcAlHx+u\u002FJ+aWJFgCJ3vz+U69Uj4i\u002F9U=\u003Cbr># url is of the form jdbc:subprotocol:DataSourceName for eg.jdbc:odbc:WebNmsDB\u003Cbr>url=jdbc:postgresql:\u002F\u002Flocalhost:2345\u002FPassTrix?ssl=require\u003Cbr>\u003Cbr># Minimum Connection pool size\u003Cbr>minsize=1\u003Cbr>\u003Cbr># Maximum Connection pool size\u003Cbr>maxsize=20\u003Cbr>\u003Cbr># Transaction Isolation level\u003Cbr># Values are constants defined in java.sql.Connection type supported TRANSACTION_NONE    0\u003Cbr># Allowed values are TRANSACTION_READ_COMMITTED, TRANSACTION_READ_UNCOMMITTED, TRANSACTION_REPEATABLE_READ, TRANSACTION_SERIALIZABLE\u003Cbr>transaction_isolation=TRANSACTION_READ_COMMITTED\u003Cbr>exceptionsorterclassname=com.adventnet.db.adapter.postgres.PostgresExceptionSorter\u003Cbr>\u003Cbr># Check if the database password is encrypted or not\u003Cbr>db.password.encrypted=true\u003Cbr>new_superuser_pass=dnKkx6zgLPOsNhc7IpO\u002FXwBo1ZSdrZ7QoNQ=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Password Cracking\u003C\u002Fh3>\u003Cp>The database connection password is encrypted. The encryption\u002Fdecryption algorithm is located in com.adventnet.passtrix.ed.PMPEncryptDecryptImpl.class within C:\\Program Files\\ManageEngine\\PMP\\lib\\AdventNetPassTrix.jar\u003C\u002Fp>\u003Cp>The fixed key is stored in com.adventnet.passtrix.db.PMPDBPasswordGenerator.class, with the content @dv3n7n3tP@55Tri*\u003C\u002Fp>\u003Cp>We can quickly write a decryption program based on the content in PMPEncryptDecryptImpl.class.\u003C\u002Fp>\u003Cp>For the decryption program, refer to: https:\u002F\u002Fwww.shielder.com\u002Fblog\u002F2022\u002F09\u002Fhow-to-decrypt-manage-engine-pmp-passwords-for-fun-and-domain-admin-a-red-teaming-tale\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The decryption of database passwords in the article is correct, but there is a bug in the Master Key decryption. The solution will be introduced in a later article.\u003C\u002Fp>\u003Cp>The decrypted connection password is Eq5XZiQpHv.\u003C\u002Fp>\u003Ch3>2. Database Connection\u003C\u002Fh3>\u003Cp>Construct the database connection command based on the configuration file.\u003C\u002Fp>\u003Ch4>(1) Failed command\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\" \"host=localhost port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connection failed with error: psql: FATAL: no pg_hba.conf entry for host \"::1\", user \"pmpuser\", database \"PassTrix\", SSL on\u003C\u002Fp>\u003Ch4>(2) Successful command\u003C\u002Fh4>\u003Cp>Replace localhost with 127.0.0.1 to connect successfully. The complete command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\" \"host=127.0.0.1 port=2345 dbname=PassTrix user=pmpuser password=Eq5XZiQpHv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) A single command to connect to the database and perform database operations\u003C\u002Fh4>\u003Cp>Format: psql --command=\"SELECT * FROM table;\" postgresql:\u002F\u002F\u003Cuser>:\u003Cpassword>@\u003Chost>:\u003Cport>\u002F\u003Cdb>\u003C\u002Fdb>\u003C\u002Fport>\u003C\u002Fhost>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\ManageEngine\\PMP\\pgsql\\bin\\psql\"  --command=\"select * from DBCredentialsAudit;\" postgresql:\u002F\u002Fpmpuser:Eq5XZiQpHv@127.0.0.1:2345\u002FPassTrix\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> username |                                                                         password                                                                         |   last_modified_time\u003Cbr>----------+----------------------------------------------------------------------------------------------------------------------------------------------------------+-------------------------\u003Cbr> postgres | \\xc30c0409010246e50cc723070408d23b0187325463ff95c0ff5c8f9013e7a37f424b5e0d1f2c11ce97c7184e112cd81536ac90937f99838124dee88239d9444ba8aff26f1a9ff29f22f4b5 | 2022-09-01 11:11:11.111\u003Cbr>(1 row)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found that the password data content is encrypted\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the Password Manager Pro vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",482,"Onedaysec",4,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Password Manager Pro Vulnerability Debugging Environment Setup Guide","Password Manager Pro, vulnerability debugging, environment setup, ManageEngine, security testing, installation, configuration, database connection",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],996,994,993,992,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.352Z","2026-07-23T16:02:24.123Z","draft","2026-07-23T16:15:58.394Z"]