[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3h_GEQhYnAMeiDY9x1GgHJhKgAiEnnG0rQJKAQw-ZBQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},925,"How do I enable remote debugging for GoAnywhere Managed File Transfer on Windows?","To enable remote debugging on Windows, modify the Java Options of the `GoAnywhere.exe` file by adding `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090`. Then restart the GoAnywhere service. This is part of setting up the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment) to analyze vulnerabilities.","\u003Cp>To enable remote debugging on Windows, modify the Java Options of the `GoAnywhere.exe` file by adding `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090`. Then restart the GoAnywhere service. This is part of setting up the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment) to analyze vulnerabilities.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-enable-remote-debugging-for-goanywhere-managed-file-transfer-on-windows-1777481238366","GoAnywhere Managed File Transfer, remote debugging, Windows, Tomcat, jdwp",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},225,"GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup","goanywhere-managed-file-transfer-vulnerability-debugging-environment","Guide to setting up GoAnywhere MFT vulnerability debugging environment: installation, Tomcat debug config, Apache Derby DB ops & password encryption details.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Requires registering an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging function\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This is achieved by enabling Tomcat debugging function; the method to enable Tomcat debugging function is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat debugging function is enabled, it listens to the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the Web port of GoAnywhere Managed File Transfer, so here we choose to modify Tomcat's default debugging port to 8090\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location under Windows: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location under Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from the ga_classes.jar file in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\lib\\\\ga_classes.jar!\\\\com\\\\linoma\\\\ga\\\\ui\\\\admin\\\\action\\\\user\\\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397686715_0_7de6739ce9.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command-line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere for the Folder.\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397694174_1_dbaea6a08a.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, disabled\u003C\u002Fp>\u003Cp>root, disabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode and is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can use Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Once we have set up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can then start learning about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Requires registering an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging function\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This is achieved by enabling Tomcat debugging function; the method to enable Tomcat debugging function is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat debugging function is enabled, it listens to the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the Web port of GoAnywhere Managed File Transfer, so here we choose to modify Tomcat's default debugging port to 8090\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location under Windows: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location under Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from the ga_classes.jar file in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\lib\\\\ga_classes.jar!\\\\com\\\\linoma\\\\ga\\\\ui\\\\admin\\\\action\\\\user\\\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397686715_0_7de6739ce9-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command-line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\userdata\\\\database\\\\goanywhere for the Folder.\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397694174_1_dbaea6a08a-1.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, disabled\u003C\u002Fp>\u003Cp>root, disabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode and is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can use Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Once we have set up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can then start learning about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",630,"Onedaysec",3,"published","2026-02-02T07:25:20.011Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"GoAnywhere MFT Vulnerability Debugging Environment Setup Steps","GoAnywhere MFT, vulnerability debugging environment setup, GoAnywhere installation, Tomcat remote debugging, Apache Derby database operations, GoAnywhere debug port, Derby database query",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],928,927,926,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.757Z","2026-07-23T16:02:17.677Z","draft","2026-07-23T16:15:35.035Z"]