[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMXqHyNk879uLJ6wadlGK8xZL7YDLtwrXgaxgX7YFuI4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1092,"How do I enable remote debugging on Linux for GoAnywhere MFT?","On Linux, modify `\u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh` to change `exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\"` to `exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"`. Then edit `goanywhere_catalina.sh` and change `JPDA_ADDRESS=\"localhost:8000\"` to `JPDA_ADDRESS=\"*:8090\"` to avoid port conflicts. Open firewall port 8090 and start GoAnywhere. This setup is covered in the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup) article.","\u003Cp>On Linux, modify `\u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh` to change `exec &quot;$PRGDIR&quot;\u002F&quot;$EXECUTABLE&quot; start &quot;$@&quot;` to `exec &quot;$PRGDIR&quot;\u002F&quot;$EXECUTABLE&quot; jpda start &quot;$@&quot;`. Then edit `goanywhere_catalina.sh` and change `JPDA_ADDRESS=&quot;localhost:8000&quot;` to `JPDA_ADDRESS=&quot;*:8090&quot;` to avoid port conflicts. Open firewall port 8090 and start GoAnywhere. This setup is covered in the [GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup](\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fgoanywhere-managed-file-transfer-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-enable-remote-debugging-on-linux-for-goanywhere-mft-1777480526587","GoAnywhere Managed File Transfer, remote debugging, Linux, Tomcat, JPDA",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},266,"GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup","goanywhere-managed-file-transfer-vulnerability-debugging-environment-setup","Step-by-step guide to setting up GoAnywhere MFT vulnerability debugging environment: installation, Tomcat debug config, Apache Derby database access & operations.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Overview\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Need to register an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively.\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\tomcat\\\\webapps\\\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging feature\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Achieve this by enabling Tomcat's debugging feature; the method to enable Tomcat's debugging feature is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat's debugging feature is enabled, it listens on the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable the debugging feature is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the web port of GoAnywhere Managed File Transfer, so we choose to modify Tomcat's default debugging port to 8090 here\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>The default database storage location under Windows is: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>The default database storage location under Linux is: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396799505_0_eecd4bb00f.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command Line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere for the Folder\u003C\u002Fp>\u003Cp>Query the user data table as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769396803305_1_c621efe1fc.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, not enabled\u003C\u002Fp>\u003Cp>root, not enabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode, which is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to learn about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article records the details of building a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Overview\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Installation\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fp>\u003Cp>Database Operations\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download Link: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Need to register an account to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed on Windows and Linux operating systems respectively.\u003C\u002Fp>\u003Cp>Default Web Path on Windows System: C:\\\\Program Files\\\\HelpSystems\\\\GoAnywhere\\\\tomcat\\\\webapps\\\\ROOT\u003C\u002Fp>\u003Cp>Default Web Path on Linux System: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable remote debugging feature\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Achieve this by enabling Tomcat's debugging feature; the method to enable Tomcat's debugging feature is as follows:\u003C\u002Fp>\u003Cp>Switch to the bin directory\u003C\u002Fp>\u003Cp>Execute the command: catalina jpda start\u003C\u002Fp>\u003Cp>After Tomcat's debugging feature is enabled, it listens on the local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable the debugging feature is as follows:\u003C\u002Fp>\u003Cp>(1) Debugging on Windows\u003C\u002Fp>\u003Cp>Modify the file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click the file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to the Java tab, and add the following to Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown in the figure below\u003C\u002Fp>\u003Cp>Restart the GoAnywhere service\u003C\u002Fp>\u003Cp>(2) Debugging on Linux\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify the file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>The default debugging port 8000 of Tomcat conflicts with the web port of GoAnywhere Managed File Transfer, so we choose to modify Tomcat's default debugging port to 8090 here\u003C\u002Fp>\u003Cp>Open the firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start the GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Database Operations\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses the Apache Derby database\u003C\u002Fp>\u003Cp>The default database storage location under Windows is: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>The default database storage location under Linux is: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this, we can get the implementation details of Web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>The extracted Java implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396799505_0_eecd4bb00f-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Read Derby Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Command Line Implementation\u003C\u002Fp>\u003Cp>Use Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to the database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Cp>(2) GUI Implementation\u003C\u002Fp>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere for the Folder\u003C\u002Fp>\u003Cp>Query the user data table as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】GoAnywhere Managed File Transfer漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396803305_1_c621efe1fc-1.png\">\u003C\u002Fp>\u003Cp>You can see there are three default users as follows:\u003C\u002Fp>\u003Cp>Administrator, not enabled\u003C\u002Fp>\u003Cp>root, not enabled\u003C\u002Fp>\u003Cp>admin, default user\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Modify the Database\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Derby database of GoAnywhere Managed File Transfer uses embedded mode, which is inaccessible to other applications, so there are two methods to modify the data as follows:\u003C\u002Fp>\u003Cp>(1) GoAnywhere Managed File Transfer is running\u003C\u002Fp>\u003Cp>Database modification can be achieved by writing a JSP file\u003C\u002Fp>\u003Cp>(2) GoAnywhere Managed File Transfer is shut down\u003C\u002Fp>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and modify it directly\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to learn about the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",234,"Onedaysec",3,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"How to Set Up GoAnywhere MFT Vulnerability Debugging Environment","GoAnywhere MFT, vulnerability debugging environment setup, GoAnywhere installation, Tomcat remote debugging, Apache Derby database operations, GoAnywhere debug port, Derby database access",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1094,1093,1091,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.706Z","2026-07-23T16:02:31.429Z","draft","2026-07-23T16:16:37.107Z"]