[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fge-K0Jw5JEvrLlTiFR-jQc2msU-oCnXky_kYXhVZMkg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},227,"What are the default web paths and why is the Tomcat debug port changed to 8090?","The default web path is `C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT` on Windows and `\u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT` on Linux. Tomcat's default JPDA debug port (8000) conflicts with GoAnywhere’s web port, so the article instructs changing it to `8090` in the `goanywhere_catalina.sh` script on Linux or via the `GoAnywhere.exe` Java Options on Windows. This port adjustment is a common step in vulnerability debugging setups, similar to those described in [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).","\u003Cp>The default web path is `C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT` on Windows and `\u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT` on Linux. Tomcat&#39;s default JPDA debug port (8000) conflicts with GoAnywhere’s web port, so the article instructs changing it to `8090` in the `goanywhere_catalina.sh` script on Linux or via the `GoAnywhere.exe` Java Options on Windows. This port adjustment is a common step in vulnerability debugging setups, similar to those described in [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsetting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-default-web-paths-and-why-is-the-tomcat-debug-port-changed-to-8090-1777484611619","default web path, Tomcat debug port, port conflict, 8090",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},59,"Setting up GoAnywhere Managed File Transfer Vulnerability Debugging Environment","setting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment","Step-by-step guide to install and configure GoAnywhere Managed File Transfer for vulnerability debugging, including database operations and debugging setup.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>GoAnywhere Managed File Transfer Installation\u003C\u002Fli>\u003Cli>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Operations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download URL: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Registration required to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed separately on Windows and Linux operating systems\u003C\u002Fp>\u003Cp>Default web path on Windows system: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default web path on Linux system: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Ch3>1. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Achieved by enabling Tomcat debugging function. The method to enable Tomcat debugging is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Switch to the bin directory\u003C\u002Fli>\u003Cli>Execute command: catalina jpda start\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After Tomcat debugging function is enabled, it listens on local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Ch4>(1) Debugging on Windows\u003C\u002Fh4>\u003Cp>Modify file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to Java tab, add in Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018736193_0_ace76b8282.png\">\u003C\u002Fp>\u003Cp>Restart GoAnywhere service\u003C\u002Fp>\u003Ch4>(2) Linux debugging\u003C\u002Fh4>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tomcat's default debug port 8000 conflicts with GoAnywhere Managed File Transfer's web port, so here we choose to modify Tomcat's default debug port to 8090\u003C\u002Fp>\u003Cp>Open firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Ch2>0x03 Database Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location on Windows: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location on Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this we can get the implementation details of web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>Extracted Java implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import com.linoma.commons.crypto.PasswordHash;\u003Cbr>import com.linoma.commons.crypto.PasswordHashFactory;\u003Cbr>import com.linoma.dpa.util.SystemInfo;\u003Cbr>public class Main {\u003Cbr>    public static void main(String[] args) throws Exception, Exception {\u003Cbr>        PasswordHash var2 = PasswordHashFactory.getPasswordHash(SystemInfo.getPasswordHashAlgorithm(), \"\");\u003Cbr>        String var3 = var2.hash(\"Password@123456\");\u003Cbr>        System.out.println(var3);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Reading Derby Database\u003C\u002Fh3>\u003Ch4>(1) Command Line Implementation\u003C\u002Fh4>\u003Cp>Using Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Ch4>(2) GUI Implementation\u003C\u002Fh4>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere as the Folder\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018746450_1_5c8f983b92.png\">\u003C\u002Fp>\u003Cp>It can be seen that the default users are the following three:\u003C\u002Fp>\u003Cul>\u003Cli>Administrator, disabled\u003C\u002Fli>\u003Cli>root, disabled\u003C\u002Fli>\u003Cli>admin, default user\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify the Database\u003C\u002Fh3>\u003Cp>GoAnywhere Managed File Transfer's Derby database uses embedded mode, which is not accessible by other applications, so there are two methods to modify the data:\u003C\u002Fp>\u003Ch4>(1) GoAnywhere Managed File Transfer is in a running state\u003C\u002Fh4>\u003Cp>Database modification can be achieved by writing a jsp file\u003C\u002Fp>\u003Ch4>(2) GoAnywhere Managed File Transfer is in a closed state\u003C\u002Fh4>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and directly modify it\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of setting up a GoAnywhere Managed File Transfer vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>GoAnywhere Managed File Transfer Installation\u003C\u002Fli>\u003Cli>GoAnywhere Managed File Transfer Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Database Operations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 GoAnywhere Managed File Transfer Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fstatic.fortra.com\u002Fgoanywhere\u002Fpdfs\u002Fguides\u002Fga6_8_6_installation_guide.pdf\u003C\u002Fp>\u003Cp>Download URL: https:\u002F\u002Fwww.goanywhere.com\u002Fproducts\u002Fgoanywhere-free\u002Fdownload\u003C\u002Fp>\u003Cp>Registration required to obtain a license\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer can be installed separately on Windows and Linux operating systems\u003C\u002Fp>\u003Cp>Default web path on Windows system: C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\webapps\\ROOT\u003C\u002Fp>\u003Cp>Default web path on Linux system: \u002Fusr\u002Flocal\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fwebapps\u002FROOT\u003C\u002Fp>\u003Ch3>1. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Achieved by enabling Tomcat debugging function. The method to enable Tomcat debugging is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Switch to the bin directory\u003C\u002Fli>\u003Cli>Execute command: catalina jpda start\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After Tomcat debugging function is enabled, it listens on local port 8000 by default\u003C\u002Fp>\u003Cp>For GoAnywhere Managed File Transfer, the method to enable debugging function is as follows:\u003C\u002Fp>\u003Ch4>(1) Debugging on Windows\u003C\u002Fh4>\u003Cp>Modify file properties of C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe\u003C\u002Fp>\u003Cp>Double-click file C:\\Program Files\\HelpSystems\\GoAnywhere\\tomcat\\bin\\GoAnywhere.exe, switch to Java tab, add in Java Options: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8090, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018736193_0_ace76b8282-1.png\">\u003C\u002Fp>\u003Cp>Restart GoAnywhere service\u003C\u002Fp>\u003Ch4>(2) Linux debugging\u003C\u002Fh4>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fstart_tomcat.sh, change exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" start \"$@\" to exec \"$PRGDIR\"\u002F\"$EXECUTABLE\" jpda start \"$@\"\u003C\u002Fp>\u003Cp>Modify file: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Ftomcat\u002Fbin\u002Fgoanywhere_catalina.sh, change JPDA_ADDRESS=\"localhost:8000\" to JPDA_ADDRESS=\"*:8090\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Tomcat's default debug port 8000 conflicts with GoAnywhere Managed File Transfer's web port, so here we choose to modify Tomcat's default debug port to 8090\u003C\u002Fp>\u003Cp>Open firewall to allow external access to port 8090: iptables -I INPUT -p tcp --dport 8090 -j ACCEPT\u003C\u002Fp>\u003Cp>Start GoAnywhere process: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fgoanywhere.sh start\u003C\u002Fp>\u003Ch2>0x03 Database Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>GoAnywhere Managed File Transfer uses Apache Derby database\u003C\u002Fp>\u003Cp>Default database storage location on Windows: C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere\u003C\u002Fp>\u003Cp>Default database storage location on Linux: \u002Fopt\u002FHelpSystems\u002FGoAnywhere\u002Fuserdata\u002Fdatabase\u002Fgoanywhere\u002F\u003C\u002Fp>\u003Cp>Implementation details of database operations can be obtained from ga_classes.jar in the lib folder\u003C\u002Fp>\u003Cp>From this we can get the implementation details of web user password encryption, corresponding location: C:\\Program Files\\HelpSystems\\GoAnywhere\\lib\\ga_classes.jar!\\com\\linoma\\ga\\ui\\admin\\action\\user\\ChangeUserPasswordAction.class\u003C\u002Fp>\u003Cp>Extracted Java implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import com.linoma.commons.crypto.PasswordHash;\u003Cbr>import com.linoma.commons.crypto.PasswordHashFactory;\u003Cbr>import com.linoma.dpa.util.SystemInfo;\u003Cbr>public class Main {\u003Cbr>    public static void main(String[] args) throws Exception, Exception {\u003Cbr>        PasswordHash var2 = PasswordHashFactory.getPasswordHash(SystemInfo.getPasswordHashAlgorithm(), \"\");\u003Cbr>        String var3 = var2.hash(\"Password@123456\");\u003Cbr>        System.out.println(var3);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Reading Derby Database\u003C\u002Fh3>\u003Ch4>(1) Command Line Implementation\u003C\u002Fh4>\u003Cp>Using Apache Derby, download address: https:\u002F\u002Farchive.apache.org\u002Fdist\u002Fdb\u002Fderby\u002Fdb-derby-10.14.2.0\u002Fdb-derby-10.14.2.0-bin.zip\u003C\u002Fp>\u003Cp>Run ij.bat in the bin directory\u003C\u002Fp>\u003Cp>Connect to database: connect 'jdbc:derby:C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere;';\u003C\u002Fp>\u003Cp>Query user configuration: SELECT * FROM DPA_USER;\u003C\u002Fp>\u003Ch4>(2) GUI Implementation\u003C\u002Fh4>\u003Cp>Use DBSchema, download link: https:\u002F\u002Fdbschema.com\u002Fdownload.html\u003C\u002Fp>\u003Cp>After launching DBSchema, select to connect to the Derby database, choose derbytools.jar org.apache.derby.jdbc.EmbeddedDriver as the JDBC Driver, and select C:\\Program Files\\HelpSystems\\GoAnywhere\\userdata\\database\\goanywhere as the Folder\u003C\u002Fp>\u003Cp>Query the user data table, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018746450_1_5c8f983b92-1.png\">\u003C\u002Fp>\u003Cp>It can be seen that the default users are the following three:\u003C\u002Fp>\u003Cul>\u003Cli>Administrator, disabled\u003C\u002Fli>\u003Cli>root, disabled\u003C\u002Fli>\u003Cli>admin, default user\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify the Database\u003C\u002Fh3>\u003Cp>GoAnywhere Managed File Transfer's Derby database uses embedded mode, which is not accessible by other applications, so there are two methods to modify the data:\u003C\u002Fp>\u003Ch4>(1) GoAnywhere Managed File Transfer is in a running state\u003C\u002Fh4>\u003Cp>Database modification can be achieved by writing a jsp file\u003C\u002Fp>\u003Ch4>(2) GoAnywhere Managed File Transfer is in a closed state\u003C\u002Fh4>\u003Cp>You can choose Apache Derby or DBSchema to open the database folder and directly modify it\u003C\u002Fp>\u003Cp>Example commands for modifying the database:\u003C\u002Fp>\u003Cp>Enable root user: UPDATE APP.DPA_USER SET ENABLED='1' WHERE USER_NAME='root';\u003C\u002Fp>\u003Cp>Set root user password: UPDATE APP.DPA_USER SET USER_PASS='$5$mpoe6zI4B6+LHRMdbFKr8g==$RnAILbYe9KDauKE3wXTFVvlXQNZeM4Z2c7x1aEtME\u002FU=' WHERE USER_NAME='root';\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the GoAnywhere Managed File Transfer vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1502,"Onedaysec",3,"published","2026-02-02T08:07:54.308Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Setup GoAnywhere MFT Vulnerability Debugging Environment Guide","GoAnywhere MFT, vulnerability debugging, installation, database setup, Tomcat debugging, Derby database",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],226,225,224,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.629Z","2026-07-23T16:01:12.900Z","draft","2026-07-23T16:04:41.311Z"]