[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVKKHQ41TlRFU2CcwWy2DIPSBRYtLA9aG3293anpmHw0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":57,"createdAt":57,"_status":56},1236,"What important aspects of Zimbra's architecture are relevant for vulnerability debugging?","Zimbra uses the Jetty framework as its web container and compiles JSP files into Java files stored under \u002Fopt\u002Fzimbra\u002Fjetty_base\u002Fwork\u002Fzimbra\u002Fjsp\u002F. A JspServletWrapper instance is registered for each accessed JSP. These can be enumerated via reflection using request scope and ConcurrentHashMap, which is useful for understanding JSP handling and potential attack surfaces during vulnerability research.\n\n---\n**Related reading:**\n- [Setting up Zimbra Vulnerability Debugging Environment](\u002Fnews\u002Fsetting-up-zimbra-vulnerability-debugging-environment) — original article\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\n- [Penetration Techniques - Enabling Anonymous Access Shares on Windows Systems via Command Line](\u002Fnews\u002Fpenetration-techniques-enabling-anonymous-access-shares-on-windows-systems-via-command-line)\n- [Penetration Technique: Python Implementation of Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-pythonimplementation-of-exchange-powershell)","\u003Cp>Zimbra uses the Jetty framework as its web container and compiles JSP files into Java files stored under \u002Fopt\u002Fzimbra\u002Fjetty_base\u002Fwork\u002Fzimbra\u002Fjsp\u002F. A JspServletWrapper instance is registered for each accessed JSP. These can be enumerated via reflection using request scope and ConcurrentHashMap, which is useful for understanding JSP handling and potential attack surfaces during vulnerability research.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Setting up Zimbra Vulnerability Debugging Environment](\u002Fnews\u002Fsetting-up-zimbra-vulnerability-debugging-environment) — original article\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003Cbr>- [Penetration Techniques - Enabling Anonymous Access Shares on Windows Systems via Command Line](\u002Fnews\u002Fpenetration-techniques-enabling-anonymous-access-shares-on-windows-systems-via-command-line)\u003Cbr>- [Penetration Technique: Python Implementation of Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-pythonimplementation-of-exchange-powershell)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsetting-up-zimbra-vulnerability-debugging-environment\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-important-aspects-of-zimbras-architecture-are-relevant-for-vulnerability-de-1777477515842","Zimbra, Jetty, JSP, JspServletWrapper, reflection, vulnerability debugging",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},296,"Setting up Zimbra Vulnerability Debugging Environment","setting-up-zimbra-vulnerability-debugging-environment","Step-by-step guide to set up Zimbra vulnerability debugging environment, enable debug mode, and use IDEA for remote debugging with JSP examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of building a Zimbra vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Enabling debug mode on Zimbra server\u003C\u002Fli>\u003Cli>Remote debugging using IDEA locally\u003C\u002Fli>\u003Cli>Common knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Enabling Debug Mode on Zimbra Server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FZimbra-Community\u002Fzimbra-tools\u002Fblob\u002Fmaster\u002Fjava-debug-zimbra-intellij-ide.md\u003C\u002Fp>\u003Cp>Detailed steps are as follows:\u003C\u002Fp>\u003Ch3>1. Stop Zimbra service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>su zimbra\u003Cbr>zmcontrol stop\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Enable debug mode\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>su\u003Cbr>cp \u002Fopt\u002Fzimbra\u002Flibexec\u002Fzmmailboxdmgr \u002Fopt\u002Fzimbra\u002Flibexec\u002Fzmmailboxdmgr.old\u003Cbr>cp \u002Fopt\u002Fzimbra\u002Flibexec\u002Fzmmailboxdmgr.unrestricted \u002Fopt\u002Fzimbra\u002Flibexec\u002Fzmmailboxdmgr\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>First backup zmmailboxdmgr here, then replace zmmailboxdmgr with zmmailboxdmgr.unrestricted\u003C\u002Fp>\u003Ch3>3. Add debug information\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>su zimbra\u003Cbr>zmlocalconfig -e mailboxd_java_options=\"`zmlocalconfig -m nokey mailboxd_java_options` -Xdebug -Xnoagent -Djava.compiler=NONE -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also directly modify the mailboxd_java_options attribute value in \u002Fopt\u002Fzimbra\u002Fconf\u002Flocalconfig.xml\u003C\u002Fp>\u003Ch3>4. Disable firewall\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo ufw disable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Restart service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>zmcontrol start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Local remote debugging using IDEA\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download jar files\u003C\u002Fh3>\u003Cp>When performing remote debugging locally using IDEA, the local and remote code must be consistent, meaning we need to obtain the zimbra-related jar files\u003C\u002Fp>\u003Cp>Zimbra file locations:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fopt\u002Fzimbra\u002Fcommon\u002Fjetty_home\u002Flib\u002F\u003C\u002Fli>\u003Cli>\u002Fopt\u002Fzimbra\u002Fcommon\u002Fjetty_home\u002Flib\u002Fapache-jsp\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Batch import jar files\u003C\u002Fh3>\u003Cp>Create a new Java project, select File-&gt;Project Structure... in sequence, under Libraries choose New Project Library-&gt;Java, set it to c:\\zimbrajar\\\u003C\u002Fp>\u003Ch3>3. Add breakpoints\u003C\u002Fh3>\u003Cp>Open .class files under External Libraries-&gt;zimbrajar, add breakpoints at appropriate locations\u003C\u002Fp>\u003Ch3>4. Set remote debugging parameters\u003C\u002Fh3>\u003Cp>Select Add Configuration... from the top menu bar, choose Remote JVM Debug in the pop-up page, fill in the remote debugging parameters, parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select JDK version 5-8 for the JDK used\u003C\u002Fp>\u003Ch3>5. Enable Debug mode\u003C\u002Fh3>\u003Cp>Return to the IDEA main interface, select the configuration file just created, and click the Debug icon (shortcut Shift+F9)\u003C\u002Fp>\u003Cp>If remote debugging executes successfully, the breakpoint icon will change, adding a checkmark\u003C\u002Fp>\u003Cp>At this point, the Console page displays the following:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Connected to the target VM, address: '\u003Chost>:\u003Cport>', transport: 'socket'\u003C\u002Fport>\u003C\u002Fhost>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Zimbra uses the Jetty framework as its web container\u003C\u002Fp>\u003Cp>When users access a JSP file, the server first parses the JSP file, which the JVM does not recognize, into a Java file, saved at the path: \u002Fopt\u002Fzimbra\u002Fjetty_base\u002Fwork\u002Fzimbra\u002Fjsp\u002Forg\u002Fapache\u002Fjsp\u002F\u003C\u002Fp>\u003Cp>After each JSP file is successfully accessed, a JspServletWrapper instance is registered. We can view all registered JspServletWrapper instances by examining the request variable through the debugger, or enumerate them in the form of JSP files via reflection\u003C\u002Fp>\u003Cp>JSP file code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>&lt;%@ page import=\"java.lang.reflect.Field\" %&gt;\u003Cbr>&lt;%@ page import=\"java.util.concurrent.ConcurrentHashMap\" %&gt;\u003Cbr>&lt;%@ page import=\"java.util.*\" %&gt;\u003Cbr>&lt;%       \u003Cbr>    Field f = request.getClass().getDeclaredField(\"_scope\");\u003Cbr>    f.setAccessible(true);  \u003Cbr>    Object obj1 = f.get(request);\u003Cbr>    f = obj1.getClass().getDeclaredField(\"_servlet\");\u003Cbr>    f.setAccessible(true);\u003Cbr>    Object obj2 = f.get(obj1);\u003Cbr>    f = obj2.getClass().getSuperclass().getDeclaredField(\"rctxt\");\u003Cbr>    f.setAccessible(true);\u003Cbr>    Object obj3 = f.get(obj2);\u003Cbr>    f = obj3.getClass().getDeclaredField(\"jsps\");\u003Cbr>    f.setAccessible(true);\u003Cbr>    ConcurrentHashMap obj4 = (ConcurrentHashMap)f.get(obj3);  \u003Cbr>    Enumeration enu = obj4.keys(); \u003Cbr>    while (enu.hasMoreElements()) { \u003Cbr>        out.println(enu.nextElement() + \"\u003Cbr>\"); \u003Cbr>    }  \u003Cbr>%&gt;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The reflection logic originates from debugging and tracing results; the implementation logic is not unique. Enumerating JspServletWrapper instances utilizes ConcurrentHashMap enumeration.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the Zimbra vulnerability debugging environment, we can proceed to study and research the vulnerabilities and the Jetty framework.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Zimbra Vulnerability Debugging: Setup Remote Debug with IDEA","Zimbra debugging, vulnerability analysis, remote debug IDEA, Jetty framework, JSP reflection",false,[],{"docs":41,"hasNextPage":52},[42,43,44,45,46,47,48,49,50,51],1249,1248,1247,1246,1245,1244,1243,1242,1241,1240,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.393Z","2026-07-23T16:02:41.999Z","draft","2026-07-23T16:17:35.760Z"]