[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8cYSNPCtN1ef09n3CLFFhMRRjO5swtppj3cRpLQ8Mwo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},443,"What is the csc configuration file and how can I decrypt it for reverse engineering?","The csc (core service controller) process reads an encrypted configuration file at \u002F_conf\u002Fcscconf.bin. To decrypt it, you can use IDA to modify the csc binary's logic so that it outputs the decrypted data before loading the Perl packages. This approach is necessary because the original file is encrypted and the normal process deletes itself after loading, preventing direct inspection. For similar setups, see [Server Backup Manager Vulnerability Debugging Environment Setup](\u002Fnews\u002Fserver-backup-manager-vulnerability-debugging-environment-setup) or [VMware Workspace ONE Access Vulnerability Debugging Environment Setup](\u002Fnews\u002Fvmware-workspace-one-access-vulnerability-debugging-environment-setup).","\u003Cp>The csc (core service controller) process reads an encrypted configuration file at \u002F_conf\u002Fcscconf.bin. To decrypt it, you can use IDA to modify the csc binary&#39;s logic so that it outputs the decrypted data before loading the Perl packages. This approach is necessary because the original file is encrypted and the normal process deletes itself after loading, preventing direct inspection. For similar setups, see [Server Backup Manager Vulnerability Debugging Environment Setup](\u002Fnews\u002Fserver-backup-manager-vulnerability-debugging-environment-setup) or [VMware Workspace ONE Access Vulnerability Debugging Environment Setup](\u002Fnews\u002Fvmware-workspace-one-access-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsophos-xg-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-csc-configuration-file-and-how-can-i-decrypt-it-for-reverse-engineer-1777483611150","csc, configuration decryption, IDA, reverse engineering, Sophos XG, cscconf.bin",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},111,"Sophos XG Vulnerability Debugging Environment Setup","sophos-xg-vulnerability-debugging-environment-setup","Learn to set up a Sophos XG vulnerability debugging environment, including Jetty debugging, CSC file decryption, and PostgreSQL database access.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Sophos UTM and Sophos XG are two distinct products; the former leans towards general threat management, while the latter focuses on hardware firewalls. This article will introduce the method for setting up a Sophos XG vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Jetty Debugging Environment Setup\u003C\u002Fli>\u003Cli>CSC Configuration File Decryption\u003C\u002Fli>\u003Cli>PostgreSQL Database Query\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Fundamentals\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Architecture as shown in the diagram below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017315579_0_4808194c6d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fcodewhitesec.blogspot.com\u002F2020\u002F07\u002Fsophos-xg-tale-of-unfortunate-re.html\u003C\u002Fp>\u003Cp>Overall, it is divided into the following three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Processes web data and forwards it to csc for further processing\u003C\u002Fli>\u003Cli>csc: Main program: Loads Perl Packages and implements core functionalities\u003C\u002Fli>\u003Cli>Postgresql: Used for data storage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my actual research, I encountered the following issues with these three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Unable to start Java after adding debugging information\u003C\u002Fli>\u003Cli>csc: csc automatically deletes after loading Perl Packages, making it impossible to obtain implementation details of the Perl Packages\u003C\u002Fli>\u003Cli>Postgresql: Low user privileges prevent querying database tables\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The following will introduce solutions to these three problems one by one\u003C\u002Fp>\u003Ch2>0x03 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.sophos.com\u002Fnsg\u002Fsophos-firewall\u002F18.5\u002FHelp\u002Fen-us\u002Fwebhelp\u002Fonlinehelp\u002FVirtualAndSoftwareAppliancesHelp\u002FVMware\u002FVMwareInstall\u002Findex.html\u003C\u002Fp>\u003Ch3>1. Download the installation package\u003C\u002Fh3>\u003Cp>The official website only provides downloads for the latest version by default, but older versions can be downloaded by guessing the correct version number\u003C\u002Fp>\u003Cp>For example, 18.5.3 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.3_MR-3.VMW-408.zip\u003C\u002Fp>\u003Cp>18.5.2 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.2_MR-2.VMW-380.zip\u003C\u002Fp>\u003Ch3>2. Import to VMware Workstation\u003C\u002Fh3>\u003Cp>After downloading the zip file, extract it and run sf_virtual.ovf\u003C\u002Fp>\u003Ch3>3. VMware Workstation network adapter configuration\u003C\u002Fh3>\u003Cp>Two network adapters, VMnet7 and VMnet8, need to be added. Set VMnet7 to Host-only with 172.16.16.0, and VMnet8 to NAT. The specific steps are as follows:\u003C\u002Fp>\u003Ch4>(1) VMnet7\u003C\u002Fh4>\u003Cp>Open VMware Workstation, then select Edit -&gt; Virtual Network Editor...\u003C\u002Fp>\u003Cp>Add Network... -&gt; VMnet7\u003C\u002Fp>\u003Cp>Set VMnet7 as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type: Host-only\u003C\u002Fli>\u003Cli>Subnet Address: 172.16.16.0\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) VMnet8\u003C\u002Fh4>\u003Cp>VMnet8 is set to:\u003C\u002Fp>\u003Cul>\u003Cli>Type: NAT\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Sophos XG Network Card Configuration\u003C\u002Fh3>\u003Cp>Network Adapter set to VMnet7\u003C\u002Fp>\u003Cp>Network Adapter 2 set to VMnet8\u003C\u002Fp>\u003Cp>Network Adapter 3 set to VMnet8\u003C\u002Fp>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017356017_1_6c75cdb1f2.png\">\u003C\u002Fp>\u003Ch3>5. Start Sophos XG\u003C\u002Fh3>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Ch3>6. View IP Address\u003C\u002Fh3>\u003Cp>Enter in sequence: 1. Network Configuration -&gt; 1. Interface Configuration\u003C\u002Fp>\u003Cp>Obtain LAN IP as 172.16.16.16\u003C\u002Fp>\u003Ch3>7. Access the web configuration page for activation\u003C\u002Fh3>\u003Cp>Access https:\u002F\u002F172.16.16.16:4444 via browser\u003C\u002Fp>\u003Cp>On the registration page, select: I don't have a serial number (start a trial)\u003C\u002Fp>\u003Cp>Proceed with registration as prompted\u003C\u002Fp>\u003Cp>After successful registration, re-access https:\u002F\u002F172.16.16.16:4444 for configuration\u003C\u002Fp>\u003Ch2>0x04 Jetty debugging environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Java process related information\u003C\u002Fh3>\u003Cp>Execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             3238   923 root     1393m  264m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the output, obtain Java version as java-11-openjdk\u003C\u002Fp>\u003Ch3>2. Locate configuration file\u003C\u002Fh3>\u003Cp>Configuration file path is \u002Fusr\u002Fbin\u002Fjetty, with content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>\u003Cbr>if   [ \"${RAM}\" == \"2GB\" ]; then\u003Cbr>        heap_size=256\u003Cbr>elif [ \"${RAM}\" == \"4GB\" ]; then\u003Cbr>        heap_size=384\u003Cbr>else\u003Cbr>        heap_size=512\u003Cbr>fi\u003Cbr>\u003Cbr>HYBRID_ENABLED=false\u003Cbr>\u003Cbr>if [ $HYBRID_ENABLED = true ]; then\u003Cbr>    HYBRID_ENABLED=`opcode gethainfo -s nosync | grep -q \"hamode=1\" &amp;&amp; echo \"true\" || echo \"false\"`\u003Cbr>fi\u003Cbr>if [ ! -d \u002Ftmp\u002Fjava ]; then\u003Cbr>    mkdir \u002Ftmp\u002Fjava\u003Cbr>fi\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\" \"mount\"\u003Cbr>\u003Cbr>##\u003Cbr># sun.jnu.encoding=UTF-8 - System property is required with file.encoding otherwise some java APIs unable to read file having double byte characters in file name.\u003Cbr>##\u003Cbr>exec \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx${heap_size}m -Xms12m -Xss256k \"-XX:MaxMetaspaceSize=100m\" \"-Dhybrid.enabled=${HYBRID_ENABLED}\" \"-Djna.tmpdir=\u002Ftmp\u002Fjava\" \"-Djava.io.tmpdir=\u002Ftmp\u002Fjava\" \"-Dsun.jnu.encoding=UTF-8\" \"-Dfile.encoding=UTF-8\" \"-Djava.awt.headless=true\" \"-Djetty.home=\u002Fusr\u002Fshare\u002Fjetty\" \"-Djetty.base=\u002Fusr\u002Fshare\u002Fjetty\" -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar \"--lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\"\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\"\u003Cbr>exit $?\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Add debugging parameters\u003C\u002Fh3>\u003Cp>Modify file attributes: mount -o rw,remount \u002F\u003C\u002Fp>\u003Cp>Add debugging parameters on the exec line: \"-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000\"\u003C\u002Fp>\u003Ch3>4. Restart service\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status is STOPPED\u003C\u002Fp>\u003Cp>To obtain detailed error information, directly run \u002Fusr\u002Fbin\u002Fjetty\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error occurred during initialization of VM\u003Cbr>Could not find agent library jdwp on the library path, with error: libjdwp.so: cannot open shared object file: No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Identified as a JDK issue, opting to replace with a complete JDK here\u003C\u002Fp>\u003Ch3>5. Replace JDK\u003C\u002Fh3>\u003Cp>Download jdk-11.0.15_linux-x64_bin.tar.gz and upload to Sophos XG\u003C\u002Fp>\u003Cp>Backup original folder: cp -r \u002Flib\u002Fjvm\u002Fjava-11-openjdk \u002Flib\u002Fjvm\u002Fjava-11-openjdk_backup\u003C\u002Fp>\u003Cp>Extract jdk-11.0.15_linux-x64_bin.tar.gz: tar zxvf \u002Ftmp\u002Fjdk-11.0.15_linux-x64_bin.tar.gz\u003C\u002Fp>\u003Cp>Replace \u002Flib\u002Fjvm\u002Fjava-11-openjdk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003Cbr>cp -r \u002Ftmp\u002Fjdk-11.0.15 \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Restart service again\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status as RUNNING\u003C\u002Fp>\u003Cp>Confirm parameters were modified, execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             1827   923 root     1454m  158m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000 -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Modify firewall rules\u003C\u002Fh3>\u003Cp>Execute command: iptables -I INPUT -p tcp --dport 8000 -j ACCEPT\u003C\u002Fp>\u003Ch3>8. Use IDEA for remote debugging\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017388600_2_54b8287203.png\">\u003C\u002Fp>\u003Cp>During debugging, if you encounter a situation where breakpoints cannot be set, restart the Java service: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Ch2>0x05 CSC configuration file decryption\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View CSC process related information\u003C\u002Fp>\u003Cp>Execute command: ps ww|grep csc\u003C\u002Fp>\u003Cp>Partial output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csc               859     1 root     25916 23600 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>csc               869   859 root      8628   452 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>cfs               870   859 root     34736 29380 S    {cfs} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>listener          871   859 root     21752 15088 S    {listener} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>lcdd              889   871 root     21108 13556 S    {lcdd} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>postgres          890   871 root     29712 25040 S    {postgres} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>sigdb             891   871 root     26756 23208 S    {sigdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>reportdb          892   871 root     26756 23104 S    {reportdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>awarrensmtp       893   871 root     25916 22296 S    {awarrensmtp} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The csc process reads \u002F_conf\u002Fcscconf.bin as the configuration file, and \u002F_conf\u002Fcscconf.bin is an encrypted file, so it is necessary to decrypt \u002F_conf\u002Fcscconf.bin here.\u003C\u002Fp>\u003Cp>The method I adopted here is to modify the program code through IDA, change the implementation logic, and export the decrypted configuration file.\u003C\u002Fp>\u003Cp>Load csc using IDA, examine the implementation logic of the main() function, partial code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signed int __cdecl csc_main(int a1, char *const *a2)\u003Cbr>{\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>  if ( strlen(v14) &gt; 4 )\u003Cbr>  {\u003Cbr>    v4 = strlen(v14);\u003Cbr>    if ( !strcmp(&amp;v14[v4 - 4], \".bin\") )\u003Cbr>    {\u003Cbr>      extract_conf((int)v14);\u003Cbr>      v17 = 1;\u003Cbr>      v14 = \"\u002F_conf\u002Fcsc\u002Fcsc.conf\";\u003Cbr>    }\u003Cbr>  }\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>    if ( v17 )\u003Cbr>      system(\u003Cbr>        \"rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.g\"\u003Cbr>        \"z \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list\");\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analyzing the above code, csc first calls the extract_conf() function to export configurations, and finally executes the system command rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list to delete configuration files, preventing us from directly obtaining the relevant configuration files.\u003C\u002Fp>\u003Cp>Examining the implementation code of the extract_conf() function:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int __cdecl extract_conf(int a1)\u003Cbr>{\u003Cbr>  int v2; \u002F\u002F [esp+18h] [ebp-10h]\u003Cbr>  unsigned int v3; \u002F\u002F [esp+1Ch] [ebp-Ch]\u003Cbr>\u003Cbr>  v3 = __readgsdword(0x14u);\u003Cbr>  system(\"mount --make-private \u002F_conf\u002Fcsc\");\u003Cbr>  if ( mount(\"none\", \"\u002F_conf\u002Fcsc\", \"tmpfs\", 0, 0) )\u003Cbr>  {\u003Cbr>    puts(\"mount tmpfs failed\");\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  v2 = sub_8052494(a1, \"\u002F_conf\u002Fcsc\u002Fcscconf.tar.gz\");\u003Cbr>  if ( v2 == -1 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  if ( v2 == -2 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file2  %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  system(\"tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc\");\u003Cbr>  return __readgsdword(0x14u) ^ v3;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on the analysis of the above code, csc first calls the sub_8052494() function to decrypt \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz, then executes the system command tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc to extract the configuration files to the folder \u002F_conf\u002Fcsc.\u003C\u002Fp>\u003Cp>Based on the comprehensive analysis above, we can adopt the following method to export the configuration files: modify the csc program to change the extraction path from \u002F_conf\u002Fcsc to another path, such as \u002Fvar\u002Faaaaa. Then, when csc attempts to delete the configuration files, it will fail because it specifies a fixed absolute path, preventing it from deleting the new folder. This allows us to obtain the complete configuration files.\u003C\u002Fp>\u003Cp>The specific implementation method is as follows:\u003C\u002Fp>\u003Ch4>(1) Modify csc\u003C\u002Fh4>\u003Cp>Load csc using IDA, view Exports, find extract_conf, double-click to enter IDA View, locate the string tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017416850_3_bffc7a633b.png\">\u003C\u002Fp>\u003Cp>Switch to Hex View, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017462276_4_96d5079147.png\">\u003C\u002Fp>\u003Cp>Change \u002F_conf\u002Fcsc to \u002Fvar\u002Faaaaa, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017478223_5_297a8b93ce.png\">\u003C\u002Fp>\u003Cp>Right-click and select Apply changes\u003C\u002Fp>\u003Cp>Select Edit-&gt;Patch program-&gt;Apply patches to input file...-&gt;OK in sequence to generate the new file csc\u003C\u002Fp>\u003Ch4>(2) Replace csc\u003C\u002Fh4>\u003Cp>Log in via SSH, upload the new file csc, save to \u002Ftmp\u002Fcsc\u003C\u002Fp>\u003Cp>Back up csc and replace it, execute the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc_original\u003Cbr>mkdir \u002Fvar\u002Faaaaa\u003Cbr>cp \u002Ftmp\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>chmod 755 \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>ll \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Confirm whether the configuration file was exported successfully\u003C\u002Fh4>\u003Cp>Wait for the system to reboot, enter the underlying shell, and sequentially input 5.Device Management-&gt;3.Advanced Shell\u003C\u002Fp>\u003Cp>Check the folder \u002Fvar\u002Faaaaa, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017488148_6_0a43185f68.png\">\u003C\u002Fp>\u003Cp>Configuration file exported successfully\u003C\u002Fp>\u003Ch4>(4) Restore csc\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc_original \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Download the configuration file\u003C\u002Fh4>\u003Cp>Log in via SSH and download the contents from the folder \u002Fvar\u002Faaaaa\u003C\u002Fp>\u003Ch2>0x06 PostgreSQL Database Query\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check port information by executing the command: netstat -tulpen | grep postgres\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      65534      3800       1087\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5433          0.0.0.0:*               LISTEN      65534      5846       1182\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5434          0.0.0.0:*               LISTEN      65534      5813       1161\u002Fpostgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Through investigation, it was found that the connection information for the above three databases corresponds to the following three files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPool.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForReports.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForSignature.cfg\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The configuration information in the files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5432\u002Fcorporate?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5433\u002Fiviewdb?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5434\u002Fsignature?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test command 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>corporate=&gt; \\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:  permission denied for relation pg_class\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates insufficient permissions\u003C\u002Fp>\u003Cp>Test command 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>select * from tbluser;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Able to retrieve user information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>User pgrouser has identical permissions as nobody\u003C\u002Fp>\u003Cp>From the above information, both users pgrouser and nobody are non-root users with limited functionality. Next, attempt to locate the root user\u003C\u002Fp>\u003Cp>Examine the decrypted csc configuration file, locate \\service\\postgres.csc. Key file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblhavmac -f \u002Ftmp\u002Fcorphavmac\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblinterface -t tblipaddress -f \u002Ftmp\u002Fcorpifdb\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -n config -T tbllivesslvpnusers -T tblhbcloudcredential -f \u002Ftmp\u002Fcorpdb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Locate the key user pgroot\u003C\u002Fp>\u003Cp>Test command 3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -U pgroot -d corporate\u003Cbr>\\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces solutions to some problems encountered during the setup of the Sophos XG debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Sophos UTM and Sophos XG are two distinct products; the former leans towards general threat management, while the latter focuses on hardware firewalls. This article will introduce the method for setting up a Sophos XG vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Jetty Debugging Environment Setup\u003C\u002Fli>\u003Cli>CSC Configuration File Decryption\u003C\u002Fli>\u003Cli>PostgreSQL Database Query\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Fundamentals\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Architecture as shown in the diagram below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017315579_0_4808194c6d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fcodewhitesec.blogspot.com\u002F2020\u002F07\u002Fsophos-xg-tale-of-unfortunate-re.html\u003C\u002Fp>\u003Cp>Overall, it is divided into the following three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Processes web data and forwards it to csc for further processing\u003C\u002Fli>\u003Cli>csc: Main program: Loads Perl Packages and implements core functionalities\u003C\u002Fli>\u003Cli>Postgresql: Used for data storage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my actual research, I encountered the following issues with these three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Jetty: Unable to start Java after adding debugging information\u003C\u002Fli>\u003Cli>csc: csc automatically deletes after loading Perl Packages, making it impossible to obtain implementation details of the Perl Packages\u003C\u002Fli>\u003Cli>Postgresql: Low user privileges prevent querying database tables\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The following will introduce solutions to these three problems one by one\u003C\u002Fp>\u003Ch2>0x03 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.sophos.com\u002Fnsg\u002Fsophos-firewall\u002F18.5\u002FHelp\u002Fen-us\u002Fwebhelp\u002Fonlinehelp\u002FVirtualAndSoftwareAppliancesHelp\u002FVMware\u002FVMwareInstall\u002Findex.html\u003C\u002Fp>\u003Ch3>1. Download the installation package\u003C\u002Fh3>\u003Cp>The official website only provides downloads for the latest version by default, but older versions can be downloaded by guessing the correct version number\u003C\u002Fp>\u003Cp>For example, 18.5.3 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.3_MR-3.VMW-408.zip\u003C\u002Fp>\u003Cp>18.5.2 Virtual Installers: Firewall OS for VMware:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdownload.sophos.com\u002Fnetwork\u002FSophosFirewall\u002Finstallers\u002FVI-18.5.2_MR-2.VMW-380.zip\u003C\u002Fp>\u003Ch3>2. Import to VMware Workstation\u003C\u002Fh3>\u003Cp>After downloading the zip file, extract it and run sf_virtual.ovf\u003C\u002Fp>\u003Ch3>3. VMware Workstation network adapter configuration\u003C\u002Fh3>\u003Cp>Two network adapters, VMnet7 and VMnet8, need to be added. Set VMnet7 to Host-only with 172.16.16.0, and VMnet8 to NAT. The specific steps are as follows:\u003C\u002Fp>\u003Ch4>(1) VMnet7\u003C\u002Fh4>\u003Cp>Open VMware Workstation, then select Edit -&gt; Virtual Network Editor...\u003C\u002Fp>\u003Cp>Add Network... -&gt; VMnet7\u003C\u002Fp>\u003Cp>Set VMnet7 as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Type: Host-only\u003C\u002Fli>\u003Cli>Subnet Address: 172.16.16.0\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) VMnet8\u003C\u002Fh4>\u003Cp>VMnet8 is set to:\u003C\u002Fp>\u003Cul>\u003Cli>Type: NAT\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Sophos XG Network Card Configuration\u003C\u002Fh3>\u003Cp>Network Adapter set to VMnet7\u003C\u002Fp>\u003Cp>Network Adapter 2 set to VMnet8\u003C\u002Fp>\u003Cp>Network Adapter 3 set to VMnet8\u003C\u002Fp>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017356017_1_6c75cdb1f2-1.png\">\u003C\u002Fp>\u003Ch3>5. Start Sophos XG\u003C\u002Fh3>\u003Cp>Default login password: admin\u003C\u002Fp>\u003Ch3>6. View IP Address\u003C\u002Fh3>\u003Cp>Enter in sequence: 1. Network Configuration -&gt; 1. Interface Configuration\u003C\u002Fp>\u003Cp>Obtain LAN IP as 172.16.16.16\u003C\u002Fp>\u003Ch3>7. Access the web configuration page for activation\u003C\u002Fh3>\u003Cp>Access https:\u002F\u002F172.16.16.16:4444 via browser\u003C\u002Fp>\u003Cp>On the registration page, select: I don't have a serial number (start a trial)\u003C\u002Fp>\u003Cp>Proceed with registration as prompted\u003C\u002Fp>\u003Cp>After successful registration, re-access https:\u002F\u002F172.16.16.16:4444 for configuration\u003C\u002Fp>\u003Ch2>0x04 Jetty debugging environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Java process related information\u003C\u002Fh3>\u003Cp>Execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             3238   923 root     1393m  264m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the output, obtain Java version as java-11-openjdk\u003C\u002Fp>\u003Ch3>2. Locate configuration file\u003C\u002Fh3>\u003Cp>Configuration file path is \u002Fusr\u002Fbin\u002Fjetty, with content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>\u003Cbr>if   [ \"${RAM}\" == \"2GB\" ]; then\u003Cbr>        heap_size=256\u003Cbr>elif [ \"${RAM}\" == \"4GB\" ]; then\u003Cbr>        heap_size=384\u003Cbr>else\u003Cbr>        heap_size=512\u003Cbr>fi\u003Cbr>\u003Cbr>HYBRID_ENABLED=false\u003Cbr>\u003Cbr>if [ $HYBRID_ENABLED = true ]; then\u003Cbr>    HYBRID_ENABLED=`opcode gethainfo -s nosync | grep -q \"hamode=1\" &amp;&amp; echo \"true\" || echo \"false\"`\u003Cbr>fi\u003Cbr>if [ ! -d \u002Ftmp\u002Fjava ]; then\u003Cbr>    mkdir \u002Ftmp\u002Fjava\u003Cbr>fi\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\" \"mount\"\u003Cbr>\u003Cbr>##\u003Cbr># sun.jnu.encoding=UTF-8 - System property is required with file.encoding otherwise some java APIs unable to read file having double byte characters in file name.\u003Cbr>##\u003Cbr>exec \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx${heap_size}m -Xms12m -Xss256k \"-XX:MaxMetaspaceSize=100m\" \"-Dhybrid.enabled=${HYBRID_ENABLED}\" \"-Djna.tmpdir=\u002Ftmp\u002Fjava\" \"-Djava.io.tmpdir=\u002Ftmp\u002Fjava\" \"-Dsun.jnu.encoding=UTF-8\" \"-Dfile.encoding=UTF-8\" \"-Djava.awt.headless=true\" \"-Djetty.home=\u002Fusr\u002Fshare\u002Fjetty\" \"-Djetty.base=\u002Fusr\u002Fshare\u002Fjetty\" -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar \"--lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\"\u003Cbr>\u002Fscripts\u002Fumnt_mount_dir.sh \"JVM\" \"\u002Ftmp\u002Fjava\"\u003Cbr>exit $?\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Add debugging parameters\u003C\u002Fh3>\u003Cp>Modify file attributes: mount -o rw,remount \u002F\u003C\u002Fp>\u003Cp>Add debugging parameters on the exec line: \"-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000\"\u003C\u002Fp>\u003Ch3>4. Restart service\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status is STOPPED\u003C\u002Fp>\u003Cp>To obtain detailed error information, directly run \u002Fusr\u002Fbin\u002Fjetty\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error occurred during initialization of VM\u003Cbr>Could not find agent library jdwp on the library path, with error: libjdwp.so: cannot open shared object file: No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Identified as a JDK issue, opting to replace with a complete JDK here\u003C\u002Fp>\u003Ch3>5. Replace JDK\u003C\u002Fh3>\u003Cp>Download jdk-11.0.15_linux-x64_bin.tar.gz and upload to Sophos XG\u003C\u002Fp>\u003Cp>Backup original folder: cp -r \u002Flib\u002Fjvm\u002Fjava-11-openjdk \u002Flib\u002Fjvm\u002Fjava-11-openjdk_backup\u003C\u002Fp>\u003Cp>Extract jdk-11.0.15_linux-x64_bin.tar.gz: tar zxvf \u002Ftmp\u002Fjdk-11.0.15_linux-x64_bin.tar.gz\u003C\u002Fp>\u003Cp>Replace \u002Flib\u002Fjvm\u002Fjava-11-openjdk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003Cbr>cp -r \u002Ftmp\u002Fjdk-11.0.15 \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Restart service again\u003C\u002Fh3>\u003Cp>Execute command: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Cp>Check service status: service -S | grep tomcat\u003C\u002Fp>\u003Cp>Found tomcat status as RUNNING\u003C\u002Fp>\u003Cp>Confirm parameters were modified, execute command: ps ww|grep java\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java             1827   923 root     1454m  158m S    \u002Flib\u002Fjvm\u002Fjava-11-openjdk\u002Fbin\u002Fjava -Xmx384m -Xms12m -Xss256k -XX:MaxMetaspaceSize=100m -Dhybrid.enabled=false -Djna.tmpdir=\u002Ftmp\u002Fjava -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:8000 -Djava.io.tmpdir=\u002Ftmp\u002Fjava -Dsun.jnu.encoding=UTF-8 -Dfile.encoding=UTF-8 -Djava.awt.headless=true -Djetty.home=\u002Fusr\u002Fshare\u002Fjetty -Djetty.base=\u002Fusr\u002Fshare\u002Fjetty -jar \u002Fusr\u002Fshare\u002Fjetty\u002Fstart.jar --lib=\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Modify firewall rules\u003C\u002Fh3>\u003Cp>Execute command: iptables -I INPUT -p tcp --dport 8000 -j ACCEPT\u003C\u002Fp>\u003Ch3>8. Use IDEA for remote debugging\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017388600_2_54b8287203-1.png\">\u003C\u002Fp>\u003Cp>During debugging, if you encounter a situation where breakpoints cannot be set, restart the Java service: service tomcat:restart -ds nosync\u003C\u002Fp>\u003Ch2>0x05 CSC configuration file decryption\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View CSC process related information\u003C\u002Fp>\u003Cp>Execute command: ps ww|grep csc\u003C\u002Fp>\u003Cp>Partial output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csc               859     1 root     25916 23600 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>csc               869   859 root      8628   452 S    csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>cfs               870   859 root     34736 29380 S    {cfs} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>listener          871   859 root     21752 15088 S    {listener} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>lcdd              889   871 root     21108 13556 S    {lcdd} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>postgres          890   871 root     29712 25040 S    {postgres} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>sigdb             891   871 root     26756 23208 S    {sigdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>reportdb          892   871 root     26756 23104 S    {reportdb} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003Cbr>awarrensmtp       893   871 root     25916 22296 S    {awarrensmtp} csc -L 3 -w -c \u002F_conf\u002Fcscconf.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The csc process reads \u002F_conf\u002Fcscconf.bin as the configuration file, and \u002F_conf\u002Fcscconf.bin is an encrypted file, so it is necessary to decrypt \u002F_conf\u002Fcscconf.bin here.\u003C\u002Fp>\u003Cp>The method I adopted here is to modify the program code through IDA, change the implementation logic, and export the decrypted configuration file.\u003C\u002Fp>\u003Cp>Load csc using IDA, examine the implementation logic of the main() function, partial code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signed int __cdecl csc_main(int a1, char *const *a2)\u003Cbr>{\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>  if ( strlen(v14) &gt; 4 )\u003Cbr>  {\u003Cbr>    v4 = strlen(v14);\u003Cbr>    if ( !strcmp(&amp;v14[v4 - 4], \".bin\") )\u003Cbr>    {\u003Cbr>      extract_conf((int)v14);\u003Cbr>      v17 = 1;\u003Cbr>      v14 = \"\u002F_conf\u002Fcsc\u002Fcsc.conf\";\u003Cbr>    }\u003Cbr>  }\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>    if ( v17 )\u003Cbr>      system(\u003Cbr>        \"rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.g\"\u003Cbr>        \"z \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list\");\u003Cbr>  \u002F\u002F****ignore code*****\u002F\u002F\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Analyzing the above code, csc first calls the extract_conf() function to export configurations, and finally executes the system command rm -rf \u002F_conf\u002Fcsc\u002Fcsc \u002F_conf\u002Fcsc\u002Fcsc.conf \u002F_conf\u002Fcsc\u002Fcscconf\u002F \u002F_conf\u002Fcsc\u002Fconstants.conf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz \u002F_conf\u002Fcsc\u002Fglobal.conf \u002F_conf\u002Fcsc\u002Fcfsconf \u002F_conf\u002Fcsc\u002Fservice \u002F_conf\u002Fcsc\u002Fbind_file_list to delete configuration files, preventing us from directly obtaining the relevant configuration files.\u003C\u002Fp>\u003Cp>Examining the implementation code of the extract_conf() function:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int __cdecl extract_conf(int a1)\u003Cbr>{\u003Cbr>  int v2; \u002F\u002F [esp+18h] [ebp-10h]\u003Cbr>  unsigned int v3; \u002F\u002F [esp+1Ch] [ebp-Ch]\u003Cbr>\u003Cbr>  v3 = __readgsdword(0x14u);\u003Cbr>  system(\"mount --make-private \u002F_conf\u002Fcsc\");\u003Cbr>  if ( mount(\"none\", \"\u002F_conf\u002Fcsc\", \"tmpfs\", 0, 0) )\u003Cbr>  {\u003Cbr>    puts(\"mount tmpfs failed\");\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  v2 = sub_8052494(a1, \"\u002F_conf\u002Fcsc\u002Fcscconf.tar.gz\");\u003Cbr>  if ( v2 == -1 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  if ( v2 == -2 )\u003Cbr>  {\u003Cbr>    printf(\"Cannot read file2  %s\\n\", a1);\u003Cbr>    exit(70);\u003Cbr>  }\u003Cbr>  system(\"tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc\");\u003Cbr>  return __readgsdword(0x14u) ^ v3;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on the analysis of the above code, csc first calls the sub_8052494() function to decrypt \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz, then executes the system command tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc to extract the configuration files to the folder \u002F_conf\u002Fcsc.\u003C\u002Fp>\u003Cp>Based on the comprehensive analysis above, we can adopt the following method to export the configuration files: modify the csc program to change the extraction path from \u002F_conf\u002Fcsc to another path, such as \u002Fvar\u002Faaaaa. Then, when csc attempts to delete the configuration files, it will fail because it specifies a fixed absolute path, preventing it from deleting the new folder. This allows us to obtain the complete configuration files.\u003C\u002Fp>\u003Cp>The specific implementation method is as follows:\u003C\u002Fp>\u003Ch4>(1) Modify csc\u003C\u002Fh4>\u003Cp>Load csc using IDA, view Exports, find extract_conf, double-click to enter IDA View, locate the string tar -zxf \u002F_conf\u002Fcsc\u002Fcscconf.tar.gz -C \u002F_conf\u002Fcsc, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017416850_3_bffc7a633b-1.png\">\u003C\u002Fp>\u003Cp>Switch to Hex View, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017462276_4_96d5079147-1.png\">\u003C\u002Fp>\u003Cp>Change \u002F_conf\u002Fcsc to \u002Fvar\u002Faaaaa, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017478223_5_297a8b93ce-1.png\">\u003C\u002Fp>\u003Cp>Right-click and select Apply changes\u003C\u002Fp>\u003Cp>Select Edit-&gt;Patch program-&gt;Apply patches to input file...-&gt;OK in sequence to generate the new file csc\u003C\u002Fp>\u003Ch4>(2) Replace csc\u003C\u002Fh4>\u003Cp>Log in via SSH, upload the new file csc, save to \u002Ftmp\u002Fcsc\u003C\u002Fp>\u003Cp>Back up csc and replace it, execute the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc_original\u003Cbr>mkdir \u002Fvar\u002Faaaaa\u003Cbr>cp \u002Ftmp\u002Fcsc \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>chmod 755 \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>ll \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Confirm whether the configuration file was exported successfully\u003C\u002Fh4>\u003Cp>Wait for the system to reboot, enter the underlying shell, and sequentially input 5.Device Management-&gt;3.Advanced Shell\u003C\u002Fp>\u003Cp>Check the folder \u002Fvar\u002Faaaaa, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017488148_6_0a43185f68-1.png\">\u003C\u002Fp>\u003Cp>Configuration file exported successfully\u003C\u002Fp>\u003Ch4>(4) Restore csc\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mount -o rw,remount \u002F\u003Cbr>cp \u002Fusr\u002Fbin\u002Fcsc_original \u002Fusr\u002Fbin\u002Fcsc\u003Cbr>reboot\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Download the configuration file\u003C\u002Fh4>\u003Cp>Log in via SSH and download the contents from the folder \u002Fvar\u002Faaaaa\u003C\u002Fp>\u003Ch2>0x06 PostgreSQL Database Query\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check port information by executing the command: netstat -tulpen | grep postgres\u003C\u002Fp>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      65534      3800       1087\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5433          0.0.0.0:*               LISTEN      65534      5846       1182\u002Fpostgres\u003Cbr>tcp        0      0 127.0.0.1:5434          0.0.0.0:*               LISTEN      65534      5813       1161\u002Fpostgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Through investigation, it was found that the connection information for the above three databases corresponds to the following three files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPool.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForReports.cfg\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fwebconsole\u002Fproperties\u002FConnectionPoolForSignature.cfg\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The configuration information in the files is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5432\u002Fcorporate?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5433\u002Fiviewdb?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003Cli>JDBCConnectionURL=jdbc:postgresql:\u002F\u002F127.0.0.1:5434\u002Fsignature?user=pgrouser&amp;autoReconnect=true\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test command 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>corporate=&gt; \\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:  permission denied for relation pg_class\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates insufficient permissions\u003C\u002Fp>\u003Cp>Test command 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -p 5432 corporate -U pgrouser\u003Cbr>select * from tbluser;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Able to retrieve user information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>User pgrouser has identical permissions as nobody\u003C\u002Fp>\u003Cp>From the above information, both users pgrouser and nobody are non-root users with limited functionality. Next, attempt to locate the root user\u003C\u002Fp>\u003Cp>Examine the decrypted csc configuration file, locate \\service\\postgres.csc. Key file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblhavmac -f \u002Ftmp\u002Fcorphavmac\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -t tblinterface -t tblipaddress -f \u002Ftmp\u002Fcorpifdb\"\u003Cbr>EXEC \u002Fbin\u002Fsynccmd \"\u002Fsbin\u002Fpg_dump -U pgroot corporate -a --disable-triggers -n config -T tbllivesslvpnusers -T tblhbcloudcredential -f \u002Ftmp\u002Fcorpdb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Locate the key user pgroot\u003C\u002Fp>\u003Cp>Test command 3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -U pgroot -d corporate\u003Cbr>\\d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces solutions to some problems encountered during the setup of the Sophos XG debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1157,"Onedaysec",8,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Sophos XG Vulnerability Debugging: Setup Jetty, CSC, PostgreSQL","Sophos XG, vulnerability debugging, Jetty setup, CSC decryption, PostgreSQL query, environment configuration",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],444,442,441,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.310Z","2026-07-23T16:01:35.518Z","draft","2026-07-23T16:06:20.864Z"]