[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foWg_k_kJFL3hS65PZazndy_brB05kSNGlytx6-2Ycok":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},677,"What steps are needed to enable remote debugging for vulnerability research in VMware Workspace ONE Access?","First, enable SSH root login by editing \u002Fetc\u002Fssh\u002Fsshd_config and changing PermitRootLogin to yes. Then modify \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh to add JVM_OPTS with `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000`. Restart the system and open the firewall with iptables commands. Set remote debugging parameters in your IDE (e.g., IDEA) as described in the Zimbra article. This process is analogous to debugging setups for other products like [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).","\u003Cp>First, enable SSH root login by editing \u002Fetc\u002Fssh\u002Fsshd_config and changing PermitRootLogin to yes. Then modify \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh to add JVM_OPTS with `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000`. Restart the system and open the firewall with iptables commands. Set remote debugging parameters in your IDE (e.g., IDEA) as described in the Zimbra article. This process is analogous to debugging setups for other products like [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvmware-workspace-one-access-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-steps-are-needed-to-enable-remote-debugging-for-vulnerability-research-in-v-1777482359526","remote debugging, JVM_OPTS, jdwp, SSH root, setenv.sh, firewall",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},168,"VMware Workspace ONE Access Vulnerability Debugging Environment Setup","vmware-workspace-one-access-vulnerability-debugging-environment-setup","Step-by-step guide to set up VMware Workspace ONE Access vulnerability debugging environment, including OVA installation, SSH setup, and remote debugging configuration.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details the process of setting up a VMware Workspace ONE Access vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>VMware Workspace ONE Access Installation\u003C\u002Fli>\u003Cli>VMware Workspace ONE Access Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VMware Workspace ONE Access Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.vmware.com\u002Fen\u002FVMware-Workspace-ONE-Access\u002F20.01\u002Fworkspace_one_access_install.pdf\u003C\u002Fp>\u003Ch3>1. Download the OVA File\u003C\u002Fh3>\u003Cp>Download page:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fsearch?query=workspace%20one%20access\u003C\u002Fp>\u003Cp>Registration is required before downloading, then select the desired version to download\u003C\u002Fp>\u003Cp>Download page for VMware Workspace ONE Access 21.08.0.1: https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fdetails?downloadGroup=WS1A_ONPREM_210801&amp;productId=1269\u003C\u002Fp>\u003Cp>Download file identity-manager-21.08.0.1-19010796_OVF10.ova\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Ch4>(1) Import the OVA file in VMware Workstation\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VMware Workstation version must be greater than 14, otherwise an error will occur indicating inability to import\u003C\u002Fp>\u003Cp>Set the Host Name on the installation page. If DHCP is configured, other options do not need to be set. My configuration uses a static IP, configured as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291780_0_a1ffbd9eed.jpeg\">\u003C\u002Fp>\u003Cp>After the OVA file import is complete, it will automatically power on for initialization. After initialization is complete, it will appear as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322087_1_a354d3d868.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configuration\u003C\u002Fh4>\u003Cp>Modify the local hosts file to point 192.168.1.11 to workspaceone.test.com\u003C\u002Fp>\u003Cp>Access the configuration page at https:\u002F\u002Fworkspaceone.test.com:8443\u003C\u002Fp>\u003Cp>Set passwords for admin, root, and sshuser users; passwords must include uppercase letters, lowercase letters, numbers, and special characters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test results show that the password length must be set to 14, otherwise root and sshuser users cannot log in\u003C\u002Fp>\u003Cp>In my test environment, the password is set to Password@12345, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371211_2_850096d6b1.jpeg\">\u003C\u002Fp>\u003Cp>Set up the database; for ease of environment setup, select Internal Database here\u003C\u002Fp>\u003Cp>Wait for the installation to complete, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395296_3_6919fa737b.jpeg\">\u003C\u002Fp>\u003Ch3>3. Enable remote SSH login for the root user\u003C\u002Fh3>\u003Cp>To log in to VMware Workspace ONE Access and modify the system configuration file, there are two login methods:\u003C\u002Fp>\u003Ch4>(1) Log in directly as the root user in the virtual machine\u003C\u002Fh4>\u003Cp>Select Login, enter root and the password Password@12345\u003C\u002Fp>\u003Ch4>(2) Log in via SSH as the sshuser user\u003C\u002Fh4>\u003Cp>After logging in, switch to the root user\u003C\u002Fp>\u003Cp>After switching to the root user, execute the following commands in sequence:\u003C\u002Fp>\u003Cul>\u003Cli>vi \u002Fetc\u002Fssh\u002Fsshd_config\u003C\u002Fli>\u003Cli>Change PermitRootLogin from no to yes\u003C\u002Fli>\u003Cli>systemctl restart sshd\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Modify the file: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh\u003C\u002Fp>\u003Cp>Modify the JVM_OPTS parameter, add: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017440225_4_c68d49328e.jpeg\">\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>Open the firewall: iptables -P INPUT ACCEPT &amp;&amp; iptables -P OUTPUT ACCEPT\u003C\u002Fp>\u003Cp>Set remote debugging parameters in IDEA, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466562_5_14c23726f6.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the complete configuration method of IDEA, please refer to the previous article 'Setting Up Zimbra Vulnerability Debugging Environment'\u003C\u002Fp>\u003Ch2>0x03 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Common Commands\u003C\u002Fh3>\u003Cp>Check system service status: chkconfig --list\u003C\u002Fp>\u003Cp>Check all service status: systemctl status\u003C\u002Fp>\u003Cp>Check IP address: ip addr show\u003C\u002Fp>\u003Cp>Check Host Name: hostname\u003C\u002Fp>\u003Cp>Log path: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Flogs\u002F\u003C\u002Fp>\u003Ch3>2. Check System Version\u003C\u002Fh3>\u003Cp>Requires root privileges to execute command: vamicli version --appliance\u003C\u002Fp>\u003Cp>Implementation details for checking system version:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fusr\u002Fbin\u002Fenv python2\u003Cbr>import sys\u003Cbr>sys.path.append(\"\u002Fopt\u002Fvmware\u002Flib\u002Fpython\u002Fsite-packages\u002F\")\u003Cbr>import pywbem\u003Cbr>def getCIMConnection (url, namespace):\u003Cbr>    cred = {}\u003Cbr>    cred ['cert_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem'\u003Cbr>    cred ['key_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem'\u003Cbr>    cliconn = pywbem.WBEMConnection (url, None, namespace, cred)\u003Cbr>    return cliconn\u003Cbr>\u003Cbr>def showVersion():\u003Cbr>  try:\u003Cbr>    cliconn = getCIMConnection ('https:\u002F\u002Flocalhost:5489', 'root\u002Fcimv2')\u003Cbr>    esis = cliconn.EnumerateInstances ('VAMI_ElementSoftwareIdentity')\u003Cbr>  except:\u003Cbr>    print('error')\u003Cbr>    return\u003Cbr>  for esi in esis:\u003Cbr>    ess = esi ['ElementSoftwareStatus']\u003Cbr>    if (ess == [2, 6]):\u003Cbr>      inst = cliconn.GetInstance (esi['Antecedent'])\u003Cbr>      print ('Version - ' + inst ['VersionString'])\u003Cbr>      print ('Description - ' + inst ['Description'])\u003Cbr>showVersion()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Root privileges are required because accessing the files \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem and \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem requires root permissions.\u003C\u002Fp>\u003Ch3>3. Database Connection Password\u003C\u002Fh3>\u003Cp>The plaintext password for connecting to the database is located at: \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd\u003C\u002Fp>\u003Cp>The encrypted password for connecting to the database is stored in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties. Example file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>datastore.jdbc.url=jdbc:postgresql:\u002F\u002Flocalhost\u002Fsaas?stringtype=unspecified\u003Cbr>datastore.jdbc.userName=horizon\u003Cbr>secure.datastore.jdbc.password=BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA==\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA== is the encrypted password.\u003C\u002Fp>\u003Cp>The following files are required as decryption keys:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass\u003C\u002Fli>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.bcfks\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Encrypted information in the database\u003C\u002Fh3>\u003Cp>The password of the admin user is encrypted and stored in the database\u003C\u002Fp>\u003Cp>Query command: saas=&gt; SELECT \"passwordAuthData\" FROM \"PasswordInformation\";\u003C\u002Fp>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480872_6_a7cc4e2a16.jpeg\">\u003C\u002Fp>\u003Cp>Main implementation code for encryption 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   private String AES_encrypt(@Nonnull byte[] clearData, @Nonnull byte[] key, @Nonnull EncryptionAlgorithms encAlg) throws EncryptionServiceException {\u003Cbr>        Preconditions.checkNotNull(clearData);\u003Cbr>        Preconditions.checkNotNull(key);\u003Cbr>        Preconditions.checkNotNull(encAlg);\u003Cbr>        Preconditions.checkArgument(clearData.length != 0);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String cipherName = encAlg.getCipherName();\u003Cbr>            Cipher cipher = Cipher.getInstance(cipherName, provider);\u003Cbr>            int nonceSize = encAlg.getNonceSize(cipher.getBlockSize());\u003Cbr>            IvParameterSpec ivSpec = null;\u003Cbr>            String encodedIv;\u003Cbr>            if (nonceSize &gt; 0) {\u003Cbr>                byte[] iv = new byte[nonceSize];\u003Cbr>                srand.nextBytes(iv);\u003Cbr>                ivSpec = new IvParameterSpec(iv);\u003Cbr>                encodedIv = new String(Hex.encode(iv), StandardCharsets.US_ASCII);\u003Cbr>            } else {\u003Cbr>                encodedIv = \"\";\u003Cbr>            }\u003Cbr>\u003Cbr>            if (encAlg.forcePadding()) {\u003Cbr>                clearData = ArrayUtils.add(clearData, (byte)1);\u003Cbr>            }\u003Cbr>\u003Cbr>            SecretKey secret = new SecretKeySpec(key, cipherName);\u003Cbr>            cipher.init(1, secret, ivSpec, srand);\u003Cbr>            byte[] data = cipher.doFinal(clearData);\u003Cbr>            String output = Integer.toString(4) + \":\" + encodedIv + \":\" + new String(Hex.encode(data), StandardCharsets.US_ASCII);\u003Cbr>            return output;\u003Cbr>        } catch (InvalidKeyException | BadPaddingException | IllegalBlockSizeException | InvalidAlgorithmParameterException | NoSuchPaddingException | NoSuchAlgorithmException | FipsUnapprovedOperationError var12) {\u003Cbr>            log.error(\"Failed to encrypt with AES: \" + var12.getMessage());\u003Cbr>            throw new EncryptionServiceException(var12);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Main implementation code for encryption 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>String encryptedData = Integer.toString(1) + \",\" + encKey.getSafeUuid().toString() + \",\" + this.AES_encrypt(clearData, aesKey, encAlg);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Port 5.8443 login password\u003C\u002Fh3>\u003Cp>Login password is encrypted and saved in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfig-admin.json\u003C\u002Fp>\u003Cp>Main implementation code for encryption:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    private void setPassword(String newPassword, boolean isSet) throws AdminAuthException {\u003Cbr>        int ic = this.passwordAuthenticationUtil.getIc(iterationCountBase, iterationCountRange);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String newEncryptedPassword = this.passwordAuthenticationUtil.createPWInfo(\"admin\", \"admin\", ic, newPassword);\u003Cbr>            PasswordInfo newPasswordInfo = new PasswordInfo(newEncryptedPassword, isSet);\u003Cbr>            if (this.passwordInfo != null) {\u003Cbr>                newPasswordInfo.setAttemptDelay(this.passwordInfo.getAttemptDelay());\u003Cbr>                newPasswordInfo.setMaxAttemptCount(this.passwordInfo.getMaxAttemptCount());\u003Cbr>            }\u003Cbr>\u003Cbr>            objectMapper.writeValue(this.passwordInfoFile, newPasswordInfo);\u003Cbr>        } catch (IOException | EncryptionServiceException var7) {\u003Cbr>            throw new AdminAuthException(\"Failed to set password\" + var7.getMessage(), var7);\u003Cbr>        }\u003Cbr>\u003Cbr>        try {\u003Cbr>            this.loadEncryptedPasswordFromFile();\u003Cbr>        } catch (IOException var6) {\u003Cbr>            throw new AdminAuthException(\"Failed to load stored password\" + var6.getMessage(), var6);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the VMware Workspace ONE Access vulnerability debugging environment, we can proceed to study the vulnerability and the method for decrypting database credentials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details the process of setting up a VMware Workspace ONE Access vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>VMware Workspace ONE Access Installation\u003C\u002Fli>\u003Cli>VMware Workspace ONE Access Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VMware Workspace ONE Access Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.vmware.com\u002Fen\u002FVMware-Workspace-ONE-Access\u002F20.01\u002Fworkspace_one_access_install.pdf\u003C\u002Fp>\u003Ch3>1. Download the OVA File\u003C\u002Fh3>\u003Cp>Download page:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fsearch?query=workspace%20one%20access\u003C\u002Fp>\u003Cp>Registration is required before downloading, then select the desired version to download\u003C\u002Fp>\u003Cp>Download page for VMware Workspace ONE Access 21.08.0.1: https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fdetails?downloadGroup=WS1A_ONPREM_210801&amp;productId=1269\u003C\u002Fp>\u003Cp>Download file identity-manager-21.08.0.1-19010796_OVF10.ova\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Ch4>(1) Import the OVA file in VMware Workstation\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VMware Workstation version must be greater than 14, otherwise an error will occur indicating inability to import\u003C\u002Fp>\u003Cp>Set the Host Name on the installation page. If DHCP is configured, other options do not need to be set. My configuration uses a static IP, configured as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291780_0_a1ffbd9eed-1.jpeg\">\u003C\u002Fp>\u003Cp>After the OVA file import is complete, it will automatically power on for initialization. After initialization is complete, it will appear as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322087_1_a354d3d868-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configuration\u003C\u002Fh4>\u003Cp>Modify the local hosts file to point 192.168.1.11 to workspaceone.test.com\u003C\u002Fp>\u003Cp>Access the configuration page at https:\u002F\u002Fworkspaceone.test.com:8443\u003C\u002Fp>\u003Cp>Set passwords for admin, root, and sshuser users; passwords must include uppercase letters, lowercase letters, numbers, and special characters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test results show that the password length must be set to 14, otherwise root and sshuser users cannot log in\u003C\u002Fp>\u003Cp>In my test environment, the password is set to Password@12345, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371211_2_850096d6b1-1.jpeg\">\u003C\u002Fp>\u003Cp>Set up the database; for ease of environment setup, select Internal Database here\u003C\u002Fp>\u003Cp>Wait for the installation to complete, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395296_3_6919fa737b-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Enable remote SSH login for the root user\u003C\u002Fh3>\u003Cp>To log in to VMware Workspace ONE Access and modify the system configuration file, there are two login methods:\u003C\u002Fp>\u003Ch4>(1) Log in directly as the root user in the virtual machine\u003C\u002Fh4>\u003Cp>Select Login, enter root and the password Password@12345\u003C\u002Fp>\u003Ch4>(2) Log in via SSH as the sshuser user\u003C\u002Fh4>\u003Cp>After logging in, switch to the root user\u003C\u002Fp>\u003Cp>After switching to the root user, execute the following commands in sequence:\u003C\u002Fp>\u003Cul>\u003Cli>vi \u002Fetc\u002Fssh\u002Fsshd_config\u003C\u002Fli>\u003Cli>Change PermitRootLogin from no to yes\u003C\u002Fli>\u003Cli>systemctl restart sshd\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Modify the file: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh\u003C\u002Fp>\u003Cp>Modify the JVM_OPTS parameter, add: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017440225_4_c68d49328e-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>Open the firewall: iptables -P INPUT ACCEPT &amp;&amp; iptables -P OUTPUT ACCEPT\u003C\u002Fp>\u003Cp>Set remote debugging parameters in IDEA, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466562_5_14c23726f6-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the complete configuration method of IDEA, please refer to the previous article 'Setting Up Zimbra Vulnerability Debugging Environment'\u003C\u002Fp>\u003Ch2>0x03 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Common Commands\u003C\u002Fh3>\u003Cp>Check system service status: chkconfig --list\u003C\u002Fp>\u003Cp>Check all service status: systemctl status\u003C\u002Fp>\u003Cp>Check IP address: ip addr show\u003C\u002Fp>\u003Cp>Check Host Name: hostname\u003C\u002Fp>\u003Cp>Log path: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Flogs\u002F\u003C\u002Fp>\u003Ch3>2. Check System Version\u003C\u002Fh3>\u003Cp>Requires root privileges to execute command: vamicli version --appliance\u003C\u002Fp>\u003Cp>Implementation details for checking system version:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fusr\u002Fbin\u002Fenv python2\u003Cbr>import sys\u003Cbr>sys.path.append(\"\u002Fopt\u002Fvmware\u002Flib\u002Fpython\u002Fsite-packages\u002F\")\u003Cbr>import pywbem\u003Cbr>def getCIMConnection (url, namespace):\u003Cbr>    cred = {}\u003Cbr>    cred ['cert_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem'\u003Cbr>    cred ['key_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem'\u003Cbr>    cliconn = pywbem.WBEMConnection (url, None, namespace, cred)\u003Cbr>    return cliconn\u003Cbr>\u003Cbr>def showVersion():\u003Cbr>  try:\u003Cbr>    cliconn = getCIMConnection ('https:\u002F\u002Flocalhost:5489', 'root\u002Fcimv2')\u003Cbr>    esis = cliconn.EnumerateInstances ('VAMI_ElementSoftwareIdentity')\u003Cbr>  except:\u003Cbr>    print('error')\u003Cbr>    return\u003Cbr>  for esi in esis:\u003Cbr>    ess = esi ['ElementSoftwareStatus']\u003Cbr>    if (ess == [2, 6]):\u003Cbr>      inst = cliconn.GetInstance (esi['Antecedent'])\u003Cbr>      print ('Version - ' + inst ['VersionString'])\u003Cbr>      print ('Description - ' + inst ['Description'])\u003Cbr>showVersion()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Root privileges are required because accessing the files \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem and \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem requires root permissions.\u003C\u002Fp>\u003Ch3>3. Database Connection Password\u003C\u002Fh3>\u003Cp>The plaintext password for connecting to the database is located at: \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd\u003C\u002Fp>\u003Cp>The encrypted password for connecting to the database is stored in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties. Example file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>datastore.jdbc.url=jdbc:postgresql:\u002F\u002Flocalhost\u002Fsaas?stringtype=unspecified\u003Cbr>datastore.jdbc.userName=horizon\u003Cbr>secure.datastore.jdbc.password=BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA==\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA== is the encrypted password.\u003C\u002Fp>\u003Cp>The following files are required as decryption keys:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass\u003C\u002Fli>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.bcfks\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Encrypted information in the database\u003C\u002Fh3>\u003Cp>The password of the admin user is encrypted and stored in the database\u003C\u002Fp>\u003Cp>Query command: saas=&gt; SELECT \"passwordAuthData\" FROM \"PasswordInformation\";\u003C\u002Fp>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480872_6_a7cc4e2a16-1.jpeg\">\u003C\u002Fp>\u003Cp>Main implementation code for encryption 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   private String AES_encrypt(@Nonnull byte[] clearData, @Nonnull byte[] key, @Nonnull EncryptionAlgorithms encAlg) throws EncryptionServiceException {\u003Cbr>        Preconditions.checkNotNull(clearData);\u003Cbr>        Preconditions.checkNotNull(key);\u003Cbr>        Preconditions.checkNotNull(encAlg);\u003Cbr>        Preconditions.checkArgument(clearData.length != 0);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String cipherName = encAlg.getCipherName();\u003Cbr>            Cipher cipher = Cipher.getInstance(cipherName, provider);\u003Cbr>            int nonceSize = encAlg.getNonceSize(cipher.getBlockSize());\u003Cbr>            IvParameterSpec ivSpec = null;\u003Cbr>            String encodedIv;\u003Cbr>            if (nonceSize &gt; 0) {\u003Cbr>                byte[] iv = new byte[nonceSize];\u003Cbr>                srand.nextBytes(iv);\u003Cbr>                ivSpec = new IvParameterSpec(iv);\u003Cbr>                encodedIv = new String(Hex.encode(iv), StandardCharsets.US_ASCII);\u003Cbr>            } else {\u003Cbr>                encodedIv = \"\";\u003Cbr>            }\u003Cbr>\u003Cbr>            if (encAlg.forcePadding()) {\u003Cbr>                clearData = ArrayUtils.add(clearData, (byte)1);\u003Cbr>            }\u003Cbr>\u003Cbr>            SecretKey secret = new SecretKeySpec(key, cipherName);\u003Cbr>            cipher.init(1, secret, ivSpec, srand);\u003Cbr>            byte[] data = cipher.doFinal(clearData);\u003Cbr>            String output = Integer.toString(4) + \":\" + encodedIv + \":\" + new String(Hex.encode(data), StandardCharsets.US_ASCII);\u003Cbr>            return output;\u003Cbr>        } catch (InvalidKeyException | BadPaddingException | IllegalBlockSizeException | InvalidAlgorithmParameterException | NoSuchPaddingException | NoSuchAlgorithmException | FipsUnapprovedOperationError var12) {\u003Cbr>            log.error(\"Failed to encrypt with AES: \" + var12.getMessage());\u003Cbr>            throw new EncryptionServiceException(var12);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Main implementation code for encryption 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>String encryptedData = Integer.toString(1) + \",\" + encKey.getSafeUuid().toString() + \",\" + this.AES_encrypt(clearData, aesKey, encAlg);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Port 5.8443 login password\u003C\u002Fh3>\u003Cp>Login password is encrypted and saved in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfig-admin.json\u003C\u002Fp>\u003Cp>Main implementation code for encryption:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    private void setPassword(String newPassword, boolean isSet) throws AdminAuthException {\u003Cbr>        int ic = this.passwordAuthenticationUtil.getIc(iterationCountBase, iterationCountRange);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String newEncryptedPassword = this.passwordAuthenticationUtil.createPWInfo(\"admin\", \"admin\", ic, newPassword);\u003Cbr>            PasswordInfo newPasswordInfo = new PasswordInfo(newEncryptedPassword, isSet);\u003Cbr>            if (this.passwordInfo != null) {\u003Cbr>                newPasswordInfo.setAttemptDelay(this.passwordInfo.getAttemptDelay());\u003Cbr>                newPasswordInfo.setMaxAttemptCount(this.passwordInfo.getMaxAttemptCount());\u003Cbr>            }\u003Cbr>\u003Cbr>            objectMapper.writeValue(this.passwordInfoFile, newPasswordInfo);\u003Cbr>        } catch (IOException | EncryptionServiceException var7) {\u003Cbr>            throw new AdminAuthException(\"Failed to set password\" + var7.getMessage(), var7);\u003Cbr>        }\u003Cbr>\u003Cbr>        try {\u003Cbr>            this.loadEncryptedPasswordFromFile();\u003Cbr>        } catch (IOException var6) {\u003Cbr>            throw new AdminAuthException(\"Failed to load stored password\" + var6.getMessage(), var6);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the VMware Workspace ONE Access vulnerability debugging environment, we can proceed to study the vulnerability and the method for decrypting database credentials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",811,"Onedaysec",5,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"VMware Workspace ONE Access Debugging Environment Setup Guide","VMware Workspace ONE Access, vulnerability debugging, environment setup, OVA installation, SSH configuration, remote debugging",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],679,678,676,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.922Z","2026-07-23T16:01:57.021Z","draft","2026-07-23T16:14:09.499Z"]