Join our Newsletter — 33% off our NHI Course

What is the difference between RMI-IIOP brute-forcing and RMI-JRMP brute-forcing?

RMI-IIOP brute-forcing is usually easier for name discovery because many methods resolve to simple string-based matches, but it is less safe because primitive-only calls can execute during probing. RMI-JRMP more often exposes type information through method hashes and casting behavior, which can make malformed guesses more obvious. The trade-off is easier enumeration versus weaker safety boundaries.

How the two brute-force paths behave differently

RMI-iiop and RMI-JRMP brute-forcing differ less in the idea of guessing remote methods than in the wire behavior you can observe while doing it. RMI-IIOP tends to be friendlier to name discovery because method resolution is often string-oriented, while RMI-JRMP exposes more protocol structure, including method hashes and type-casting behavior, so malformed guesses can fail more visibly.

The practical effect is that RMI-IIOP often lets an attacker test more names with less upfront knowledge, but that flexibility can come at the cost of accidentally triggering real execution paths. RMI-JRMP is usually more self-describing during probing, which can make enumeration cleaner, but it does not automatically make probing safe.

Why enumeration safety is the real difference

The key distinction is not just which protocol is easier to guess against, but which one gives you better feedback without crossing into action. With IIOP-style discovery, primitive-only calls can execute during probing, so a harmless-looking brute-force pass may have side effects. With JRMP, the hash-and-cast workflow can reveal when a candidate is wrong before deeper interaction, which helps separate discovery from execution.

That means brute-force tooling has to treat result quality and operational safety as separate questions. A method name that looks promising is not the same thing as a method that can be probed safely, and a protocol that rejects bad guesses loudly is not the same thing as a protocol that is harder to enumerate.

What this means for assessment and defensive testing

For defenders and testers, the useful comparison is how much signal the protocol leaks during enumeration and how much unintended behavior it allows before a mismatch is obvious. In practice, RMI-IIOP deserves more caution during exploratory probing because “discovery” may already have crossed into execution. RMI-JRMP is more suited to controlled validation of known or suspected methods because its type and hash behavior can surface mismatches earlier.

That also means you should not treat brute-force success as a stable indicator of exploitability by itself. The method surface, parameter types, and remote object behavior all matter, and the same target can behave very differently depending on whether the probing path is safe, stateful, or able to invoke real logic.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK provides the primary governance reference for this topic.

Framework Control / Reference Relevance
MITRE ATT&CK T1046 — Network Service Discovery Method brute-forcing is a discovery technique against remote services.
Recommendation — Map remote enumeration attempts to discovery telemetry and alert on repeated malformed probes.

Practitioner Guidance

What to verify: Before relying on a brute-force result, confirm whether the probe was purely descriptive or whether it could have invoked state-changing logic. For RMI-IIOP, assume method discovery may be unsafe until proven otherwise; for RMI-JRMP, validate that hash or cast failures are being interpreted correctly rather than treated as definitive proof of absence.

Decision rule: If your goal is enumeration, prefer the path that gives the clearest mismatch signal with the least chance of execution. If your goal is risk reduction, test both protocols in a lab first, because the safer-looking probe is not always the safer one.

Practitioner takeaway: The important difference is not just discoverability, it is where the line between probing and execution sits. A protocol that leaks more structure can still be the safer assessment path if it fails cleanly before side effects begin.