
استغلال RCE في Laravel. CVE-2018-15133
_ _ _
| | __ _ _ __ __ _ ___ ___ _ __ (_) _ __ | |_
| | / _` || '__| / _` |/ __| / __|| '__|| || '_ \ | __|
| |___ | (_| || | | (_| |\__ \| (__ | | | || |_) || |_
|_____| \__,_||_| \__,_||___/ \___||_| |_|| .__/ \__|
|_|
المؤلفون: @pwnedshell & @rsgbengi
</pre>
<p align="center">
<img alt="GitHub last commit" src="https://img.shields.io/github/last-commit/PwnedShell/Larascript?style=for-the-badge">
<img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/PwnedShell/Larascript?style=for-the-badge">
<img alt="GitHub" src="https://img.shields.io/github/license/pwnedshell/Larascript?style=for-the-badge">
</p>
<p align="center">
<img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/pwnedshell?style=for-the-badge">
<img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/rsgbengii?style=for-the-badge">
</p>
<br>
<h2>📌 ما هو Larascript؟</h2>
Larascript هو سكربت يستفيد من <code>CVE-2018-15133</code> ويمكنه تنفيذ أوامر عن بُعد إذا كان تطبيق Laravel معرّضًا للخطر. يمكنك إرسال الأوامر والحصول على استجابة مثل <code>cat /etc/passwd</code>. كما يمكنك أيضًا طلب شيل ليمنحك شيلًا عكسيًا (reverse shell). لديه بعض التخصيصات في الوسائط (arguments) بحيث يمكنك تحديد نوع الشيل العكسي الذي تحصل عليه (bash أو sh)، ولغة الشيل العكسي المستخدمة لاسترداد الشيل (php، bash، mkfifo، python...) أو طريقة RCE الخاصة بـ Laravel (1، 2، 3 أو 4). كما يوفر تفاعلًا جيدًا مع الشيل ومراجع لمعالجة الشيل أو تصعيد الامتيازات في لينكس.
<h2>🧨 CVE-2018-15133</h2>
في إطار عمل Laravel حتى الإصدار 5.5.40 و5.6.x حتى 5.6.29، قد يحدث تنفيذ عن بُعد للكود (RCE) نتيجة لاستدعاء unserialize على قيمة X-XSRF-TOKEN غير موثوقة. يتضمن ذلك طريقة decrypt في Illuminate/Encryption/Encrypter.php وPendingBroadcast في gadgetchains/Laravel/RCE/3/chain.php داخل phpggc. يجب أن يعرف المهاجم مفتاح التطبيق (application key)، وهو أمر لا يحدث عادة، لكنه قد يحدث إذا كان المهاجم قد حصل سابقًا على وصول مميز أو نجح في تنفيذ هجوم سابق.
<h2>📦 التثبيت</h2>
<pre>
git clone https://github.com/PwnedShell/Larascript
pip3 install -r requirements.txt
</pre>
<h2>📘 الاستخدام</h2>
المعلمات المطلوبة هي <strong>url</strong> الخاص بالتطبيق المعرّض للخطر و<strong>app_key</strong> بصيغة base64. راجع <code>larascript.py -h</code>.<br><br>
<pre>
usage: larascript.py [-h] -k APPKEY [-c COMMAND] [-m {1,2,3,4,5}] [-s {bash,python,perl,php,ruby,nc,mkfifo,lua,java}]
[-t {bash,sh}] [-p PORT] [-P LPORT] [-U LHOST]
url
</pre>
أرسل الأمر <code>whoami</code><br><br>
<p align="center">
<img width="80%" src="https://raw.githubusercontent.com/PwnedShell/Larascript/master/pictures/command-poc.png">
</p>
احصل على شيل عكسي باستخدام حمولة mkfifo. مع ضبط lhost على جهازك المحلي<br><br>
<p align="center">
<img width="80%" src="https://raw.githubusercontent.com/PwnedShell/Larascript/master/pictures/shell-poc1.png">
</p>
<h2>📎 المراجع</h2>
<ul>
<li><a href="https://www.cvedetails.com/cve/CVE-2018-15133/">CVE-2018-15133</a></li>
<li><a href="https://github.com/aljavier/exploit_laravel_cve-2018-15133">إكسبلويت Aljavier</a></li>
<li><a href="https://github.com/kozmic/laravel-poc-CVE-2018-15133">Kozmic POC</a></li>
<li><a href="https://github.com/ambionics/phpggc">Phpggc</a></li>
<li><a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md">Payload all the things</a></li>
</ul>