
Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.
Lab nay dung GeoServer/PostGIS de nghien cuu OGC Filter SQL injection trong moi truong cuc bo, co tach ro operator/setup mode va attacker mode.
GeoServer 2.22.0 nhung GeoTools vulnerable. GeoServer 2.22.2 nhung GeoTools patched. Lab giu cung schema/request de A/B test version, mitigation va privilege boundary.
| Mode | Surface | Muc dich |
|---|---|---|
| Setup/operator REST | cve-operator internal container | REST setup, validation and backend log review |
| Single gateway | 127.0.0.1:8889 | Mot port duy nhat cho UI operator va cac OWS route |
| Operator Web UI | 127.0.0.1:8889/geoserver/web/ | GeoServer UI cho nguoi van hanh; co Basic Auth proxy |
| Attacker vulnerable | 127.0.0.1:8889/vuln/geoserver/ows | WFS/OWS vulnerable, loi DB hien trong response |
| Attacker patched | 127.0.0.1:8889/patched/geoserver/ows | GeoServer 2.22.2 / GeoTools 28.2 |
| Attacker realistic | 127.0.0.1:8889/realistic/geoserver/ows | WFS/OWS vulnerable nhung gateway strip error detail |
| Mitigation function | 127.0.0.1:8889/mit-functions/geoserver/ows | GeoServer 2.22.0, encode functions=false |
| Mitigation FeatureId | 127.0.0.1:8889/mit-featureid/geoserver/ows | GeoServer 2.22.0, preparedStatements=true |
PostgreSQL/PostGIS khong publish port ra host. GeoServer khong publish truc tiep port 8080 ra host; host chi thay cve-gateway tren 127.0.0.1:8889. Container cve-attacker chi o attacker-net; no khong co route toi PostgreSQL hoac GeoServer internal service. REST setup di qua container noi bo cve-operator tren geoserver-net.
Mo tren browser:
http://127.0.0.1:8889/geoserver/web/
Dang nhap 2 lop:
operator / operator_labadmin / geoserverTat ca di qua cung mot gateway 8889, khong can nho nhieu port. Burp co the giu proxy mac dinh 127.0.0.1:8080.
.\lab.ps1 reset all
.\lab.ps1 validate
powershell -ExecutionPolicy Bypass -File .\verify-lab.ps1
powershell -ExecutionPolicy Bypass -File .\negative-controls.ps1
powershell -ExecutionPolicy Bypass -File .\attack-chain.ps1
Lenh quan ly:
.\lab.ps1 start vulnerable
.\lab.ps1 start patched
.\lab.ps1 start mitigated
.\lab.ps1 start worstcase
.\lab.ps1 reset all
.\lab.ps1 stop
.\lab.ps1 status
Bang seed:
cities: integer primary key, cot name text, dung cho strStartsWith/strEndsWith.sensors_text: text primary key, dung cho FeatureId injection.sensors_int: integer primary key, negative control cho FeatureId.events: JSONB research layer.internal_assets: khong publish, chua LAB-CANARY-<UUID> moi sau moi lan reset.local_points: shapefile non-JDBC negative control.Role:
geoserver_readonly: CONNECT, USAGE schema, SELECT chi tren bang publish.geoserver_impact: SELECT them internal_assets de minh hoa app DB user qua rong quyen.geoserver_worstcase: profile rieng, co pg_read_server_files de doc file canary gia /lab/flag.txt.attack-chain.ps1 thuc hien:
GetCapabilities.DescribeFeatureType.encode functions=false.preparedStatements=true.internal_assets, impact branch leak canary, patched/realistic khong disclose canary.Evidence duoc luu vao evidence/attack-chain-*. Folder hien tai chi giu lai evidence pass moi nhat de tranh bi roi.
Profile nay khong nam trong kich ban chinh:
.\lab.ps1 start worstcase
powershell -ExecutionPolicy Bypass -File .\worstcase-demo.ps1
No chi doc file canary gia /lab/flag.txt, khong doc /etc/passwd, khong dump hash, khong crack password.