
Dockerfile et manifests Kubernetes pour reproduire la CVE-2024-3094
Dockerfile et manifestes Kubernetes pour reproduire CVE-2024-3094
Nous utilisons la version debian des utilitaires xz vulnérables comme image de base. Nous devons également patcher la bibliothèque. La version patchée de la bibliothèque liblzma est tirée du dépôt xzbot.
FROM debian:experimental-20240311@sha256:16cc2b09c44d991d36f63153f13a7c98fb7da6bd2ba9d7cc0f48baacb7484970
# use debian with a vulnerable version of xz utils as the base image
RUN apt-get update && apt-get install -y openssh-server
RUN mkdir /var/run/sshd
RUN echo 'root:root123' | chpasswd
RUN sed -i 's/#PermitRootLogin prohibit-password/PermitRootLogin yes/' /etc/ssh/sshd_config
RUN sed -i 's/#PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config
EXPOSE 22
COPY liblzma.so.5.6.0.patch /root/
# in order to exploit the vulnerability you must use a patched library because
# the exploit author originally hardcoded his public key
# in the patched library this key has been swapped out
ENV LD_PRELOAD=/root/liblzma.so.5.6.0.patch
# load the patched library via LD_PRELOAD
CMD ["/usr/sbin/sshd", "-D"]
D'abord, nous devons déployer un simple Pod, avec l'image assemblée à l'étape précédente :
apiVersion: v1
kind: Pod
metadata:
name: cve-2024-3094
labels:
app: cve-2024-3094
spec:
containers:
- name: cve-2024-3094
image: r0binak/xzk8s:v1
ports:
- containerPort: 22
Ensuite, redirigeons les ports :
kubectl port-forward backdoor-cve-2024-3094 2222:22
Utilisons l'exploit xzbot :

Enfin, entrons dans le conteneur et vérifions les résultats de l'exploit :
