
Testa e sfrutta i server STUN/TURN per configurazioni errate, consentendo il pivoting della rete interna tramite proxy SOCKS, attacchi di memory leak e scansione delle porte interne.
Stunner è uno strumento per testare e sfruttare server STUN, TURN e TURN su TCP. TURN è un protocollo utilizzato principalmente nelle videoconferenze e chat audio (WebRTC).
Se trovi un server configurato in modo errato, puoi usare questo strumento per aprire un proxy socks locale che instrada tutto il traffico tramite il protocollo TURN nella rete interna dietro il server.
Ho sviluppato questo strumento durante un test di Cisco Expressway che ha portato ad alcune vulnerabilità: https://firefart.at/post/multiple_vulnerabilities_cisco_expressway/
Per ottenere il nome utente e la password necessari, devi recuperarli utilizzando un metodo out-of-band, ad esempio sniffando la richiesta Connect da un browser web con Burp. Ho aggiunto un flusso di esempio alla fine del readme su come testare un server di questo tipo.
Quest'opera è distribuita con licenza Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International. Per visualizzare una copia di questa licenza, visita http://creativecommons.org/licenses/by-nc-sa/4.0/ o invia una lettera a Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.
STUN: RFC 5389
TURN: RFC 5766
TURN per TCP: RFC 6062
Estensione TURN per IPv6: RFC 6156
Questo comando stampa informazioni sul server stun o turn, come i protocolli supportati e gli attributi, ad esempio il software utilizzato.
--debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS/DTLS on connecting to the STUN or TURN server (default: false)
--timeout value connect timeout to turn server (default: 1s)
--help, -h show help (default: false)
./stunner info -s x.x.x.x:443
Questo comando prova diversi intervalli privati e limitati per verificare se il server TURN è configurato per consentire connessioni agli indirizzi IP specificati. Se un determinato intervallo non è proibito, puoi enumerare ulteriormente quell'intervallo con gli altri comandi forniti. Se un IP è raggiungibile, significa che il server TURN inoltrerà il traffico verso quell'IP.
--debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS/DTLS on connecting to the STUN or TURN server (default: false)
--protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp")
--timeout value connect timeout to turn server (default: 1s)
--username value, -u value username for the turn server
--password value, -p value password for the turn server
--help, -h show help (default: false)
Connessione TURN basata su TCP (connessione da te al server TURN):
./stunner range-scan -s x.x.x.x:3478 -u username -p password --protocol tcp
Connessione TURN basata su UDP (connessione da te al server TURN):
./stunner range-scan -s x.x.x.x:3478 -u username -p password --protocol udp
Questo è uno dei comandi più utili per server TURN che supportano connessioni TCP a server di backend. Avvia un server socks5 locale senza autenticazione e instradera tutto il traffico TCP attraverso il protocollo TURN (UDP tramite SOCKS non è attualmente supportato). Se il server è configurato in modo errato, inoltrerà il traffico verso indirizzi interni, quindi può essere utilizzato per raggiungere sistemi interni e abusare del server come proxy nella rete interna. Se scegli di eseguire anche richieste DNS tramite socks, verranno risolte utilizzando il tuo nameserver locale, quindi è meglio lavorare con indirizzi IPv4 e IPv6 privati. Tieni presente che questo modulo può solo instradare traffico TCP.
--debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS/DTLS on connecting to the STUN or TURN server (default: false)
--protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp")
--timeout value connect timeout to turn server (default: 1s)
--username value, -u value username for the turn server
--password value, -p value password for the turn server
--listen value, -l value Address and port to listen on (default: "127.0.0.1:1080")
--drop-public, -x Drop requests to public IPs. This is handy if the target can not connect to the internet and your browser want's to check TLS certificates via the connection. (default: true)
--help, -h show help (default: false)
./stunner socks -s x.x.x.x:3478 -u username -p password -x
Dopo aver avviato il proxy, apri il browser, punta il proxy nelle impostazioni a socks5 con un IP di 127.0.0.1:1080 (assicurati di non impostare l'opzione di bypass degli indirizzi locali, poiché vogliamo raggiungere gli indirizzi locali remoti) e chiama l'IP di tua scelta nel browser.
Esempio: https://127.0.0.1, https://127.0.0.1:8443 o https://[::1]:8443 (questi chiameranno le porte sul server TURN testato dalle interfacce locali).
Puoi anche configurare proxychains per utilizzare questo proxy (ma sarà molto lento poiché ogni richiesta comporta più richieste per abilitare il proxy). Basta modificare /etc/proxychains.conf e inserire il valore socks5 127.0.0.1 1080 sotto ProxyList.
Esempio di nmap attraverso questo proxy socks5 con un proxychains configurato correttamente (nota che è -sT per fare TCP syn, altrimenti non userà il proxy socks5):
sudo proxychains nmap -sT -p 80,443,8443 -sV 127.0.0.1
Questo molto probabilmente non fornirà informazioni utili, ma può essere utile per enumerare tutti i trasporti disponibili (= protocolli verso sistemi interni) supportati dal server. Potrebbe mostrare alcune implementazioni di protocolli personalizzati, ma nella maggior parte dei casi restituirà solo i valori predefiniti.
--debug, -d enable debug output (default: false)
--turnserver value, -s value turn server to connect to in the format host:port
--tls Use TLS/DTLS on connecting to the STUN or TURN server (default: false)
--protocol value protocol to use when connecting to the TURN server. Supported values: tcp and udp (default: "udp")
--timeout value connect timeout to turn server (default: 1s)
--username value, -u value username for the turn server
--password value, -p value password for the turn server
--help, -h show help (default: false)
./stunner brute-transports -s x.x.x.x:3478 -u username -p password
Questo comando prova tutte le password da un file specificato per un nome utente tramite il protocollo TURN (UDP). Può essere utile quando si analizza un pcap in cui si vede il nome utente ma non la password. Tieni presente che un brute-force offline è molto più veloce in questo caso.