
Bro 用 ShellShock 攻撃・エクスプロイト検出器。
このスクリプトは、通称「ShellShock」と呼ばれる Bash の脆弱性(CVE-2014-6271)の悪用に成功した動作を検出します。攻撃を受けたホストの、実際の侵害や脆弱性を示す可能性のある挙動を監視している点で、既存のほとんどの検出方法よりも包括的です。
ホストが HTTP 経由で攻撃を受けているのが確認された場合、Bro はそのホストがドロッパーペイロードをダウンロードするか、ICMP ping を送信するかを監視します。他にも多くのメカニズムが現れる可能性がありますが、これにより既知の応答メカニズムのほとんどをカバーできます。このスクリプトはデフォルトで、MIME タイプ application/x-executable のファイルを監視するように設定されており、以下の攻撃に記載されているドロッパーをカバーします:
https://gist.github.com/anonymous/929d622f3b36b00c0be1
あるいは、攻撃者が単に ping コマンドでテストしているだけの場合、このスクリプトは攻撃が検出された直後に、被害者からの ping コマンドを監視します。
このスクリプトはまた、攻撃の可能性があるリクエストについて、HTTP ログの "tags" フィールドにタグを追加します。タグの内容は次のとおりです: ShellShock::HIT。
ちなみに、このスクリプトはクラスタ対応であり、Bro クラスタ上で問題なく動作し、運用環境でも問題なく実行できます。
このスクリプトは現在、Bro 2.3、2.4、2.5 をサポートしています。サポート対象の Bro バージョンで問題が発生した場合は、チケットを登録してください。
このリポジトリには、サンプルサーバーを攻撃する exploit.pcap という名前のサンプルパケットキャプチャが含まれています。以下は、出力される関連ログです。
notice.log
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2014-09-26-10-47-02
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p peer_descr actions suppress_for dropped remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] interval bool string string string double double
1411666207.583791 - - - - - - - - - ShellShock::Scanner 10.246.50.2 sent at least 1 CVE-2014-6271 exploit attempts in 0m0s. Used payload: "() { :;}; /bin/ping -c1 10.246.50.2" :: against sample victim hosts: 10.246.50.6 10.246.50.2 - - - bro Notice::ACTION_LOG 3600.00000-
1411666207.588581 - - - - - - - - - ShellShock::Exploit High likelihood of successful CVE-2014-6271 exploitation against 10.246.50.6. Attack over HTTP and sent a ping to 10.246.50.2 within 0.000 seconds of an attack. Attack over HTTP and sent a ping to 10.246.50.2 within 0.000 seconds of an attack. 10.246.50.6 - - - bro Notice::ACTION_LOG 3600.000000 F - - - - -
http.log
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path http
#open 2014-09-26-10-47-02
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p trans_depth method host uri referrer user_agent request_body_len response_body_len status_code status_msg info_code info_msg filename tags username password proxied orig_fuids orig_mime_types resp_fuids resp_mime_types
#types time string addr port addr port count string string string string string count count count string count string string set[enum] string string set[string] vector[string] vector[string] vector[string] vector[string]
1411666207.583791 CC7s232GDnmtxZUly5 10.246.50.2 43616 10.246.50.6 80 1 GET 10.246.50.6 /exploitable.cgi - () { :;}; /bin/ping -c1 10.246.50.2 0 615 500 Internal Server Error - - - ShellShock::HIT - - - - - FgVgjb1GU12ixSuugc text/html
#close 2014-09-26-10-47-02
bro-pkg refresh
bro-pkg install corelight/bro-shellshock
設定変数がいくつかあります。
## The number of apparent attacks a host must send for it to be
## detected as ShellShock::Scanner.
const ShellShock::scan_threshold = 10 &redef;
## The period over which scanner detection is performed.
const ShellShock::scan_detection_period = 10min &redef;
これらを使用すると、ShellShock スキャナを監視する期間と、スキャン中として宣言されて通知が作成されるまでに必要な攻撃回数を拡張できます。
Seth Hall <[email protected]>
Stephen Hosom - 完全な攻撃用パケットキャプチャを提供。
Nick Weaver - Shellshock が悪用可能であるか否かについて貴重な議論を提供。
Vlad Grigorescu - 次々と機能要求を出してくれた。
Mike Patterson - 攻撃後のドロッパーとしてシェルスクリプトを監視することを提案。