Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2023-25157 — OGC Filter SQL 인젝션(CVE-2023-25157/25158)을 재현하는 로컬 GeoServer/PostGIS 랩으로, 취약, 패치, 완화된 A/B 테스트 모드를 제공합니다. | Kitploit
도구/GitHubGitHub/ivanesk315/cve-2023-25157
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationDatabase SecurityLabs & Practice
GitHubivanesk315/cve-2023-25157

CVE-2023-25157

OGC Filter SQL 인젝션(CVE-2023-25157/25158)을 재현하는 로컬 GeoServer/PostGIS 랩으로, 취약, 패치, 완화된 A/B 테스트 모드를 제공합니다.

1820일 전아직 검토되지 않음
저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Lab CVE-2023-25157 및 CVE-2023-25158

이 Lab은 GeoServer/PostGIS를 사용하여 로컬 환경에서 OGC Filter SQL injection을 연구하며, operator/setup mode와 attacker mode를 명확히 분리합니다.

  • CVE-2023-25157: GeoServer product 표면, WFS/WMS 요청이 JDBC filter encoding으로 진입.
  • CVE-2023-25158: GeoTools JDBC library의 근본 원인, GeoServer에 내장되어 OGC filter를 SQL로 변환.

GeoServer 2.22.0은 취약한 GeoTools를 내장. GeoServer 2.22.2는 패치된 GeoTools를 내장. Lab은 동일한 schema/request를 유지하여 version, mitigation 및 privilege boundary를 A/B 테스트합니다.

아키텍처

ModeSurface목적
Setup/operator RESTcve-operator internal containerREST setup, validation 및 backend log review
Single gateway127.0.0.1:8889UI operator 및 OWS route를 위한 단일 포트
Operator Web UI127.0.0.1:8889/geoserver/web/운영자를 위한 GeoServer UI; Basic Auth proxy 포함
Attacker vulnerable127.0.0.1:8889/vuln/geoserver/owsWFS/OWS 취약, DB 오류가 response에 노출
Attacker patched127.0.0.1:8889/patched/geoserver/owsGeoServer 2.22.2 / GeoTools 28.2
Attacker realistic127.0.0.1:8889/realistic/geoserver/owsWFS/OWS 취약하지만 gateway가 error detail 제거
Mitigation function127.0.0.1:8889/mit-functions/geoserver/owsGeoServer 2.22.0, encode functions=false
Mitigation FeatureId127.0.0.1:8889/mit-featureid/geoserver/owsGeoServer 2.22.0, preparedStatements=true

PostgreSQL/PostGIS는 host로 port를 publish하지 않음. GeoServer는 port 8080을 host로 직접 publish하지 않음; host는 127.0.0.1:8889에서 cve-gateway만 볼 수 있음. cve-attacker container는 attacker-net에만 위치; PostgreSQL 또는 GeoServer internal service로의 route가 없음. REST setup은 geoserver-net의 내부 container cve-operator를 통해 진행.

Web UI operator

브라우저에서 열기:

http://127.0.0.1:8889/geoserver/web/

2단계 로그인:

  1. Proxy operator Basic Auth: operator / operator_lab
  2. GeoServer UI: admin / geoserver

모두 동일한 gateway 8889를 통해 진행되며, 여러 port를 기억할 필요 없음. Burp는 기본 proxy 127.0.0.1:8080을 유지할 수 있음.

Lab 실행

.\lab.ps1 reset all
.\lab.ps1 validate
powershell -ExecutionPolicy Bypass -File .\verify-lab.ps1
powershell -ExecutionPolicy Bypass -File .\negative-controls.ps1
powershell -ExecutionPolicy Bypass -File .\attack-chain.ps1

관리 명령:

.\lab.ps1 start vulnerable
.\lab.ps1 start patched
.\lab.ps1 start mitigated
.\lab.ps1 start worstcase
.\lab.ps1 reset all
.\lab.ps1 stop
.\lab.ps1 status

Data 및 role

Seed 테이블:

  • cities: integer primary key, name text 컬럼, strStartsWith/strEndsWith에 사용.
  • sensors_text: text primary key, FeatureId injection에 사용.
  • sensors_int: integer primary key, FeatureId에 대한 negative control.
  • events: JSONB research layer.
  • internal_assets: publish되지 않음, 매 reset 후 LAB-CANARY-<UUID> 포함.
  • local_points: shapefile non-JDBC negative control.

Role:

  • geoserver_readonly: CONNECT, USAGE schema, publish된 테이블에만 SELECT.
  • geoserver_impact: internal_assets에 추가 SELECT를 허용하여 과도한 권한을 가진 app DB user를 시연.
  • geoserver_worstcase: 별도 profile, pg_read_server_files를 보유하여 가짜 canary 파일 /lab/flag.txt를 읽음.

Attack-chain flow

attack-chain.ps1 수행:

  1. WFS GetCapabilities recon.
  2. DescribeFeatureType schema enum.
  3. Baseline 및 negative requests.
  4. realistic proxy에서 Boolean TRUE/FALSE oracle.
  5. vulnerable, patched 및 encode functions=false로 CVE-2023-25157 확인.
  6. vulnerable, patched 및 preparedStatements=true로 CVE-2023-25158 확인.
  7. Negative controls: integer PK 및 non-JDBC shapefile.
  8. impact branch를 통해 DB user leak 및 hidden table discover.
  9. least-privilege가 internal_assets를 차단하고, impact branch가 canary를 leak하며, patched/realistic이 canary를 disclose하지 않음을 증명.

Evidence는 evidence/attack-chain-*에 저장됨. 현재 folder는 혼란을 피하기 위해 최신 pass evidence만 유지.

Worst-case profile

이 profile은 주요 시나리오에 포함되지 않음:

.\lab.ps1 start worstcase
powershell -ExecutionPolicy Bypass -File .\worstcase-demo.ps1

가짜 canary 파일 /lab/flag.txt만 읽으며, /etc/passwd를 읽지 않고, hash를 dump하지 않으며, password를 crack하지 않음.

공식 출처

  • GeoServer advisory: https://github.com/geoserver/geoserver/security/advisories/GHSA-7g5f-wrx8-5ccf
  • GeoTools advisory: https://github.com/geotools/geotools/security/advisories/GHSA-99c3-qc2q-p94m
  • GeoServer statement: https://geoserver.org/vulnerability/2023/02/20/ogc-filter-injection.html
  • NVD CVE-2023-25157: https://nvd.nist.gov/vuln/detail/CVE-2023-25157
  • NVD CVE-2023-25158: https://nvd.nist.gov/vuln/detail/CVE-2023-25158
도구 다운로드