Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the
Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We
responsibly disclosed this vulnerability and in the current version of Jenkins
it has been fixed and the according
Jenkins Security Advisory 2019-09-12
has been published. In this blogpost I want to report a bit on the technical
details of the vulnerability.
Description
The groovy sandbox transforms some AST nodes of the script to add security
checks. For example
Recently, we identified security issues in the Nexus Repository Manager software
developed by Sonatype. The tested versions were OSS 3.12.1-01 and OSS 3.13.1-01.
We identified a Java Expression Language Injection in the role and user creation
function. In order to exploit this issue, the attacker needs to be authenticated
with high privileges, the standard anonymous user is not sufficient.
We recently identified security issues in the UNIFY OpenScape Desk Phone CP600
HFA software. We disclosed the vulnerabilities to Unify, as a fix is now
provided we want to give a brief overview of the vulnerability affecting the web
interface.
We were able to identify the following vulnerabilities in the Web interface of
the telephone:
Command Injection in Picture Delete function of OpenScape Desk Phone Webportal
Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal
Memory Corruption in the OpenScape Desk Phone Webservice
Missing Hardening of the OpenScape Desk Phone Webservice Binary
Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice
Birk an me basically fully disclosed a 0day in
Squirrelmail yesterday. This is a short Q&A to
answer the most common questions about the issue to calm you all down a little
bit. 😉
What is the punchline, what do I need to know?
An attacker able to exploit this vulnerability can extract files of the server
the application is running on. This may include configuration files, log files
and additionally all files that are readable for all users on the system. This
issue is post-authentication. That means an attacker would need valid
credentials for the application to log in or needs to exploit an additional
vulnerability of which we are not aware of at this point of time.
Last year I encountered a slight variation of an internal port scan
vulnerability for the CrystalReports component of SAP Business Objects. The
original vulnerability was presented and disclosed by rapid7 in the talk
“Hacking SAP Business Objects”. The corresponding slides can be found
here.
Basically, the original vulnerability allowed port scanning of (internal)
systems via the URL
http://hostname/CrystalReports/viewrpt.cwr?id=$ID&wid=$WID&apstoken=ip:port@$TOKEN.
By accessing this URL, different responses were received depending on if the
port (parameter port in the URL) of the system (parameter ip in the URL) was in
the state “open” or “closed”. The original vulnerability has been fixed a long
time ago (SAP security note 1432881), but the fix did allow for a slight
variation to make the attack work again.
As you have probably already recognized, some of us here at ERNW are doing
research in the area of smart home technologies e.g. KNX. Recently, we took a
deeper look into a device which is used to control a smart home system produced
by the vendor BAB TECHNOLOGIE GmbH called “eibPort”. This device can be used to
control smart home systems based on different technologies e.g. EnoCean or KNX
depending on the version of the device. The eibPort comes with a visualization
running on a webserver to control the whole system e.g. open or close windows,
changing the temperature in different rooms or turning the alarm system on or
off by simply clicking on symbols. The following screenshots illustrate an
example of such a visualization:
Some of you (especially the .Net guys) might have heard of the query language
Linq (Language Integrated Query) used by Microsoft .Net applications and web
sites. It’s used to access data from various sources like databases, files and
internal lists. It can internally transform the accessed data in application
objects and provides filter mechanisms similar to SQL. As it is used directly
inside the application source code, it will be processed at compile time and not
interpreted at runtime. While this provides a great type safety and almost no
attack surface for injection attacks (except from possible handling problems in
the different backends), it is extremely difficult to implement a dynamic filter
system (e.g. for datatables which should allow users to select the column to
filter on). That’s probably the reason why Scott Guthrie (Executive Vice
President of the Cloud and Enterprise group in Microsoft, also one of the
founders of the .Net project)
presented the
System.Linq.Dynamic package as part of the VS-2008 samples in 2008. This library
allows to build Linq queries at runtime and therefore simplify dynamic filters.
But as you may know, dynamic interpretation of languages based on user input is
most of the time not the best option….
In course of a recent research project, I had a look at SolarWinds DameWare,
which is a commercial Remote Access Software product running on Windows Server.
I identified a remote file download vulnerability in the download function for
the client software that can be exploited remotely and unauthenticated and that
allows to download arbitrary files from the server that is running the software.
A very simple proof of concept HTTP request to download the C:\Windows\win.ini
file of the target machine is the following:
Hope those of you who attended Troopers16 enjoyed it as much as we did! In this
post I want to summarize my
Troopers16 talk
and provide you with some details about freshly assigned CVE-2016-1542 and
CVE-2016-1543 related to BMC BladeLogic software.
To start with, BMC Software Inc. is an American company specializing in business
service management software; they develop software used for multiple functions,
including IT service management, data center automation, performance management,
virtualization lifecycle management and cloud computing management. Among other
products they have developed a BladeLogic suite that includes Database
Automation, Middleware Automation, Server Automation, and Network Automation
tools. The one under our focus was BladeLogic Server Automation (BSA).
I’ve recently found some sort of classic web vulnerabilities in the Google
Search Appliance (GSA) and as they are now fixed [0][1][2], I’d like to
share them with you.
First of all, some infrastructure details about the GSA itself. The GSA is used
by companies to apply the Google search algorithms to their internal documents
without publishing them to cloud providers. To accomplish this task, the GSA
provides multiple interfaces including a search interface, an administrative
interface and multiple interfaces to index the organization’s data.