çŸåšãä»®æ³ã·ã¹ãã ã®ã»ãã¥ãªãã£ã¯æµè¡ã®åŸåã«ããããããã®è³ªåã¯ç¡èŠã§ããŸããã ä»æ¥ãVMwareã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžå¿ã§ããvCenterãµãŒããŒãç Žå£ããŸãã åæã«ã0æ¥éã®è匱æ§ã䜿çšããŠã人çãèèã®ããã«èŠããªãããã«ããŸãã ä»®æ³ãã¯ãããžãŒãšã¯ãŸã£ããé¢ä¿ã®ãªãæ§åŒã®æ¹æ³ã§ãããæã¡ç ŽããŸãããã¡ãããæµè¡ã¯æµè¡ããŸããããã°ã¯ãã¹ãŠå¹³å¡ã§ãã
PSïŒè²¬ä»»ãããã¯ã€ããããã§ã¯ãã€ãã®ããã«ãããã§èª¬æãããŠãããã¹ãŠã®ãã°ã¯æ¢ã«éããããŠããã¯ãã§ãããããã³ã°ã®æç¹ãã€ãŸã2011幎ã«ã¯0æ¥ã§ããã ãã®ããã¹ãã¯ãHacker Magazine No. 7/12ïŒ162ïŒã«æ²èŒãããCONFidence 2012ãPHD 2012ãããã³Defcon 20ã§ã®ã¬ããŒãã®åºç€ã«ããªããŸããã
VMware vCenter
å€ãã®ãšã³ã¿ãŒãã©ã€ãºã·ã¹ãã ã¯ä»®æ³ç°å¢ã«äœãã§ããŸãã å®ãã§ãã ãã䟿å©ã§ãããã¯ãŒã«ã§ãïŒ ãããã®åãç°å¢ãæäŸãããªãŒããŒã¯ãæªåé«ãVMware瀟ã§ãã ãããã®äººãã¡ã¯ãã¯ãŒã«ãªãã€ããŒãã€ã¶ãŒãšãéèŠãªããšã§ããããå°å
¥ã管çãå¶åŸ¡ã容æã«ããããã®ããããçš®é¡ã®ãœãããŠã§ã¢ãæã£ãŠããŸãã ããã«ãããVMwareãœãªã¥ãŒã·ã§ã³ã¯æè»ã§ã¹ã±ãŒã©ãã«ã«ãªããæçµçã«å¹ççã«ãªããŸãã ãã®ã¯ãŒã«ãªå°ããªç·ããã¹ãŠäŸ¿å©ã«ç®¡çããããã«ã圌ãã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡çéšåã§ããVMware vCenterãçµ±åãããµãŒããŒãœãããŠã§ã¢ãéçºããŸããã ã€ãŸããããšãã°ãVMware ESXïŒiïŒãæèŒãã10å°ã®éã®ãã·ã³ããããŸãã åèšã§50å°ã®ä»®æ³ãã·ã³ããããã§å®è¡ãããŠããŸãã ãã®vCenterããªãå Žåããã®ä»®æ³åç©åã®ç®¡çã¯éåžžã«äžäŸ¿ã§ãã ããã«ãvCenterã®ãããã§ãESXã®1ã€ãæ©èœããªããªã£ãå Žåã®ä»®æ³ã€ã¡ãŒãžã®ééçãªç§»è¡ãªã©ãããŸããŸãªããªãã¯ãå¯èœã§ããèŠããã«ãéåžžã«äŸ¿å©ã§éèŠãªããšã§ãã ããã§åºåã®çµããã§ãã äž»ãªãã€ã³ãã¯ãæªæã®ããããã«ãŒãvCenterãç Žå£ããå Žåããããã¯ãŒã¯å
šäœãæã«è² ããªããªããšããããšã§ãã
é²è¡ãçªç ŽããŸã
æåãªç 究è
Claudio Crisconeã¯ããã®ãã»ã³ã¿ãŒãã«äœåºŠãåºäŒã£ãããããã®ç Žå£æ¹æ³ãç¥ã£ãŠããŸãã ãã®ããããã³ãã¹ãã®1ã€ã§ããã®ãœãããŠã§ã¢ã«åºäŒããããã«ãããã¹ãŠã®ãã®ãå¿ããããã«Claudioã®ç¥æµã䜿ãããšã«ããŸããã å®éãClaudioã®ã¢ã€ãã¢ã¯ã·ã³ãã«ã§ãããå人ãvCenterã¢ããããŒããããŒãžã£ãŒã«è匱æ§ãçºèŠããŸããã ãã®è匱æ§ã¯VMwareããã°ã©ãã®ããã§ããããŸããã§ããã å®éããã®ãããŒãžã£ãŒã®Webã€ã³ã¿ãŒãã§ãŒã¹ïŒTCPããŒã9084ã§ãã³ã°ïŒã¯ãJettyãWebãµãŒããŒãšããŠäœ¿çšããŠããŸãã ãããã£ãŠãClaudioã¯ããã§è匱æ§ãçºèŠããŸããã è匱æ§-ãžã£ã³ã«ã®å€å
žïŒã«ã¿ãã°ã®å¢çãè¶ããŠïŒ
target:9084/vci/download/health.xml/%3f/../../../../../../FILE.EXT
BlackHatã«ã³ãã¡ã¬ã³ã¹ã®Claudioã¹ã©ã€ã;-)
ç°¡åã§ããvCenterãå®è¡ããŠããã¢ã«ãŠã³ãã«ååãªæš©éããããã¹ãŠã®ãã¡ã€ã«ãèªã¿åããŸãã ããããããã«ã¯ã©ãŠãã£ãªãå°ãã質åããããŸã-ã©ãããã°ãã¡ã€ã«ãèªãããšãã§ããŸããïŒ äžè¬çã«ã圌ã¯ãã¡ã€ã«ã·ã¹ãã ã調ã¹ãã»ãã·ã§ã³ã³ãŒããä¿åããããã°ãããã¢ã¯ã»ã¹ãã°ãã¡ã€ã«ãèŠã€ããŸããïŒã¹ã©ã€ãã®ã¹ã¯ãªãŒã³ã·ã§ãããåç
§ïŒã
äžéãªãã¡ã€ã«ã®å
容;-)
ãã®ã³ãŒãã¯äœã§ããïŒ å®éã«ã¯ãvSphereã¯ã©ã€ã¢ã³ãã¯SOAPãä»ããŠvCenterãšé£æºããŸããã€ãŸããéåžžã®HTTPSãã©ãã£ãã¯ã§ããããã®æ¬äœã¯ããŒã¿ãã³ãã³ããªã©ã®XMLæ§é ã§ãããã®å Žåã管çè
èªèšŒåŸãSOAPã»ãã·ã§ã³ã³ãŒããæžã蟌ãŸããŸãã ããããŠãã®ã³ãŒãã¯ãã¢ããã°8ãªã©ã®PHPSESSIONIDãæã€CookieãšããŠãã§ãã¯ãããŸããæããã«ããã®ã³ãŒããçãã ã®ã§ãSOAPãªã¯ãšã¹ãã«ãããå
¥ããããšãã§ããvCenterã¯ãã§ã«ç®¡çè
ãšããŠèªèšŒãããŠãããšèããŸãïŒ ã€ãŸããClaudioã¯ãJetty WebãµãŒããŒã®è匱æ§ãéããŠããããã®SOAPã³ãŒãã§ãã°ãèªã¿åãããšãææ¡ããŠããŸãã
target:9084/vci/download/health.xml/%3f/../../../../../../ProgramData\VMware\VMware VirtualCenter\Logs\vpxd-profiler-6.log
次ã«ããããã®ã³ãŒããvSphereããã®ãªã¯ãšã¹ãã«çœ®ãæããŸãã ãããè¡ãããã«ã圌ã¯ãããã·ãµãŒããŒãéçºããŸããããã®ãµãŒããŒã¯ãvSphereã®ããã±ãŒãžå
ã®ã»ãã·ã§ã³ã³ãŒãããã®å Žã§çœ®ãæããMetasploitã¢ããªã³VASTOã«ãã®ãããã·ãå«ããŸããã ããã«ããã®ã¢ããªã³ã«ã¯ä»ã«ãå€ãã®ãããããããŸãããããã«ã€ããŠã¯ä»ãã説æããŸããã
ãã®ããã«ãGoogleã®ã€ã¿ãªã¢äººã®å人ã¯vCenterã眰ããããšãææ¡ããŠããŸãã ãããåé¡ã¯ããããã®ãã¹ãŠã®ãã°ãç§ã®ãã³ãã¹ãïŒ2011幎æ¥å€ïŒã®æç¹ã§æ代é
ãã«ãªã£ãŠããããšã§ããææ°ããŒãžã§ã³ã®ãœãããŠã§ã¢ã«å¯ŸåŠããå¿
èŠããããŸãããã€ãŸããJettyã«ããããé©çšãããŸããã
ã·ã§ã«ãåãæŒæã«2ååœãããªãã®ã§ããïŒå€±æïŒæ¯åãæ©èœããªãã£ãïŒãæããŠãç§ã¯äœããã¹ããèãå§ããŸããã äžè¬ã«ããã®ç¶æ³ã®ãã³ãã¹ã¿ãŒã¯ããã®ãªãœãŒã¹ã«è匱æ§ããªãããšãåã«å ±åæžã«èšèŒããŸãã ãããããã€ãã®ããã«ããã©ãŒã¹ã«inããæããŠãç§ã¯ããªãã®ããããä¿¡çšããŸããã§ããã æªçšãªãã·ã§ã³ãçµã¿åãããŠãã£ã¬ã¯ããªå€ã«ç§»åããããšã§ãJettyã®ã¢ãã¯ãäœãç¶ããŸããã ãããŠã15ååŸã«çµæãåŸãããŸããã åãã¢ããããŒããããŒãžã£ã®å¥ã®å Žæã«ãã§ã«è匱æ§ããããŸããïŒ
target:9084/vci/download/.\..\..\..\..\..\..\..\..\FILE.EXT
SOAPã³ãŒãã§ãã¡ã€ã«ãèªãããšãã§ããã®ã§ãããã¯ãã§ã«äœãã§ãïŒ
ããªãã®å¹žããèŠã€ããããšããŠããŸã...
ããããåã³å€±æããŸãã-ã»ãã·ã§ã³ã³ãŒãã¯ããã®ãã°ããããã¡ã€ã«ã«ã¯å«ãŸããŠããŸããã ãã°ãäžæããç§ãã¡ãçœæ¿ãããVMwareã®ããã°ã©ããŒã®ãã°ãããä»äºã«ãã泚ç®ã§ããŸããã ããã§ã¯ããã¡ã€ã«ã·ã¹ãã äžã§ä»ã«äœãã§ããã®ããäœã圹ã«ç«ã€ã®ããèªåã§æ¢ããŠã¿ãŸããããæåã«æãæµ®ãã¶ã®ã¯ãSSLã®ç§å¯éµãçãããšã§ãã 次ã«ããã®ããŒã䜿çšããŠãSSLãã©ãã£ãã¯ãã€ã³ã¿ãŒã»ããããŠåŸ©å·åã§ããŸãïŒwiresharkã䜿çšãããšãåé¡ãªããããè¡ãããšãã§ããŸãïŒã ããŒèªäœã¯æ¬¡ã®ããã«èŠã€ããããšãã§ããŸãã
target:9084/vci/downloads/.\..\..\..\..\..\..\..\Documents and Settings\All Users\Application Data\VMware\VMware VirtualCenter\SSL\rui.key
ãããã£ãŠãARP SPOOFINGã䜿çšããŠäžéè
æ»æãç·šæããå ŽåããµãŒããŒãšç®¡çã¯ãŒã¯ã¹ããŒã·ã§ã³éã®ãã©ãã£ãã¯ãååã§ããŸãã ãšããã§ã管çè
ã®IPã¢ãã¬ã¹ãšãã®ãã°ã€ã³ã¯ããããã¡ã€ã©ãŒãã¡ã€ã«ã§åŒãç¶ãèŠã€ããããšãã§ããŸãã ãã¡ãããSSL蚌ææžã眮ãæãïŒåé¡ãªããããè¡ãããšãã§ããŸãïŒãããŒãçãããšãªããã©ãã£ãã¯ã埩å·åã§ããŸããã管çè
ã«ã¯ç¡å¹ãªSSL蚌ææžã«é¢ããèŠåã衚瀺ãããŸãã ããŒãçãã å Žåã管çè
ã«ã¯äœã衚瀺ãããŸããã蚌ææžãæ£ããããã§ãã ã€ãŸãããã®ãããªæ»æã¯ããcã§ç§å¯äž»çŸ©çã§ã...
åœã®èšŒææžã®èŠåïŒ
VMware vCenter OrchestratorããããvCenterãåãããµãŒããŒã«ã¯ãç¡æã®ã¢ããªã³ãä»å±ããŠãããèªç±ã«ã€ã³ã¹ããŒã«ã§ãããã1ã€ã®çŽ æŽããããã®ããããŸãããããããªãŒã±ã¹ãã©ãã§ãã å¥ã®ç®¡çã€ã³ã¿ãŒãã§ã€ã¹ãä»åã¯ã»ã³ã¿ãŒèªäœã ããã¯äœã®ããã§ããïŒ ãããŠãããã¯ã¯ãŒã«ãªããšã§ãã ããŒã¿ã»ã³ã¿ãŒã®ã©ã€ããµã€ã¯ã«ã管çããããã«äœ¿çšãããŸãã ããã¯ãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããŸããŸãªããã»ã¹ãéçºããã³èªååããããã®ãã¬ãŒã ã¯ãŒã¯å
šäœã§ãã èŠããã«ãããã¯ã¯ãŒã«ã§ãããããã ãã§ãã ãã¡ã€ã«ã·ã¹ãã ã調ã¹ãŠã¿ããšã次ã®ãã¡ã€ã«ã«åºäŒããŸããã
target:9084/vci/download/.\..\..\..\..\..\..\..\..\Program files\VMware\Infrastructure\Orchestrator\configuration\jetty\etc\passwd.properties
ãã§ã«äœãïŒ
ããããŸãã«MD5ããã·ã¥ãååŸããæ¹æ³ã§ãã æããã«ããã®åãããªãŒã±ã¹ãã©ãã®ç®¡çã¢ã«ãŠã³ãã«ã¯ãã¹ã¯ãŒããé ãããŠããŸãã äœãèšããŸããïŒ ç¡å¡©MD5ã®äœ¿çšã¯ç§å¯ã§ã¯ãããŸããã ãã®ããããã®ã³ã³ããã¹ãã§ã¯ãéåžžã«è¿
éã«ãã¹ã¯ãŒããååŸããŸããïŒã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ãããã©ã«ãã®ãã¹ã¯ãŒãããã¹ã¯ãŒããããã·ã¥åããããã管çè
ãåé¡ãåŒãèµ·ããå¯èœæ§ããããŸãïŒã åãåã£ããã¹ã¯ãŒãã䜿çšããŠãWebã€ã³ã¿ãŒãã§ãŒã¹ãããã°ã€ã³ããŸããã å¿«é©ã§ããã¥ãŒãã§ãçŽ æµãªãã¶ã€ã³ã§ããããã£ãšå¿
èŠã§ãã Webã€ã³ã¿ãŒãã§ãŒã¹ããã£ãšèŠãŠã¿ããšãåãvCenter Serverãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡çã«äœ¿çšãããŠããããšãããããŸãããã€ãŸãããªãŒã±ã¹ãã¬ãŒã¿ãŒã¯ããã§èªèšŒã§ããå¿
èŠããããŸãã ãŸããèšå®ã®ã©ããã«ã¢ã¯ã»ã¹ãã¹ã¯ãŒããèšå®ãããŠããããã圌ã¯ãã®æ¹æ³ãç¥ã£ãŠããŸãã
vCenterã®èšå®ã«ã¢ã¯ã»ã¹ããŸãã
HTMLã³ãŒããéããŠãç§ã¯å¬ããã£ãã§ãããã¹ã¯ãŒãã¯ãã®ãŸãŸã§ããã©ãŠã¶ã§ã¯èŠèŠçã«ã¯ãæãã®åŸãã«é ããŠãã®ãŸãŸè¡šç€ºãããŸãã
vCenterã®ç®¡çè
ã¢ã«ãŠã³ãã¯ç§ãã¡ã®ãã®ã§ãïŒ
ããã«ãã¡ãŒã«ã¢ã«ãŠã³ãããã¡ã€ã³ã¢ã«ãŠã³ããããã³ãªãŒã±ã¹ãã¬ãŒã¿ãŒã䜿çšã§ãããã®ä»ã®ãã®ããã®ãã¹ã¯ãŒãããããŸãã ããã«ãŒåãã®ã¹ãã¬ãŒããã¹ã¯ãŒããããŒãžã£ãŒïŒ ä»®æ³ã ãã§ãªãããã¡ã€ã³ã³ã³ãããŒã©ãŒãå«ããŠãã·ã¹ãã å
šäœãæ£åžžã«ãããã³ã°ãããããšã¯æããã§ãã
ããïŒ
ããã¯ãã¹ãŠã®ããã«æããŸããããã1ã€ã®è©³çŽ°ããããŸãã ãæ°ã¥ãã®ããã«ãOrchestratorã¯ãã¹ã¯ãŒããã©ããã«ä¿åããŸãã ãããŠãããããçŽç²ãªåœ¢ã§å
¥æããŠäœ¿çšã§ããããã«ããŸãã ããã¯ãMD5ããã·ã¥ãç Žãã®ã§ã¯ãªãããããã®ãã¹ã¯ãŒããã©ãã«ããã®ããæ¢ãããšãå¯èœã§ãã£ãããšã瀺ããŠããŸãã å°ãæãäžãããšãããããããèŠã€ãããŸãããããšãã°ãvCenterã¢ã¯ã»ã¹ââã®ãã¹ã¯ãŒããä¿åãããŠããŸãã
target:9084/vci/download/.\..\..\..\..\..\..\..\..\Program Files\VMware\Infrastructure\Orchestrator\app-server\server\vmo\conf\plugins\VC.xml
ããã«ããšã³ã³ãŒããããæååã®åœ¢åŒã«ãã£ãŠå€æãããšããã®æå·åã¯å¯éçã§ãã åæ§ã®ãã¹ã¯ãŒãã§ãéåžžã«æå·åãããŠããŸãã
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <virtual-infrastructure-hosts> <virtual-infrastructure-host xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="VirtualCenterHost"> <enabled>true</enabled> <url>https://new-virtual-center-host:443/sdk</url> <administrator-username>vmware</administrator-username> <administrator-password>000a506275767b74786b383a4a60be767864740329d5fcf324ec7fc98b1e0aaeef </administrator-password> <pattern>%u</pattern> </virtual-infrastructure-host> </virtual-infrastructure-hosts>
ãã1ã€ã®èå³æ·±ããã¡ã€ã«ã¯CïŒ\ Program Files \ VMware \ Infrastructure \ Orchestrator \ app-server \ server \ vmo \ conf \ vmo.propirtiesã§ãã ããã§ãDBMSãã¹ã¯ãŒãã¯åãæ¹æ³ã§ãšã³ã³ãŒããããŸãã
ãšã³ã³ãŒãæ¹æ³ã®æ¬è³ªãç解ããæšæž¬ãçå®ãã©ãããç解ããããšã¯æ®ã£ãŠããŸãã ãããç§ã®å人ãšååã®åºçªã§ãããããŒãã¿ã€ã ã§LeetMore CTFããŒã ãã¬ãŒã€ãŒã®Alexander
jug Minozhenkoãåå ããŠããŸãã 圌ã«ãšã£ãŠããã®ãããªã¿ã¹ã¯ã¯2æ¬ã®æã®ãããªãã®ã§ã...äžèŠãããšã圌ã¯æåã®2ãã€ãããã¹ã¯ãŒãå
šäœã®é·ããè¡šãããã®åŸãšã³ã³ãŒããããè¡šçŸãæ¥ããšå€æããŸããã Sashaã¯ããã¹ã¯ãŒãã®ä¿åãæ
åœãããOrchestratorãã®Javaã¯ã©ã¹ãåã«éã³ã³ãã€ã«ãããšã³ã³ãŒãã¢ã«ãŽãªãºã ã解æããŸããã äžçªäžã®è¡ã¯ç°¡åã§ãããã¹ã¯ãŒãã®é·ããååŸãããã¹ã¯ãŒãã®åãã€ãã16é²æ°ã«ãšã³ã³ãŒããããã€ãäœçœ®çªå·ãè¿œå ããŸãïŒãŒãããéå§ïŒã ãããã£ãŠããPassword01ãã®ãšã³ã³ãŒããããå€ã¯æ¬¡ã®ããã«ãªããŸãã
000a506275767b74786b383a4a60be767864740329d5fcf324ec7fc98b1e0aaeef
Sashaã¯ãã³ãŒããŒãïŒRubyã§ïŒæžããŸããïŒ
ãããã£ãŠãæ»æã¯ããã¡ã€ã«ãèªã¿åãããã«0ãã€ã䜿çšããèªã¿åã£ããã¡ã€ã«ãããã¹ã¯ãŒãããã³ãŒãããããã«2çªç®ã䜿çšããããšã«ãªããŸãã ãŸããvCenterã«ãã«ã¢ã¯ã»ã¹ã§ããŸãã æ°ç§ã§...ïŒMetasploitã«å¯Ÿå¿ããã¢ãžã¥ãŒã«ã®æºåãã§ããŸããïŒ
ãã¡ã€ãã«
ã芧ã®ãšããã0æ¥ã¯åçŽã§å±éºã§ãã ããã«èšããŸããïŒ..管çè
ããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠã¢ã¯ã»ã¹ããã£ã«ã¿ãªã³ã°ãã管çããŒããžã®ã¢ã¯ã»ã¹ãå¶éãããšãæ»æã¯ããã«é£ãããªããŸãã ä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿è·ã¯1åã ãã§ãªãã1å°ã®ãµãŒããŒã§ããªããããå€ãã®ããšãèå°è£ã«æ®ã£ãŠããŸãã VMware Hardening GuideïŒhttp://www.vmware.com/files/pdf/techpaper/VMW-TWP-vSPHR-SECRTY-HRDNG-USLET-101-WEB-1.pdfïŒã§ãã¹ãŠã®äººã«ã¢ããã€ã¹ã§ããŸãã ãã®PDFã«ã¯ã泚ç®ã«å€ããå€ãã®å Žæããªã¹ããããŠããŸãã ããã ãã§ããç
æ°ã«ãªããªãã§ãã ããïŒ