目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2017-3164 PoC — Apache Solr 代码问题漏洞

来源
关联漏洞
标题: Apache Solr 代码问题漏洞 (CVE-2017-3164)
Description:Apache Solr是美国阿帕奇(Apache)软件基金会的一款基于Lucene(一款全文搜索引擎)的搜索服务器。该产品支持层面搜索、垂直搜索、高亮显示搜索结果等。 Apache Solr 1.3版本至7.6.0版本中存在服务器端请求伪造漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Description
Apache Solr Poc CVE-2017-3164 CVE-2017-12629
介绍
# Apache Solr Poc CVE-2017-3164 CVE-2017-12629

This folder contains example exploits for Apache Solr CVE-2017-3164 CVE-2017-12629

To be use ONLY for education purposes and with full permission of the Apache Solr Server owner.

You will need to know the IP or DNS name of the Apache Solr server and the name of a Collection.

# CVE-2017-3164

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

---

This SSRF is extremely powerful because all you have to do is send a GET request to this and it will make a POST request to the target. Additionally, you can supply the POST request body as a URL parameter along with the GET request.

# CVE-2017-12629

Rmote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

---

I just chose this RCE to exploit, but Apache Solr has lots of RCE vulnerabilities you could exploit with the SSRF. You could also just as easily exploit any other server the Solr sever has access to e.g. supply Redis commands and get a reverse shell on Redis servers instead.

# exploit-javascript.html

You can host this file on a public web server and then email it to the target user. If the target loads the webpage the JavaScript will automatically exploit the Apache Solr server.

The Port number needs to be supplied in the `?n=` URL param. This way you can send emails to multiple targets and have a unique listener for each one.

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →