Sitemap
R3d Buck3T

R3d Buck3T focuses on Penetration Testing & Vulnerability Assessment (Red Teaming).My goal is to document what I learn, and share the knowledge with the InfoSec Community

Remote Code Execution in OpenNetAdmin

4 min readOct 20, 2020

--

Exploit Analysis of OpenNetAdmin v18.1.1

Press enter or click to view image in full size
Photo by Kev Seto on Unsplash

$_ What_is_OpenNetAdmin?

OpenNetAdmin is a Network Management application that provides a database of managed inventory of IPs, subnets, and hosts in a network with a centralized AJAX web interface. The application is an Opensource written in PHP; you can view the source code on GitHub “ONA Project.”

$_Features_of_OpenNetAdmin

  • Full command-line interface for scripting and batch maintenance. Local or remote capabilities.
  • Plugin system to extend the functionality
  • Manage DNS and DHCP server configs, archive host configs
  • Full CLI interface for batch and scripting

$_Vulnerability_Impact

The vulnerability found in v18.1.1 allows for a code execution that leads to a full compromise of the hosting machine.

One of the things I like to do before delving into the exploitation or vulnerability analysis process is jotting down quick notes on the information I gather and map them into Enumeration & Attack vectors notes that help me later understand the root cause of the vulnerability and how it was exploited.

💡 _Enumeration_& Attack_Vectors_:

[+] When I see a PHP application, the first thing that comes to mind is “Command Injection” and “LFI/RFI vulnerabilities.”

[+] PHP is known for years for security bugs/vulnerabilities that stem from the basic unsanitization of inputs.

[+] PHP functions that allows for code execution are :exec(), shell_exec(), curl_exec(), system().

For this exercise, the command injection is the one we are looking for. I was inspired by zacheller.dev to dig deeper into the code and understand what it exploits while working through Hack the box OpenAdmin machine.

Here we go…

$_Exploit_Analysis
The exploit takes advantage of the unsanitized PHP function — shell_exec that executes the shell commands and returns the output as a string. Shell_Exec is notoriously known for leaving a security hole/vulnerability in an application if not appropriately implemented; Secure Code practices y’all !!!

Press enter or click to view image in full size
RCE Exploit by Mattpascoe

Let’s break down the curl command in the exploit to understand where the code execution happens:

Window_Submit is a function identified in the “webwin.inc.php” file as a generic wrapper handling form submits. The function takes 3 parameters:

  • $windows_name: the name of the “window” submitting the data. In our case, it is Tooltips.
  • $form[]: the submitted data in the form of an array. The value expected is an IP Address extracted from the form id=ip.’
  • $function: the action that will be performed. In this case, is the ws_ping that performs the pinging requests.
  • The first the parameter in the curl command of xajaxr=1574117726710 can be ignored as it does not do anything for exploit. The Unix timestamp is when the author discovered the vulnerability.
Press enter or click to view image in full size
ws_ping fuction

ws_ping is the function that uses the shell_exec to execute the ping command. It takes 2 parameters, which in this case ‘Tooltips’ where the ws_ping function is defined “tooltips.inc.php” and form id value extracted from the form — the IP address.

As you see below, the function lacks any input validation or character sanitizations that makes it vulnerable to command injection. To execute shell commands, we will use the basic command execution technique of adding semicolon to append a command after the IP “=>” sign and inject our commands into it.

Press enter or click to view image in full size
ws_ping function

Now that we understand where the exploit is present, we can use the generic wrapper window_name to call the function and pass the commands to it.

$window_name = tooltips, the name of the module we want to call that has the ws_ping function

$form =expects an IP address, but we are going to inject shell commands 😝

$function = calls the function needed to perform the action on the $form

Press enter or click to view image in full size
window_submit function

Lastly, the curl output is piped into sed, tail, and head to display the executed command’s output only.

Press enter or click to view image in full size
OpenAdmin Machine onHTB

$_Recommendation

  • Always validate input and escape values in the application’s code. Never trust the user’s input😃. Anyone can execute arbitrary commands on the system and compromise it.
  • Patch regularly and upgrade when possible on all publicly exposed interfaces to avoid becoming an easy foothold for attackers.

--

--

R3d Buck3T
R3d Buck3T

Published in R3d Buck3T

R3d Buck3T focuses on Penetration Testing & Vulnerability Assessment (Red Teaming).My goal is to document what I learn, and share the knowledge with the InfoSec Community