Linux Pling-Store RCE©¶´Í¨¸æ

Ðû²¼Ê±¼ä 2021-06-24

0x00 ©¶´¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-06-24

Àà      ÐÍ

XSS¡¢RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ

¸ß

Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

Pling-Store ÊÇÒ»¿îÊÊÓÃÓÚ OCS ¼æÈÝÍøÕ¾£¨Èç pling.com¡¢gnome-look.org¡¢appimagehub.com µÈ£©µÄÓ¦Ó÷¨Ê½ºÍʵÓ÷¨Ê½É̵꣬¿ÉÒÔʹÓÃËüÏÂÔØ¡¢°²×°ºÍÓ¦ÓÃ×ÀÃæÖ÷Ì⡢ͼ±êÖ÷Ìâ¡¢±ÚÖ½µÈ¡£Pling-StoreʹÓà Appimage °ü¸ñʽ£¬Ó¦ÊÊÓÃÓÚÈç Ubuntu¡¢Debian¡¢Arch¡¢Suse¡¢Redhat µÈ¿¯Ðаæ¡£

2021Äê06ÔÂ22ÈÕ£¬¹úÍâÄþ¾²Ñо¿Ô±¹ûÈ»Åû¶ÁË Plingƽ̨£¨°üÂÞ AppImage Hub¡¢Gnome-Look¡¢KDE Discover App Store¡¢Pling.com ºÍ XFCE-Look£©Öз¢ÏÖµÄXSSºÍRCE©¶´£¬Ç°ÕßÈÝÒ×Êܵ½XSSÈ䳿¹¥»÷£¬²¢¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷ £»ºóÕß¿ÉÄܵ¼ÖÂ͵¶ÉʽÏÂÔØ¹¥»÷¡£

 

KDE Discover XSS

Ñо¿ÈËÔ±Ê×ÏÈÔÚKDE Discover Öз¢ÏÖÁË´Ë´æ´¢ÐÍXSS©¶´£¬Í¨¹ýÔÚwebÓ¦Ó÷¨Ê½ÖвåÈë¶ñÒâ½Å±¾£¬µ±·ÃÎʶñÒâÁбíʱ´¥·¢ XSS¡£ÕâÖÖ´æ´¢ÐÍXSS¿ÉÓÃÓÚÐ޸ĻÁбí£¬»òÔÚÆäËûÓû§µÄÅä¾°ÏÂÔÚPling-storeÐû²¼ÐµÄÁбí£¬´Ó¶øµ¼ÖÂXSSÈ䳿¹¥»÷¡£³ýÁ˵äÐ͵ÄXSSÓ°ÏìÍ⣬¹¥»÷Õß¿ÉÒÔͨ¹ýÉÏ´«ºóÃÅ»ò¸ü¸ÄPayload½øÐй©Ó¦Á´¹¥»÷¡£

image.png

image.png

 

Pling-Store RCE

ËùÓлùÓÚPling¿ª·¢µÄÓ¦Ó÷¨Ê½É̵궼Ðû´«Ê¹ÓÃÔ­ÉúµÄPling-StoreÓ¦Ó÷¨Ê½£¬ ÕâÊÇÒ»¸ö¿ÉÒÔÏÔʾ²îÒìÍøÕ¾²¢¿ÉÒÔÒ»¼ü°²×°Ó¦Ó÷¨Ê½µÄ Electron Ó¦Ó÷¨Ê½¡£

¸ÃElectronÓ¦Ó÷¨Ê½Ò²¿ÉÒÔ´¥·¢XSS£¬¶øÇÒµ±ÓëElectronɳºÐÈÆ¹ý½áºÏʹÓÃʱÄܹ»µ¼ÖÂRCE¡£

ÒòΪÔÚÉè¼ÆÊ±£¬¸ÃÓ¦Ó÷¨Ê½¿ÉÒÔ°²×°ÆäËûÓ¦Ó÷¨Ê½£¬ËüÓÐÁíÒ»¸öÄÚÖõĻúÖÆ£¬¿ÉÒÔÔÚϵͳÉÏÖ´ÐдúÂë¡£¶øµ±Pling-StoreÓ¦Ó÷¨Ê½ÔÚºǫ́´ò¿ªÊ±£¬¸Ã»úÖÆ¿ÉÒÔ±»ÈκÎÍøÕ¾ÀûÓÃÀ´ÔËÐÐÈÎÒâµÄµ±µØ´úÂë¡£µ±XSSÔÚÓ¦Ó÷¨Ê½ÄÚ²¿±»´¥·¢Ê±£¬Payload¿ÉÒÔ½¨Á¢Óëµ±µØWebSocket·þÎñÆ÷µÄÁ¬½Ó£¬²¢·¢ËÍÏûÏ¢ÒÔÖ´ÐÐÈÎÒâµ±µØ´úÂ루ͨ¹ýÏÂÔØºÍÖ´ÐÐAppImageÎļþ£©¡£

Ñо¿ÈËÔ±Ðû²¼ÁËPoC£¬±íÃ÷¿ÉÒÔͨ¹ýÔÚÈκÎä¯ÀÀÆ÷ÖзÃÎʶñÒâÍøÕ¾À´½øÐй¥»÷¡£

 

0x02 ´¦Öý¨Òé

ÓÉÓÚÎÞ·¨ÁªÏµµ½Pling¿ª·¢ÍŶÓ£¬Ä¿Ç°´Ë©¶´ÔÝδÐÞ¸´¡£½¨ÒéʹÓÃÒÔÏÂÁÙʱ»º½â´ëÊ©£º

ÔÚRCE©¶´ÐÞ¸´Ö®Ç°£¬²»ÒªÔËÐÐPring-Store ElectronÓ¦Ó÷¨Ê½£¨×îºÃɾ³ýAppImage£©¡£

×¢Ò⣬appimagehub.com¡¢store.kde.org¡¢gnome-look.org¡¢xfce-look.orgºÍpling.comÉϵÄÕË»§¶¼¿ÉÄܱ»XSS½Ù³Ö£¬ÈκοÉÏÂÔØµÄ×ʲú¶¼¿ÉÄܱ»ÆÆ»µ¡£×îºÃ×¢ÏúÕË»§£¬ÔÚ©¶´±»ÐÞ¸´Ö®Ç°²»ÒªÊ¹ÓÃÕâÐ©ÍøÕ¾¡£

 

0x03 ²Î¿¼Á´½Ó

https://positive.security/blog/hacking-linux-marketplaces

https://threatpost.com/unpatched-linux-marketplace-bugs-rce/167155/

https://breaking.systems/plingstore_rce_poc.html

 

0x04 ʱ¼äÏß

2021-06-24  VSRCÐû²¼Äþ¾²Í¨¸æ

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png