Në projektin në zhvillim OpenBSD për serverin e postës u zbulua (CVE-2020-7247), e cila lejon ekzekutimin e komandeve shell në server me të drejtat e përdoruesit root. Dobësia u identifikua gjatë një auditi të dytë, të kryer nga kompania Qualys Security (auditi i mëparshëm OpenSMTPD në vitin 2015, ndërsa dobësia e re është e pranishme që nga maji i vitit 2018). Problemi ndodhet në versionin OpenSMTPD 6.6.2. Të gjithë përdoruesve u rekomandohet të instalojnë urgjentisht përditësimin (për OpenBSD, rregullimi mund të instalohet përmes syspatch).
Janë propozuar dy variante të sulmit. Varianti i parë punon në konfigurimin OpenSMTPD siç është gjithmonë (pranimi i kërkesave vetëm nga localhost) dhe lejon shfrytëzimin e problemit në mënyrë lokale, kur sulmuesi ka mundësi të aksesojë ndërfaqen e rrjetit lokal (loopback) në server (p.sh., në sistemet e hostimit). Varianti i dytë shfaqet në rastin e konfigurimit të OpenSMTPD për të pranuar kërkesat e rrjetit të jashtëm (serveri i postës, që pranon email nga palë të treta). Kërkuesit kanë përgatitur një prototip të eksploitit, i cili funksionon me sukses si me variantin OpenSMTPD të përfshirë në OpenBSD 6.6, ashtu edhe me versionin e tij portativ për OS të tjera (të testuar në Debian Testing).
Problemi shkaktohet nga njĂ« gabim nĂ« funksionin smtp_mailaddr(), i cili thirret pĂ«r tĂ« verifikuar saktĂ«sinĂ« e vlerave nĂ« fushat âMAIL FROMâ dhe âRCPT TOâ, qĂ« pĂ«rkufizojnĂ« dĂ«rguesin/pranon dhe dĂ«rgohen gjatĂ« lidhjes me serverin e postĂ«s. PĂ«r tĂ« verifikuar pjesĂ«n e adresĂ«s postare qĂ« vjen para simbolit â@â, nĂ« smtp_mailaddr() thirret funksioni
valid_localpart(), i cili konsideron si simbolikĂ« tĂ« lejuara (MAILADDR_ALLOWED) simbolet â!#$%&â*\/Âż^`{|}~+-=_â, sipas kĂ«rkesave tĂ« RFC 5322.
NĂ« tĂ« njĂ«jtĂ«n kohĂ«, ekranuar direkt teksti bĂ«het nĂ« funkcionin mda_expand_token(), i cili zĂ«vendĂ«son vetĂ«m simbolĂ«t â!#$%&â*?`{|}~â (MAILADDR_ESCAPE). MĂ« pas, teksti i pĂ«rgatitur nĂ« mda_expand_token() pĂ«rdoret gjatĂ« thirrjes sĂ« agjentit tĂ« dĂ«rgesĂ«s (MDA) pĂ«rmes komandĂ«s 'execle("/bin/sh", "/bin/sh", "-c", mda_command,âŠ'. NĂ« rast se letra vendoset nĂ« mbox pĂ«rmes /bin/sh, startohet me komandĂ«n "/usr/libexec/mail.local -f %%{mbox.from} %%{user.username}", ku vlera "%{mbox.from}" pĂ«rfshin tĂ« dhĂ«nat e ekranizuara nga parametri "MAIL FROM".
The essence of the vulnerability is that smtp_mailaddr() has a logical error, which causes it to return a successful validation code when an empty domain is passed in the email, even if the part of the address before the "@" contains invalid characters. Then, when preparing the string with the mda_expand_token() function, not all possible shell special characters are escaped, only those that are allowed in the email address. Thus, to execute one's command, it is enough to use the symbol ";" and a space in the local part of the email, which are not included in the MAILADDR_ESCAPE set and are not escaped. For example:
$ nc 127.0.0.1 25
HELO professor.falken
MAIL FROM:<;sleep 66;>
RCPT TO:<root>
DATA
.
QUIT
After this session, OpenSMTPD will execute the command through the shell when delivering to mbox
/usr/libexec/mail.local -f ;sleep 66; root
At the same time, the attack opportunities are limited by the fact that the local part of the address cannot exceed 64 characters, and the special characters â$â and â|â are replaced with ":" when escaping. To bypass this limitation, the fact that the body of the email is passed after executing /usr/libexec/mail.local through the input stream is used; that is, by manipulating the address, only the command interpreter sh can be started, and the body of the email can be used as a set of instructions. Since the SMTP headers are specified at the beginning of the email, it is proposed to use the command read in a loop to skip them. The working exploit looks approximately like this:
$ nc 192.168.56.143 25
HELO professor.falken
MAIL FROM:<;for i in 0 1 2 3 4 5 6 7 8 9 a b c d;do read r;done;sh;exit 0;>
RCPT TO:<root@example.org>
DATA
#0
#1
âŠ
#d
for i in W O P R; do
echo -n "($i) " && id || break
done > /root/x.»`id -u`».»$$»
.
QUIT
Burimi: opennet.ru
