Linux Pling-Store RCEÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2021-06-24

0x00 Îó²î¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-06-24

Àà      ÐÍ

XSS¡¢RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ

¸ß

Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

Pling-Store ÊÇÒ»¿îÊÊÓÃÓÚ OCS ¼æÈÝÍøÕ¾£¨Èç pling.com¡¢gnome-look.org¡¢appimagehub.com µÈ£©µÄÓ¦ÓóÌÐòºÍÊÊÓóÌÐòÊÐËÁ£¬£¬ £¬£¬¿ÉÒÔʹÓÃËüÏÂÔØ¡¢×°ÖúÍÓ¦ÓÃ×ÀÃæÖ÷Ì⡢ͼ±êÖ÷Ìâ¡¢±ÚÖ½µÈ¡£¡£¡£¡£¡£Pling-StoreʹÓà Appimage °üÃûÌ㬣¬ £¬£¬Ó¦ÊÊÓÃÓÚÈç Ubuntu¡¢Debian¡¢Arch¡¢Suse¡¢Redhat µÈ¿¯Ðаæ¡£¡£¡£¡£¡£

2021Äê06ÔÂ22ÈÕ£¬£¬ £¬£¬ÍâÑóÇå¾²Ñо¿Ô±¹ûÕæÅû¶ÁË Plingƽ̨£¨°üÀ¨ AppImage Hub¡¢Gnome-Look¡¢KDE Discover App Store¡¢Pling.com ºÍ XFCE-Look£©Öз¢Ã÷µÄXSSºÍRCEÎó²î£¬£¬ £¬£¬Ç°ÕßÈÝÒ×Êܵ½XSSÈ䳿¹¥»÷£¬£¬ £¬£¬²¢¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷£»£»£»£» £»£»£»ºóÕß¿ÉÄܵ¼ÖÂ͵¶ÉʽÏÂÔØ¹¥»÷¡£¡£¡£¡£¡£

 

KDE Discover XSS

Ñо¿Ö°Ô±Ê×ÏÈÔÚKDE Discover Öз¢Ã÷ÁË´Ë´æ´¢ÐÍXSSÎó²î£¬£¬ £¬£¬Í¨¹ýÔÚwebÓ¦ÓóÌÐòÖвåÈë¶ñÒâ¾ç±¾£¬£¬ £¬£¬µ±»á¼û¶ñÒâÁбíʱ´¥·¢ XSS¡£¡£¡£¡£¡£ÕâÖÖ´æ´¢ÐÍXSS¿ÉÓÃÓÚÐ޸ĻÁбí£¬£¬ £¬£¬»òÔÚÆäËûÓû§µÄÅä¾°ÏÂÔÚPling-storeÐû²¼ÐµÄÁбí£¬£¬ £¬£¬´Ó¶øµ¼ÖÂXSSÈ䳿¹¥»÷¡£¡£¡£¡£¡£³ýÁ˵䷶µÄXSSÓ°ÏìÍ⣬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÉÏ´«ºóÃÅ»ò¸ü¸ÄPayload¾ÙÐй©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£

image.png

image.png

 

Pling-Store RCE

ËùÓлùÓÚPling¿ª·¢µÄÓ¦ÓóÌÐòÊÐËÁ¶¼Ðû´«Ê¹ÓÃÔ­ÉúµÄPling-StoreÓ¦ÓóÌÐò£¬£¬ £¬£¬ ÕâÊÇÒ»¸ö¿ÉÒÔÏÔʾ²î±ðÍøÕ¾²¢¿ÉÒÔÒ»¼ü×°ÖÃÓ¦ÓóÌÐòµÄ Electron Ó¦ÓóÌÐò¡£¡£¡£¡£¡£

¸ÃElectronÓ¦ÓóÌÐòÒ²¿ÉÒÔ´¥·¢XSS£¬£¬ £¬£¬²¢ÇÒµ±ÓëElectronɳºÐÈÆ¹ýÁ¬ÏµÊ¹ÓÃʱÄܹ»µ¼ÖÂRCE¡£¡£¡£¡£¡£

ÓÉÓÚÔÚÉè¼ÆÊ±£¬£¬ £¬£¬¸ÃÓ¦ÓóÌÐò¿ÉÒÔ×°ÖÃÆäËûÓ¦ÓóÌÐò£¬£¬ £¬£¬ËüÓÐÁíÒ»¸öÄÚÖõĻúÖÆ£¬£¬ £¬£¬¿ÉÒÔÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¶øµ±Pling-StoreÓ¦ÓóÌÐòÔÚºǫ́·­¿ªÊ±£¬£¬ £¬£¬¸Ã»úÖÆ¿ÉÒÔ±»ÈκÎÍøÕ¾Ê¹ÓÃÀ´ÔËÐÐí§ÒâµÄÍâµØ´úÂë¡£¡£¡£¡£¡£µ±XSSÔÚÓ¦ÓóÌÐòÄÚ²¿±»´¥·¢Ê±£¬£¬ £¬£¬Payload¿ÉÒÔ½¨ÉèÓëÍâµØWebSocketЧÀÍÆ÷µÄÅþÁ¬£¬£¬ £¬£¬²¢·¢ËÍÐÂÎÅÒÔÖ´ÐÐí§ÒâÍâµØ´úÂ루ͨ¹ýÏÂÔØºÍÖ´ÐÐAppImageÎļþ£©¡£¡£¡£¡£¡£

Ñо¿Ö°Ô±Ðû²¼ÁËPoC£¬£¬ £¬£¬Åú×¢¿ÉÒÔͨ¹ýÔÚÈκÎä¯ÀÀÆ÷Öлá¼û¶ñÒâÍøÕ¾À´¾ÙÐй¥»÷¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÓÉÓÚÎÞ·¨ÁªÏµµ½Pling¿ª·¢ÍŶÓ£¬£¬ £¬£¬ÏÖÔÚ´ËÎó²îÔÝδÐÞ¸´¡£¡£¡£¡£¡£½¨ÒéʹÓÃÒÔÏÂÔÝʱ»º½â²½·¥£º

ÔÚRCEÎó²îÐÞ¸´Ö®Ç°£¬£¬ £¬£¬²»ÒªÔËÐÐPring-Store ElectronÓ¦ÓóÌÐò£¨×îºÃɾ³ýAppImage£©¡£¡£¡£¡£¡£

×¢ÖØ£¬£¬ £¬£¬appimagehub.com¡¢store.kde.org¡¢gnome-look.org¡¢xfce-look.orgºÍpling.comÉϵÄÕË»§¶¼¿ÉÄܱ»XSSÐ®ÖÆ£¬£¬ £¬£¬ÈκοÉÏÂÔØµÄ×ʲú¶¼¿ÉÄܱ»ÆÆË𡣡£¡£¡£¡£×îºÃ×¢ÏúÕË»§£¬£¬ £¬£¬ÔÚÎó²î±»ÐÞ¸´Ö®Ç°²»ÒªÊ¹ÓÃÕâÐ©ÍøÕ¾¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://positive.security/blog/hacking-linux-marketplaces

https://threatpost.com/unpatched-linux-marketplace-bugs-rce/167155/

https://breaking.systems/plingstore_rce_poc.html

 

0x04 ʱ¼äÏß

2021-06-24  VSRCÐû²¼Ç徲ͨ¸æ

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png