daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

24007-24008-24009-49152-pentesting-glusterfs.md (8142B)


      1 ---
      2 title: "24007-24008-24009-49152 - Pentesting GlusterFS"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/24007-24008-24009-49152-pentesting-glusterfs.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/24007-24008-24009-49152-pentesting-glusterfs.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 24007-24008-24009-49152 - Pentesting GlusterFS
     14 
     15 ## Basic Information
     16 
     17 **GlusterFS** is a **distributed file system** that combines storage from multiple servers into one **unified namespace**. Gluster documentation calls for management ports **24007–24008** and brick ports that historically started at **49152** (older deployments used **24009** onward). From Gluster 10, brick ports are selected within the configured `base-port` to `max-port` range rather than simply incremented.<sup>[[7]](#references)</sup>
     18 
     19 ```text
     20 PORT      STATE  SERVICE        VERSION
     21 24007/tcp open   glusterd       GlusterFS (RPC)
     22 49152/tcp open   gluster-brick  SSL (TLS optional)
     23 ```
     24 
     25 > Port 24007 can identify `glusterd` even when a probed node does not itself host a brick for the target volume. Treat management-plane exposure as a separate finding from volume access.
     26 
     27 ## Enumeration
     28 
     29 Install the client utilities on your attacking box:
     30 
     31 ```bash
     32 sudo apt install -y glusterfs-cli glusterfs-client   # Debian/Ubuntu
     33 ```
     34 
     35 1. **Peer discovery & health**
     36 
     37 ```bash
     38 # Test whether the exposed management plane returns peer state
     39 gluster --remote-host 10.10.11.131 peer status
     40 ```
     41 
     42 2. **Volume reconnaissance**
     43 
     44 ```bash
     45 # Retrieve the list of all volumes and their configuration
     46 gluster --remote-host 10.10.11.131 volume info all
     47 ```
     48 
     49 3. **Mount an accessible volume**
     50 
     51 ```bash
     52 sudo mount -t glusterfs 10.10.11.131:/<vol_name> /mnt/gluster
     53 ```
     54 
     55 If mounting fails, check `/var/log/glusterfs/<vol_name>-<uid>.log` on the client side.  Common issues are:
     56 
     57 * TLS enforcement (`option transport.socket.ssl on`)
     58 * Address based access control (`option auth.allow <cidr>`)
     59 
     60 ### Certificate troubleshooting
     61 
     62 In an authorized lab, obtain the following files from a provisioned client and place them in the paths expected by that test client. A private key is sensitive; do not copy production credentials outside the agreed scope.<sup>[[8]](#references)</sup>
     63 
     64 ```text
     65 /etc/ssl/glusterfs.pem
     66 /etc/ssl/glusterfs.key
     67 /etc/ssl/glusterfs.ca
     68 ```
     69 
     70 ---
     71 
     72 ## Version-specific vulnerabilities
     73 
     74 The affected versions and impacts below come from the cited CVE records and vendor advisory; distribution backports may change package-level status.<sup>[[2]](#references)[[3]](#references)[[6]](#references)</sup>
     75 
     76 | CVE | Affected versions | Impact | Notes |
     77 |-----|-------------------|--------|-------|
     78 | **CVE-2022-48340** | GlusterFS 11.0 in the CVE record | Use-after-free in `dht_setxattr_mds_cbk` | Network-reachable denial of service; consult the distribution advisory for patched packages. |
     79 | **CVE-2023-26253** | GlusterFS 11.0 in the CVE record | Stack buffer over-read in the FUSE notify path | Network-triggerable denial of service in affected deployments. |
     80 | **CVE-2018-1088** | GlusterFS 3.x snapshot scheduler | Symlink-based write into a root cron file through shared storage | Privilege escalation when the vulnerable snapshot-scheduler setup exists. |
     81 
     82 Do not infer affected ranges or RCE from a CVE title alone. Check `gluster --version` on every node, identify packaged backports, and compare with the CVE and distribution advisory.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup>
     83 
     84 ### Assessing `gluster_shared_storage`
     85 
     86 `gluster_shared_storage` is a special volume used by features such as geo-replication and snapshot scheduling. If it is exposed to unauthorized clients, mount it read-only first and inspect its actual contents and consumers. Do not assume a universal root-execution hook.<sup>[[4]](#references)</sup>
     87 
     88 ```bash
     89 # 1. Attempt a read-only mount of the shared-storage volume
     90 mkdir /tmp/gss
     91 sudo mount -t glusterfs -o ro 10.10.11.131:/gluster_shared_storage /tmp/gss
     92 
     93 # 2. Enumerate files, ownership, ACLs, and references without modifying them
     94 find /tmp/gss -xdev -printf '%M %u:%g %p\n'
     95 ```
     96 
     97 #### Historical snapshot-scheduler escalation (CVE-2018-1088)
     98 
     99 The useful privilege-escalation primitive in older GlusterFS is **not** a cluster-wide `hooks/1/start/post` directory. In an affected 3.x snapshot-scheduler setup, `snap_scheduler.py init` created `/etc/cron.d/glusterfs_snap_cron_tasks` as a symlink to `glusterfs_snap_cron_tasks` in the shared volume. A client able to mount that volume read/write could therefore control a root-parsed cron file.<sup>[[6]](#references)</sup>
    100 
    101 An earlier draft also suggested checking `/ss_bricks/` when `hooks/1/` was absent. That path is retained as a historical filesystem-search hint, but no documented version mapping or automatic execution behavior was found; inspect ownership and consumers instead of assuming that files placed there execute.
    102 
    103 Check the server-side preconditions first:
    104 
    105 ```bash
    106 gluster volume get all cluster.enable-shared-storage
    107 readlink -f /etc/cron.d/glusterfs_snap_cron_tasks
    108 ls -l /etc/cron.d/glusterfs_snap_cron_tasks
    109 ```
    110 
    111 For an explicitly authorized, disposable vulnerable lab, a non-destructive validation entry can create a marker rather than a reverse shell:
    112 
    113 ```bash
    114 # Remount read/write only after confirming the exact vulnerable lab setup.
    115 sudo mount -o remount,rw /tmp/gss
    116 printf '* * * * * root /usr/bin/touch /tmp/ht-gluster-cve-2018-1088\n' | \
    117   sudo tee /tmp/gss/glusterfs_snap_cron_tasks
    118 ```
    119 
    120 The test mutates a root cron source. Remove the entry immediately after validation; patched releases changed the shared-storage access controls, and current deployments should not be assessed with this historical assumption.<sup>[[6]](#references)</sup>
    121 
    122 ### CVE-2023-26253 testing note
    123 
    124 The flaw is in GlusterFS 11.0's FUSE notify handling. A generic short XDR record sent to `glusterd` is not a valid reproducer. Use the upstream issue's matching client/server setup in an isolated lab and monitor the affected FUSE client process.<sup>[[3]](#references)</sup>
    125 
    126 ---
    127 
    128 ## Hardening & Detection
    129 
    130 * **Upgrade** to a vendor-supported package. Upstream 11.2 is the newest published GitHub release at the time of this review, but downstream support and backports determine the appropriate production version.<sup>[[5]](#references)</sup>
    131 * Enable **TLS** on both client and server sides for the volume, provision trusted certificates, and restrict certificate identities with `auth.ssl-allow` where appropriate:<sup>[[8]](#references)</sup>
    132 
    133   ```bash
    134   gluster volume set <vol> client.ssl on
    135   gluster volume set <vol> server.ssl on
    136   gluster volume set <vol> auth.ssl-allow <certificate-identity>
    137   ```
    138 * Restrict clients with CIDR lists:
    139 
    140   ```bash
    141   gluster volume set <vol> auth.allow 10.0.0.0/24
    142   ```
    143 * Expose management port 24007 only on a **private VLAN** or through SSH tunnels.
    144 * Watch logs: `tail -f /var/log/glusterfs/glusterd.log` and configure **audit-log** feature (`volume set <vol> features.audit-log on`).
    145 
    146 ---
    147 
    148 ## References
    149 
    150 - [1] [GlusterFS security advisories](https://docs.gluster.org/en/latest/release-notes/#security)
    151 - [2] [NVD — CVE-2022-48340](https://nvd.nist.gov/vuln/detail/CVE-2022-48340)
    152 - [3] [GlusterFS issue 3954 — CVE-2023-26253](https://github.com/gluster/glusterfs/issues/3954)
    153 - [4] [Gluster documentation — Geo-replication and shared storage](https://docs.gluster.org/en/main/Administrator-Guide/Geo-Replication/)
    154 - [5] [GlusterFS upstream releases](https://github.com/gluster/glusterfs/releases)
    155 - [6] [Red Hat — CVE-2018-1088 shared-storage snapshot-scheduler escalation](https://access.redhat.com/articles/3414511)
    156 - [7] [Gluster documentation — Client and brick ports](https://docs.gluster.org/en/latest/Administrator-Guide/Setting-Up-Clients/)
    157 - [8] [Gluster documentation — TLS setup and certificate authorization](https://docs.gluster.org/en/v3/Administrator%20Guide/SSL/)