3632-pentesting-distcc.md (6167B)
1 --- 2 title: "3632 - Pentesting Distcc" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3632-pentesting-distcc.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3632-pentesting-distcc.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3632 - Pentesting Distcc 14 15 ## Basic Information 16 17 `distcc` distributes compilation jobs across networked machines. A client preprocesses source locally and sends the result to a server running `distccd`, which invokes a compiler and returns the output.<sup>[[1]](#references)</sup> 18 19 **Common port:** 3632/TCP 20 21 ```text 22 PORT STATE SERVICE 23 3632/tcp open distccd 24 ``` 25 26 The native TCP transport is a trust boundary: unless GSS-API support is compiled in and `--auth` is enabled, access control is based on source IP rather than user identity. The transport also provides no confidentiality or integrity for preprocessed source and returned object files.<sup>[[6]](#references)[[7]](#references)</sup> 27 28 ## Enumeration 29 30 ```bash 31 nmap -Pn -sV -p 3632 <IP> 32 ``` 33 34 An open TCP port is not enough to prove command execution. In daemon mode, `distccd` applies IP allow rules and silently closes connections from addresses that do not match one; therefore, an immediate EOF/reset after sending a request often indicates an IP allowlist rather than a patched service. Test from the same network position as an authorized build client when the assessment scope permits it.<sup>[[6]](#references)</sup> 35 36 ### Protocol-aware identification 37 38 The version 1 request used by common exploit tools is a fixed token stream. Every header is a four-byte ASCII token followed by an eight-character hexadecimal value; body-bearing tokens then contain exactly that many bytes. A request contains `DIST` (protocol version), `ARGC`, repeated `ARGV` values and `DOTI` (preprocessed input). The response contains `DONE`, `STAT`, `SERR`, `SOUT` and `DOTO` (object output). The ASCII tokens make packet captures and partial/error responses useful even when generic service detection returns no banner.<sup>[[5]](#references)</sup> 39 40 ```bash 41 # Inspect tokens and payloads in a lab capture 42 sudo tcpdump -ni <iface> -s0 -A 'tcp port 3632' 43 ``` 44 45 ## Exploitation 46 47 Older or explicitly insecure `distccd` deployments that accept the tester's address may be vulnerable to CVE-2004-2687. The classic primitive submits a fake compilation whose argument vector starts with `sh -c <command>` and appends compile-looking arguments; the command output is recovered from the `SOUT`/`SERR` response fields.<sup>[[2]](#references)[[3]](#references)[[5]](#references)</sup> 48 49 Nmap provides an NSE check and Metasploit provides a corresponding module. Both checks are **intrusive** because they confirm the issue by executing a command; the NSE argument prefix is the current script name, `distcc-cve2004-2687.cmd`.<sup>[[3]](#references)[[4]](#references)</sup> 50 51 ```bash 52 nmap -p 3632 <IP> --script distcc-cve2004-2687 \ 53 --script-args="distcc-cve2004-2687.cmd='id'" 54 55 msfconsole 56 use exploit/unix/misc/distcc_exec 57 set RHOSTS <IP> 58 set RPORT 3632 59 check 60 set PAYLOAD cmd/unix/generic 61 set CMD id 62 run 63 ``` 64 65 For environments where those frameworks are unavailable, DarkCoderSc's standalone Python proof of concept shows the raw command-execution exchange.<sup>[[5]](#references)</sup> 66 67 ### Interpreting failed exploitation 68 69 Do not treat a failed `sh` payload as proof that the exposed build service is safe: 70 71 - Since distcc 3.3, TCP mode normally accepts only compiler names represented by masquerade links under the distcc compiler directory. The server option `--enable-tcp-insecure` disables that check and explicitly re-enables arbitrary executable names.<sup>[[6]](#references)</sup> 72 - A connection closed without a protocol response commonly means that the source address missed the effective IP allowlist (`--allow`/`--allow-private`). A compiler-whitelist rejection instead means the client passed network authorization but the requested `argv[0]` was rejected.<sup>[[6]](#references)</sup> 73 - Even a compiler-only command list is not a strong sandbox. Upstream warns that compilers process hostile arguments and inputs and recommends assuming that any client allowed to submit jobs can act with the privileges of the `distccd` account.<sup>[[7]](#references)</sup> 74 75 ### On-path build poisoning 76 77 Plain TCP mode neither encrypts nor signs requests or responses. A passive observer can recover preprocessed source and object code, while an active on-path attacker can change either side of the exchange. Replacing the returned object file can implant code into the final locally linked binary without needing the direct `sh` primitive on the server.<sup>[[7]](#references)</sup> 78 79 ## Hardening notes 80 81 Keep TCP/3632 on a trusted build network, bind it to the build interface with `--listen`, use narrow `--allow` CIDRs plus a firewall, and run the daemon as an unprivileged dedicated account. Do not enable `--enable-tcp-insecure`. Where clients cannot be fully trusted at the network layer, use SSH transport or a build with GSS-API mutual authentication (`--auth` and principal allowlisting) rather than relying only on source IP.<sup>[[6]](#references)[[7]](#references)</sup> 82 83 Post created by **Álex B (@r1p)**. 84 85 86 ## References 87 88 - [1] [distcc documentation - How distcc works](https://www.distcc.org/man/distcc_1.html) 89 - [2] [NIST NVD - CVE-2004-2687](https://nvd.nist.gov/vuln/detail/CVE-2004-2687) 90 - [3] [Nmap NSE documentation - `distcc-cve2004-2687`](https://nmap.org/nsedoc/scripts/distcc-cve2004-2687.html) 91 - [4] [Rapid7 - DistCC Daemon Command Execution module](https://www.rapid7.com/db/modules/exploit/unix/misc/distcc_exec/) 92 - [5] [DarkCoderSc - standalone DistCC command-execution proof of concept](https://gist.github.com/DarkCoderSc/4dbf6229a93e75c3bdf6b467e67a9855) 93 - [6] [distcc upstream - current `distccd(1)` manual](https://github.com/distcc/distcc/blob/master/man/distccd.1) 94 - [7] [distcc upstream - security notes](https://www.distcc.org/security.html)