daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3632-pentesting-distcc.md (6167B)


      1 ---
      2 title: "3632 - Pentesting Distcc"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3632-pentesting-distcc.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3632-pentesting-distcc.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3632 - Pentesting Distcc
     14 
     15 ## Basic Information
     16 
     17 `distcc` distributes compilation jobs across networked machines. A client preprocesses source locally and sends the result to a server running `distccd`, which invokes a compiler and returns the output.<sup>[[1]](#references)</sup>
     18 
     19 **Common port:** 3632/TCP
     20 
     21 ```text
     22 PORT     STATE SERVICE
     23 3632/tcp open  distccd
     24 ```
     25 
     26 The native TCP transport is a trust boundary: unless GSS-API support is compiled in and `--auth` is enabled, access control is based on source IP rather than user identity. The transport also provides no confidentiality or integrity for preprocessed source and returned object files.<sup>[[6]](#references)[[7]](#references)</sup>
     27 
     28 ## Enumeration
     29 
     30 ```bash
     31 nmap -Pn -sV -p 3632 <IP>
     32 ```
     33 
     34 An open TCP port is not enough to prove command execution. In daemon mode, `distccd` applies IP allow rules and silently closes connections from addresses that do not match one; therefore, an immediate EOF/reset after sending a request often indicates an IP allowlist rather than a patched service. Test from the same network position as an authorized build client when the assessment scope permits it.<sup>[[6]](#references)</sup>
     35 
     36 ### Protocol-aware identification
     37 
     38 The version 1 request used by common exploit tools is a fixed token stream. Every header is a four-byte ASCII token followed by an eight-character hexadecimal value; body-bearing tokens then contain exactly that many bytes. A request contains `DIST` (protocol version), `ARGC`, repeated `ARGV` values and `DOTI` (preprocessed input). The response contains `DONE`, `STAT`, `SERR`, `SOUT` and `DOTO` (object output). The ASCII tokens make packet captures and partial/error responses useful even when generic service detection returns no banner.<sup>[[5]](#references)</sup>
     39 
     40 ```bash
     41 # Inspect tokens and payloads in a lab capture
     42 sudo tcpdump -ni <iface> -s0 -A 'tcp port 3632'
     43 ```
     44 
     45 ## Exploitation
     46 
     47 Older or explicitly insecure `distccd` deployments that accept the tester's address may be vulnerable to CVE-2004-2687. The classic primitive submits a fake compilation whose argument vector starts with `sh -c <command>` and appends compile-looking arguments; the command output is recovered from the `SOUT`/`SERR` response fields.<sup>[[2]](#references)[[3]](#references)[[5]](#references)</sup>
     48 
     49 Nmap provides an NSE check and Metasploit provides a corresponding module. Both checks are **intrusive** because they confirm the issue by executing a command; the NSE argument prefix is the current script name, `distcc-cve2004-2687.cmd`.<sup>[[3]](#references)[[4]](#references)</sup>
     50 
     51 ```bash
     52 nmap -p 3632 <IP> --script distcc-cve2004-2687 \
     53   --script-args="distcc-cve2004-2687.cmd='id'"
     54 
     55 msfconsole
     56 use exploit/unix/misc/distcc_exec
     57 set RHOSTS <IP>
     58 set RPORT 3632
     59 check
     60 set PAYLOAD cmd/unix/generic
     61 set CMD id
     62 run
     63 ```
     64 
     65 For environments where those frameworks are unavailable, DarkCoderSc's standalone Python proof of concept shows the raw command-execution exchange.<sup>[[5]](#references)</sup>
     66 
     67 ### Interpreting failed exploitation
     68 
     69 Do not treat a failed `sh` payload as proof that the exposed build service is safe:
     70 
     71 - Since distcc 3.3, TCP mode normally accepts only compiler names represented by masquerade links under the distcc compiler directory. The server option `--enable-tcp-insecure` disables that check and explicitly re-enables arbitrary executable names.<sup>[[6]](#references)</sup>
     72 - A connection closed without a protocol response commonly means that the source address missed the effective IP allowlist (`--allow`/`--allow-private`). A compiler-whitelist rejection instead means the client passed network authorization but the requested `argv[0]` was rejected.<sup>[[6]](#references)</sup>
     73 - Even a compiler-only command list is not a strong sandbox. Upstream warns that compilers process hostile arguments and inputs and recommends assuming that any client allowed to submit jobs can act with the privileges of the `distccd` account.<sup>[[7]](#references)</sup>
     74 
     75 ### On-path build poisoning
     76 
     77 Plain TCP mode neither encrypts nor signs requests or responses. A passive observer can recover preprocessed source and object code, while an active on-path attacker can change either side of the exchange. Replacing the returned object file can implant code into the final locally linked binary without needing the direct `sh` primitive on the server.<sup>[[7]](#references)</sup>
     78 
     79 ## Hardening notes
     80 
     81 Keep TCP/3632 on a trusted build network, bind it to the build interface with `--listen`, use narrow `--allow` CIDRs plus a firewall, and run the daemon as an unprivileged dedicated account. Do not enable `--enable-tcp-insecure`. Where clients cannot be fully trusted at the network layer, use SSH transport or a build with GSS-API mutual authentication (`--auth` and principal allowlisting) rather than relying only on source IP.<sup>[[6]](#references)[[7]](#references)</sup>
     82 
     83 Post created by **Álex B (@r1p)**.
     84 
     85 
     86 ## References
     87 
     88 - [1] [distcc documentation - How distcc works](https://www.distcc.org/man/distcc_1.html)
     89 - [2] [NIST NVD - CVE-2004-2687](https://nvd.nist.gov/vuln/detail/CVE-2004-2687)
     90 - [3] [Nmap NSE documentation - `distcc-cve2004-2687`](https://nmap.org/nsedoc/scripts/distcc-cve2004-2687.html)
     91 - [4] [Rapid7 - DistCC Daemon Command Execution module](https://www.rapid7.com/db/modules/exploit/unix/misc/distcc_exec/)
     92 - [5] [DarkCoderSc - standalone DistCC command-execution proof of concept](https://gist.github.com/DarkCoderSc/4dbf6229a93e75c3bdf6b467e67a9855)
     93 - [6] [distcc upstream - current `distccd(1)` manual](https://github.com/distcc/distcc/blob/master/man/distccd.1)
     94 - [7] [distcc upstream - security notes](https://www.distcc.org/security.html)