5985-5986-pentesting-omi.md (3299B)
1 --- 2 title: "5985, 5986 - Pentesting OMI" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/5985-5986-pentesting-omi.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/5985-5986-pentesting-omi.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 5985, 5986 - Pentesting OMI 14 15 ## Basic Information 16 17 Microsoft's **Open Management Infrastructure (OMI)** is an open-source implementation of the Distributed Management Task Force's CIM and WS-Management standards for Unix-like systems.<sup>[[1]](#references)</sup> Some Azure management extensions install OMI on Linux virtual machines, including extensions associated with services such as:<sup>[[3]](#references)</sup> 18 19 - **Azure Automation** 20 - **Azure Automatic Update** 21 - **Azure Operations Management Suite** 22 - **Azure Log Analytics** 23 - **Azure Configuration Management** 24 - **Azure Diagnostics** 25 26 Depending on the extension and configuration, `omiengine` may run as root and expose an HTTPS listener. OMI can also operate through a local Unix socket, so installation alone does not prove that a network listener is reachable.<sup>[[3]](#references)</sup> 27 28 Common WS-Management ports are **5985/TCP** for HTTP and **5986/TCP** for HTTPS.<sup>[[4]](#references)</sup> 29 30 ## CVE-2021-38647 (OMIGOD) 31 32 Microsoft disclosed CVE-2021-38647 in September 2021. Vulnerable OMI versions could incorrectly authorize an unauthenticated request sent to the `/wsman` endpoint when the `Authorization` header was omitted.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 33 34 On a network-exposed vulnerable instance, an attacker could send an `ExecuteShellCommand` SOAP request without that header and execute commands as root.<sup>[[4]](#references)</sup> The following is only the relevant body excerpt; a complete request also needs the WS-Management envelope fields described in the linked analysis and proof of concept: 35 36 ```xml 37 <s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://schemas.xmlsoap.org/ws/2004/08/addressing" 38 ... 39 <s:Body> 40 <p:ExecuteShellCommand_INPUT xmlns:p="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem"> 41 <p:command>id</p:command> 42 <p:timeout>0</p:timeout> 43 </p:ExecuteShellCommand_INPUT> 44 </s:Body> 45 </s:Envelope> 46 ``` 47 48 Patch OMI and restrict WS-Management listeners to trusted management networks. Horizon3.ai's repository contains a technical proof of concept suitable for controlled validation.<sup>[[5]](#references)</sup> 49 50 ## References 51 52 - [1] [Microsoft - Open Management Infrastructure](https://github.com/microsoft/omi) 53 - [2] [Microsoft Security Response Center - CVE-2021-38647](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647) 54 - [3] [Wiz Research - OMIGOD vulnerabilities in OMI](https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure) 55 - [4] [Horizon3.ai - OMIGOD RCE in Azure Linux deployments](https://www.horizon3.ai/omigod-rce-vulnerability-in-multiple-azure-linux-deployments/) 56 - [5] [Horizon3.ai - CVE-2021-38647 proof of concept and analysis](https://github.com/horizon3ai/CVE-2021-38647)