daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

5985-5986-pentesting-omi.md (3299B)


      1 ---
      2 title: "5985, 5986 - Pentesting OMI"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/5985-5986-pentesting-omi.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/5985-5986-pentesting-omi.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 5985, 5986 - Pentesting OMI
     14 
     15 ## Basic Information
     16 
     17 Microsoft's **Open Management Infrastructure (OMI)** is an open-source implementation of the Distributed Management Task Force's CIM and WS-Management standards for Unix-like systems.<sup>[[1]](#references)</sup> Some Azure management extensions install OMI on Linux virtual machines, including extensions associated with services such as:<sup>[[3]](#references)</sup>
     18 
     19 - **Azure Automation**
     20 - **Azure Automatic Update**
     21 - **Azure Operations Management Suite**
     22 - **Azure Log Analytics**
     23 - **Azure Configuration Management**
     24 - **Azure Diagnostics**
     25 
     26 Depending on the extension and configuration, `omiengine` may run as root and expose an HTTPS listener. OMI can also operate through a local Unix socket, so installation alone does not prove that a network listener is reachable.<sup>[[3]](#references)</sup>
     27 
     28 Common WS-Management ports are **5985/TCP** for HTTP and **5986/TCP** for HTTPS.<sup>[[4]](#references)</sup>
     29 
     30 ## CVE-2021-38647 (OMIGOD)
     31 
     32 Microsoft disclosed CVE-2021-38647 in September 2021. Vulnerable OMI versions could incorrectly authorize an unauthenticated request sent to the `/wsman` endpoint when the `Authorization` header was omitted.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     33 
     34 On a network-exposed vulnerable instance, an attacker could send an `ExecuteShellCommand` SOAP request without that header and execute commands as root.<sup>[[4]](#references)</sup> The following is only the relevant body excerpt; a complete request also needs the WS-Management envelope fields described in the linked analysis and proof of concept:
     35 
     36 ```xml
     37 <s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://schemas.xmlsoap.org/ws/2004/08/addressing"
     38    ...
     39    <s:Body>
     40       <p:ExecuteShellCommand_INPUT xmlns:p="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem">
     41          <p:command>id</p:command>
     42          <p:timeout>0</p:timeout>
     43       </p:ExecuteShellCommand_INPUT>
     44    </s:Body>
     45 </s:Envelope>
     46 ```
     47 
     48 Patch OMI and restrict WS-Management listeners to trusted management networks. Horizon3.ai's repository contains a technical proof of concept suitable for controlled validation.<sup>[[5]](#references)</sup>
     49 
     50 ## References
     51 
     52 - [1] [Microsoft - Open Management Infrastructure](https://github.com/microsoft/omi)
     53 - [2] [Microsoft Security Response Center - CVE-2021-38647](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647)
     54 - [3] [Wiz Research - OMIGOD vulnerabilities in OMI](https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure)
     55 - [4] [Horizon3.ai - OMIGOD RCE in Azure Linux deployments](https://www.horizon3.ai/omigod-rce-vulnerability-in-multiple-azure-linux-deployments/)
     56 - [5] [Horizon3.ai - CVE-2021-38647 proof of concept and analysis](https://github.com/horizon3ai/CVE-2021-38647)