He has achieved many successes in vulnerability research and has identified the security vulnerabilities of many global companies such as Zoom, Microsoft, Apple and WhatsApp. Gais Cyber Security This time, the Researcher team, together with Senior Cyber Security Engineer Numan Türle, found a vulnerability with a critical score of 9.8.
CentOS Web Panel (CWP), one of the most popular open source and free hosting control panel applications, is used on more than 200,000 servers all over the world. This web-based control panel allows users to manage their websites and servers. Its features include functions such as creating e-mail accounts, database management and software installation.
Vulnerability Detection Senior Cyber Security Engineer from Gais Cyber Security team Numan Turle found an unauthorized remote code execution (RCE) vulnerability in the popular admin panel CWP. This vulnerability was fixed with a security update with version number 0.9.8.1147. The identification number CVE-2022-44877 was assigned to this vulnerability by Miter, the cyber attack encyclopedia that creates a database of cyber attacks in the world. While there are very few vulnerabilities in the world with a critical security level of 10, this vulnerability was evaluated at a critical level with a score of 9.8, according to the US National Vulnerability Database data.Description of VulnerabilityAccording to the information shared by Numan Türle, the vulnerability is caused by "Command Substitution", a structure that allows using the output of one command as the input of another command. This shows that the security vulnerability actually occurred due to an incorrect logging process. The vulnerability occurs because the incorrect records use the Request_URI address in double quotes ("command substitution") in the information architecture where the erroneous transactions of a user trying to log in to this management panel are recorded. The values received from the user are combined with the "bash" feature, which allows the command line to be changed easily, and as a result, a security vulnerability is triggered.
https://github.com/numanturle/CVE-2022-44877
https://www.youtube.com/watch?v=kiLfSvc1SYY
Rob Joyce, Director of the US National Security Agency, cited the vulnerability found by Numan Türle on his social media as an example and said that precautions against this vulnerability, which is advanced through remote code execution, should be taken for similar panels as well. Foreign news sources and hacker communities that publish vulnerabilities around the world also announced this news separately on their own pages. You can access relevant news sources from the links below.
https://twitter.com/NSA_CSDirector/status/1613850710453501955
https://thehackernews.com/2023/01/alert-hackers-actively-exploiting.html
https://portswigger.net/daily-swig/exploit-drops-for-remote-code-execution-bug-in-control-web-panel