OMIGOD HTTP No Authentication RCE

 Original Source: [Sigma source]
Title: OMIGOD HTTP No Authentication RCE
Status: stable
Description:Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
References:
  -https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
  -https://twitter.com/neu5ron/status/1438987292971053057?s=20
Author: Nate Guagenti (neu5ron)
Date: 2021-09-20
modified:2019-09-20
Tags:
  • -'attack.privilege-escalation'
  • -'attack.initial-access'
  • -'attack.execution'
  • -'attack.lateral-movement'
  • -'attack.t1068'
  • -'attack.t1190'
  • -'attack.t1203'
  • -'attack.t1021.006'
  • -'attack.t1210'
Logsource:
  • product: zeek
  • service: http
  • definition: Enable the builtin Zeek script that logs all HTTP header names by adding "@load policy/protocols/http/header-names" to your local.zeek config file. The script can be seen here for reference https://github.com/zeek/zeek/blob/d957f883df242ef159cfd846884e673addeea7a5/scripts/policy/protocols/http/header-names.zeek
Detection:
  selection:
    status_code: '200'
    uri: '/wsman'
    method: 'POST'
  auth_header:
    client_header_names|contains: 'AUTHORIZATION'
  too_small_http_client_body:
    request_body_len: '0'
  condition:selection and not auth_header and not too_small_http_client_body
Falsepositives:
  -Exploits that were attempted but unsuccessful.
  -Scanning attempts with the abnormal use of the HTTP POST method with no indication of code execution within the HTTP Client (Request) body. An example would be vulnerability scanners trying to identify unpatched versions while not actually exploiting the vulnerability. See description for investigation tips.
Level: high