Detection: Splunk Persistent XSS via Props Conf

REMOVED DETECTION

This detection has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: Detection is deprecated as the associated CVEs have been patched in the latest Splunk release.

Removed in version: 5.6.0

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the “admin” or “power” Splunk roles could craft a malicious payload through entity.details in props.conf that could result in execution of unauthorized JavaScript code in the browser of a user.

1`splunkd_ui` status=201 uri_path="*/splunkd/__raw/servicesNS/*/*/configs/*" 
2
3| stats count min(_time) as firstTime max(_time) as lastTime by host clientip user uri status 
4
5| `security_content_ctime(firstTime)` 
6
7| `security_content_ctime(lastTime)` 
8
9| `splunk_persistent_xss_via_props_conf_filter`

Data Source

Name Platform Sourcetype Source
Splunk Splunk icon Splunk 'splunkd_ui_access' 'splunkd_ui_access.log'

Macros Used

Name Value
splunkd_ui index=_internal sourcetype=splunkd_ui_access
splunk_persistent_xss_via_props_conf_filter ``
splunk_persistent_xss_via_props_conf_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic
T1189 Drive-by Compromise Initial Access

CVE

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule N/A
Earliest Time N/A
Latest Time N/A
Schedule Window N/A
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) No
Hunting detections do not generate a Finding (Notable) or Intermediate Findings (Risk Events).

Implementation

Requires access to internal index and web component enabled.

Known False Positives

This is a hunting search that provides information on the creation of a scheduled view against the targeted endpoint("/splunkd/__raw/servicesNS/user/search/configs/"). In the attack flow the payload is saved via scheduled view then sent to the victim.

Associated Analytic Story

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation Not Applicable N/A N/A N/A
Unit Not Applicable N/A N/A N/A

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 5