SMF is now exploitable

No explicit questions like "how do I hack xxx.com" please!
User avatar
rambo
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 232
Joined: 29 Jun 2007, 16:00
16
Contact:

SMF is now exploitable

Post by rambo »

0day SMF discovered by The-Dark_Man && Nexen --->Italian Bug Hunter <---

Translated in english by cybermilitant

Note:The bug is pubblic


This is a dangerous bug because many upload system are affected, whit this bug you can upload a phpshell bypassing the restrictions.

Begin:
Prepare your shell (like c99 or nexpl0rer).
Rename it as shell.php.zip (advertence: You mustn't put the shell in an archive but you must only rename it!).
After upload it intermediary upload's attachments of SMF.
Now, if you are lucky, and the admin haven't enabled the opction encrypt filenames, you will find your phpshell here:
http://victim/path/attachments/shell.php.zip


Discovered by The-Dark_Man && NexeN

Enjoy
Rambo

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

Thanks rambo, I may look further into this and post my findings.

User avatar
mo2332
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 705
Joined: 28 Apr 2007, 16:00
16
Contact:

Post by mo2332 »

any u mind takingavideo on how to use it :)?

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

He just told you how to use it, just read his post and do some research.

User avatar
mo2332
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 705
Joined: 28 Apr 2007, 16:00
16
Contact:

Post by mo2332 »

Prepare your shell (like c99 or nexpl0rer). ?

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

Do the following:

www.google.com > type shell + c99 (or nexpl0rer) > search

Then read all the skiddie tutorials on the aforementioned.

User avatar
mo2332
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 705
Joined: 28 Apr 2007, 16:00
16
Contact:

Post by mo2332 »

ty :) u are the l33t. But cloud not find any tuts:(

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

That does not make me 'l337' it makes me a human capable of doing very un-complex searches for useless information of which have no applicable use other than to be a nuisance to people browsing the internet. Again, people using this exploit are idiots who use skiddie tactics, calling themselves hackers.

User avatar
mo2332
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 705
Joined: 28 Apr 2007, 16:00
16
Contact:

Post by mo2332 »

i just want to know o how to use it for knowladge

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

If you want something to do, I suggest reading up on the TCP/IP protocol, OSI Model and various other networking topics. Then, if you where to learn a programming language, you could write your own P-O-C exploits and be a real hacker, much like many of us here strive to be.

User avatar
mo2332
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 705
Joined: 28 Apr 2007, 16:00
16
Contact:

Post by mo2332 »

before i can do that i need to knw how it works btw im exploting my site so no harm done.

User avatar
isapiens
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 533
Joined: 05 May 2006, 16:00
17
Location: Turn around

Post by isapiens »

well i didnt know whats c99, so this is what i typed in google

Code: Select all

c99 shell
And it gave me the info i needed

Btw, i didnt know whats smf either. Its a forum building software correct? (stands for simple machine smth..)

So, anyway, about the exploit... So the only thing you have to do is give the php file a fake zip extension?
Fluoridation is the most monstrously conceived and dangerous communist plot we have ever had to face.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »


rhysh
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 767
Joined: 15 Nov 2006, 17:00
17
Contact:

Post by rhysh »

ok this doesnt really surprise me
now alot of you will find uploaders disable .php extenshions to be uploaded
now whats say you want to upload a shell
but .php and.asp is disbaled
but they have enabled .zip .rar .gif .jpg and so on
now you rename it making sure you have .php as the first extension
eg

shel.php
rename to shel.php.rar
or try
shel.php.zip
shel.php.gif
shel.php.jpg


there are many diferent filetypes
loook them up
but when you upload your shell as .php.rar or something the file is opened as its format now as extension
now your standard shell will be text/html format so the server executes it as that

some admins choose to make it auto rename to
whats say
y4h7h5frj4h78kz7s0n1c0n1.html
thats encrypted and automaticly executed as html code
useless to you

hope this helps
but many sites i have shells on i have used this trick on an uploader
enjoy

User avatar
rambo
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 232
Joined: 29 Jun 2007, 16:00
16
Contact:

Post by rambo »

Im not being nasty or anything mo2332 but if you do not know or understand how to use it.. Don't touch it..

Newbs often screw up their computers by not knowing how to do something and just self-experimneting.

Locked