Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

Thursday, 15 March 2012

Updates to Insecurety Research - PHP Command Injection!

So, we have written an article about PHP Command Injection (Applies to other platforms too, we just covered PHP).

Read it here! PHP Command Injection - Insecurety Research

More to come...

~Insecurety Research Team.

Wednesday, 14 March 2012

[802.11] Wireless Jamming

Ok. Infodox BRIEFLY touched upon 802.11 jamming in his talk at CampusCon (their site seems to be down at the moment).

For those interested, the talk can be downloaded here: Insecurety Research

Anyways, onward to "The Good Stuff". I (x41) am simply posting the parts he wrote so far, and when he comes back he says he will finish the job.

Wireless Jamming. Sometimes one wants to disable all 802.11 stuff within range (i.e. WiFi) for some reason (perhaps deauth everyone so a KARMA style attack will work better?) and often this can be a bit of a challenge.

Challenge accepted.

First off, let's get to grips with some software called "mdk3".

MDK3 is a 802.11 flooding tool, and comes preinstalled on BackTrack and several other Pentest distros.

However, let's assume you are running a standard Ubuntu box and have not got it installed... So start by installing aircrack.

apt-get install aircrack-ng (ubuntu)
yum install aircrack-ng (fedora)
...Or, compile from sauce...
http://www.aircrack-ng.org/

Now. MDK3.

http://homepages.tu-darmstadt.de/~p_larbig/wlan/

Grab the source from here, untar, ./configure, make && make install (as root).

Then to run (as root):

PUT CARD INTO MONITOR MODE BEFORE CONTINUING!
sudo airmon-ng start wlan0 (where wlan0 is your wifi card)

mdk3 (arguements)

Some samples... (assumes mon0 is your monitor mode interface)

1. mdk3 mon0 x 1 -c (target client MAC) -t (target AP MAC)
This one simply deauths the victim client. Good for targetted jamming.

2. mdk3 mon0 d -b /root/blacklist
assuming you have a list of MAC addresses you DONT wish to have online, you put em in a list and blacklist em. This jams them.

3. mdk3 mon0" d -w (and the path to your whitelist file)
This kills everyones WiFi EXCEPT the devices in the whitelist.

Now. On to more fun things... Killing AP's.

Introducing "ap fucker".















AP Fucker is a python script that automates these DoS attacks. My preferred mode is "Destruction Mode". For obvious reasons.

Grab AP fucker here.. ApFucker - Pastebin

Running this is very simple. Just sudo bash (must be root), start the interface in monitor mode, and run it.

More to come - this was just an introduction!

Friday, 2 March 2012

WebApp Haxploitation with Weevely, Introducing InterSect.

Ok. This is a fairly pointless demo I made to demonstrate how a web-application bug (in this case LFI + Command Injection) can be leveraged to gain complete root access over a server. I simply took a bunch of screencaps during the demo I made to show a friend "Why web app bugs are dangerous".

So. Here goes!

The web app we used here was THIS: Mutillidae - IronGeek

Part One: The Buggy Page.
This shows the buggy applications vulnerable page. It is a simple "Do a DNS lookup" page that just by looking at we can discern certainly has a Local File Inclusion vulnerability, and more than likely a Command Injection vulnerability.












Part Two: Lets Look for LFI
So. I knew there was LFI, and decided I would let fimap check for me, to see could I pull off any LFI-RCE stuff.




























So. Now we know Fimap no canhaz RCE on the site, however there IS LFI. I want RCE, so I move swiftly along to the second vulnerability - Command injection.

Part Three: Command Injection
I decided to inject a Weevely Webshell into the app, so I put it up on my webserver and used wget to "inject" it.
Here is a screencap...












Ok. Shell seems injected, so we move on and try connect to it using the Weevely Client.

Part Four: There are Weevils In Your WWWROOT
Connecting to Weevely's PHP backdoor with the client. This is too easy...















So, lets see what it looks like in there...
















SO! Got remote code execution and a "shell" like session. Let's see does Weevely's reverse shell work for us and try become uid=0 :D

Part Five: Netcat Sais Meow
First off, we start Weevely's reverse shell plugin and tell it to phone home to us... We will be listening for it...















Ok. Now for the listener end of things...
















w00t! We haz a shell :D
... Moving Swiftly along...

We decide to check kernel version and randomly see what commands work. I decided to lsusb for some arbitrary reason. Don't ask.
















Ok. So we move on to escalating/exploring!

Part Six: Enter InterSect.
So I decide to test out InterSect, a wonderful post-exploitation tool developed by ohdae of BindShell Labs.

Here is a screencap of wgetting Intersect to the target box...















Aaaaand now to RUN Intersect ......













Ok. Intersect does not want to run as NON root, so it tells me how to get root on the box... Seeing as I like root... lets go get some!

Part Seven: We Are uid=0, + Harvest Some Infodox
So. I simply run a hypothetical root-exploit I had left in /tmp and getr00t! (It was actually a SUID shell I dropped earlier, as my kernel doesnt like localroots and panics!)












So. Got root. What next? Lets try see does InterSect want to run this time...













It Works! Sadly my battery promptly /quit a moment later but I think you get the idea of what you can do!

LINKS:
BindShell Labs
Intersect 2 - GitHub
Weevely - GoogleCode
Fimap - GoogleCode
And Finally
Insecurety Research

Wednesday, 1 February 2012

Bricked!

Ok, so I did SOMETHING wrong with SVN and broke 2 of my SVN repos. I also seem to have broken several other things on my computer, so its time for the infamous rm -rf and restart.

I will be documenting every thing I change, I am starting with XUbuntu 10.04 and will be turning it into a bit of a pentesting distro. Compiling lots of shit from source, apt-getting lots of other shit, and generally fucking about until it works.

If you are looking for nice information on making your own PT distro, watch this space. I will be logging every last thing I do, from the MetaSploit Install to compiling nmap, and it may be interesting to some of you :)

Seeing as I focus a lot on Wireless and Web App testing you will see a lot of focus on those applications, and on making MSF work from source.

Hope you find it useful and interesting - I will be doing it all over the next few hours :D

Sunday, 29 January 2012

New Linux Local Root Exploit in the wild

Just a quick post, plan to test this in a VM later and make a video for all to see... (if I remember!)

http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c

Very interesting technique!

Play safe...