Login Register
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Exploit Development Exercise [Beginner] filter_list
Author
Message
Exploit Development Exercise [Beginner] #1
While bored in school today I came across an advisory on Sucuri for a relatively small wordpress plugin (~90k installs). The plugin allows unauthenticated users to obtain an admin session with only his username - a pretty ridiculous flaw to say the least. Since @Eclipse is always hitting me up for projects, and this vulnerability is as straight forward as it gets, I figured it would make a good exercise for individuals who want to get their feet wet in web app exploit development.

Sucuri Wrote:*Due to the severity we will not provide a Proof of Concept and will be very light on the technical details. Make sure to update asap!
Since Sucuri didn't release an exploit, and there are currently none available on the net atm, you have the perfect opportunity to create your own and practice basic exploit dev skills.

Advisory: http://blog.sucuri.net/2015/03/security-...lugin.html
Download: https://downloads.wordpress.org/plugin/m....0.9.1.zip
Goal: Make a fully functional exploit that achieves php/bash/sh command execution in some way or another.

Below is an example of my exploit for this vulnerability:
Spoiler:
[Image: JYhZCiL.gif]


l33ts, please refrain from shitting on this thread. This is meant to help beginners learn by using real world examples.

Feel free to post below if you need any help or would like my code.

[+] 2 users Like Dyme's post
Reply

RE: Exploit Development Exercise [Beginner] #2
Bookmarked. I'll get onto this when I have time.

Reply

RE: Exploit Development Exercise [Beginner] #3
I enjoy things like this.

When I get home I will probably setup a barebone WP site and make something.

Reply

RE: Exploit Development Exercise [Beginner] #4
Nice thanks a lot for the share m8.

Reply

RE: Exploit Development Exercise [Beginner] #5
*nods in silent approval*
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Exploit Development Exercise [Beginner] #6
*nods approvingly* Nice post all together. Let's hope that people will build on this and improve their skills.

Reply

RE: Exploit Development Exercise [Beginner] #7
Well it's been 10+ days now; deciding to release my exploit code.

http://goo.gl/D2zr3R

Reply

RE: Exploit Development Exercise [Beginner] #8
https://gist.github.com/libeclipse/d1b31...d04d88c505

idk why I couldn't do this last year

[+] 1 user Likes Eclipse's post
Reply

RE: Exploit Development Exercise [Beginner] #9
(05-30-2016, 07:48 PM)Eclipse Wrote: https://gist.github.com/libeclipse/d1b31...d04d88c505

idk why I couldn't do this last year

cause u were skid but now woah nice job thumbs up ????

Reply

RE: Exploit Development Exercise [Beginner] #10
(05-30-2016, 07:48 PM)Eclipse Wrote: https://gist.github.com/libeclipse/d1b31...d04d88c505

idk why I couldn't do this last year

Hey, nice! I remember giving you advice over a year ago on Python with exactly this in mind (see; https://sinister.ly/Thread-Reverence-Pyt...#pid298690)

Glad to see that you actually got somewhere, keep at it.
whoami

Reply







Users browsing this thread: 1 Guest(s)