2009-12-30 22:24:22 +00:00
|
|
|
##
|
2010-04-30 08:40:19 +00:00
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
2009-12-30 22:24:22 +00:00
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
2012-02-21 01:40:50 +00:00
|
|
|
# web site for more information on licensing and terms of use.
|
|
|
|
# http://metasploit.com/
|
2009-12-30 22:24:22 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
require 'rex/proto/http'
|
|
|
|
require 'msf/core'
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class Metasploit3 < Msf::Auxiliary
|
|
|
|
|
|
|
|
include Msf::Exploit::Remote::HttpClient
|
2012-02-03 21:43:21 +00:00
|
|
|
include Msf::Auxiliary::WmapScanFile
|
2009-12-30 22:24:22 +00:00
|
|
|
include Msf::Auxiliary::Scanner
|
|
|
|
include Msf::Auxiliary::Report
|
|
|
|
|
|
|
|
def initialize(info = {})
|
2010-04-30 08:40:19 +00:00
|
|
|
super(update_info(info,
|
2009-12-30 22:24:22 +00:00
|
|
|
'Name' => 'HTTP Backup File Scanner',
|
|
|
|
'Description' => %q{
|
2010-04-30 08:40:19 +00:00
|
|
|
This module identifies the existence of possible copies
|
2009-12-30 22:24:22 +00:00
|
|
|
of a specific file in a given path.
|
|
|
|
},
|
|
|
|
'Author' => [ 'et [at] cyberspace.org' ],
|
2013-01-03 00:05:45 +00:00
|
|
|
'License' => BSD_LICENSE))
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2009-12-30 22:24:22 +00:00
|
|
|
register_options(
|
|
|
|
[
|
2012-03-18 05:07:27 +00:00
|
|
|
OptString.new('PATH', [ true, "The path/file to identify backups", '/index.asp'])
|
2010-04-30 08:40:19 +00:00
|
|
|
], self.class)
|
|
|
|
|
2009-12-30 22:24:22 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def run_host(ip)
|
|
|
|
bakextensions = [
|
|
|
|
'.backup',
|
|
|
|
'.bak',
|
|
|
|
'.copy',
|
2012-02-20 22:28:19 +00:00
|
|
|
'.copia',
|
2010-04-30 08:40:19 +00:00
|
|
|
'.old',
|
2009-12-30 22:24:22 +00:00
|
|
|
'.orig',
|
|
|
|
'.temp',
|
|
|
|
'.txt',
|
|
|
|
'~'
|
|
|
|
]
|
|
|
|
|
|
|
|
bakextensions.each do |ext|
|
2012-11-08 16:42:48 +00:00
|
|
|
file = normalize_uri(datastore['PATH'])+ext
|
2009-12-30 22:24:22 +00:00
|
|
|
check_for_file(file)
|
|
|
|
end
|
|
|
|
if datastore['PATH'] =~ %r#(.*)(/.+$)#
|
|
|
|
file = $1 + $2.sub('/', '/.') + '.swp'
|
|
|
|
check_for_file(file)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
def check_for_file(file)
|
|
|
|
begin
|
|
|
|
res = send_request_cgi({
|
|
|
|
'uri' => file,
|
|
|
|
'method' => 'GET',
|
|
|
|
'ctype' => 'text/plain'
|
|
|
|
}, 20)
|
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
if (res and res.code >= 200 and res.code < 300)
|
2009-12-30 22:24:22 +00:00
|
|
|
print_status("Found #{wmap_base_url}#{file}")
|
2012-06-06 05:22:36 +00:00
|
|
|
|
2012-02-21 20:13:12 +00:00
|
|
|
report_web_vuln(
|
|
|
|
:host => ip,
|
2009-12-30 22:24:22 +00:00
|
|
|
:port => rport,
|
2012-02-21 20:13:12 +00:00
|
|
|
:vhost => vhost,
|
|
|
|
:ssl => ssl,
|
2012-03-18 01:37:42 +00:00
|
|
|
:path => file,
|
2012-02-21 20:13:12 +00:00
|
|
|
:method => 'GET',
|
|
|
|
:pname => "",
|
|
|
|
:proof => "Res code: #{res.code.to_s}",
|
|
|
|
:risk => 0,
|
|
|
|
:confidence => 100,
|
|
|
|
:category => 'file',
|
|
|
|
:description => 'Backup file found.',
|
|
|
|
:name => 'backup file'
|
2009-12-30 22:24:22 +00:00
|
|
|
)
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2009-12-30 22:24:22 +00:00
|
|
|
else
|
2011-07-15 15:33:35 +00:00
|
|
|
vprint_status("NOT Found #{wmap_base_url}#{file}")
|
2009-12-30 22:24:22 +00:00
|
|
|
#To be removed or just displayed with verbose debugging.
|
|
|
|
end
|
|
|
|
|
|
|
|
rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout
|
2010-04-30 08:40:19 +00:00
|
|
|
rescue ::Timeout::Error, ::Errno::EPIPE
|
2009-12-30 22:24:22 +00:00
|
|
|
end
|
2010-04-30 08:40:19 +00:00
|
|
|
|
|
|
|
|
2009-12-30 22:24:22 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
end
|