Failed exploit

Viewing 6 reply threads
  • Author
    Posts
    • #8643
      ccpik
      Participant

      Hi guys,

      I am doing an internal pen test for the company I work at and having a few issues with an exploit. I have identified a vulnerable PHP service running and launched the correct exploit and set all the payload options. The exploit failed so I thought I would check the firewall to see what was happening.

      The firewall recognised the exploit and dropped all packets. I sent the exploit over port 80 which the service was running over. I have heard of encrypting the exploit so the firewall does not recognise the signature but do not know where to start. What is best practice in a situation like this?
       
      Thanks guys for any help

    • #53753
      dynamik
      Participant

      Which exploit are you using? Where did it come from?

      Is the service also running over 443? SSL would probably prevent the firewall from seeing the traffic.

    • #53754
      ccpik
      Participant

      Port 443 is not open but I thought there was a way of encapsulating the exploit to bypass firewall heuristic detection? I am attempting to exploit PHP 5.2 service with the 0P5 license.php remote command execution and the PHP CGI argument injection

    • #53755
      dynamik
      Participant

      I believe you’re thinking of encoding payloads. It really depends on what the firewall is identifying as malicious.

      I assume you’re using Metasploit for this. If it’s identifying the generic HTTP request that Metasploit uses to trigger the exploit, you’re probably going to have to copy that module and make modifications to it in order to make it unique. For example, this is the data used for executing your payload in the OP5 module: data = ‘timestamp=1317050333`’ + payload.encoded + ‘`&action=install&install=Install’;

      The firewall check may simply be looking for timestamp=1317050333 since it would be quite unusual for legitimate users to have that timestamp, but it will always be present when using the MSF module (that value was also used in the original PoC: http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf). You may be able to get around this by simply modifying that value or making other minor changes to the exploit template.

      When you’ve selected the module, you can also issue a “show encoders” command to see what your options are for encoding the payload. You unfortunately have very few options in these two cases since you’re primarily working with text and not actual shellcode. Therefore, you’re not going to be able to use encoders like shikata_ga_nai.

      You can also try setting EnableContextEncoding to true. Additionally, the argument injection module provides advanced payload options for EnableStageEncoding and StageEncoder, which might be useful if you’re using a staged payload and the firewall is actually catching the stage and not the exploit itself.

    • #53756
      ccpik
      Participant

      Excellent. Very informative post and I appreciate that. I’ll take the advice you have given and read up on it and hopefully I’ll get somewhere with my issue 🙂

      Thanks again

    • #53757
      ccpik
      Participant

      Just a quick one –

      I can’t find the timestamp value that needs changing in the exploit code. Is metasploit adding that timestamp to it and therefore I am looking in the wrong place? I was looking in the op5_welcome source code. I have looked online and where the timestamp should be, I have this….

      data = ‘do=do=Login&password=” + payload.encoded + ‘`&action=install&install=Install’;

      How does metasploit insert the timestamp of 1317050333 into the above??

    • #53758
      ccpik1
      Participant

      Please delete above post mods if possible. I have found what I was looking for. Apologies

Viewing 6 reply threads
  • You must be logged in to reply to this topic.

Copyright ©2021 Caendra, Inc.

Contact Us

Thoughts, suggestions, issues? Send us an email, and we'll get back to you.

Sending

Sign in with Caendra

Forgot password?Sign up

Forgot your details?