Pwn them for Learn





Hello guys! This days i'm not much active because of college life :( but this weekend i got enough time to write about one of my Finding on a
private site :-) from which i was able to get a Remote code execution on the server :) 

Site : B*******.com
Description : Bitcoin sell and buy site 
Bug : Remote Code Execution

Ok lets start! first of all the site login system was fully different they send you "Access Code"(An 7 digit code) on the registered email whenever u want to login and it was working on Cloudflare. 

Playing around uploader : 

After login there was a page to upload documents which includes ID proof upload which have unrestricted file upload but whenever i upload php and open it, it was getting downloaded, then i started messing around uploader and giving some unsuitable characters given me server error which leaked server full path, upload script path, and server type (nginx).





Lets Read some files : 

The thing i noticed is anyfile.js was script and node-modules and things like was there (Zero knowledge in node.js) two thing was confirmed  Ngnix - Node.js, but why php wasn't executing cause HTML was executed which means stored XSS but i was looking for RCE, now one thing i was missing that nginx some times have problem with uploader so i did ../../a.php in filename which uploaded the  a.php in root directory of site, but it was still not executing :/ means php was not configured on nodejs, as i said anyfile.js and its path was there in debug message so i opened it and i was fully shocked :O it was node.js file with Mysql login(root user :D ), SMTP mail login(gmail, the same email which sends "Access code" which means we do account takeover from here) and publicly accessible ;)




Lets shell :

Doing some more work i was able to read many files which means i got Arbitary source code read, now as i said cloudflare, Real IP was not available to me, so i started getting its IP which landed me to Email headers which leaked me Server IP, ok but the mysql port 3306 was closed(may be its only up on 127.0.0.1 not on 0.0.0.0) (the same port was configured in anyfile.js) so i started finding another port on the same ip which given me 2 ports, ip:7788 and ip:8899, ip:8899 was clone of site, while ip:7788 have api documentations so by doing some work on ip:7788 one i got its full path which was /home/*user*/php/application/file.php :D  damn php was configured here now i gone back to port 8899 which was clone of site and used ../../../user/php/a.php and checked it on ip:7788/a.php and bhoom php executed :D 




./My reaction : Lets get into it xD but as Whitehat i can't, it will violate program's policy




./Root cause : 
Uploader miss configured in 2 ways -> allowed php and directory change (most probably cause of nginx) --- --- --- Eq. 1 
Leak of full path of a server which had php installed. -- --- --- Eq. 2

By Combining Eq1 and Eq2 ; Eq1 + Eq2 = RCE

./Game Over
./Bounty awarded
./Special Thanks to Waleed, Rahul Maini, Daniel;

26 comments:

  1. YoBit lets you to claim FREE CRYPTO-COINS from over 100 unique crypto-currencies, you complete a captcha one time and claim as many as coins you want from the available offers.

    After you make about 20-30 claims, you complete the captcha and keep claiming.

    You can press claim as many times as 50 times per one captcha.

    The coins will stored in your account, and you can exchange them to Bitcoins or Dollars.

    ReplyDelete
    Replies
    1. I'm a professional in all kinds of hacking services, which leads me into giving out a blank ATM card to all individuals & serious minded people only. I hack, clone ATM cards worth's the total sum of $500,000.00 United States Dollars, with this card you can withdraw the sum of $3500 as daily limit till you cash out the sum total said sum & this cards has been cloned & hacked in the manner that you'll never be caught not detected during usage. For more info, kindly email us: fastatmhackers@gmail.com OR Call/WhatsApp: +16626183756



      Delete
    2. Haven't you heard about global hacking company blank ATM card and how other people had benefited from it? I am Williams vivian by name, i want to share a blog and forums on how to get real blank ATM card,thank to global hacking company who helped me with an already hacked ATM CARD and i was so poor without funds that i got frustrated. One morning as i was browsing on the internet, i saw different comments of people testifying of how global hacking company helped him from being poor to a rich man through this already hacked ATM CARD. I was skeptical if this was true, i decided to contact him to know if he is real he proved to me beyond all doubts that its was really for real so i urgently receive my blank ATM card. Contact his email globalhackingcompany@gmail.com or WhatsApp +1(929)390-8581 and today am also testifying on how global hacking company helped me. I never believed in it until the card was sent to me, which am using today Contact the company now and become rich. Email: globalhackingcompany@gmail.com or WhatsApp +1(929)390-8581 ....

      Delete
    3. Sell dumps with pin CA/UK/JANPAN/CA/USA/CHINA and many different countries
      100% GUARANTEE - DUMPS * FOR SALE - Dumps 101 + 201 - Valid Rate 98%
      - I SALES DUMPS / Track1+Track2+Track3+***.. - 1st Hand Dumps . - Daily Update .
      - Fast automatic payment methods . - I checking balance cards over $3500 .
      - Discount System for favourite clients is very loyal.
      - Refund in 1-3 hours if dumps is dead or invalid - Replace lost/stolen/hold/card error/call.
      - Quality Services . Quality Dumps Shop . - Support 24/7 . *** Demo Dumps CHINA , USA , UK , CA , CHILE :
      Good balance of cc 3500k
      ------------------------
      - Us
      - Uk
      - Ca
      -Au
      - Eu
      - spain
      And many more

      List fullz
      ----------------------------------
      - Italy
      - Spain
      - Denmark
      - Sweden
      - France
      - Germany
      - Ireland
      - Mexico
      - Asia

      ___________ Dumps track 1 track 2 with pin ___________

      - Dumps,Tracks 1&2 Us
      - Dumps,Tracks 1&2 Uk
      - Dumps,Tracks 1&2 Ca
      - Dumps,Tracks 1&2 Au
      - Dumps,Tracks 1&2 Eu
      ---------------------------------------
      dumps without pin
      ------------------------------
      - Dumps, Us
      - Dumps,Uk
      - Dumps, Ca
      - Dumps, Au
      - Dumps, Eu
      ----------------------------------
      Price For PayPal
      1000$=100$
      2000$=200$
      3000$=300$
      4000$=400$
      5000$=500$
      100$=10$
      200$=20$
      300$=30$
      400$=40$
      500$=50$

      WESTERN UNION Rates:

      1000$=100$
      2000$=200$
      3000$=300$
      4000$=400$
      5000$=500$
      100$=10$
      200$=20$
      300$=30$
      400$=40$
      500$=50$

      contact me now and lets get business done .

      bobbdyfred@gmail.com

      Delete
  2. Hack and take money directly from any ATM Machine Vault with the use of ATM Programmed Card which runs in automatic mode. email (hydracards63@gmail.com) for how to get it and it cost,and how to also hack credit cards and send the money to your self,we are located around the world, these cards works on any ATM machine and it works according to it's activation.

    ………. EXPLANATION OF HOW THESE CARD WORKS……….

    You just slot in these card into any ATM Machine and it will automatically bring up a MENU of 1st VAULT #1,000, 2nd VAULT #5,000, RE-PROGRAMMED, EXIT, CANCEL. Just click on either of the VAULTS, and it will take you to another SUB-MENU of ALL, OTHERS, EXIT, CANCEL. Just click on others and type in the amount you wish to withdraw from the ATM and you have it cashed instantly… Done.

    ***NOTE: DON’T EVER MAKE THE MISTAKE OF CLICKING THE “ALL” OPTION. BECAUSE IT WILL TAKE OUT ALL THE AMOUNT OF THE SELECTED VAULT. To get the card email (hydracards63@gmail.com)

    ReplyDelete
  3. On Moon Bitcoin you can claim FREE satoshis. 514 satoshis per day.

    ReplyDelete
  4. If you are looking to buy bitcoins online, Paxful is the ultimate source for bitcoins as it allows buying bitcoins by 100's of payment methods, such as MoneyGram, Western Union, PayPal, Credit Cards and even converting your gift cards for bitcoins.

    ReplyDelete
  5. Are you tired of searching for bitcoin faucets?
    Triple your claiming speed with this advanced BITCOIN FAUCET ROTATOR.

    ReplyDelete
  6. I'm a professional in all kinds of hacking services, which leads me into giving out a blank ATM card to all individuals & serious minded people only. I hack, clone ATM cards worth's the total sum of $500,000.00 United States Dollars, with this card you can withdraw the sum of $3500 as daily limit till you cash out the sum total said sum & this cards has been cloned & hacked in the manner that you'll never be caught not detected during usage. For more info, kindly email us: fastatmhackers@gmail.com OR Call/WhatsApp: +16626183756



    ReplyDelete
  7. Are you in need of quick and urgent loan with relatively low interest rate as low as 6%? We offer business loans, personal loans, home loans, auto loans,student loans, debt consolidation loans e.t.c. no matter your credit score. We are guaranteed in giving out financial services to our numerous clients all over world. With our flexible lending packages, loans can be processed and transferred to the borrower within the shortest time possible, contact our specialist for advice and finance planning.contact us via Email: sunloans.apply@gmail.com or sunloans.apply24@outlook.com and witness a life changing financial experience.

    ReplyDelete
  8. Haven't you heard about global hacking company blank ATM card and how other people had benefited from it? I am Williams vivian by name, i want to share a blog and forums on how to get real blank ATM card,thank to global hacking company who helped me with an already hacked ATM CARD and i was so poor without funds that i got frustrated. One morning as i was browsing on the internet, i saw different comments of people testifying of how global hacking company helped him from being poor to a rich man through this already hacked ATM CARD. I was skeptical if this was true, i decided to contact him to know if he is real he proved to me beyond all doubts that its was really for real so i urgently receive my blank ATM card. Contact his email globalhackingcompany@gmail.com or WhatsApp +1(929)390-8581 and today am also testifying on how global hacking company helped me. I never believed in it until the card was sent to me, which am using today Contact the company now and become rich. Email: globalhackingcompany@gmail.com or WhatsApp +1(929)390-8581 ....

    ReplyDelete
  9. Sell dumps with pin CA/UK/JANPAN/CA/USA/CHINA and many different countries
    100% GUARANTEE - DUMPS * FOR SALE - Dumps 101 + 201 - Valid Rate 98%
    - I SALES DUMPS / Track1+Track2+Track3+***.. - 1st Hand Dumps . - Daily Update .
    - Fast automatic payment methods . - I checking balance cards over $3500 .
    - Discount System for favourite clients is very loyal.
    - Refund in 1-3 hours if dumps is dead or invalid - Replace lost/stolen/hold/card error/call.
    - Quality Services . Quality Dumps Shop . - Support 24/7 . *** Demo Dumps CHINA , USA , UK , CA , CHILE :
    Good balance of cc 3500k
    ------------------------
    - Us
    - Uk
    - Ca
    -Au
    - Eu
    - spain
    And many more

    List fullz
    ----------------------------------
    - Italy
    - Spain
    - Denmark
    - Sweden
    - France
    - Germany
    - Ireland
    - Mexico
    - Asia

    ___________ Dumps track 1 track 2 with pin ___________

    - Dumps,Tracks 1&2 Us
    - Dumps,Tracks 1&2 Uk
    - Dumps,Tracks 1&2 Ca
    - Dumps,Tracks 1&2 Au
    - Dumps,Tracks 1&2 Eu
    ---------------------------------------
    dumps without pin
    ------------------------------
    - Dumps, Us
    - Dumps,Uk
    - Dumps, Ca
    - Dumps, Au
    - Dumps, Eu
    ----------------------------------
    Price For PayPal
    1000$=100$
    2000$=200$
    3000$=300$
    4000$=400$
    5000$=500$
    100$=10$
    200$=20$
    300$=30$
    400$=40$
    500$=50$

    WESTERN UNION Rates:

    1000$=100$
    2000$=200$
    3000$=300$
    4000$=400$
    5000$=500$
    100$=10$
    200$=20$
    300$=30$
    400$=40$
    500$=50$

    contact me now and lets get business done .

    bobbdyfred@gmail.com

    ReplyDelete

Powered by Blogger.