x0rz / EQGRP

Decrypted content of eqgrp-auction-file.tar.xz
4.09k stars 2.07k forks source link

ELIDESKEW #31

Open tosepf opened 7 years ago

tosepf commented 7 years ago

Hi,

Can someone help me, where can i find elideskew.pl script which is used in ELIDESKEW ???

Thanks

doomguy commented 7 years ago

@tosepf My bet is you won't find it, as the file was not released by TheShadowBrokers. However, as stated in the file you mentioned, the elideskew.pl is using a publicly known RCE vulnerability which was fixed in 1.4.8. The funny thing is: there is no RCE mentioned on http://squirrelmail.org/security/ - just an LFI, Maybe they were able to upgrade the LFI to RCE.

If you want this exploit, you need to reverse it yourself. Grab the source for 1.4.7 and 1.4.8, make a diff and try to understand the differences in the code and why they introduced them. From there you might be able to craft a working exploit.

doomguy commented 7 years ago

You could try to combine the information from those two sites to achieve your goal: