Description
This module exploits an authenticated insecure file upload and code execution flaw in Ahsay Backup v7.x - v8.1.1.50. To successfully execute the upload, credentials are needed; default Ahsay Backup trial accounts are enabled so an account can be created.
It can be exploited in Windows and Linux environments to get remote code execution (usually as SYSTEM). This module has been tested on Ahsay Backup v8.1.1.50 with Windows 2003 SP2 Server. Because of this flaw all connected clients can be configured to execute a command before the backup starts. Allowing an attacker to takeover even more systems and make it rain shells!
Setting the CREATEACCOUNT to true will create a new account, this is enabled by default. If credeantials are known enter these and run the exploit.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/misc/ahsay/backup_fileuploadmsf undefined(backup_fileupload) > show actions ...actions...msf undefined(backup_fileupload) > set ACTION < action-name >msf undefined(backup_fileupload) > show options ...show and set options...msf undefined(backup_fileupload) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub