Unconfigured Ad Widget

Collapse

Anúncio

Collapse
No announcement yet.

[Ajuda] Site Vul?

Collapse
X
 
  • Filter
  • Tempo
  • Show
Clear All
new posts

  • Font Size
    #1

    [Ajuda] Site Vul?

    Bom olá gente primeiramente!.
    Eu consegui pegar a página de admin desse site : aionarena.com.br
    a pagina de admin é : Apenas usuários registrados e ativados podem ver os links., Clique aqui para se cadastrar...
    mas na hora de pegar a senha do admin não consigo gostaria de saber qual a vulnerabilidade dele já tentei explorar mas não consegui..
    Obrigado!
    Similar Threads

  • Font Size
    #2
    a versão do forum e vbulletin 4.1.9 existe exploits que permitem acesso..
    "Respect your efforts, respect yourself. Self-respect leads to self-discipline.
    When you have both firmly under your belt, that's real power."

    Comment


    • Font Size
      #3
      Ok.. Vou dar uma pesquisada aqui...
      Mas se não for muito encomodo poderia me mandar o código deste exploit?

      Comment


      • Font Size
        #4
        Código:
        ########################################################
        #
        # Exploit Title : vBulletin 4.1.10 Sql Injection Vulnerabilitiy
        #
        # Author        : IrIsT.Ir
        #
        # Discovered By : Am!r
        #
        # Home          : http://IrIsT.Ir
        #
        # Software Link : http://vbulletin.com
        #
        # Security Risk : High
        #
        # Version       : All Version
        #
        # Tested on     : GNU/Linux Ubuntu - Windows Server - win7
        #
        # Dork          : "Powered By Vbulletin"
        #
        ########################################################
        #
        #  Expl0iTs :
        #
        #  [TarGeT]/announcement.php?a=&announcementid=[Sql]
        #
        #########################################################
        #
        # Greats : Zarbat.Org - Aria-Security.Com - datacoders.org - black-hg.org
        # 
        #     Security7.ir - AjaxTm.Com - Sepehr-Team.Org And All Iranian Hackers
        #
        #########################################################
        Código:
        # Exploit Title: vBulletin 4.1.7 => 4.1.10 XSS Vulnerability 
        # Google Dork: intitle: powered by vBulletin 4.1.10
        # Date: 20/02/2012
        # Author: .e0f
        # Software Link: [http://www.vbulletin.com/]
        # Version: [4.1.10 Others not tested]
        # Tested on: [BackTrack 5 | BlackBuntu | Windows 7/xp]
        # Contact: [https://twitter.com/#!/e0fx]
        # Home: [http://brutezone.ru]
        # Greetz: Inj3ct0r Exploit DataBase 1337day.com
        # Video: [http://vimeo.com/39049790]
        ######################################################################################################
        Vulnerability:
        1.
        Send New Private Message > 
                                 > 
           Message text > %22%3E%3Cscript%3Ealert('XSS')%3C/script%3E (encode script UTF-8)
        ######################################################################################################
        
        Watch the video: [http://vimeo.com/39049790]
        
        ##########################################################################################
                               4ll 1nformati0n is pr0vid3d f0r ref3rence 0nly!
        ##########################################################################################
        Greetz to: Babka | F1xeR | ga1Do4ok | Dark-x | Moderor | 2FED | 4elovek 
          v1nest | .e0f | ka0z | silver | Saint | x0r | Duman | ugly | Shadow008 | AlphaSky
           * special thanks to: fpteam-cheats.com | brutezone.ru | From Russia with Love....
        ###########################################################################################
        
        
        # 1337day.com [2012-03-24]
        "Respect your efforts, respect yourself. Self-respect leads to self-discipline.
        When you have both firmly under your belt, that's real power."

        Comment


        • Font Size
          #5
          qual a programação do exploit ?..
          Sorry i'm very noob

          Comment


          • Font Size
            #6
            Bom, eu fiz a analise aqui pelo acunetix , e o site está vulneravel a XSS
            /login.php ...
            o login.php está vulneravel, mas como poderei explorar o erro ?
            este será meu primeiro Deface t.t

            Comment


            • Font Size
              #7
              o exploit não esta escrito em nenhuma linguagem de programação, estes mostram locais onde pode ser possível fazer injecção de SQL e XSS
              "Respect your efforts, respect yourself. Self-respect leads to self-discipline.
              When you have both firmly under your belt, that's real power."

              Comment


              • Font Size
                #8
                Nossa. vou ter que estudar e muito , não consegui fazer nada com este exploit .. nossa!

                Comment


                • Font Size
                  #9
                  Postado Originalmente por Pwunkz Ver Post
                  a versão do forum e vbulletin 4.1.9 existe exploits que permitem acesso..
                  e não é o fórum que eu quero é a admin do site..
                  fórum não quero nada kk '

                  Comment

                  X
                  Working...
                  X