Jump to content

Bigojey

Members
  • Posts

    26
  • Joined

  • Last visited

    Never

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

Bigojey's Achievements

Newbie

Newbie (1/14)

10

Reputation

  1. Microsoft Security Bulletin List With some public exploits with source code and executables try it get in...jav.ch greetz
  2. nice mersi ghici
  3. yes thank you very much anonim
  4. wow thank you very much m8... nice work
  5. <div class='quotetop'>QUOTE("Xavier")</div> pls in english german or espanol i hope it isnt such negativsentence
  6. i got this exploit from a friend. his name is Mustafa Can Bjorn but everybody knows him as nukedx ps: i dont know if this exploit was given before so dont be angry pls if you already know this exploit here's the exploit : Vendor: MKPortal (http://www.mkportal.it/) Version: 1.1 RC1 and prior versions must be affected. (Runs on vBulletin!) About: Via this methods remote attacker can inject arbitrary SQL queries to ind parameter in index.php of MKPortal. Vulnerable code can be found in the file mkportal/include/VB/vb_board_functions.php at line 35-37, as you can see it easy to by pass this SQL update function. Also there is cross-site scripting vulnerability in pm_popup.php the parameters u1,m1,m2,m3,m4 did not sanitized properly. Level: Critical --- How&Example: SQL Injection : GET -> http://[victim]/[mkportaldir]/index.php?ind= EXAMPLE -> [url]http://[victim]/[/url][mkportaldir]/index.php?ind=',userid='1 So with this example remote attacker updates his session's userid to 1 and after refreshing the page he can logs as userid 1. XSS: GET -> [url]http://[victim]/[/url][mkportaldir]/includes/pm_popup.php?u1=[XSS]&m1=[XSS]&m2=[XSS]&m3=[XSS]&m4=[XSS] --- Timeline: * 21/04/2006: Vulnerability found. * 21/04/2006: Contacted with vendor and waiting reply. --- Exploit: http://www.nukedx.com/?getxpl=26 --- Dorks: "MKPortal 1.1 RC1" --- Original advisory can be found at: http://www.nukedx.com/?viewdoc=26
  7. <div class='quotetop'>QUOTE("Alex")</div> Alex m8 ive already found one but thx... but i will not flame now we are all brothers xD
  8. thx m8! but the page is down i think look @ the pic KLICK FOR THE PIC
  9. thx for the tutorial nos could you pls post the url to the decoder ???
  10. Bigojey

    Shell !

    very cool. n1 thank you very much . everybody needs these shells
  11. Yeah i saw it after downloading and opening it. Very useful! Thx again
  12. i dont know what it is but i will download and look thx for sharing
  13. i have looked for a crack but i am not sure if it will work. my sockscap32.exe is the 2.38 version but i've found only crackz for the 2.37 <= versions i will upload some crackz i hope it will work if you test it. but pls check the crackz with your av! http://rapidshare.de/files/24296638/crackz.rar.html greetz
  14. yes : P thank you i hope the other users like it ,too. greetz
×
×
  • Create New...