Jump to content
scytalevsbijaz

vBulletin 5.x.x exploit

Recommended Posts

Posted

Se poate sa fie posibil nu zic ca nu dar sa fim seriosi facut de 1337Day Team cred ca numai reclama la 1337day si cand mai vad si in spatele titlului 0day si pretul .

Este ca exploitul lui ala The Black Devils 1337day Inj3ct0r Exploit Database : vulnerability : 0day : shellcode by Inj3ct0r Team , firefox Crash Exploit nu e problema pretul dar ca membru din Inj3ct0r team si vinde asa ceva, daca era un user normal nu era problema dar ca membru din Inj3ct0r team, parerea mea este sau a fiecaruia care este pasionat de exploit development si cunoaste materie este simplu sa provoci un firefox Crash problema este sa controlezi exploitul pina la capat nu numai sa provoci Crash.

Concluzie:Toti aproape din Inj3ct0r team castiga bani de pe incepatori surse copiate si modificate si cum am scris mai sus daca permite la un membru din team sa vinda firefox Crash Exploit sint niste jigodi.

Posted

New details

According to Brian Krebs, MacRumors representatives have told him that the attacker hacked a moderator’s account which he used to embed JavaScript code in an announcement. When an administrator loaded the announcement page, a plugin was installed in the background allowing the attackers to execute PHP code.

Arnold Kim, the owner of MacRumors, has noted that the moderator whose account has been compromised had used the same username and password on vBulletin.com as well.

It remains to be seen if the zero-day is real or not. Krebs says some users have already purchased the exploit sold by Inject0r so we’ll probably find out soon enough.

In the meantime, DEF CON, OVH, and Garage4Hackers have disabled their forums as a precaution.

this vuln at the price of $200 in Bitcoins :D

krebsonsecurity.com/wp-content/uploads/2013/11/2btcVbseller.png

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...