Tampilkan postingan dengan label Deface. Tampilkan semua postingan
Tampilkan postingan dengan label Deface. Tampilkan semua postingan

SQL Injection - Bypass WAF

OK, so I showed you how to perform some basic SQLi previously, but there will be times that it starts off working and then you find yourself facing a FORBIDDEN page (403 Error) or Not Acceptable. Typically you can find the vulnerable page, find the column count and then when you switch to use the UNION SELECT statement you get the errors starting up. This is typically due to the server side rules that are filtering out your request. This is often referred to as the Web Application Firewall or WAF, but don’t worry as there are ways we can beat them. You can get pretty creative with the methods used but for now I will show how to use comments to bypass the filters, sometimes referred to as inline comments or C comments.

SQL Injection - Using Double Query Injection

Double Query
Works exactly the same as error based injection but, the Error Based Query will be doubled as a single query statement. 
So that we again successfully get an error message.


Determine when we should use error or double query Injection.

you switch over to union select statements the page then returns an error saying something like:

Case 1:
The Used Select Statements Have  Different Number Of Columns.
Case 2:
Unknown column 1;
Case 3:
Nothing returns at all. And you can't find the columns on the web content.
Then you can also use error based Injection.

SQL Injection - Error Based

Error Based

By injecting a specific query, i will show you this later in the tutorial. We get an error message returning in the page.
This msg actually gives us sensitive database information. That's why we call this error based SQL injection.


Determine when we should use error or double query Injection.


you switch over to union select statements the page then returns an error saying something like:


Case 1:

The Used Select Statements Have  Different Number Of Columns.
Case 2:
Unknown column 1;
Case 3:
Nothing returns at all. And you can't find the columns on the web content.
Then you can also use error based Injection.


MyBB Ajaxfs SQL Injection

########################################################
# Exploit Title            : Mybb Ajaxfs Plugin Sql Injection vulnerability
# Author                     : Iranian Exploit DataBase
# Discovered By       : IeDb
# Software Link        : http://mods.mybb.com/download/ajax-forum-stat-v-2
# Security Risk         : High
# Tested on               : Linux
# Dork                        : inurl:ajaxfs.php
########################################################

WordPress Pretty Photo Cross Site Scripting

Details
+++++++++++++++++++++++++++++++++++++++++++++
Product               : PrettyPhoto Plugin
Security-Risk      : Moderate
Remote-Exploit  : yes
Company            : RHAINFOSEC
Website               : http://services.rafayhackingarticles.net
Vendor-URL       : https://github.com/scaron/prettyphoto
Vendor-Status    : informed
Advisory-Status  : published

WordPress iThemes2 Shell Upload

############################################################
#Title                : Wordpress iThemes2 Themes Arbitrary File Upload
#Author            : DevilScreaM
#Date               : 11/20/2013 - 20 November 2013
#Category        : Web Applications
#Type               : PHP
#Vendor           : http://themify.me/
#Link                 : http://themify.me/themes/ithemes2
#Greetz             : 0day-id.com | newbie-security.or.id | Borneo Security | Indonesian Security
                             Indonesian Hacker | Indonesian Exploiter | Indonesian Cyber | Indonesian Coder
#Thanks           : ShadoWNamE | gruberr0r | Win32Conficker | Xrwrr | Rec0ded |
#Tested            : Mozila, Chrome, Opera -> Windows & Linux
#Vulnerabillity  : Arbitrary File Upload
############################################################

WordPress Suco Shell Upload

##############################################################
#Title               : Wordpress Suco Themes Arbitrary File Upload
#Author           : DevilScreaM
#Date              : 11/20/2013 - 20 November 2013
#Category      : Web Applications
#Type              : PHP
#Vendor          : http://themify.me/
#Link               : http://themify.me/themes/suco
#Greetz           : 0day-id.com | newbie-security.or.id | Borneo Security | Indonesian Security
                           Indonesian Hacker | Indonesian Exploiter | Indonesian Cyber | Indonesian Coder
#Thanks          : ShadoWNamE | gruberr0r | Win32Conficker | Xrwrr | Rec0ded |
#Tested          : Mozila, Chrome, Opera -> Windows & Linux
#Vulnerabillity : Arbitrary File Upload
################################################################

phpliteadmin <= 1.9.3 Remote PHP Code Injection Vulnerability Exploit

#########################################################
# Exploit Title               : phpliteadmin <= 1.9.3 Remote PHP Code Injection Vulnerability
# Google Dork             : inurl:phpliteadmin.php (Default PW: admin)
# Vendor Status          : Informed
# Version                     : 1.9.3
# Tested on                  : Windows and Linux
######################################################### 

PayPal Billsafe Cross Site Scripting

Document Title:
+++++++++++++++++++++++++++++++++++++++++
PayPal Inc Bug Bounty #42 - Persistent POST Inject Vulnerability

References (Source):
+++++++++++++++++++++++++++++++++++++++++
http://www.vulnerability-lab.com/get_content.php?id=801

PayPal Security UID: kxy1ea5ech

Release Date:
+++++++++++++++++++++++++++++++++++++++++
2013-11-18

Vulnerability Laboratory ID (VL-ID):
+++++++++++++++++++++++++++++++++++++++++
801

Common Vulnerability Scoring System:
+++++++++++++++++++++++++++++++++++++++++
3.5

Ruckus Wireless Zoneflex 2942 Wireless Access Point Vulnerable to Authentication Bypass

###########################################################
# Exploit Title      : Ruckus Wireless Zoneflex 2942 Wireless Access Point vulnerable to Authentication bypass
# Date                  : 10/10/2013
# Exploit Author   : myexploit
# Homepage       : http://www.ruckuswireless.com/
# Version             : 2942 Wireless Access Point version 9.6.0.0.267
# CVE                  : CVE-2013-5030
###########################################################

Optomise System Ltd XSS / Information Disclosure

OPTOMISE SYSTEM Ltd (UK Ministry of Defence and emergency services) Full Directory Information Disclosure/ Persistent
XSS /

Time Line Vulnerability************************
04-11-2013 Security Advisory
07-11-2013 Ask About the Issues -> Not Reponse
14-11-2013 Ask About the Issues-> Not Response -> Not Fixed
18-11-2013 Full Disclosure

TinyMCE v3.2.x <= (AuthBypass/ShellUpload) Multiple Vulnerabilites

########################################################
# Exploit Title  : TinyMCE v3.2.x <= (AuthBypass/ShellUpload) Multiple Vulnerabilites
# Author          : KedAns-Dz
# Platform       : PHP / WebApp
# Cat/Tag       : Shell / File Upload , Auth Bypassing , Multiple
# TinyMCE v3.2.7 or ..X is suffer from Multiple vuln's / bug :p
# Remote Attacker can bypassin auth and upload files , shell's etc...
# 1st try with this dork :
# google dork : allinurl:/plugins/imagemanager/pages/im/index.html
########################################################

WP Front-End Repository Manager Arbitrary File Upload Vulnerability

#############################################################
#Exploit Title                   : WP Front-End Repository Manager Arbitrary File Upload Vulnerability
# Author                           : DaOne aka MockingBird
# Vendor Homepage     : http://wordpress.org/plugins/wp-front-end-repository/
# Download link              : http://downloads.wordpress.org/plugin/wp-front-end-repository.1.1.zip
# Version                         : 1.1
# Category                       : webapps/php
# Google dork                 : inurl:wp-content/plugins/wp-front-end-repository

#############################################################

WordPress Project 10 Themes Remote File Upload Vulnerability

###############################################################
# Exploit Title               : WordPress Project 10 Themes - Remote File Upload Vulnerability
# Author                        : Byakuya
# Date                           : 11/18/2013
# Vendor Homepage  : http://themeforest.net/
# Themes Link             : http://themeforest.net/item/project-10-magazine-theme/2513938
# Affected Version       : v1.0
# Infected File               : upload-handler.php
# Category                    : webapps/php
# Google dork               : inurl:/wp-content/themes/project10-theme/
# Tested on                   : Windows/Linux
###############################################################

WordPress Tweet Blender 4.0.1 CSS

Advisory ID                         : HTB23180
Product                               : Tweet Blender Wordpress Plugin
Vendor                                : kirilln
Vulnerable Version(s)       : 4.0.1 and probably prior
Tested Version                  : 4.0.1
Advisory Publication         : October 25, 2013  [without technical details]
Vendor Notification           : October 25, 2013 
Vendor Patch                     : November 13, 2013 
Public Disclosure              : November 15, 2013 
Vulnerability Type              : Cross-Site Scripting [CWE-79]
CVE Reference                 : CVE-2013-6342
Risk Level                           : Low 
CVSSv2 Base Score        : 2.6 (AV:N/AC:H/Au:N/C:N/I:P/A:N)
Solution Status                   : Fixed by Vendor
Discovered and Provided : High-Tech Bridge Security Research Lab ( https://www.htbridge.com/advisory/ ) 

Facebook Open Redirection

# Exploit Title: Facebook URL open Redirection
# Date: 05/11/2013 - 01/01/1435
# Exploit Author: The Black Devils " Asesino04"
# Vendor Homepage: http://www.facebook.com/      
# Tested on: Mozilla firefox

Type of Hash

1 . DES ( Unix )
[ + ] Used in Linux and the like .
[ + ] Length : 13 Characters .
[ + ] Description : The first two characters are the salt ( random characters , in our example the salt is string "Iv.") Followed by the hash .
[ + ] Example : IvS7aeT4NzQPM

2 . Domain Cached Credentials
[ + ] Used to cache the windows domain passwords .
[ + ] Length : 16 bytes (32 characters)
[ + ] Algorithm : MD4(MD4(Unicode($pass)). Unicode(strtolower($username)))
[ + ] Example : Admin : b474d48cdfc4974d86ef4d24904cdd91

Cookie Logger Script - for Silently Stealing Website Cookies


For when you want to steal someone's session cookies but you don't want to raise the alarm!

What/why? Stealing cookies isn't complicated, but sometimes it can be tricky depending on what is filtered from your JS injection. It can be made much harder if your aim is to steal them silently without the person knowing.

Exploiting POST Method XSS Silently


POST HTTP method XSS exploitation without the target filling out a form... SILENTLY

What's POST method XSS?

A cross-site scripting vulnerability that is exploited by sending the input from a form to the vulnerable website via POST HTTP method (so it could be a search box on a site that uses POST not GET).

How does exploitation differ from GET method XSS?
When a GET request is made, the request is sent over HTTP in the form: website.com/search.php?keyword=whatever.

When a POST request is made, the request is sent over HTTP in the form:
website.com/search.php

(the content, e.g keyword=whatever, is sent in the body as part of the HTTP request rather than as part of the URL).

With that in mind, the typical reflected XSS attack can't be sent to the target like normal:

website.com/search.php?keyword="><script>evil-javascript</script> 
With POST method, the user actually has to fill out a form on your evil-site, and usually click "submit" which allows evil-site to then send the user along with the POST request to the target website. The contents of the POST request will contain the javascript payload and end up running. 

How to Shell a Server via Image Upload and Bypass Extension + Real Image Verification


During a website audit, upload forms and other interactive 'user-content' driven facilities are often found to be protected by client side and/or server side security checks. This tutorial presents the methods that can be used to circumvent these security checks. In this case we're specifically considering image uploads that allow JPG files in particular.

Each security measure numbered below will be briefly discussed and paired with an appropriate bypass method, this tutorial aims to provide a complete'ish solution.


[ PLAYGROUND ]

Indonesian Coder || Codenesia || Exploit Database || Exploit ID || HN Community || devilzc0de || Packet Storm || cxsecurity