lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <003501c53deb$7f897190$0100a8c0@server>
Date: Sun Apr 10 17:37:05 2005
From: corryl at sitoverde.com (CorryL)
Subject: TowerBlog <= 0.6 Admin Account View [x0n3-h4ck]

-=[--------------------ADVISORY-------------------]=-
-=[                                                                         
      ]=-
-=[               TowerBlog <= 0.6                                   ]=-
-=[                                                                         
      ]=-
-=[  Author: CorryL        x0n3-h4ck.org                       ]=-
-=[                                                                         
      ]=-
-=[-----------------------------------------------------]=-


-=[+] Application:    TowerBlog
-=[+] Version:        0.6
-=[+] Vendor's URL:   http://tower.hybryd.org/?x=home
-=[+] Platform:       Windows\Linux\Unix
-=[+] Bug type:       view admin account
-=[+] Exploitation:   Remote/Local
-=[-]
-=[+] Author:         CorryL  ~ corryl80[at]gmail[dot]com ~
-=[+] Reference:      www.x0n3-h4ck.org ~ irc.xoned.net #x0n3-h4ck


..::[ Descriprion ]::..

TowerBlog is, in short, a single user web-log (or web journal if you will)
content management system, aka CMS.
While there are many others out there
(MovableType and GreyMatter as linked amongst the others)
none quite filled my own personal needs and desires.
Mind you, this isn't meant to be an insult to the other CMS' out there,
I myself used both MovableType and GreyMatter extensively for some time,
however no system I could find was as powerful as I needed, nor as easily
expanded.
The only one that came close, was PHPNuke, but it was too bulky and bloated
for my needs.




..::[ Bug ]::..

this application and' he/she cuts to a type of bug that would allow to an
attacker
to come in possession of very precious information as user and admin pass.
This and' caused because' the data related to the admin acount are saved in
a text file,
that and' easily visible on the browser.


..::[ Proof Of Concept ]::..

http://host/path of blog/_dat/login

189bbbb00c5f1fb7fba9ad9285f193d1      << UserName Admin
81dc9bdb52d04dc20036dbd8313ed055      << Password Admin


the result I am the relative users and admin password in md5,
the first one corresponds to the user, the second to the password




..::[ Disclousure Timeline ]::..

[10/04/2005] - Vendor notification
[10/04/2005] - Vendor Response
[10/04/2005] - Public disclousure

CorryL
corryl80@...il.com
www.x0n3-h4ck.org
Italian Security Team
Fax (+39) 02700520894
Tel (+39) 06452215277
irc.xoned.net #x0n3-h4ck

_________________________________
www.seekstat.it is your web stat

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ