|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 86
Members: 0
Total: 86
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Hacking Information Request! |
|
Posted: Sat Jan 24, 2009 8:45 pm |
|
|
tekcap |
Beginner |
|
|
Joined: Jan 24, 2009 |
Posts: 3 |
Location: Montreal |
|
|
|
|
|
|
There is this particular forum I visit where members make posts with links to download music releases. The only problem is they use a system that only allows you see the link if you have a certain amount of posts. This is pretty frustrating considering they put such high post requirements to get anything half decent. Now I didn't sign up here to say please hack this site for me because its pathetic to do that. I did a bit of work and found out some things... first by opening the source file on the website I found out they use this "Cascading Style Sheet(CSS 467), for Invision Power Board 2.2.0". Now I searched Invision Power Board and came up with a link and found this very nice piece of information... "The application is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data to the 'name' parameter before using it in an SQL query." They also listed "Invision Power Services Invision Power Board 2.2.0 " on there list of versions that can be exploited! All this is good news but now I have no idea what to do heh. My ultimate goal is to somehow change my post count and download away . Could someone point me in the right direction from here? Maybe tell me if its way out of my league? I have Network+ certification if that helps? |
|
|
|
|
|
|
|
|
Posted: Sat Jan 24, 2009 9:08 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Try suggested test from this thread:
http://www.waraxe.us/ftopict-3293.html
If you get error message, then probably sql injection is possible. There are more exploits for such old IPB version (if it's not patched allready), so just search for exploits (milw0rm and other places) and try them against target.
If you can successfully exploit sql injection vulnerability, then it's possible to fetch admin and user password hashes. In case of successful hash cracking you can log in as admin and do whatever you want, or as alternative you can impersonate some other user, who has more points |
|
|
|
|
|
|
|
|
Posted: Sat Jan 24, 2009 9:16 pm |
|
|
tekcap |
Beginner |
|
|
Joined: Jan 24, 2009 |
Posts: 3 |
Location: Montreal |
|
|
|
|
|
|
Thank you for such a quick response! Very cool
I got this message
Routing Error
No route matches "/forums/index.php" with {:method=>:get}
Good or bad news?
Also just checked the milw0rm site and found nothing for version 2.2
Do you mind sharing some of these other places? |
|
|
|
|
Posted: Sat Jan 24, 2009 11:39 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
You probably used wrong url. So first open target forum's main page - this is base url. Example:
Code: |
http://www.victim.com/forum/
|
Then concatenate needed stuff:
Code: |
http://www.victim.com/forum/?act=xmlout&do=check-display-name&name=%2527
|
For security vulnerabilities listings look at Secunia:
http://secunia.com/advisories/product/3705/?task=advisories |
|
|
|
|
Posted: Sun Jan 25, 2009 4:03 am |
|
|
tekcap |
Beginner |
|
|
Joined: Jan 24, 2009 |
Posts: 3 |
Location: Montreal |
|
|
|
|
|
|
The site has been patched
Thanks for the little lesson though |
|
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|