Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-22-2013, 09:17 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 ... 8 9 10 11 12 ... 15 Next »

Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability

Home General Computer Multimedia Business Lounge

Pages (2): 1 2 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
02-15-2011, 12:16 PM (This post was last modified: 02-15-2011 12:18 PM by supermenganteng.)
Post: #1
supermenganteng Offline
SPA Holic
********
Jendral Team
Posts: 1,961
Joined: Jun 2010
Reputation: -188
Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
Quote:###########################################################################
# Exploit Title: Social Engine 4.x (Music Plugin) Arbitrary File Upload
# Google Dork: inurl:"user/auth/forgot"
# Date: 22/12/2010
# Author: MyDoom ( Moroccan Hacker )
# Contact: MyDoom2009@gmail.com
# Software Link: http://http://www.socialengine.net
# Version: Social Engine 4.x (should work on previous versions but no tested)
# Tested on: Windows 7 - Linux 3.6.33 2010 - Linux 3.6.18 2010 -
Windows Server 2003
# Greetz to : ALBoraaq Hackers ;) - Especially T3es
###########################################################################

Vulnerable Javascript Source Code:

window.addEvent('domready', function() { // wait for the content

...snip...

// remove that line to select all files, or edit it, add more items
typeFilter: {
'Music (*.mp3,*.m4a,*.aac,*.mp4)': '*.mp3; *.m4a; *.aac; *.mp4'
},

Description:

The File filter used in the code don't check the uploaded file but
only set the type of files that can be veiwed in the upload window
so if we type *.* in the filename we will see all others file and
then we can upload any type of file.

Exploit:

[~] Step 1 : Find A social network using the Social Engine with MUSIC PLUGIN

[~] Step 2: Register A Fake Account

[~] Step 3: Click On Music Link in the menu or go to http://www.xxxx.com/music

[~] Step 4: Click On Upload Music And Then Fill the Playlist info

[~] Step 5: Click On Add Music And Select The php file ( If you can
see php file in the upload window type *.* in the file name )

[~] Step 6: And Click on save music to playlist

[~] Step 7: You Will See the Music Player Move the Cursor on the php
filename and copy the link of the shell.

Generaly it will be :
http://www.xxx.com/public/music_song/1000000/[numbers]/[user_id]/[some_numbers].php

ini salah satu waktu ane pas godam 1malaysia.com
sekarang kita kan dah damai ama malaysia jadi jangan ditest lagi ya ngegodam 1malaysia.com kalau seandainya servernya dah up lagi.

shell ane di 1malaysia.com
http://1malaysia.com/public/b374k.php

tapi di 1malaysia.com ada 2 bug yang bisa dimasukin, ne ane share bug yang satu ne dl ya...yang keduanya menyusul.

refrensi
http://www.exploit-db.com/exploits/15830/
Find all posts by this user
Quote this message in a reply
02-15-2011, 12:18 PM
Post: #2
chaer.newbie Offline
--------------------------
*****
Dewa
Posts: 5,275
Joined: Dec 2009
Reputation: 184
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
ga bagus tutorialnya

ngacir
Find all posts by this user
Quote this message in a reply
02-15-2011, 12:23 PM
Post: #3
n0wn Offline
./Devilz Advisor
Posts: 583
Joined: Dec 2010
Reputation: 9
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
waw,,

om2 diatas hacker semua,,

ngacir

piss
Visit this user's website Find all posts by this user
Quote this message in a reply
02-15-2011, 12:42 PM
Post: #4
Matmund Newbie Away
Devilzc0deR Sejati
****
Global Moderators
Posts: 856
Joined: Mar 2010
Reputation: 36
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
(02-15-2011 12:18 PM)chaer.newbie Wrote:  ga bagus tutorialnya

ngacir

Iya gak bagus.. cuma copas doank........ seneng
Visit this user's website Find all posts by this user
Quote this message in a reply
02-15-2011, 12:44 PM
Post: #5
PrOReBeLL Offline
Newbie Yang Mencoba Maju.
Posts: 574
Joined: Jul 2010
Reputation: 26
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
(02-15-2011 12:18 PM)chaer.newbie Wrote:  ga bagus tutorialnya

ngacir
iya nih
ga bagus tutnya..
coba kalo di tambahi bumbu2 Poc ganteng dkit hmm

ente pasti heker ya om ? smangat
Find all posts by this user
Quote this message in a reply
02-15-2011, 12:53 PM
Post: #6
badwolves1986 [RJ] Offline
Staf Registrasi DIC
RJ
Posts: 2,881
Joined: Oct 2010
Reputation: 91
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
wah di atas ane pasti hacker semua nie,....asikasik
Find all posts by this user
Quote this message in a reply
02-15-2011, 12:54 PM
Post: #7
supermenganteng Offline
SPA Holic
********
Jendral Team
Posts: 1,961
Joined: Jun 2010
Reputation: -188
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
gak bagus2 ..langsung pada testing ne dorkny..wkwkkkwkkw
Find all posts by this user
Quote this message in a reply
02-15-2011, 12:55 PM
Post: #8
Matmund Newbie Away
Devilzc0deR Sejati
****
Global Moderators
Posts: 856
Joined: Mar 2010
Reputation: 36
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
(02-15-2011 12:54 PM)supermenganteng Wrote:  gak bagus2 ..langsung pada testing ne dorkny..wkwkkkwkkw

yg ke index ma google dah di bantai smua'a........ =))
Visit this user's website Find all posts by this user
Quote this message in a reply
02-15-2011, 01:15 PM
Post: #9
PrOReBeLL Offline
Newbie Yang Mencoba Maju.
Posts: 574
Joined: Jul 2010
Reputation: 26
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
nah gini om, ane coba test langsung dsni
http://www.onesenegal.com/
nah ane udah daftar, lalu msuk ke directory music
nah dsna ane coba upload dari add music nya
tapi ada warning seperti ini : 404.php {"viewer":{},"viewer_id":68,"status":false,"message":"Invalid file type"}
nah kira2 itu gmna ?

kalau berhasil ane bsa manggil shellnya dmna om ? mohon pencerahan... hehehe
Find all posts by this user
Quote this message in a reply
02-15-2011, 01:31 PM
Post: #10
patriot Offline
Citeureup York
****
Global Moderators
Posts: 602
Joined: Dec 2009
Reputation: 23
RE: Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
klo dagh selesai upload music (shell). Cara memanggil shell yg sudah di pasang...klik tab "my music" aja mas bro. nanti disitu ada list music2 ente. trs cara melihat direktori url penyimpanan tgl klik kanan "View Image Info"

Soktau.com
xixiii....
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (2): 1 2 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] WordPress Exploit (easy-comment-uploads/upload-form.php) XPByte 16 1,034 05-19-2013 05:40 PM
Last Post: oe_c0x
Bug CMS Balitbang - CSRF/XSS Vulnerability nuxbie_cyber 7 350 04-19-2013 09:12 PM
Last Post: paijocode
  WordPress LeagueManager Plugin v3.8 eskiel go.id 12 184 04-01-2013 02:00 PM
Last Post: beg3nk newb1e
Thumbs Up [Tutor] POC + Exploit Wordpress ~ Video Blogging Arbitrary File Upload Regel 11 672 02-02-2013 12:19 AM
Last Post: copaker21
  #DiyWeb Admin Bypass dan Remote file/shell Upload exploit AnonymousOpsID 4 336 11-06-2012 05:07 PM
Last Post: rock_me
Star [Share] Remote PHP Shell Upload Vulnurabillity brianfahmi 9 345 10-27-2012 09:31 AM
Last Post: mariachi
  [Tutor] Sistem Biwes Multiple Vulnerability eidelweiss 10 259 09-01-2012 10:09 AM
Last Post: Super Moderator
  [Tutor] php-tool bwt Upload shell WP-Plugin Radykal Fancy Gallery Regel 9 372 07-07-2012 09:40 AM
Last Post: Regel
Bug CMS Schoolhos - Remote Arbitrary File Upload nuxbie_cyber 10 346 06-28-2012 06:47 PM
Last Post: Loex
Bug CMS DMS-Easy - Multiple Vulnerability nuxbie_cyber 6 165 06-23-2012 09:15 PM
Last Post: chiboga

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-22-2013, 09:17 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE