what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

SMF 2.0 RC5 Shell Upload

SMF 2.0 RC5 Shell Upload
Posted Apr 7, 2011
Authored by KedAns-Dz

SMF version 2.0 RC5 suffers from a shell upload vulnerability.

tags | exploit, shell
SHA-256 | a1f21657fc82224f89166bb64fd9ca7bc1faefc521a9ff441c0acaa998fae69e

SMF 2.0 RC5 Shell Upload

Change Mirror Download
###
# Title : SMF 2.0 RC5 Remote Shell Upload Exploit
# Author : KedAns-Dz
# E-mail : ked-h@hotmail.com
# Home : HMD/AM (30008/04300) - Algeria -(00213555248701)
# Twitter page : twitter.com/kedans
# platform : php
# Impact : Remote Shell Upload
# Tested on : Windows XP sp3 FR
##
# [»] ~ ********* In The name of Allah ************
###

# Go0Gle D0rk : "Powered by SMF 2.0 RC5 "

# Exploit :

You Are Can Upload The Shell in (attachments) Folder from 'SMF 2.0 RC5'

(+) In Any Topic .. Submit New Reply and Upload Shell (*.gif) on Attachment
(+) After Reply .. You Are Can Access to Shell in :
> http://[target/Path]/attachments/{fileID}_{fileHASH}
> The HASH Is encoder by : SHA1
(+) Because the 'SMF 2.0 RC5' Change the Any Attach name Ex :
'1_86e1d5b5ec318635ec9ece9b4586bd8c1d07faca' << This is From Ex file I'm uploaded From My Local SMF
(+) After You Are Detect The SHA HASH .. access in the shell !
Usage : http://127.0.0.1:8888/smf/attachments/1_86e1d5b5ec318635ec9ece9b4586bd8c1d07faca
OR access in this url :
> http://[target/Path]/index.php?action=dlattach;topic={topicID};attach={attach-SHELL-id};image
but this access with URL not succeeding always

# ** In The Peace of Allah **
=================================================================================================
#================[ Exploited By KedAns-Dz * HST-Dz * ]===========================================
# Greets To : [D] HaCkerS-StreeT-Team [Z] < Algerians HaCkerS >
# Islampard * Zaki.Eng * Dr.Ride * Red1One * Badr0 * XoreR * Nor0 FouinY * Hani * Mr.Dak007 * Fox-Dz
# Masimovic * TOnyXED * r0073r (inj3ct0r.com) * TreX (hotturks.org) * KelvinX (kelvinx.net) * Dos-Dz
# Nayla Festa * all (sec4ever.com) Members * PLATEN (Pentesters.ir) * Gamoscu (1923turk.com)
# Greets to All ALGERIANS EXPLO!TER's & DEVELOPER's :=> {{
# Indoushka (Inj3ct0r.com) * [ Ma3sTr0-Dz * MadjiX * BrOx-Dz * JaGo-Dz (sec4ever.com) ] * Dr.0rYX
# Cr3w-DZ * His0k4 * El-Kahina * Dz-Girl * SuNHouSe2 ; All Others && All My Friends . }} ,
# 1337day.com * www.packetstormsecurity.org * exploit-db.com * bugsearch.net * exploit-id.com
# www.metasploit.com * www.securityreason.com * All Security and Exploits Webs ...
#================================================================================================
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close