what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

alabanza.txt

alabanza.txt
Posted Sep 27, 2000
Authored by Weihan Leow

This hole is for the control panel of all Alabanza based resellers/hosts. There could be more bugs. This is serious enough since you can delete all resold domains for a particulr webhosting company. You can also change the default MX and CNAME records of all associated domains.

tags | exploit
SHA-256 | 53801f2b11521cbfb88f3a244efe6da453e8cf7c77bc1c4480c79b3231bb1fc6

alabanza.txt

Change Mirror Download

Vulnerability: Ability to add/modify domains in name servers of webhosting
companies who are reselling for Alabanza.

Vendor Contacted: Yes, 09-14-99 - Hole still exists.

==========================================================================
Hello everyone, I currently discovered a serious bug in the control
panel that can really bring a webhost to it's knees. This hole is for the
control panel of all Alabanza based resellers/hosts. There could be more
bugs but I did not take the time to find them yet. This is serious enough
since you can delete all resold domains for a particulr webhosting
company. You can also change the default MX and CNAME records of all
associated domains.

By copying the following url to *most* alabanza host resellers, you have
the ability to add a domain to their NS without the control panel user
name and password:

http://www.domain.com/cp/rac/nsManager.cgi?Domain=HAHAHA.org&IP=127.0.0.1&OP=add&Language=english&Submit=Confirm
*The above link has been broken to prevent abuse. If you are an Alabanza
based host/reseller, you can easily fix it*

I have tested this on multiple domains and so far, most of them worked.
You can substitute domain.com for any Alabanza host/reseller domain and
for the domain you want DNS set up for, substitute HAHAHA.org for it. I
also changed the ip to localhost instead of whatever was in there. The ip
you put after IP= is the ip the domain will resolve to.

Here is an example after typing in the above fixed link with a proper
Alabanza domain in the beginning.

Name Server Manager
Domain HAHAHA.org will be added within 1 hour!
Your domain HAHAHA.org 127.0.0.1 will be setup within 1 hour!

Please click here to go back.

After the submission of the domain, you are even given a link to take a
look at the changes to be made. From this page, you can delete as well
as modify all associated domains:

http://www.domain.com/cp/rac/nsManager.cgi?Language=english
*Again, it's been broken*

Again, no user name and password is required.

This is one of the exploits I have currently found in the control panel.
I have not looked further since this notice should make everyone aware of
what potential problems can exist. Serious damage to a host can be caused
through this.

If you would like to get it fixed, you better email the admins at
Alabanza. It's been more than a week since I have contacted them and no
fix yet. Hopefully, this will speed them up.

Weihan Leow

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close