what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

towerBlog06.txt

towerBlog06.txt
Posted Apr 18, 2005
Authored by CorryL | Site x0n3-h4ck.org

TowerBlog versions 0.6 and below allows for remote access of the administrative password hash.

tags | advisory, remote
SHA-256 | c0f316cb7aa0bee4f3c9604080646ef61a3da5dddf1f138aa4035337587e7b17

towerBlog06.txt

Change Mirror Download
-=[--------------------ADVISORY-------------------]=-
-=[
]=-
-=[ TowerBlog <= 0.6 ]=-
-=[
]=-
-=[ Author: CorryL x0n3-h4ck.org ]=-
-=[
]=-
-=[-----------------------------------------------------]=-


-=[+] Application: TowerBlog
-=[+] Version: 0.6
-=[+] Vendor's URL: http://tower.hybryd.org/?x=home
-=[+] Platform: Windows\Linux\Unix
-=[+] Bug type: view admin account
-=[+] Exploitation: Remote/Local
-=[-]
-=[+] Author: CorryL ~ corryl80[at]gmail[dot]com ~
-=[+] Reference: www.x0n3-h4ck.org ~ irc.xoned.net #x0n3-h4ck


..::[ Descriprion ]::..

TowerBlog is, in short, a single user web-log (or web journal if you will)
content management system, aka CMS.
While there are many others out there
(MovableType and GreyMatter as linked amongst the others)
none quite filled my own personal needs and desires.
Mind you, this isn't meant to be an insult to the other CMS' out there,
I myself used both MovableType and GreyMatter extensively for some time,
however no system I could find was as powerful as I needed, nor as easily
expanded.
The only one that came close, was PHPNuke, but it was too bulky and bloated
for my needs.




..::[ Bug ]::..

this application and' he/she cuts to a type of bug that would allow to an
attacker
to come in possession of very precious information as user and admin pass.
This and' caused because' the data related to the admin acount are saved in
a text file,
that and' easily visible on the browser.


..::[ Proof Of Concept ]::..

http://host/path of blog/_dat/login

189bbbb00c5f1fb7fba9ad9285f193d1 << UserName Admin
81dc9bdb52d04dc20036dbd8313ed055 << Password Admin


the result I am the relative users and admin password in md5,
the first one corresponds to the user, the second to the password




..::[ Disclousure Timeline ]::..

[10/04/2005] - Vendor notification
[10/04/2005] - Vendor Response
[10/04/2005] - Public disclousure

CorryL
corryl80@gmail.com
www.x0n3-h4ck.org
Italian Security Team
Fax (+39) 02700520894
Tel (+39) 06452215277
irc.xoned.net #x0n3-h4ck

_________________________________
www.seekstat.it is your web stat
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close