Recub Version 1.0

RECUB Features.
1 RC4 Encripted Reverce connect Shell for XP,2k,2003.
2 Bypass Firewalls by starting new instance of Internet explorer and injecting code
 

And Many More
 

Download (Win32 Version)
 

For Unix Version : Click Here

 

Date: 10/12/03
Product : Mambo Open Source 4.0.14 webserver
Vendor : www.mamboserver.com
Discovered By : Chintan Trivedi - chesschintan [at] hotmail.com
Security Focus : http://www.securityfocus.com/archive/1/347137 l

===========================================================
Advisory by Eye On Security Research Group - India www.eos-india.net
===========================================================


 

Product
-------
Mambo Open Source 4.0.14


Vendor
------
http://www.mamboserver.com


Details
-------
Mambo Open Source is the open source Web Content Management System.

Mambo Open Source CMS is used by many websites including the commercial ones.

The function show() in mambo/articles.php file is like

function show ($articles, $database, $dbprefix, $artid, $gid, $db) {

$query = "SELECT title, content, author FROM ".$dbprefix."articles, ".

$dbprefix."categories WHERE artid=$artid AND ".$dbprefix."articles.published=1 AND ".$dbprefix."categories.categoryid=".$dbprefix."articles.catid AND ".$dbprefix.

"categories.access <=$gid";
$result = $database->openConnectionWithReturn($query);

.
.
.
}

There hasn't been any input validation for the variable artid. An attacker can thus

insert his own sql query and get the administrator md5 pass from mod_users table

and use it in cookie to gain admin access to the Mamboo CMS system.

How do I know whether I am vulnerable ?
--------------------------------------------

http://www.sitewithmambo.com/index.php?option=articles&task=viewarticle&artid=

5%20UNION%20somequery

If you get an error message as

Query failed with error: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'UNION somequery AND mos_articles.published=1 AND mos_categories.

means you are vulnerable. An attacker can use "/*" to comment rest of the querry.

------------

Chintan Trivedi - http://www.hackersprogrammers.com
"Eye On Security Research Group India".

------------

 

Cross Site Scripting vulnerability in bb_func_usernfo.php

 

XSS Bug in XOOPS 1.0.5.1

Mambo Open Source 4.0.14 Webserver SQL injection.
Ltrace buffer overrun bug.

 

 

 

 

06.05.2004: Pound <=1.5 remote format string exploit (public version)
 

01.05.2004: X-Chat 1.8.0 - 2.0.8 Remote Exploit

 

06.04.2004: Monit <= 4.2 Basic Authentication - Username overflow remote root exploit

 

28.03.2004: Ethereal 0.10.0-0.10.2 IGAP Dissector Message Overflow Remote Root Exploit

 

02.3.2004: PSO-Proxy 0.9 PoC Remote Exploit