Bbsxp latest Vulnerability
Vulnerability Date: January 1, July 1, 2005
Affected Version: All bbsxp instances
Vulnerability exploitation:
Check the foreground password injection statement:
Blog. asp? Id = 1% 20 Union % 20 select % ,,1, userpass, username, 1%, 20 from % 20 [user] % 20 where % 20 membercode = 5
Query the password injection statement in the background:
Blog. asp? Id = 1% 20 Union % 20 select % ,,1, adminpassword, username, 1%, 20 from % 20 [user] % 20 where % 20 membercode = 5
First open www.google.com and enter po ...... bbsxp5.15 has a lot of such forums, just click one at a time, so this bbs.yuntea.com is really lucky. This station hasn't been patched yet, and it's just a bit of gas to kill it. The latest bbsxp5.15 Vulnerability
The vulnerability mainly lies in the ability of blog. asp to directly construct database commands
Blog. asp? Id = 1% 20 Union % 20 select % 20top % 201% 201, [adminpassword], 1%, 20 from % 20 [clubconfig]
The md5password of the background administrator is displayed.
The front-end password is also available,
Related animations and software are available on the Internet.
By exploiting this vulnerability, a batch of bbsxp sites are about to fall.
Next we will talk about the tool and prepare the md5password cracking tool.
For MD5 cracking, md5cracker speed enhancement is better than compaction.
1. First Run with 8 or 9 digits. Very fast.
2. If not, run it with lowercase letters. 5-6 bits are better than the limit.
3. No, it means that the password may add a number to the letter, which can be used to touch your luck. You can configure a classic app, for example, 10 Gb,
Run on and for several hours. (Your machine configuration must be very good)
4. No, I suggest you give up. It's so abnormal.
Foreground OK... background password... (Note: you must know the Administrator account)
The default configuration is to directly win the background password...
Run the md5password command on the front-end.
The rest is about to crack MD5.
Now we are starting to work.
It becomes a token.
His password is 7cb2be65eb9f215215a0725a10b6e39e. The front-end password may be the same as the backend password. If there are two encrypted passwords, one is the front-end password, and the other is the back-end password.
Follow the introduction of the above tool to use numbers first,
Breaking === patience, etc.
If you don't mind ~
Come out, password is 82246124, login, his account is wzwu, password82246124, login successful, background login, password82246124, login successful, the following should know, I will not talk much about it, so as not to be scolded by others.
The author of the latest bbsxp5.15 vulnerability is unclear.
74d2710bd75c06a057e842c8ca55c576
Name 'or ''= 'password is' or'' ='
'
In general, ASP systems have similar urls: http://www.xxx.com/xxx.ASP? Id = ××. We only add a single quote to this URL. If the server error message is returned, it means that the program does not filter the single quote signature, in addition, some server configuration information can be obtained from the returned error message. Then access http:/www.xxx.com/xxx.asp? Id = ××
And 1 = 1, http:/www.xxx.com/xx.asp? Id = ×× and
1 = 2. If the returned page is different, the page can be injected.
Bbsxp latest vulnerability simple injection detection universal password