Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
security report 3.1.2
#16
shawn_a: thanks for checking all of it. Very good job! Smile

Now your answers:
- I'm doing a lot of webapplication penetration testing, bug hunting, etc etc, and once uppon a day I found at sourceforge 'GetSimple CMS', when I was looking for 'php mysql cms'.
- next was checking if this version from sourceforge = your-latest-version at this site (get-simple.info).
- next when I confirmed that this is 'latest' once, I've downloaded it, and install on my Ubuntu 12.04 box (with Apache and PHP - if you need version I can check it too, but it was default ubuntu installation).
- next: cache/history/cookies was cleared, firefox was restarted.
- exploit(s) work fine ;P

Let me know if you need more details. Mike has a directly contact to me, so you can also mail me (because, from now to tommorow I'll be offline).

Also: as my post at blog was about 'vulnerability' - let me know when patched version will be available cuz I want to add to post information about your work (as I described it for example for Concrete5 CMS or Joomla, etc etc...)

Cheers,
Jakub o/


(2013-01-11, 00:21:51)shawn_a Wrote: HauntIT, I appreciate your assistance finding anything else.

I would love to know how your test setup got to this state that it is missing the salt.
Was this a fresh install, an upgrade from x -> x, I would like to nail down or at least identify who might be at risk.

Did you wipe your data directories at some point ?

Is this windows, do we have a path slash issue on install.php.

There are many variables and your exploit post does not detail configuration.
Reply


Messages In This Thread
security report 3.1.2 - by shawn_a - 2013-01-10, 04:30:06
RE: SECURITY EXPLOIT 3.1.2 - by n00dles101 - 2013-01-10, 06:34:09
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 06:37:54
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 07:01:33
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 08:15:49
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 09:56:34
RE: SECURITY EXPLOIT 3.1.2 - by Connie - 2013-01-10, 17:27:27
RE: SECURITY EXPLOIT 3.1.2 - by D.O. - 2013-01-10, 18:08:20
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 19:17:26
RE: SECURITY EXPLOIT 3.1.2 - by D.O. - 2013-01-10, 20:11:07
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 21:04:24
RE: SECURITY EXPLOIT 3.1.2 - by Connie - 2013-01-10, 22:01:31
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 22:48:39
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 00:00:50
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 00:21:51
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-11, 01:06:06
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 01:14:43
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 01:38:58
RE: security report 3.1.2 - by shawn_a - 2013-01-11, 06:55:04
RE: security report 3.1.2 - by HauntIT - 2013-01-11, 17:40:42
RE: security report 3.1.2 - by shawn_a - 2013-01-11, 23:10:14
RE: security report 3.1.2 - by n00dles101 - 2013-01-12, 01:05:43
RE: security report 3.1.2 - by shawn_a - 2013-01-12, 02:03:11
RE: security report 3.1.2 - by D.O. - 2013-01-17, 18:55:34
RE: security report 3.1.2 - by n00dles101 - 2013-01-17, 19:39:31
RE: security report 3.1.2 - by D.O. - 2013-01-17, 21:08:04



Users browsing this thread: 1 Guest(s)