<<< Date Index >>>     <<< Thread Index >>>

TowerBlog <= 0.6 Admin Account View [x0n3-h4ck]



-=[--------------------ADVISORY-------------------]=-
-=[
      ]=-
-=[               TowerBlog <= 0.6                                   ]=-
-=[
      ]=-
-=[  Author: CorryL        x0n3-h4ck.org                       ]=-
-=[
      ]=-
-=[-----------------------------------------------------]=-


-=[+] Application:    TowerBlog
-=[+] Version:        0.6
-=[+] Vendor's URL:   http://tower.hybryd.org/?x=home
-=[+] Platform:       Windows\Linux\Unix
-=[+] Bug type:       view admin account
-=[+] Exploitation:   Remote/Local
-=[-]
-=[+] Author:         CorryL  ~ corryl80[at]gmail[dot]com ~
-=[+] Reference:      www.x0n3-h4ck.org ~ irc.xoned.net #x0n3-h4ck


..::[ Descriprion ]::..

TowerBlog is, in short, a single user web-log (or web journal if you will)
content management system, aka CMS.
While there are many others out there
(MovableType and GreyMatter as linked amongst the others)
none quite filled my own personal needs and desires.
Mind you, this isn't meant to be an insult to the other CMS' out there,
I myself used both MovableType and GreyMatter extensively for some time,
however no system I could find was as powerful as I needed, nor as easily
expanded.
The only one that came close, was PHPNuke, but it was too bulky and bloated
for my needs.




..::[ Bug ]::..

this application and' he/she cuts to a type of bug that would allow to an
attacker
to come in possession of very precious information as user and admin pass.
This and' caused because' the data related to the admin acount are saved in
a text file,
that and' easily visible on the browser.


..::[ Proof Of Concept ]::..

http://host/path of blog/_dat/login

189bbbb00c5f1fb7fba9ad9285f193d1      << UserName Admin
81dc9bdb52d04dc20036dbd8313ed055      << Password Admin


the result I am the relative users and admin password in md5,
the first one corresponds to the user, the second to the password




..::[ Disclousure Timeline ]::..

[10/04/2005] - Vendor notification
[10/04/2005] - Vendor Response
[10/04/2005] - Public disclousure

CorryL
corryl80@xxxxxxxxx
www.x0n3-h4ck.org
Italian Security Team
Fax (+39) 02700520894
Tel (+39) 06452215277
irc.xoned.net #x0n3-h4ck

_________________________________
www.seekstat.it is your web stat