Jump to content

Recommended Posts

Well yeah some kids like this old sloppy coded forum so I'll just patch what ever I can until Summer 08 when I estimate when my new forum will be released in PHP 5 OOP.

 

https://sourceforge.net/projects/nevuxab

 

Download, run the installer.php, chmod config.php to 0777 if necessary.

 

Post all the vulns that you find so I can patch.

Link to comment
https://forums.phpfreaks.com/topic/76206-looking-for-someone-to-test-old-forum/
Share on other sites

Banned!

Hacking Logged.

You are attempting to hack this BB you are now logged and banned until further notice!

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/youcade/public_html/nab/classes/template.php

Doesn't actually ban you.

 

http://youcade.net/nab/index.php?act=viewforum&id=1%20UNION%20ALL%20SELECT%20null,null,null,null,null,null,null,null%20FROM%20blah

On Line: 7 In file: /home/youcade/public_html/nab/classes/template.php

CAPTCHA:

The CAPTCHA never changes.

 

Cross Site Scripting:

There is Cross Site Scripting on http://nab.geekrack.net/ip.php if the ip address field contains code.

 

Full Path Disclosure:

http://www.youcade.net/nab/index.php?act=newtopic

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/youcade/public_html/nab/classes/template.php

 

Full Path Disclosure:

http://www.youcade.net/nab/index.php?act=topicshow&id=a

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/youcade/public_html/nab/classes/template.php

 

Full Path Disclosure:

http://www.youcade.net/nab/index.php?act=viewforum

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/youcade/public_html/nab/classes/template.php

 

SQL Error:

http://nab.geekrack.net/index.php?act=viewforum&id=1&p=a

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '-7,7' at line 1

 

User Enumeration:

http://www.youcade.net/~root

 

User Enumeration:

http://www.youcade.net/~youcade

Still can't register. Just says

Your verification characters were incorrect. Please go back and try again. If you can't see the characters, refresh else contact the administrator.

 

 

http://nab.geekrack.net/index.php?act=viewforum&id=4&p='

http://nab.geekrack.net/index.php?act=viewforum&id=4&p=00

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '-7,7' at line 1

 

http://nab.geekrack.net/index.php?act=viewforum&id=b

Banned!

Hacking Logged.

You are attempting to hack this BB you are now logged and banned until further notice!

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/nab/public_html/classes/template.php

Still can't register. Just says

 

I can reg fine O-o..

 

Banned!

Hacking Logged.

You are attempting to hack this BB you are now logged and banned until further notice!

The file "/templates/footer.tpl" doesn't exist.

On Line: 7 In file: /home/nab/public_html/classes/template.php

 

Forgot to remove that error.

 

 

User Enumeration:

http://www.youcade.net/~root

 

User Enumeration:

http://www.youcade.net/~youcade

 

What exactly is user enumeration?  because all sites does that for me...

oh snap rofl.. that was test code :D.

 

<?php
if(!isset($_POST['p']))
{
	echo
	("
		<form method='post' action=''>
			<textarea name='ip'></textarea><br />
			<input type='submit' name='p' value='Ban IPs' />
		</form>
	");
}
else
{
	$ips = split("\n",$_POST['ip']);
	foreach($ips as $ip)
	{
		echo "$ip <br />";
	}
}
?>

This was in a file.

 

Domain: nab.geekrack.net

| Ip: 74.53.139.226 

| HasCgi: y

| UserName: removed

| PassWord: removed

| CpanelMod: x3

| HomeRoot: /home

| Quota: 100 Meg

| NameServer1: srv1.geekrack.net

| NameServer2: srv2.geekrack.net

| NameServer3:

| NameServer4:

| Contact Email: scheols@gmail.com

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.