LOGiN PANeL



«    August 2007    »
MoTuWeThFrSaSu
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
 
PoLL

Yes
Yes


NAViGATiON
CMS WAP Chat Blog Clones Exploits Modules Tutorials Counters Top Sites Education Templates Multimedia Guestbooks Web Search E-Commerce Forum Boards Hosting Scripts Free Templates Image Galleries Support System Ad Management WYSIWYG Editors Banner Exchange SCRiPTMAFiA.ORG
ADVERTiSiNG
Newware | Design share
TOP 10
FRiENDS
Astalavista.com – the IT News & Security community Free Video Tutorial Nulled.org Software GxIso.com WarezUN SeoMafia mp3 games pda free flash banner maker logo maker
RSS
LaST oN NULLeD.org
AVG Internet Security 2012 Build 2176a4990 (x86) AVG Internet Security 2012 Build 2176a4990 (x86) | 145 MB Get complete protection from the most ...
Emma Hewitt - Burn The Sky Down (2012) Emma Hewitt - Burn The Sky Down (2012) 13 Tracks | Release: 2012 | MP3 320kbps | 44.1 Khz | ...
MusicLab RealGuitar 2.3L x86/x64 (Repost) MusicLab RealGuitar 2.3L x86/x64 | 186 MB If you are serious about creating truly realistic ...
CyberLink Media Suite 10.0.0.1529 Ultra Retail CyberLink Media Suite 10.0.0.1529 Ultra Retail | 1.71 GB CyberLink Media Suite is designed to give ...
Transform Windows 7 To Mac OS X Lion 10.7 (x86/x64) Transform Windows 7 To Mac OS X Lion 10.7 (x86/x64) OS : Windows 7 | Year : 2012 | 143 MB


Fair pricing servers - No bullshit promise

Last questions on ask.SCRiPTMAFiA.ORG

Looking Tarnished style version 2.1
Does anyone have a style Tarnished version 2.1 http://themeforest.net/item/tarnished-modern-grunge-wordpress-theme/162472?ref=GhostPool is at 1.5 but has a problem with the installation.
[REQUEST] THEMEFOREST WORDPRESS TEMPLATE
It's name is: VALERA THANKS
Answered: Any one have WP Theme IFeature Pro 4 to share?
are u looking for this free theme? or something else? http://www.wordpress.org/extend/themes/ifeature
Any one have Mgid clone script ?
or 2leep.com or wahoha.com like this one : http://2leep.3fusion.in/ it is $99 dolar I need a free one or nulled
license for x10media mp3 script
Hello  i want this system  x10media.Mp3.Script that work well without a license  tnx advance 

Category: ---

/////-------------------------------------------------------///
// Uploaded by Xtreme @ Scriptmafia.org ///
//--------Xtreme-Web.net------------------------- ///
/////-------------------------------------------------------///
/////----------------SCRIPT INFO.......---------------------------------------///

File Size:1.1 MB
Latest Release:12th July, 2007
Version:1.4.7
Price: $90.00
Demo Details
Demo Url: http://demos.kubelabs.com/kubelance/

Admin Url: http://demos.kubelabs.com/kubelance/adm/
Admin User: demo
Admin Pass: demo

/////-----------------------END SCRIPT INFO--------------------------------///
Create a site where buyers can post projects/jobs and providers can bid on them. You charge a fee for each project/job created.

Feature List

Easy to edit html template files
Simple wizard installation
Charge a fee for each project and job
Plugin payment system (allows for additional payment methods to be installed easily)
Supports Paypal and NoChex
Easy to edit language files
No need to setup a cronjob
Powerful Admin panel for controlling your site
1 year of upgrades

/////----------------------END DESCRIPTION----------------------------------///
/////--------------END ALL----------------------------------------------------------///

Download Post Comment [5]


Category: Exploits

Vendor Site: http://ugamela.com
Download: http://itablackhawk.altervista.org/ogameclone.rar <- do copy/paste with this link otherwise the system will give you a 404 error
Type: Login Bypass
Severity: Hight
Patch: You can patch all manually by reading the last part of the advisory


Vuln Explanation:

The authentication check of this script doesn't work properly:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); }
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");}


the use of the header function do not stop the execution of the code, so an attacker may build a special script to send command to the site without even have a registered account.
I think that even the official site might be vulnerable, even if it is working with the 0.6 version of the script.
I'll try to contact the authors to get the last version of the script and check.
If so, you'll find it nearly on this pages. ;)


Solution: The only way to solve this problem is changing the previously lines in all admin files with this lines:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); exit;}
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");exit;}

Download Post Comment [3]


Category: Multimedia

/////-------------------------------------------------------///
// Uploaded by Xtreme @ Scriptmafia.org ///
//--------Xtreme-Web.net------------------------- ///
/////-------------------------------------------------------///
/////----------------SCRIPT INFO.......---------------------------------------///

- Script Name : Rayzz - Youtube Clone Script

Youtube clone, Metacafe clone, Myspace clone, Vidilife Clone

A community style clone of youtube, myspace like profile customization, fun stuff like vidilife,
functions like metacafe, so the net result you get an all in one product which is amazing

////----------------------------------------------------------------------------------------------------------///

Download Post Comment [6]