LOGiN PANeL



«    August 2007    »
MoTuWeThFrSaSu
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
 
PoLL

1
2
3
4
5
6
7
8
9


NAViGATiON
CMS WAP Chat Blog Clones Exploits Modules Tutorials Counters Top Sites Education Templates Multimedia Guestbooks Web Search E-Commerce Forum Boards Hosting Scripts Free Templates Image Galleries Support System Ad Management WYSIWYG Editors Banner Exchange SCRiPTMAFiA.ORG
ADVERTiSiNG
Newware | Design share
TOP 10
FRiENDS
Astalavista.com – the IT News & Security community Free Video Tutorial Nulled.org Software GxIso.com WarezUN SeoMafia mp3 games pda free flash banner maker logo maker
RSS
LaST oN NULLeD.org
AVG Internet Security 2012 Build 2176a4990 (x86) AVG Internet Security 2012 Build 2176a4990 (x86) | 145 MB Get complete protection from the most ...
Emma Hewitt - Burn The Sky Down (2012) Emma Hewitt - Burn The Sky Down (2012) 13 Tracks | Release: 2012 | MP3 320kbps | 44.1 Khz | ...
MusicLab RealGuitar 2.3L x86/x64 (Repost) MusicLab RealGuitar 2.3L x86/x64 | 186 MB If you are serious about creating truly realistic ...
CyberLink Media Suite 10.0.0.1529 Ultra Retail CyberLink Media Suite 10.0.0.1529 Ultra Retail | 1.71 GB CyberLink Media Suite is designed to give ...
Transform Windows 7 To Mac OS X Lion 10.7 (x86/x64) Transform Windows 7 To Mac OS X Lion 10.7 (x86/x64) OS : Windows 7 | Year : 2012 | 143 MB


Fair pricing servers - No bullshit promise

Last questions on ask.SCRiPTMAFiA.ORG

Looking Tarnished style version 2.1
Does anyone have a style Tarnished version 2.1 http://themeforest.net/item/tarnished-modern-grunge-wordpress-theme/162472?ref=GhostPool is at 1.5 but has a problem with the installation.
[REQUEST] THEMEFOREST WORDPRESS TEMPLATE
It's name is: VALERA THANKS
Answered: Any one have WP Theme IFeature Pro 4 to share?
are u looking for this free theme? or something else? http://www.wordpress.org/extend/themes/ifeature
Any one have Mgid clone script ?
or 2leep.com or wahoha.com like this one : http://2leep.3fusion.in/ it is $99 dolar I need a free one or nulled
license for x10media mp3 script
Hello  i want this system  x10media.Mp3.Script that work well without a license  tnx advance 

Ugamela (Ogame clone) 0.2 Login Bypass

Category: Exploits


Vendor Site: http://ugamela.com
Download: http://itablackhawk.altervista.org/ogameclone.rar <- do copy/paste with this link otherwise the system will give you a 404 error
Type: Login Bypass
Severity: Hight
Patch: You can patch all manually by reading the last part of the advisory


Vuln Explanation:

The authentication check of this script doesn't work properly:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); }
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");}


the use of the header function do not stop the execution of the code, so an attacker may build a special script to send command to the site without even have a registered account.
I think that even the official site might be vulnerable, even if it is working with the 0.6 version of the script.
I'll try to contact the authors to get the last version of the script and check.
If so, you'll find it nearly on this pages. ;)


Solution: The only way to solve this problem is changing the previously lines in all admin files with this lines:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); exit;}
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");exit;}

Download Ugamela (Ogame clone) 0.2 Login Bypass with high speed

   
   
   

Your Ad Here

Related news:
 (Votes #: 28)







 

Information

 
  Members of GUESTS cannot leave comments.  



Наши металлопластиковые окна сертифицированы!