Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Remote access vulnerability using BigDump ver. 0.29b

Remote access vulnerability using BigDump ver. 0.29b

From: <XiaShing_at_gmail.com>
Date: Thu, 6 Nov 2008 01:45:08 -0700
('binary' encoding is not supported, stored as-is) ============================================================
!vuln
BigDump ver. 0.29b
Previous versions may also be affected.
============================================================

============================================================
!risk
Medium
There are currently many websites circulating with BigDump
enabled.
============================================================

============================================================
!dork
Dork: intitle:"BigDump ver. 0.29b"
============================================================

============================================================
!discussion
A user is able to successfully upload files onto a server by
uploading a php shell such as c99.php, by renaming it
c99.php.sql
============================================================

============================================================
!solution
Do not use BigDump or put non-root/guest permissions on the
folder containing BigDump. The vendor has not yet been
notified.
============================================================

============================================================
!greetz
Greetz go out to the people who know me.
============================================================

============================================================
!author
Xia Shing Zee
============================================================
Received on Nov 06 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]