what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Simple And Nice Index File 1.5.2 Arbitrary File Download

Simple And Nice Index File 1.5.2 Arbitrary File Download
Posted Jan 31, 2010
Authored by Aodrulez

Snif (Simple And Nice Index File) version 1.5.2 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary
SHA-256 | 8d49044a22bb6ef51032fbf025432f7ed888926d599eceff9c9eaf303f52a675

Simple And Nice Index File 1.5.2 Arbitrary File Download

Change Mirror Download
--------------------------------------------
-: Snif - "Any Filetype" Download Exploit :-
--------------------------------------------

Script : Snif - (Simple And Nice Index File)
Version : 1.5.2 (possibly lower versions too)
Found By : Aodrulez.
Email : f3arm3d3ar[at]gmail.com

Vulnerability:
--------------

Some Default Settings are:

$hiddenFilesWildcards = Array("*.php", "*~");
$allowPHPDownloads = false;

The first option will prevent any php file
from being listed in the directory listing.
Second one will prevent download of files
with ".php" extension.

Even with these options set,we can still
download php files....due to the following
vulnerable code:-

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
if ($_GET["download"]!="") {

$download = stripslashes($_GET["download"]);
$filename = safeDirectory($path.rawurldecode($download));
if (
!file_exists($filename)
OR fileIsHidden($filename)
OR (substr(strtolower($filename), -4)==".php" AND !$allowPHPDownloads)) {


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The last line in the above code checks the
file's extension to make sure its not a php
file.This line of code is Vulnerable though

Exploit:
--------

Lets say the script is located here:
http://www.a.com/snif.php

The following url will bypass all restrictions
and let you download a php file :-

http://www.a.com/snif.php?download=snif.php%00


Greetz Fly Out To
-----------------

Amforked() : My Mentor.
The Blue Genius : My Boss.
www.orchidseven.com
www.isac.org.in







Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close