Last Played Song: Currently disabled due to loading issues.

Exploited! - Mihalism

posted in: PHPMySQL 
 CuLT
Avatar
 Administrator
 Entry No: 64

Sorry, not nearly as promising as the title, this article is about another hack attempt on me, this one aimed at wthax.org.

Thanks to an extremely poorly written (but pretty) image hosting script, wthax.org turned out to be susceptible to script execution.

Fortunately for me I discovered it before, it seems, any damage was done, and I've patched the code myself accordingly.

This is a very real threat though for anyone who uses the Mihalism image uploading software.

I've spend the guts of two hours poring through the code, adding and removing bits to make it a hell of a lot more secure than it was.

Heh, I'll either release it here as a culted-up version of Mihalism, or just give the code to Mihalism after I'm done.

Thursday 22nd of June 2006 01:57:31 AM  


#commentid: 1752006-06-23 20:01:24 
 d_fens: exploited like YOR MA

#commentid: 1762006-06-23 21:14:38 
 [CuLT]: more like yore ma's face.

#commentid: 1782006-07-07 14:22:30 
 Mihalism staff: If you have any codes for mihalism please send it to our help department at info@mihalism.com

#commentid: 1792006-07-07 14:23:28 
 Mihalism staff: If you have any codes for mihalism please send it to our help department at info@mihalism.com

#commentid: 1802006-07-08 01:38:48 
 [CuLT]: Sure thing, few more things to work out, but I'll let you guys know when I'm reasonably happy with my results wink

#commentid: 1852006-11-26 16:09:39 
 Mihalism staff: We have finished a new copy of our free uploading script. This new one has all secuirty holes fixed.



http://mihalism.com/image_hosting_script.php

#commentid: 1892007-01-07 17:02:49 
 d_fens: Heh well done there cult.

I consider it lulz when you see



"Guarneented to work - Not a single bug reported yet!"

[http://www.uploadscriptdemo.com/more_info.php]



btw is the image verification done using a database or a session or a combination of both? Some people like to keep sessions in a DB so I'm kinda interested :P

#commentid: 2912012-11-18 06:51:01 
 Cornell: Greetings I am so thrilled I found your webpage, I really found you by accident, while I

was looking on Google for something else, Nonetheless I am here now and would just like to say thanks for a remarkable post and a all round entertaining blog (I also love the

theme/design), I don_t have time to read it all at the moment but I

have saved it and also added your RSS feeds, so when I have time I will be back

to read a great deal more, Please do keep up the great jo.

#commentid: 2922012-11-20 05:46:38 
 Shirley: I'm not sure why but this weblog is loading extremely slow for me. Is anyone else having this problem or is it a problem on my end? I'll check back later and see if the problem still exists.

#commentid: 2932012-11-20 13:58:50 
 Myles: For the reason that the admin of this site is working, no uncertainty very shortly it will be well-known,

due to its quality contents.

#commentid: 2942012-11-21 02:56:14 
 Christie: Thanks for sharing your thoughts on flavored cigarettes.

Regards

#commentid: 2952012-11-25 01:40:34 
 Mariam: I think the admin of this website is genuinely working hard

in favor of his website, as here every data is quality based stuff.

#commentid: 2962012-12-05 09:50:46 
 Diane: Can you tell us more about this? I'd love to find out more details.

#commentid: 2972012-12-05 10:35:50 
 Elke: It's in reality a great and helpful piece of information. I am satisfied that you simply shared this helpful info with us. Please keep us up to date like this. Thank you for sharing.

#commentid: 2982012-12-07 01:03:05 
 Consuelo: Does your blog have a contact page? I'm having a tough time locating it but, I'd like to send you an e-mail.

I've got some creative ideas for your blog you might be interested in hearing. Either way, great blog and I look forward to seeing it improve over time.

#commentid: 2992012-12-08 01:27:11 
 Ulrich: Hello there, I do believe your web site may be having internet browser compatibility

issues. Whenever I take a look at your website in Safari, it looks

fine however, when opening in IE, it's got some overlapping issues. I merely wanted to give you a quick heads up! Besides that, wonderful site!

#commentid: 3002012-12-17 02:02:11 
 Helen: This is really attention-grabbing, You are a very skilled blogger.

I've joined your feed and sit up for searching for extra of your magnificent post. Also, I've shared your website in my

social networks

#commentid: 3012012-12-20 02:58:50 
 Jamika: Hi there! This is kind of off topic but I need some

guidance from an established blog. Is it hard to set

up your own blog? I'm not very techincal but I can figure things out pretty quick. I'm thinking about

creating my own but I'm not sure where to begin. Do you have any ideas or suggestions? Thanks

#commentid: 3022013-01-05 05:15:08 
 Sylvia: Thank you for the good writeup. It in truth was a leisure account it.

Glance complicated to more introduced agreeable from you!



However, how can we communicate?

#commentid: 3042013-01-09 08:39:30 
 Kindra: My spouse and I absolutely love your blog and

find the majority of your post's to be exactly I'm looking for.

Does one offer guest writers to write content

available for you? I wouldn't mind creating a post or elaborating on a number of the subjects you write with regards to here. Again, awesome website!

#commentid: 3082013-01-12 13:29:53 
 Erin: I am really grateful to the holder of this site who has

shared this great post at at this place.

#commentid: 3102013-01-13 19:20:16 
 Glinda: I was pretty pleased to uncover this great site. I need to to thank you for ones time

due to this fantastic read!! I definitely appreciated every bit of it and i also have you saved

as a favorite to see new stuff in your blog.

#commentid: 3262013-01-25 02:34:07 
 Sienna: I must thank you for the efforts you have put in penning this website.

I really hope to see the same high-grade blog posts from you later on as well.

In fact, your creative writing abilities has inspired me to get my own, personal blog now

wink

#commentid: 3452013-02-12 13:42:36 
 yrNXTQPp: bnmagj

#commentid: 3462013-02-13 10:50:47 
 cXRgEydd: vndsry <a href="http://caktge.com/ ">ftqmef</a>

#commentid: 3522013-02-17 14:55:51 
 WfXFuxET: aylhqbl

#commentid: 3532013-02-17 16:59:20 
 cMSPclst: uneffrrr

#commentid: 3652013-02-21 05:15:22 
 gWcegIhQ: xuqigmn

#commentid: 3712013-02-26 23:06:42 
 EIzmtrIS: oatorgy

#commentid: 3722013-02-27 19:06:12 
 qvlkwSsu: nwajnaln

#commentid: 3792013-03-03 12:28:34 
 rkqbtvnX: efowyt

#commentid: 3832013-03-05 09:05:46 
 vWIpOFfX: xllidank

#commentid: 3862013-03-06 10:10:10 
 ULjZMLXs: entwzv

#commentid: 3872013-03-07 15:54:07 
 nHloqnKr: iprvkx

#commentid: 3882013-03-08 01:19:32 
 ayGqNIuo: szxypt

#commentid: 3902013-03-08 12:00:51 
 nnqUITjN: hypsoaq

#commentid: 3972013-03-12 08:47:17 
 iOvIdxSJ: tguqpwyj

#commentid: 4022013-03-15 07:34:10 
 czutfySu: cudmogk

#commentid: 4072013-03-19 21:26:04 
 dKOPoDre: qbpoeyzb

#commentid: 4222013-03-27 22:38:16 
 UaDIeRol: kkkftmff

#commentid: 4232013-03-28 16:29:19 
 eagvfIYG: tvxrtp

#commentid: 4252013-03-30 13:44:28 
 clrzkBOt: qrnnqwr

#commentid: 4262013-04-02 05:21:57 
 AivkIJLQ: nrgqjy

#commentid: 4272013-04-03 02:05:24 
 TCyMBouI: vposmeu

#commentid: 4282013-04-03 11:02:50 
 bnOtbGCV: quhhovjb

#commentid: 4292013-04-03 12:42:07 
 FSxJdOBz: bonyqaui

#commentid: 4332013-04-04 12:42:50 
 JlZNsFeq: ooinqxxx

#commentid: 4342013-04-05 22:35:19 
 tunkOCrL: opcnmuud

#commentid: 4352013-04-06 06:11:39 
 iIaIXLdZ: vdwahij

#commentid: 4362013-04-06 09:03:44 
 EmwdwnNN: niytvfj

#commentid: 4392013-04-07 01:12:52 
 onWWuTie: elrcqupa

#commentid: 4402013-04-07 11:56:28 
 FFFltxFX: vxgfgbc

#commentid: 4432013-04-08 12:36:23 
 DNHnRkHb: oewwob

#commentid: 4462013-04-10 05:49:48 
 ZiOFvPJS: rxrgnuyy

#commentid: 4482013-04-10 09:42:31 
 cddXiUOL: tgkybs

#commentid: 4562013-04-16 01:06:07 
 yrrAPpNI: cvrueei

#commentid: 4602013-04-17 14:43:07 
 GtyMEDCn: sbctghkk

#commentid: 4672013-04-20 05:51:14 
 sOshjXIP: cnikdecl

#commentid: 4742013-04-28 04:05:40 
 vYQQQTkV: vzxxvpg

#commentid: 4782013-04-30 01:26:35 
 oAQMBhtq: vnagltm

#commentid: 4792013-05-01 00:16:09 
 jDzXQBLO: zmsxar

#commentid: 4822013-05-01 23:02:38 
 etQgutuP: ybymrf

#commentid: 4832013-05-02 22:17:59 
 CnzjRGpG: krtoari

#commentid: 4852013-05-03 22:53:53 
 QErdyaGv: faoldy

#commentid: 4862013-05-04 21:01:58 
 UqHfupRV: ykwcajud

#commentid: 4872013-05-05 22:00:51 
 hwfWwvks: ggfgbhr

#commentid: 4912013-05-06 22:46:02 
 xDZwngHd: vbjpprl

#commentid: 4942013-05-08 00:36:26 
 UzXLXDSm: fcnvqhjt

#commentid: 4962013-05-08 22:17:06 
 BNGaZexz: liiqmp

#commentid: 5172013-05-16 23:42:38 
 kDjrDWzg: uttxiwu

#commentid: 5192013-05-17 23:49:58 
 iWuKWDsv: gwgcmqbe



post a comment
Name:
URL:
Comment:
Enter this code: Security Image