Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow FormMail exploitation
EH-Net
May 21, 2013, 09:49:21 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: FormMail exploitation  (Read 3216 times)
0 Members and 1 Guest are viewing this topic.
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« on: August 26, 2012, 09:53:37 AM »

HI guys'
I want to do a pentest form my friend's website and during the Nikto scan i found this message:
FormMail could allow remote code execution  for the attacker.

I did a lot of search to find out how to exploit it but i couldnt find anything useful
however i hacked the ftp service with an awesome exploit but i want to patch this vulnerability too but firstly give me a good exploit if you have then i'll find the patch
thank you
Logged

ICS Academy Network Security Certified
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #1 on: August 26, 2012, 02:05:37 PM »

i forgot  to ask is formail famous mail server app? If it is why i counldnt find exploit?
Logged

ICS Academy Network Security Certified
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #2 on: August 26, 2012, 04:44:13 PM »

Check this out http://www.exploit-db.com/exploits/8950/ basically it makes it easier to create form to email type sites.  One of the issues with this is that it gives a possible method of spamming the recipients of those form messages as well as allowing someone to toss in code such as SQLi into the forms.  And it is PHP based which has a slew of other security issues to worry about.
Logged

Certs: GCWN
(@)Dewser
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: August 26, 2012, 09:51:44 PM »

The exploit seems legit as it's from USH as well, but from a very quick look it's an XSS exploit that seems to need user interaction.
Logged

I'm an InterN0T'er
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #4 on: August 27, 2012, 03:02:13 PM »

i dont know how to use it becuase its XSS can anyone help me? and MAxe if your meaning about user interaction is they can trace and find me its ok becuase as i said this site is for my friend and all of them know what im donig can anybody help me to run the exploit
Logged

ICS Academy Network Security Certified
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #5 on: August 27, 2012, 11:39:03 PM »

http://lmgtfy.com/?q=How+does+xss+work

Please, just try a LITTLE harder.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.