Welcome!

Join our community of MMORPG enthusiasts and private server developers! By registering, you'll gain access to in-depth discussions on source codes, binaries, and the latest developments in MMORPG server files. Collaborate with like-minded individuals, explore tutorials, and share insights on building and optimizing private servers. Join us today and unlock the full potential of MMORPG server development!

Join Today!

KOPANEL security hole

Newbie Spellweaver
Joined
Jun 29, 2007
Messages
22
Reaction score
0
hi,
recently i was testing kopanel security and i found a way to get dbpass on any site who has kopanel installed
(then sql connect->exec master xp cmdshell net user add....administrator->remote and ur server is mine)

i wont tell u the exploit here, turks would abuse it.


if u want me to check if ur server is vulnerable or not write me a pm.


if i ll find the fix i ll post it here
 
Last edited by a moderator:
hi,
recently i was testing kopanel security and i found a way to get dbpass on any site who has kopanel installed
(then sql connect->exec master xp cmdshell net user add....administrator->remote and ur server is mine)

i wont tell u the exploit here, turks would abuse it.


if u want me to check if ur server is vulnerable or not write me a pm.


if i ll find the fix i ll post it here

is this apache based panels or all?
 
seems like most server got it fixed tho

or atleast have it fixed now :o
 
interesting..my guess is that its an sql injection which lets you upload a php file which has the following line you just mentioned.
 
interesting..my guess is that its an sql injection which lets you upload a php file which has the following line you just mentioned.
it is

well 2 more lines to be exact i think... then open the server via command on your pc
the method of this thing is pretty old (well, if it is the thing i think it is :D)
 
Don't worry about it Asian yours is fine. Gerydeft, This only works on IIS. Apache servers have built in protection. Infact, if you setup your security properties correctly for the IIS user, it doesn't work then either. It seems most peopleusing IIS are giving the IIS full administrative permissions.
 
Spamman, I would like to see this as well, as I have a very nice defensive system. It would be a good test to my defense system.. However I need a new power supply first.
 
guys can someone share me the files that used on lostsoulz.net ( i mean there was an older version of that i need this i don't mean give me files of lostsoulz.net ) thanks a lot
 
guys can someone share me the files that used on lostsoulz.net ( i mean there was an older version of that i need this i don't mean give me files of lostsoulz.net ) thanks a lot
LOL

On-Topic : I would suggest using Heretic's KO Panel because I heard it was the most protected from SQL Inject of the released KO Panels...
 
Back