This isn&#39;t a password disclosure, it&#39;s a leak of password information.<br><br>It&#39;s a password hash, you super hacker.<br><br><div><span class="gmail_quote">On 1/5/07, <b class="gmail_sendername"><a href="mailto:corrado.liotta@alice.it">
corrado.liotta@alice.it</a></b> &lt;<a href="mailto:corrado.liotta@alice.it">corrado.liotta@alice.it</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">







<div>

<br>

<p><font size="2">-=[--------------------ADVISORY-------------------]=-<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FLog 1.1.2&nbsp;&nbsp;&nbsp;&nbsp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br>
&nbsp; Author: CorryL&nbsp;&nbsp;&nbsp; [<a href="mailto:corryl80@gmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">corryl80@gmail.com</a>]&nbsp;&nbsp;<br>
-=[-----------------------------------------------]=-<br>
<br>
<br>
-=[+] Application:&nbsp;&nbsp;&nbsp; FLog<br>
-=[+] Version:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1.1.2<br>
-=[+] Vendor&#39;s URL:&nbsp;&nbsp; <a href="http://www.fluffington.com/index.php?page=flog" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.fluffington.com/index.php?page=flog</a><br>
-=[+] Platform:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows\Linux\Unix<br>
-=[+] Bug type:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Remote Admin Password Disclosure<br>
-=[+] Exploitation:&nbsp;&nbsp; Remote<br>
-=[-]<br>
-=[+] Author:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CorryL&nbsp; ~ corryl80[at]gmail[dot]com ~<br>
-=[+] Reference:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href="http://www.x0n3-h4ck.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">www.x0n3-h4ck.org</a><br>
-=[+] Virtual Office:&nbsp; <a href="http://www.kasamba.com/CorryL" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.kasamba.com/CorryL</a><br>
-=[+] Irc Chan:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href="http://irc.darksin.net" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">irc.darksin.net</a> #x0n3-h4ck&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br>
<br>
<br>
..::[ Descriprion ]::..<br>
<br>
FLog is a simple yet powerful weblog script that doesn&#39;t require a database to run.<br>
Features include easy installation, comments, multiple users, links, categories,<br>
and full plugin and theme APIs.<br>
<br>
<br>
..::[ Proof Of Concept ]::..<br>
<br>
<a href="http://remote_server/data/users.0.dat" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://remote_server/data/users.0.dat</a><br>
<br>
<br>
<br>
..::[ Disclousure Timeline ]::..<br>
<br>
<br>
[07/01/2007] - Public disclousure<br>
<br>
**************<br>
Registrati ad Alice Basic e scarica Alice Messenger,<br>
il nuovo instant messenger che ti fa chattare GRATIS con i tuoi amici!<br>
Per maggiori informazioni vai su:<br>
<a href="http://adsl.alice.it/servizi/alicebasic.html?pmk=psmail_foot01" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://adsl.alice.it/servizi/alicebasic.html?pmk=psmail_foot01</a></font>
</p>

</div>

<br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
<br></blockquote></div><br>