Chocapikk / CVE-2024-8504

VICIdial Unauthenticated SQLi to RCE Exploit (CVE-2024-8503 and CVE-2024-8504)
38 stars 4 forks source link

my issue #1

Closed starbismk closed 1 month ago

starbismk commented 1 month ago

[*] Using provided credentials for exploitation... [-] Failed to authenticate with credentials. Maybe hashing is enabled? All is same

Chocapikk commented 1 month ago

Let me debug. Are you sure you have the right credentials?

starbismk commented 1 month ago

Thank you for your answer, I have results from sqli mode.

here is a part :

https://qbao.fund:admin:admin https://plian.org/:admin:admin https://globe.exchange/:admin:admin https://goldfinx.com/:admin:admin https://mvs.org/:admin:admin https://www.dehealth.world/:admin:admin

Do you have a telegram ?

On Sun, Sep 15, 2024 at 2:27 PM Valentin Lobstein @.***> wrote:

Let me debug. Are you sure you have the right credentials?

— Reply to this email directly, view it on GitHub https://github.com/Chocapikk/CVE-2024-8504/issues/1#issuecomment-2351547984, or unsubscribe https://github.com/notifications/unsubscribe-auth/BLJWFHT6HQUYTVK2IYG53CLZWVVITAVCNFSM6AAAAABOHSTQRCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDGNJRGU2DOOJYGQ . You are receiving this because you authored the thread.Message ID: @.***>

Chocapikk commented 1 month ago

Lol these are not vicidial servers it makes no sense to use this code on that. That's why it doesn't work.

starbismk commented 1 month ago

Will help me a lot a direct contact trought telegram with you. I have a list of domains that I need to be checked. OFC I will pay for your time / efforts

On Sun, Sep 15, 2024 at 2:47 PM Valentin Lobstein @.***> wrote:

Lol these are not vicidial servers it makes no sense to use this code on that. That's why it doesn't work.

— Reply to this email directly, view it on GitHub https://github.com/Chocapikk/CVE-2024-8504/issues/1#issuecomment-2351554357, or unsubscribe https://github.com/notifications/unsubscribe-auth/BLJWFHVCKKMFAY55FGNRQCTZWVXU7AVCNFSM6AAAAABOHSTQRCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDGNJRGU2TIMZVG4 . You are receiving this because you authored the thread.Message ID: @.***>

starbismk commented 1 month ago

maybe another CVE will help me to get the full DB, in order to work

On Sun, Sep 15, 2024 at 3:25 PM star bis @.***> wrote:

Will help me a lot a direct contact trought telegram with you. I have a list of domains that I need to be checked. OFC I will pay for your time / efforts

On Sun, Sep 15, 2024 at 2:47 PM Valentin Lobstein < @.***> wrote:

Lol these are not vicidial servers it makes no sense to use this code on that. That's why it doesn't work.

— Reply to this email directly, view it on GitHub https://github.com/Chocapikk/CVE-2024-8504/issues/1#issuecomment-2351554357, or unsubscribe https://github.com/notifications/unsubscribe-auth/BLJWFHVCKKMFAY55FGNRQCTZWVXU7AVCNFSM6AAAAABOHSTQRCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDGNJRGU2TIMZVG4 . You are receiving this because you authored the thread.Message ID: @.***>

Chocapikk commented 1 month ago

No, you got the wrong person, I'm not into that kind of thing.

I'm not interested.

starbismk commented 1 month ago

Hey! I am not asking for nothing illegally ! I just want to see if I find some vulnerable sites, and ofc to tell them about vuln. I am sure any vulnerable sql website will be grateful to know about it.

Thank you

On Sun, Sep 15, 2024 at 3:38 PM Valentin Lobstein @.***> wrote:

No, you got the wrong person, I'm not into that kind of thing.

I'm not interested.

— Reply to this email directly, view it on GitHub https://github.com/Chocapikk/CVE-2024-8504/issues/1#issuecomment-2351574528, or unsubscribe https://github.com/notifications/unsubscribe-auth/BLJWFHS2LA7HLO3ZIOGDUNLZWV5SXAVCNFSM6AAAAABOHSTQRCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDGNJRGU3TINJSHA . You are receiving this because you authored the thread.Message ID: @.***>