Geez, this is even lamer than the last video you posted. Still don't have things setup the way anyone that knows anything would setup a production DNN site. Unencrypted MachineKey section in web.config? Let's see the error.aspx page. Default SuperUser name? C'mon!
Aside from the likelyhood that you did successfully rip off the PadBuster script and learn how to use an editor enough to put your name and e-mail address on the screen at launch, this shows nada.
@eduncan911 What's wrong with you? Didn't you see that it's a virtual machine running Windows, and the exploit was launched from a Mac? How can that be "localhost"?
And what happens when you change your customErrors to mode="On"?
What you show in the video is to your localhost. And you currently have customErrors="RemoteOnly", which means you are not getting custom errors - the "Microsoft Workaround" recommendation.
If you want to truly test this, please change mode="On" and re-run - you should not found any key then.
This has been flagged as spam show
Geez, this is even lamer than the last video you posted. Still don't have things setup the way anyone that knows anything would setup a production DNN site. Unencrypted MachineKey section in web.config? Let's see the error.aspx page. Default SuperUser name? C'mon!
Aside from the likelyhood that you did successfully rip off the PadBuster script and learn how to use an editor enough to put your name and e-mail address on the screen at launch, this shows nada.
TheBittwiddler 1 year ago
When are you going to release the POET with the exploit? :P
newunderground 1 year ago
@eduncan911 What's wrong with you? Didn't you see that it's a virtual machine running Windows, and the exploit was launched from a Mac? How can that be "localhost"?
Please stop complaining, and start patching.
cryptbe 1 year ago 2
And what happens when you change your customErrors to mode="On"?
What you show in the video is to your localhost. And you currently have customErrors="RemoteOnly", which means you are not getting custom errors - the "Microsoft Workaround" recommendation.
If you want to truly test this, please change mode="On" and re-run - you should not found any key then.
eduncan911 1 year ago