Welcome to World of IPTV

With

+23k members
+11k threads
+106k posts

we are the most popular IPTV community on the web. 

IMPORTANT NOTE:
WE HAVE RECENTLY NOTICED THAT TOO MANY DOUBLE FAKE ACCOUNTS ARE CREATED IN THE PAST.
TO PREVENT THIS ISSUE THE DECISION WAS MADE THAT IN THE FUTURE A ANNUALLY FEE 20 EURO WILL BE RAISED FOR NEW MEMBERSHIPS.

Join now to the World of IPTV

Forum Rules

Before you start, check out the forum rules first

Account upgrade

Upgrade your account to get access to full features

Advertising

Would you like to place your advertisement with us ?

Resources Manager

Hundreds of IPTV scripts and apps are available for download

Info exploit xtream codes

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
Last days some new methond attack happened, anyone have information for patch file allow input this sql injection
 

leadersat

Extended Member
Ext. Member
Joined
Oct 2, 2019
Messages
55
Reaction score
79
Points
29
Location
USA
Last days some new methond attack happened, anyone have information for patch file allow input this sql injection
How do you know it was injection and not just brute forced. Was the attack at your panel login or your SQL admin. Also what version number is the xtream UI your using.
 

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
How do you know it was injection and not just brute forced. Was the attack at your panel login or your SQL admin. Also what version number is the xtream UI your using.
this new attack is more advance than that
is some exploit in base files
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

leadersat

Extended Member
Ext. Member
Joined
Oct 2, 2019
Messages
55
Reaction score
79
Points
29
Location
USA
this new attack is more advance than that
is some exploit in base files
They would still need some way in to your server to attack it. Either by ssh access or as I mentioned above. You say they changing base files, which files have you noticed have been changed. Are the files they have changed allowing a backdoor for easy access. More info on your part would help to be able to find a solution.
 

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
attack not change files, dont access by ssh, not by panel
is SQL injection, only do querys in DB
 

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
Please stop send me PM about this topic
At moment i dont have more information
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

abelcustoms

Extended Member
Ext. Member
Joined
Sep 23, 2019
Messages
58
Reaction score
255
Points
64
Location
EdgeOfNowhere
Please stop send me PM about this topic
At moment i dont have more information
the attack is not sql injection, its known as a CLI injection, the method is very similar to a Snyk CLI Exploit released this last September.
 

shitping

Extended Member
Ext. Member
Joined
Sep 24, 2019
Messages
119
Reaction score
187
Points
54
Location
home
the attack is not sql injection, its known as a CLI injection, the method is very similar to a Snyk CLI Exploit released this last September.
And do you have a fix to stop this CLI injection?
 

abelcustoms

Extended Member
Ext. Member
Joined
Sep 23, 2019
Messages
58
Reaction score
255
Points
64
Location
EdgeOfNowhere
And do you have a fix to stop this CLI injection?
nope, it's the reason why I don't use XUI or even XUI One. There is the saying, you pay for what you get for. It's the main reason why many are making their own xui API compatible panels with built-in better security. Once you see the source code, you can identify where and how to get into the panel by injecting in calls that do not have proper checks. Because it was poorly written, you get these results. A quick example of how to use request URI and be able to get "ALL" accounts inside the panel except admin.
REQUEST_URI/live/zihin61/170322/38132.ts?token=SENdBBYMEwlAUlRZUl1QBQ8AAFZRDloOBFoGUQMHXg4HB1RSVlEJA1JAGhpHEURUWA9oCFEbWQsPCAMCTUFNRFYTagwBRgsRU1MHDABVFB0bFl4MUBtZCQEMBgFZVQ4BAE0XFQwAEwlAUQMBBlQUHRsHTxVQSw1ZW2ZUVRcKW1IRW1sQCQgdEQ0MaVxRCFdfXUANQwUbTxpeSkASW0FsQkEKFTEACFRYDQ9DVl0OV0JADVlBdFcMVl5UEGMIEVNSRwgXSUcGWEcQA0JdFl8UAwpSA0MZGwBXQldEQhhBAhVnMxdJRwFJRwcMRVFbCxQLGxZEQxkbCktoS1VDFRFdVl4ER0dfRgERTkBbWUw6VV5XDFICQVAMVkQbChJQQRQVXg5bDBELQ2wSC1IaDkcECQ1VDkNI With the proper tools you can inject and get access to pretty much every user. Tools like these are offered by a close group sharing new backdoors and methods to get past the auth system.
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
exploit use last attack is not for bypass user auth
it was some kind breach allow sql queries
the guy who has this script is laughing reading these silly comments
 

shitping

Extended Member
Ext. Member
Joined
Sep 24, 2019
Messages
119
Reaction score
187
Points
54
Location
home
nope, it's the reason why I don't use XUI or even XUI One. There is the saying, you pay for what you get for. It's the main reason why many are making their own xui API compatible panels with built-in better security. Once you see the source code, you can identify where and how to get into the panel by injecting in calls that do not have proper checks. Because it was poorly written, you get these results. A quick example of how to use request URI and be able to get "ALL" accounts inside the panel except admin.
REQUEST_URI/live/zihin61/170322/38132.ts?token=SENdBBYMEwlAUlRZUl1QBQ8AAFZRDloOBFoGUQMHXg4HB1RSVlEJA1JAGhpHEURUWA9oCFEbWQsPCAMCTUFNRFYTagwBRgsRU1MHDABVFB0bFl4MUBtZCQEMBgFZVQ4BAE0XFQwAEwlAUQMBBlQUHRsHTxVQSw1ZW2ZUVRcKW1IRW1sQCQgdEQ0MaVxRCFdfXUANQwUbTxpeSkASW0FsQkEKFTEACFRYDQ9DVl0OV0JADVlBdFcMVl5UEGMIEVNSRwgXSUcGWEcQA0JdFl8UAwpSA0MZGwBXQldEQhhBAhVnMxdJRwFJRwcMRVFbCxQLGxZEQxkbCktoS1VDFRFdVl4ER0dfRgERTkBbWUw6VV5XDFICQVAMVkQbChJQQRQVXg5bDBELQ2wSC1IaDkcECQ1VDkNI With the proper tools you can inject and get access to pretty much every user. Tools like these are offered by a close group sharing new backdoors and methods to get past the auth system.
A good proxy with geo block, Tor block, Mod Security , Fail2ban aso for main

And for LB you can level up the Security with geo block or allow only and again tor block.

Then you will be reasonable safe i think.
 

chris

Extended Member
Ext. Member
Joined
Jul 26, 2019
Messages
123
Reaction score
320
Points
74
Location
spain
A good proxy with geo block, Tor block, Mod Security , Fail2ban aso for main

And for LB you can level up the Security with geo block or allow only and again tor block.

Then you will be reasonable safe i think.


No, is that problem LB
LB have some vulnerability, bypass queries
Someone have that script running in match
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com
shape1
shape2
shape3
shape4
shape5
shape6
Top
AdBlock Detected

We know, ad-blocking software do a great job at blocking ads. But our site is sponsored by advertising. 

For the best possible site experience please take a moment to disable your AdBlocker.
You can create a Account with us or if you already have account, you can prefer an Account Upgrade.

I've Disabled AdBlock