This exploit demonstrates a SQL injection vulnerability in the SoftMP3 bittorrent tracker's minbrowse.php file, allowing an attacker to extract user credentials (id, username, and passhash) from the database. The PoC includes a method to generate the encrypted passhash for cookie-based authentication.
Classification
Working Poc 90%
Target:
SoftMP3 bittorrent tracker (source code release)
No auth needed
Prerequisites:
Access to the minbrowse.php endpoint · Database containing user credentials