|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 80
Members: 0
Total: 80
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
don't know to crack this password |
|
Posted: Sat Aug 06, 2005 8:23 pm |
|
|
Rakesh |
Beginner |
|
|
Joined: Aug 06, 2005 |
Posts: 1 |
|
|
|
|
|
|
|
hey all i'm new here. i found a password in /config/password.txt on sphpblog site :
$1$f7Ia/Xi3$P
its not a real password that was i got, its password look like that and with 34 characters !
i've tried to crack it but still can't get the result. can anybody here tell me what is the best way to crack it
? |
|
|
|
|
Posted: Wed Aug 10, 2005 9:49 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
So this is coming from:
http://echo.or.id/adv/adv12-y3dips-2005.txt
Code: |
C. Critical Information dislosures
Critical file (password and config file) are vulnerable to direct access
to view 'critical' information about the blog and the user.
Password file are using PHP`s crypt() function
http://[Url]/sphpblog/config/password.txt
http://[Url]/sphpblog/config/config.txt
|
As we can see, crypt() function is used, so i suggest to try John the Ripper |
|
|
|
|
www.waraxe.us Forum Index -> General discussion
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|