Waraxe IT Security Portal
Login or Register
April 28, 2025
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 80
Members: 0
Total: 80
Full disclosure
[IWCC 2025] CfP: 14th International Workshop on Cyber Crime -Ghent, Belgium, Aug 11-14, 2025
Inedo ProGet Insecure Reflection and CSRF Vulnerabilities
Ruby on Rails Cross-Site Request Forgery
Microsoft ".library-ms" File / NTLM Information Disclosure (Resurrected 2025)
HNS-2025-10 - HN Security Advisory - Local privilege escalation in Zyxel uOS
APPLE-SA-04-16-2025-4 visionOS 2.4.1
APPLE-SA-04-16-2025-3 tvOS 18.4.1
APPLE-SA-04-16-2025-2 macOS Sequoia 15.4.1
APPLE-SA-04-16-2025-1 iOS 18.4.1 and iPadOS 18.4.1
Business Logic Flaw: Price Manipulation - AlegroCartv1.2.9
Stored XSS in "Message" Functionality - AlegroCartv1.2.9
XSS via SVG Image Upload - AlegroCartv1.2.9
BBOT 2.1.0 - Local Privilege Escalation via Malicious ModuleExecution
83 vulnerabilities in Vasion Print / PrinterLogic
[CVE-2025-32102, CVE-2025-32103] SSRF and Directory Traversal in CrushFTP 10.7.1 and 11.1.0 (as well as legacy 9.x)
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> PhpBB -> Please help. I'm a noob and im hungry for revenge
Post new topicReply to topic View previous topic :: View next topic
Please help. I'm a noob and im hungry for revenge
PostPosted: Sun Nov 25, 2007 4:56 am Reply with quote
AqualungFury
Beginner
Beginner
Joined: Nov 25, 2007
Posts: 4




I'm not normally a vengeful person though , so please hear me out.

I've been admin of 3 phpbb boards.
the first was defaced by a rogue admin.
the second was deleted by the person who owned the server.
and the latest , i have been squeezed out of ( my own forum ).
I feel humiliated and sick that people i trusted , and entrusted with authority , have stabbed me in the back , because of their arrogance and greed.

If i can bring the whole forum down , i want that.
If i can only deface it , i'll do that.

I am currently banned.
I dont know exactly what version it is , but its definitely not 3.0 , or 1.0

I'm a complete noob , because ive never had to learn this before , so please help me with laymans terms if possible.
I'd like to make the forum inoperable if possible , so that the backups ( which i myself made at one time ) will not work.

If this seems unethical...........i built the forum sections myself , so im only wanting to take apart what i originally made , so those who slyly stole it from me , cant use it.

please help. i feel humiliated.
View user's profile Send private message
PostPosted: Sun Nov 25, 2007 6:37 am Reply with quote
AqualungFury
Beginner
Beginner
Joined: Nov 25, 2007
Posts: 4




a little bit more info

the sites server is godaddy , and the parent website was hosting my forum.
there are over 3000 members , and about 2600 are spambots.
the owner of the website ( who deleted me for not being there , due to crisis like having to move country , losing jobs etc.... ) has never installed any mods to prevent the spambots registering , as it would make upgrading phpbb impossible , so there must be many holes.

please help.

*edit

i found a backup from a few months ago. its the phpbb_db.sql file , and i found the version in it.

its 2.0.20

anyone ?
View user's profile Send private message
PostPosted: Sun Nov 25, 2007 10:02 am Reply with quote
Sm0ke
Moderator
Moderator
Joined: Nov 25, 2006
Posts: 141
Location: Finland




Very Happy take the hash of Admin from backup and submit here or try to crack your self
View user's profile Send private message
PostPosted: Sun Nov 25, 2007 4:27 pm Reply with quote
AqualungFury
Beginner
Beginner
Joined: Nov 25, 2007
Posts: 4




Sm0ke wrote:
Very Happy take the hash of Admin from backup and submit here or try to crack your self


Firstly , many thanks for replying Sm0ke.
I'm looking in the backup fot this " hash " , but to be honest , i dont know what im looking for Laughing
Theres quite a bit of info in it... a lot of it relating to banned email addresses , forum layout etc.
Any hints on what i should be looking for ?
I've never attempted an exploit before , so i have zero knowledge of this stuff.

I'm right now at this minute , looking into proxys , as i cant get to within 2 feet of my forum , due to being banned. Any recommendations on these ?

Thanks again !!



*edit --- i've gained access to the forum in question using an anonymous proxy provider called cloaked but i still cant post or register using this
.
Is there any way i can find the hash in the .sql using "find" and "find next" in the text editor ?

here is the link to the .sql file

*Link removed*

thx Very Happy
View user's profile Send private message
PostPosted: Sun Nov 25, 2007 8:12 pm Reply with quote
Sm0ke
Moderator
Moderator
Joined: Nov 25, 2006
Posts: 141
Location: Finland




your backup didnt have users data, backup function must have been modified , like only user id2 gets userdata in backup.
View user's profile Send private message
PostPosted: Sun Nov 25, 2007 8:53 pm Reply with quote
AqualungFury
Beginner
Beginner
Joined: Nov 25, 2007
Posts: 4




So i cant do anything Sm0ke ?

i would pay to see this forum become inoperable. Please tell me there is an exploit / vulnerability , that i can do this with.

I cant bear to sit by and let them get away with this mate.

I was admin of the forum itself , but there was an admin above me who maybe did something to the backup so it would give him access even if we couldnt , so he would reign supreme.
Thats who im after.
I wanna see this forum closed down.
please help. im prepared to do the work myself of course.

thanks for replying.
View user's profile Send private message
PostPosted: Mon Nov 26, 2007 6:18 am Reply with quote
Sm0ke
Moderator
Moderator
Joined: Nov 25, 2006
Posts: 141
Location: Finland




well it have 500 websites so if you could get shell up on one of those you can get in to your target Smile


check the site on this http://www.seologs.com/ip-domains.html
and start finding vulnerable sites
View user's profile Send private message
Please help. I'm a noob and im hungry for revenge
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.065 Seconds