|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2004-12-21, 07:38
|
marleyandmarley 
Regular
|
|
|
|
phpBB 2.0.10 & 2.0.11
OK apparently there is a flaw where as you can execute sql commands in live threads, this is all the info I have on it (unfortunately people dont like giving out a lot of info about it):
"If you turn all ascii characters into char() (decimal), and change any variable on the page in a live thread to have a mysql query in it, and every character of the query, it will execute the command.
Make sure no one knows what your tables are named. "
If anyone could help me, that would be great (I realize this is very n00bish, but I really wanna learn how to do it)
|
|
#2
 2004-12-21, 07:51
|
Doc 057 
Regular
|
|
|
|
Re: phpBB 2.0.10 & 2.0.11
dependz on the security-- sometimes sql goes just in login user -- 'or 1=1-- in user- password URL and rewrite page-- be specific-- i am getting fairly good with sql- i can help- be specific if u can-
u could try URL javainject or sql--- index.php/cmd/etc. exploits or a stupid simple update.php?= could work-- trial and error killer-- let me know if u need help--i'm horrible with explaining unless u can be specific----------
document 057
[This message has been edited by Doc 057 (edited 12-21-2004).]
|
|
#3
 2004-12-21, 08:06
|
marleyandmarley 
Regular
|
|
|
|
Re: phpBB 2.0.10 & 2.0.11
well yah, I am good with PHP & MySQL, I am actually developing my own board system right now, and have severely modified my own DiscoBoard. But all I know is what I posted in the first post. Someone posted it on IGN, and thats all they would say, so I was hoping someone here would know about it.
But I am pretty sure it is some form of sql injection.
|
|
#4
 2004-12-21, 09:41
|
Doc 057 
Regular
|
|
|
|
Re: phpBB 2.0.10 & 2.0.11
from what i understand even if you r good with web design u are still vulnerable to an SQL, java, ELO, email forgeing 4 passwords or half a dozen other exploits-- i think pearl is a good alternative? but there are peral exploits too-- if u wanna keep out script kidz then u sound like you can but unfortunately no matter what, i dont think you can keep out a dedicated hacker 'cause they will try every little thing and succed in something-- i'm working with peoplez right now that could crack any site in a few minutes 'or hours(depending on secutiy) so don't feel like you can keep every1 out-soory 'bout the spelling, i type fast & been drankin' too, fuck corrects-- i guess just look up exploits and cover them as best you can but there are so many it can be difficult-- that's why i never list my home on hacker prone sites- -- oh! don't forget to disable SSIs-- google on SSI for admin use only-- i don't do great webpagez but keep out SSI unix commands-once again, sorry if i'm being vague but there is just too much ground to cover if you aren't building a site for secure online banking-057
[This message has been edited by Doc 057 (edited 12-21-2004).]
|
|
#5
 2004-12-21, 21:49
|
marleyandmarley 
Regular
|
|
|
|
Re: phpBB 2.0.10 & 2.0.11
Well I got some more info on the hack:
All it really involves is changing a GET variable to a mysql_query command, and then changing every single letter to char() decimal.
There's one more step that involves an unchecked character but I really already said too much and anyone who really wants to know can google it.
search through your logfiles for lines with "viewtopic" and "system" in them, and a whole bunch of characters like
252echr(110)%252echr(97)%252echr(109)%252echr(101) )%252e%25
This is like a fuckin puzzle trying to piece it all together
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|