About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2005-01-07, 23:14
sniper22 sniper22 is offline
Regular
 
Default Exploiting a server

Some of you might remember my last post. That was a joke. :tru said this would be the place to come if I had a real question about hacking. And :tru, yelling at it hasn't worked so far.

So I have a server that I am completely able to legally test out the security by trying to hack it (I have permission). My problem comes in that I am not extremely good at hacking. I have run nmap against it and found the open ports (this is a webserver, listening on the HTTPS port).

I am curious as to how I go about finding the software they use on the server for each individual port that is open and also the version number. From there I believe all I do is research known exploits for that version and then execute the exploit. If you have a favorite website for new exploit, please post. Also, if that is incorrect, please correct me.

[This message has been edited by sniper22 (edited 01-09-2005).]
 #2 
Old 2005-01-08, 00:25
cvh cvh is offline
Regular
 
Default Re: Exploiting a server

If you have used nmap against the server then:

Use this commando for netcat to get the banner (services name + version number + more) from the sercives that listens on that open port nc -vv -w2 xx.xxx.xx.xx 21 23 25 80 110 (where xxx.xxx.xxx.xxx is the ip adress and the other numbers are the open ports, you can quickly write a script to use netcat to scan the complete server to not only know if the ports are open but directly knowing the banner).

Then go to a security site thats hosts a collection of exploits something like http://www.securityfocus.com/bid and search for your services and look if that version is vulnerable, this simple tut explains on how to compile and use the exploits http://clarozamesa.atspace.org/tutorials/16.htm

If all of the services aren't vulnerable, you look at the website itself. Does it host a board and is it vulnerable (phpbb <= 2.10 are highly vulnerable), do they use php if so try the newest exploits against php if you don't know what version they use.

They will probably use sql so try to know which version, also look for phpmyadmin (gui for sql server its almost always vulnerable).

If nothing is vulnerable, then try some xss (http://www.h4ckerx.net/article.php?story=20020927075119197)

and sql injection (use google for finding white papers about sql injection something like this one http://www.spidynamics.com/papers/SQLInjectionWhitePaper.pdf)

If you tried all of this and nothing isvulnerable (highly unlikely ) you can ask for some more techniques, but this should be sufficient.
 #3 
Old 2005-01-09, 01:03
sniper22 sniper22 is offline
Regular
 
Default Re: Exploiting a server

You're kick ass. :tru, you were right; Totse is a bit better than LEH.

So anyways, am I supposed to use netcat locally or would it be just as effective if it were remote?
 #4 
Old 2005-01-09, 16:02
DeathShadow DeathShadow is offline
Regular
 
Default Re: Exploiting a server

remote will work.
 #5 
Old 2005-01-09, 20:57
Geeksta Geeksta is offline
Regular
 
Default Re: Exploiting a server

www.securityfocus.com (http://www.securityfocus.com) has many of the latest sercurity holes and flaws

www.linuxsecurity.com (http://www.linuxsecurity.com) (or .org i dont remeber) has the latest for linux servers

www.astalavista.com (http://www.astalavista.com) has many exploit tutorials and tips on exploiting
 #6 
Old 2005-01-09, 21:08
document 057 document 057 is offline
Regular
 
Default Re: Exploiting a server

research SSI- side scroll inquery---- ou unix in url or advanced sql(with this you can write your own page, kinda add it in with your own password and you'll be in-- unix codes in the right places can show you paswords-- javainjects-- fuck dude the list goes on-- good luck- 057
 #7 
Old 2005-01-10, 03:28
Regular
 
Sierra Vista, Arizona
Default Re: Exploiting a server

quote:Originally posted by document 057:

research SSI- side scroll inquery-057

Your a fucking reject SSI is Server Side includes not Scroll side inquiry you dumbfuck.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics