About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-26, 18:03
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Talking Defacing websites

This is my aim.
Litle background info, I have phished for some time now. I had obtained the admin password at my school.

But we all really know that is small time, relativly unskilled. So I want to improve. I love the experience of hacking into anything, , the adrenaline rush is just immense.

Too be honest, when it comes to defacing websites I am clueless. I know MQsql injections can be used, but I don't know how to go from finding a vulnerability to exploiting it.

I know the basics of finding them, but then it is like..."well, what now? " I know from lurking a while back that Javascript can be used (you guys used it on a flash game website or something) where you used some Java to change the cookie to admin.

So, basically, tips, advice? I don't want to be spoonfed, more along the lines of pointing me in the right direction. Thanks very much NS&H
Reply With Quote
  #2   Add Prometheum to your ignore list  
Old 2008-07-26, 19:15
Prometheum Prometheum is online now
Regular
 
01 Send a message via AIM to Prometheum Send a message via MSN to Prometheum
Default Re: Defacing websites

You will learn far more by selecting a target (don't be too ambitious) and fully researching what it takes to gain knowledge of it than you will by saying "I want to deface websites", finding a canned vulnerability, and then going on your script-kiddie way and mowing down whatever fits the mark.
Reply With Quote
  #3   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-26, 19:30
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Default Re: Defacing websites

Okay, these faggots seem like good targets;
http://www.emo-corner.com/.
Erm, hypothetically, of couse
Watch this space, I will update with details.
Nmpa can't identift OS, but it looks to be windows in some form.
Also says something about a Urchin RSS aggreter.,

http://urchin.sourceforge.net/ Which is this thing here;

This ius there cookie;
114090387.1217100442.1.1.utmccn=(organic)|utmcsr=g oogle|utmctr=emo|utmcmd=organic

http://www.emo-corner.com/%271%27or%271%27 Also got that.

Server is Apache/2.0.54

Okay, I will admit it, I don't have a clue as of yet, just gathering info at moment.

Last edited by Neighbourhood-Sniper; 2008-07-26 at 19:57.
Reply With Quote
  #4   Add O RLY to your ignore list  
Old 2008-07-26, 20:21
O RLY O RLY is offline
Moderator
 
Padmasana Send a message via AIM to O RLY Send a message via MSN to O RLY
Talking Re: Defacing websites

Quote:
Originally Posted by Neighbourhood-Sniper View Post
Okay, these faggots seem like good targets;
http://www.emo-corner.com/.
Erm, hypothetically, of couse
Watch this space, I will update with details.
Nmpa can't identift OS, but it looks to be windows in some form.
Also says something about a Urchin RSS aggreter.,

http://urchin.sourceforge.net/ Which is this thing here;

This ius there cookie;
114090387.1217100442.1.1.utmccn=(organic)|utmcsr=g oogle|utmctr=emo|utmcmd=organic

http://www.emo-corner.com/%271%27or%271%27 Also got that.

Server is Apache/2.0.54

Okay, I will admit it, I don't have a clue as of yet, just gathering info at moment.


You're better off picking another target. Something that uses PHP, and has a lot going on. The more things going on for a certain website, the more chances of there being holes.
__________________
In Silence I lay for that Fateful Day. 0day.

jamato@email.itt-tech.edu <-- My Email
Reply With Quote
  #5   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-26, 20:43
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Default Re: Defacing websites

What about a chan? That would be epic
Obvoiouls hightened security would have to be done,but I have tor:


Promising results from Nmap

Quote:
C:\Documents and Settings\HP_Administrator.YOUR-E6F02835AE>nmap -v -A freechan.org

Starting Nmap 4.11 ( http://www.insecure.org/nmap ) at 2008-07-26 21:36 GMT Stan
dard Time
DNS resolution of 1 IPs took 16.50s.
Initiating SYN Stealth Scan against [1680 ports] at 21:37
Discovered open port 113/tcp on
Discovered open port 25/tcp on
Discovered open port 23/tcp on
Discovered open port 22/tcp on
Discovered open port 80/tcp on
Discovered open port 21/tcp on
Discovered open port 587/tcp on
Discovered open port 548/tcp on
Discovered open port 948/tcp on
The SYN Stealth Scan took 37.94s to scan 1680 total ports.
Initiating service scan against 9 services on at 21:37
The service scan took 62.03s to scan 9 services on 1 host.
Initiating RPCGrind Scan against at 21:38
The RPCGrind Scan took 2.27s to scan 1 ports on
For OSScan assuming port 21 is open, 1 is closed, and neither are firewalled
Host appears to be up ... good.
Interesting ports on :
Not shown: 1670 closed ports
PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.1
22/tcp open ssh OpenSSH 4.3p2 Debian 9etch2 (protocol 2.0)
23/tcp open telnet Linux telnetd
25/tcp open smtp Postfix smtpd
80/tcp open http Apache httpd 2.0.61 ((Unix) PHP/4.4.7 mod_ssl/2.0.6
1 OpenSSL/0.9.7e mod_fastcgi/2.4.2)
111/tcp filtered rpcbind
113/tcp open auth?
548/tcp open afpovertcp?
587/tcp open smtp Postfix smtpd
948/tcp open status 1 (rpc #100024)
Device type: general purpose
Running: Linux 2.4.X|2.5.X
OS details: Linux 2.4.0 - 2.5.20
Uptime 6.222 days (since Sun Jul 20 16:19:21 2008)
TCP Sequence Prediction: Class=random positive increments
Difficulty=2343695 (Good luck!)
IPID Sequence Generation: All zeros
Service Info: OSs: Unix, Linux

Nmap finished: 1 IP address (1 host up) scanned in 134.344 seconds
Raw packets sent: 1760 (77.960KB) | Rcvd: 1749 (70.640KB

Last edited by oddballz194; 2008-07-26 at 20:51. Reason: Removed IP address
Reply With Quote
  #6   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-26, 20:56
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Default Re: Defacing websites

http://f*******.org/mod_ssl/2.0.6
It syas that page ecist, but doesnt want to give it to me.
I could edit the cookie right?
Then I have mod control. Not quite bringing it down, BUT its something

Am I along the right lines here?
Reply With Quote
  #7   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-26, 21:04
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Default Re: Defacing websites

http://img254.imageshack.us/img254/8031/freechancookiewq1.th.png
This is the cookie that page produces.
What can I do with it?
I m launching google

Sorry, that image is tiny, it reads
Name : PostPassword
Content:YOOghR8y
Host www.f*******.org
Path/

I have an idea, instead of "postpassword" I put to GETpassword?

Last edited by Neighbourhood-Sniper; 2008-07-26 at 21:12.
Reply With Quote
  #8   Add sgaltair to your ignore list  
Old 2008-07-27, 03:47
sgaltair sgaltair is offline
Regular
 
Gainesville, Florida
Default Re: Defacing websites

Quote:
Originally Posted by Neighbourhood-Sniper View Post
http://f*******.org/mod_ssl/2.0.6
It syas that page ecist, but doesnt want to give it to me.
I could edit the cookie right?
Then I have mod control. Not quite bringing it down, BUT its something

Am I along the right lines here?
I am fairly sure the mod_ssl is actually a module for apache webserver.

http://httpd.apache.org/docs/trunk/mod/mod_ssl.html
Reply With Quote
  #9   Add Nightside Eclipse to your ignore list  
Old 2008-07-27, 04:16
Nightside Eclipse Nightside Eclipse is offline
Regular
 
Black Metal Elite
Default Re: Defacing websites

Quote:
Originally Posted by Neighbourhood-Sniper View Post
What about a chan? That would be epic
Obvoiouls hightened security would have to be done,but I have tor:


Promising results from Nmap
Wow theres a ton of open ports there
Reply With Quote
  #10   Add Neighbourhood-Sniper to your ignore list  
Old 2008-07-27, 10:09
Neighbourhood-Sniper Neighbourhood-Sniper is offline
Regular
 
Default Re: Defacing websites

http://freechan.org/mod_ssl/2.0.6/ss...%5C%22%20%b%22

Any use here?
Reply With Quote
This thread continued for 5 pages in the real archive, 41 posts total - only page 1 survived here.
Reply

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics