|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
# 1

2008-07-26, 18:03
|
|
|
Defacing websites
This is my aim.
Litle background info, I have phished for some time now. I had obtained the admin password at my school.
But we all really know that is small time, relativly unskilled. So I want to improve. I love the experience of hacking into anything, , the adrenaline rush is just immense.
Too be honest, when it comes to defacing websites I am clueless. I know MQsql injections can be used, but I don't know how to go from finding a vulnerability to exploiting it.
I know the basics of finding them, but then it is like..."well, what now? " I know from lurking a while back that Javascript can be used (you guys used it on a flash game website or something) where you used some Java to change the cookie to admin.
So, basically, tips, advice? I don't want to be spoonfed, more along the lines of pointing me in the right direction. Thanks very much NS&H 
|
# 2

2008-07-26, 19:15
|
|
Regular
|
|
01
|
|
Re: Defacing websites
You will learn far more by selecting a target (don't be too ambitious) and fully researching what it takes to gain knowledge of it than you will by saying "I want to deface websites", finding a canned vulnerability, and then going on your script-kiddie way and mowing down whatever fits the mark.
|
# 3

2008-07-26, 19:30
|
|
|
Re: Defacing websites
Okay, these faggots seem like good targets;
http://www.emo-corner.com/.
Erm, hypothetically, of couse 
Watch this space, I will update with details.
Nmpa can't identift OS, but it looks to be windows in some form.
Also says something about a Urchin RSS aggreter.,
http://urchin.sourceforge.net/ Which is this thing here;
This ius there cookie;
114090387.1217100442.1.1.utmccn=(organic)|utmcsr=g oogle|utmctr=emo|utmcmd=organic
http://www.emo-corner.com/%271%27or%271%27 Also got that.
Server is Apache/2.0.54
Okay, I will admit it, I don't have a clue as of yet, just gathering info at moment.
Last edited by Neighbourhood-Sniper; 2008-07-26 at 19:57.
|
# 4

2008-07-26, 20:21
|
|
Moderator
|
|
Padmasana
|
|
Re: Defacing websites
Quote:
Originally Posted by Neighbourhood-Sniper
Okay, these faggots seem like good targets;
http://www.emo-corner.com/.
Erm, hypothetically, of couse 
Watch this space, I will update with details.
Nmpa can't identift OS, but it looks to be windows in some form.
Also says something about a Urchin RSS aggreter.,
http://urchin.sourceforge.net/ Which is this thing here;
This ius there cookie;
114090387.1217100442.1.1.utmccn=(organic)|utmcsr=g oogle|utmctr=emo|utmcmd=organic
http://www.emo-corner.com/%271%27or%271%27 Also got that.
Server is Apache/2.0.54
Okay, I will admit it, I don't have a clue as of yet, just gathering info at moment.
|
You're better off picking another target. Something that uses PHP, and has a lot going on. The more things going on for a certain website, the more chances of there being holes.
__________________
In Silence I lay for that Fateful Day. 0day.
jamato@email.itt-tech.edu <-- My Email
|
# 5

2008-07-26, 20:43
|
|
|
Re: Defacing websites
What about a chan? That would be epic 
Obvoiouls hightened security would have to be done,but I have tor:
Promising results from Nmap
Quote:
C:\Documents and Settings\HP_Administrator.YOUR-E6F02835AE>nmap -v -A freechan.org
Starting Nmap 4.11 ( http://www.insecure.org/nmap ) at 2008-07-26 21:36 GMT Stan
dard Time
DNS resolution of 1 IPs took 16.50s.
Initiating SYN Stealth Scan against [1680 ports] at 21:37
Discovered open port 113/tcp on
Discovered open port 25/tcp on
Discovered open port 23/tcp on
Discovered open port 22/tcp on
Discovered open port 80/tcp on
Discovered open port 21/tcp on
Discovered open port 587/tcp on
Discovered open port 548/tcp on
Discovered open port 948/tcp on
The SYN Stealth Scan took 37.94s to scan 1680 total ports.
Initiating service scan against 9 services on at 21:37
The service scan took 62.03s to scan 9 services on 1 host.
Initiating RPCGrind Scan against at 21:38
The RPCGrind Scan took 2.27s to scan 1 ports on
For OSScan assuming port 21 is open, 1 is closed, and neither are firewalled
Host appears to be up ... good.
Interesting ports on :
Not shown: 1670 closed ports
PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.1
22/tcp open ssh OpenSSH 4.3p2 Debian 9etch2 (protocol 2.0)
23/tcp open telnet Linux telnetd
25/tcp open smtp Postfix smtpd
80/tcp open http Apache httpd 2.0.61 ((Unix) PHP/4.4.7 mod_ssl/2.0.6
1 OpenSSL/0.9.7e mod_fastcgi/2.4.2)
111/tcp filtered rpcbind
113/tcp open auth?
548/tcp open afpovertcp?
587/tcp open smtp Postfix smtpd
948/tcp open status 1 (rpc #100024)
Device type: general purpose
Running: Linux 2.4.X|2.5.X
OS details: Linux 2.4.0 - 2.5.20
Uptime 6.222 days (since Sun Jul 20 16:19:21 2008)
TCP Sequence Prediction: Class=random positive increments
Difficulty=2343695 (Good luck!)
IPID Sequence Generation: All zeros
Service Info: OSs: Unix, Linux
Nmap finished: 1 IP address (1 host up) scanned in 134.344 seconds
Raw packets sent: 1760 (77.960KB) | Rcvd: 1749 (70.640KB
|
Last edited by oddballz194; 2008-07-26 at 20:51.
Reason: Removed IP address
|
# 6

2008-07-26, 20:56
|
|
|
Re: Defacing websites
http://f*******.org/mod_ssl/2.0.6
It syas that page ecist, but doesnt want to give it to me.
I could edit the cookie right?
Then I have mod control. Not quite bringing it down, BUT its something
Am I along the right lines here?
|
# 7

2008-07-26, 21:04
|
|
|
Re: Defacing websites
http://img254.imageshack.us/img254/8031/freechancookiewq1.th.png
This is the cookie that page produces.
What can I do with it?
I m launching google
Sorry, that image is tiny, it reads
Name : PostPassword
Content:YOOghR8y
Host www.f*******.org
Path/
I have an idea, instead of "postpassword" I put to GETpassword?
Last edited by Neighbourhood-Sniper; 2008-07-26 at 21:12.
|
# 8

2008-07-27, 03:47
|
|
Regular
|
|
Gainesville, Florida
|
|
Re: Defacing websites
Quote:
Originally Posted by Neighbourhood-Sniper
http://f*******.org/mod_ssl/2.0.6
It syas that page ecist, but doesnt want to give it to me.
I could edit the cookie right?
Then I have mod control. Not quite bringing it down, BUT its something
Am I along the right lines here?
|
I am fairly sure the mod_ssl is actually a module for apache webserver.
http://httpd.apache.org/docs/trunk/mod/mod_ssl.html
|
# 9

2008-07-27, 04:16
|
|
Regular
|
|
Black Metal Elite
|
|
Re: Defacing websites
Quote:
Originally Posted by Neighbourhood-Sniper
What about a chan? That would be epic 
Obvoiouls hightened security would have to be done,but I have tor:
Promising results from Nmap
|
Wow theres a ton of open ports there 
|
# 10

2008-07-27, 10:09
|
|
|
Re: Defacing websites
http://freechan.org/mod_ssl/2.0.6/ss...%5C%22%20%b%22
Any use here?
|
This thread continued for 5 pages in the real archive, 41 posts total - only page 1 survived here.
| Thread Tools |
 Show Printable Version
 Email this Page
|
| Display Modes |
Linear Mode
 Switch to Hybrid Mode
 Switch to Threaded Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|