About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-09-03, 13:08
ZouZ ZouZ is offline
Regular
 
Default CGI vulnerability

I need Help About CGI Vulnerability..
I know The Basics. N i Found Some Holes In Some Websites.. But i Dunno How to Use them..
Holes Like..
PWD Hole
PWF Hole
Hole: VTI BIN [shtml.dll]
Hole: VTI BIN [shtml.exe]
Hole: VTI INF [_vti_inf.html]
Can Anybody Help Please ...
Thanks
 #2 
Old 2002-09-03, 14:11
phender phender is offline
Regular
 
Default Re: CGI vulnerability

I dont know what youre talking about with these CGI vuln's but I really suggest that you read A LOT of texts and tech books before trying to exploit anything because otherwise it will be very hard to understand what is going on in the exploit and most of the time it will not work, but if you want to skip it and just go straight to exploitation, be my guest, aklthough I wouldn't reccomend this.
 #3 
Old 2002-09-04, 09:20
ZouZ ZouZ is offline
Regular
 
Default Re: CGI vulnerability

well man..
remember the hacking tutorial that you told me to download..
it had somethin about CGI vulnerability
but it wasn't really detailed..
so that's y i was askin..
hope somebody will help
 #4 
Old 2002-09-04, 18:19
cense cense is offline
Regular
 
Default Re: CGI vulnerability

Firstly, define a few thingst to yourself:

What CGI stands for? What that acronym mean to you? How does CGI work?. These simple questions are the first questions you should ask yourself. Knowing the system will allow you to understand what has to be done to break it, and more importantly WHY it has to be done.

Understanding is far more powerful than immatiating.
 #5 
Old 2002-09-06, 10:49
skalez skalez is offline
Regular
 
Default Re: CGI vulnerability

find a list of stuff that you can run from shtml.exe/shtml.dll

i know i've read of about a billion different exploits using them, but i can't remember them. use google, it's cool
 #6 
Old 2002-09-07, 10:06
daydreamer daydreamer is offline
Regular
 
Default Re: CGI vulnerability

The first thing I would do is check manually wether the cgis really exist on the webserver. Most scanners work like this:
1. Make a request for the cgi
2. Analyze the response
If the errormessage is userdefined, most scanners will give a false alert, because they don't mention it as an error message. The vulnerabilities you mentioned are verry old and I woudn't scan for phf since apache might log any attemp to access it. You would see something like this:
Thanks for supporting the fight against hackers. Your IP has benn logged and send to the administrator.
You have a really little chance that phf is still installed. Try to understand how cgi-vulnerabilities work. Make a search on input validation vulnerabilities and insecure system calls etc. Good luck! I hope i didn't make too much spelling misstakes, I'm Swiss.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics