|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2002-09-03, 13:08
|
ZouZ 
Regular
|
|
|
|
CGI vulnerability
I need Help About CGI Vulnerability.. I know The Basics. N i Found Some Holes In Some Websites.. But i Dunno How to Use them.. Holes Like.. PWD Hole PWF Hole Hole: VTI BIN [shtml.dll] Hole: VTI BIN [shtml.exe] Hole: VTI INF [_vti_inf.html] Can Anybody Help Please ... Thanks
|
|
#2
 2002-09-03, 14:11
|
phender 
Regular
|
|
|
|
Re: CGI vulnerability
I dont know what youre talking about with these CGI vuln's but I really suggest that you read A LOT of texts and tech books before trying to exploit anything because otherwise it will be very hard to understand what is going on in the exploit and most of the time it will not work, but if you want to skip it and just go straight to exploitation, be my guest, aklthough I wouldn't reccomend this.
|
|
#3
 2002-09-04, 09:20
|
ZouZ 
Regular
|
|
|
|
Re: CGI vulnerability
well man.. remember the hacking tutorial that you told me to download.. it had somethin about CGI vulnerability but it wasn't really detailed.. so that's y i was askin.. hope somebody will help
|
|
#4
 2002-09-04, 18:19
|
cense 
Regular
|
|
|
|
Re: CGI vulnerability
Firstly, define a few thingst to yourself:
What CGI stands for? What that acronym mean to you? How does CGI work?. These simple questions are the first questions you should ask yourself. Knowing the system will allow you to understand what has to be done to break it, and more importantly WHY it has to be done.
Understanding is far more powerful than immatiating.
|
|
#5
 2002-09-06, 10:49
|
skalez 
Regular
|
|
|
|
Re: CGI vulnerability
find a list of stuff that you can run from shtml.exe/shtml.dll
i know i've read of about a billion different exploits using them, but i can't remember them. use google, it's cool
|
|
#6
 2002-09-07, 10:06
|
daydreamer 
Regular
|
|
|
|
Re: CGI vulnerability
The first thing I would do is check manually wether the cgis really exist on the webserver. Most scanners work like this: 1. Make a request for the cgi 2. Analyze the response If the errormessage is userdefined, most scanners will give a false alert, because they don't mention it as an error message. The vulnerabilities you mentioned are verry old and I woudn't scan for phf since apache might log any attemp to access it. You would see something like this: Thanks for supporting the fight against hackers. Your IP has benn logged and send to the administrator. You have a really little chance that phf is still installed. Try to understand how cgi-vulnerabilities work. Make a search on input validation vulnerabilities and insecure system calls etc. Good luck! I hope i didn't make too much spelling misstakes, I'm Swiss.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|