Waraxe IT Security Portal  
  Login or Register
::  Home  ::  Search  ::  Your Account  ::  Forums  ::   Waraxe Advisories  ::  Tools  ::
April 25, 2024
Menu
 Home
 Logout
 Discussions
 Forums
 Members List
 IRC chat
 Tools
 Base64 coder
 MD5 hash
 CRC32 checksum
 ROT13 coder
 SHA-1 hash
 URL-decoder
 Sql Char Encoder
 Affiliates
 y3dips ITsec
 Md5 Cracker
 User Manuals
 AlbumNow
 Content
 Content
 Sections
 FAQ
 Top
 Info
 Feedback
 Recommend Us
 Search
 Journal
 Your Account



User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9145

People Online:
Visitors: 778
Members: 0
Total: 778
PacketStorm News
·301 Moved Permanently

read more...
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index
Search found 7 matches
Going from superAdmin to direct database access
PostForum: PhpNuke   Posted: Fri Oct 20, 2006 12:42 am   Subject: Going from superAdmin to direct database access
nicknomo
 
Replies: 0
Views: 8196




Ok, so lets say hypothetically that a hacker has compromised your phpNuke account and has achieved super admin access. Would there be a way of discovering the location of your database, or database ...
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 2:32 pm   Subject: More needed than just Hash: phpBBmysql_sid
nicknomo
 
Replies: 11
Views: 14300




found out a solution

While I couldn't figure out how to display both, I did figure out how to display the username in the same order the passwords are displayed.

http://localhost/modules.php?nam ...
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 4:35 am   Subject: More needed than just Hash: phpBBmysql_sid
nicknomo
 
Replies: 11
Views: 14300




sorry if that came out wrong..

I was wondering if there was a way to get the hash for a specific user id.

I've tried:

http://[site here]/modules.php?name=Top&querylang=union%20select%200, ...
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 4:25 am   Subject: More needed than just Hash: phpBBmysql_sid
nicknomo
 
Replies: 11
Views: 14300




Well I've tried

http://[site here]/modules.php?name=Top&querylang=union%20select%200,pwd,0,0%20from%20nuke_users%20where%20user_id=MYNAME

and it turns up no results. Is my syntax wrong?
...
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 4:15 am   Subject: More needed than just Hash: phpBBmysql_sid
nicknomo
 
Replies: 11
Views: 14300




Also I noticed wit hthe users that the hashes don't match up with the user names when I display them...

I'm not sure how I would format the query to search for a hash based on a user name... Anyone ...
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 3:54 am   Subject: no dice
nicknomo
 
Replies: 11
Views: 14300




unfortunately, there is only one admin

This is actually the exploit I used to get the hashes in the first place. Does this mean I'm screwed?
More needed than just Hash: phpBBmysql_sid
PostForum: PhpBB   Posted: Wed Nov 02, 2005 2:39 am   Subject: More needed than just Hash: phpBBmysql_sid
nicknomo
 
Replies: 11
Views: 14300




I'm working off of a board with php-Nuke. It appears to be using version 7.0, and a yet to be identified version of phpBB.

I read the cookie tutorial in this forum, but it appears to be missing cr ...
Page 1 of 1
All times are GMT
  




Powered by phpBB © 2001-2008 phpBB Group






Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2020 Janek Vind "waraxe"
Page Generation: 0.205 Seconds