| 
	|  |  |  |  
        
          | 
              
                | 
                    
                      | 
                          
                            | 
	| 
	
		|  |  |  
		|  | IT Security and Insecurity Portal |  |  
 
	|  | PhpBB <= 2.0.20 Admin/Restore Database remote cmmnds xctn |  |  
	| 
	
		|  Posted: Sat May 13, 2006 8:03 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| retrog |  | Beginner |  |  
  |  |  |  | Joined: Apr 09, 2006 |  | Posts: 1 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Sun May 14, 2006 5:12 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| szmatlawiec |  | Regular user |  |  
  |  |  |  | Joined: May 14, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| hi, how to use this php exploit ? its just showing me the source of file like this: 
 
  	  | Code: |  	  | #!/usr/bin/php -q -d short_open_tag=on PhpBB <= v2.0.20 "Admin/Restore Database/default_lang remote commands execution by rgod rgod@autistici.org site: http://retrogod.altervista.org -> you need an admin sid, works regardless of magic_quotes_gpc settings tested and working against a fresh PhpBB installation Usage: php host path sid cmd OPTIONS host: target server (ip/hostname) path: path to PhpBB sid: session id cmd: a shell command Options: -p[port]: specify a port other than 80 -P[ip:port]: specify a proxy Examples: php localhost /phpbb/ 8db5cef976c7e0f51c25c92152b56881 cat config.php php localhost /phpbb/ 8db5cef976c7e0f51c25c92152b56881 ls -la -p81 php localhost / 8db5cef976c7e0f51c25c92152b56881 ls -la -P1.1.1.1:80 | 
 
 thanks in advance
 
 edit:/
 
 or maybe anyone can explain to me, how to use php srcipts with this on top:
 
  	  | Code: |  	  | #!/usr/bin/php -q -d short_open_tag=on | 
 ?
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Mon May 15, 2006 9:29 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| sljyro |  | Advanced user |  |  
  |  |  |  | Joined: Mar 23, 2006 |  | Posts: 53 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| yeah i would like to know the above too, thanks. |  |  
		|  |  |  
	|  |  
	|  | Re: PhpBB <= 2.0.20 Admin/Restore Database remote cmmnds |  |  
	| 
	
		|  Posted: Tue May 16, 2006 2:13 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| 
 pls tell me more about how to get the session id
 
 when the admin klick on some link, the sid can be retrieved??
 
 greetz ketchup
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 3:03 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| szmatlawiec |  | Regular user |  |  
  |  |  |  | Joined: May 14, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 5:18 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| 
 i have tested this exploit on my own forums. Its easy.
 
 You need active perl for windows, install this first
 
 save perl script in .pl file with notepad or something path e.g. in c:\
 
 then open cmd (command prompt)
 
 run perl script by typing: "perl nameofperlscripthere.pl"
 
 in linux:
 
 do the same in console
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 5:34 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| 
 this sucks because in freshly installed phpbb html is turned off and you would
 have to be a huge retard to turn it on
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 5:43 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 5:51 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| szmatlawiec |  | Regular user |  |  
  |  |  |  | Joined: May 14, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| ketchup, you can pm admin with link to cookie stealer, just change name to something like index.php and upload it on some site with nice address and tell him in pm something like: hey check this out, its some cool site with phpbb themes or something, just think ;p 
 OR we can do like this... i will help you to steal cookie and you will tell me how to use this php exploit
  ? |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Tue May 16, 2006 8:42 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			|  	  | szmatlawiec wrote: |  	  | ketchup, you can pm admin with link to cookie stealer, just change name to something like index.php and upload it on some site with nice address and tell him in pm something like: hey check this out, its some cool site with phpbb themes or something, just think ;p 
 OR we can do like this... i will help you to steal cookie and you will tell me how to use this php exploit
  ? | 
 
 okay, what dont you understand about the exploit?
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue May 16, 2006 9:53 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| szmatlawiec |  | Regular user |  |  
  |  |  |  | Joined: May 14, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		| 
		
			| 
 Last edited by szmatlawiec on Wed May 17, 2006 1:06 am; edited 1 time in total
 |  |  |  
	|  |  
	| 
	
		|  Posted: Wed May 17, 2006 12:43 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| trace |  | Regular user |  |  
  |  |  |  | Joined: May 17, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| Thanks for sharing, although I dont's know how to use it to a nicety |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Wed May 17, 2006 3:06 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| ketchup |  | Regular user |  |  
  |  |  |  | Joined: May 16, 2006 |  | Posts: 23 |  | Location: no |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| 
 wtf
 
 run it on your computer, dont upload it
  |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Wed May 17, 2006 11:52 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| szmatlawiec |  | Regular user |  |  
  |  |  |  | Joined: May 14, 2006 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| on apache with intsalled php its still not working, so how? tell me how you used it? and how it works then?  |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Wed May 17, 2006 1:09 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| Chb |  | Valuable expert |  |  
  |  |  |  | Joined: Jul 23, 2005 |  | Posts: 206 |  | Location: Germany |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			|  	  | szmatlawiec wrote: |  	  | on apache with intsalled php its still not working, so how? tell me how you used it? and how it works then?  | 
 
 And why not?
   Otherwise try using "php <file>" in console.
 |  |  
		|  |  |  
	|  |  
	| www.waraxe.us Forum Index -> PhpBB 
 
	
		| You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 | All times are GMT Page 1 of 2
			Goto page 1, 2Next
 
 |  |  
	|  |  
 Powered by phpBB © 2001-2008 phpBB Group
 
 
 
 
 |  |  |  |  |