Post: Hacking with a shell by VipVince.
11-11-2010, 02:35 PM #1
VipVince
Save Point
(adsbygoogle = window.adsbygoogle || []).push({}); Ok, I will show you via images how I successfully uploaded a c99 shell on a hacked site.

First I obtained the Admin login details via Sqli, I then found the login prompt, and successfully logged in.

You must login or register to view this content.

Secondly, I browsed around looking for something interesting, I found the login details to the MySQL server of the website.

You must login or register to view this content.

I finally found an image upload function, lets change our shell to php.gif format and attempt to upload it.

You must login or register to view this content.

Damn, must be patched to prevent this, lets keep looking...

You must login or register to view this content.

Interesting, I found a template modifier that lets me edit the code of different functions and plug in's on the website.

You must login or register to view this content.

Lets try removing the current source code and adding c99 shell source code then saving it.

You must login or register to view this content.

It saved successfully, now the problem is locating that function on the website and making it run, I try different variable path's in the URL trying to find a directory that the file might be saved in, Eg /files/ /uploads/ /plugins/ etc. I experienced error messages like below, telling me that directory did not exist.

You must login or register to view this content.

I finally guess correct with the directory /themes/

You must login or register to view this content.

Remember, the msg.php plug in's theme name was classic, so with that we can assume the URL to the shell would be www.site.com/themes/classic/msg.php, I run this and get the following result.

You must login or register to view this content.

Voila my c99 shell is now on the site, the possibility's now are endless. Happy Hacking :blackhat:

**Link to shells* You must login or register to view this content.
11-11-2010, 07:12 PM #2
Default Avatar
Oneup
Guest
Not actually hacking if you are using someone else's work, that just makes you a skiddie
11-11-2010, 07:42 PM #3
Sempiternal
Previously uG~ Wounded
Originally posted by UP View Post
Not actually hacking if you are using someone else's work, that just makes you a skiddie


This is his thread :confused: Why do you think that he did not write this. Did you do any research to back up your claim? If you did, you would have found that this thread is his.
11-11-2010, 07:43 PM #4
VipVince
Save Point
Originally posted by UP View Post
Not actually hacking if you are using someone else's work, that just makes you a skiddie


The thread was written and demonstrated by me, if you are referring to not coding my own shell as skiddie, then I bet your hacking expertise is far minimal to your verbal statements, I have seen alot of threads on here like 'how do i port forward' and 'how do i scan ports' that is what I regard as skiddie, but rooting a server with someone else's shell is not skiddie, do you honestly think top hackers go to the bother of coding their own shells when they do not have to, have you ever coded a shell? I have yet to see any r00ting tuts on here, or cross site scripting threads, or blind sql injection threads, or even a thread on compiling exploits, yet you want to call this skiddie. Get off your high horse.
11-11-2010, 07:50 PM #5
Sempiternal
Previously uG~ Wounded
Sorry to say this 1_UP, But you just got OWNED! Happy

The following user thanked Sempiternal for this useful post:

Bad Luck Brian
11-11-2010, 07:58 PM #6
And that was so hard. The real tut is how to get login you fail lol
11-11-2010, 08:02 PM #7
VipVince
Save Point
Originally posted by Ag3nt View Post
And that was so hard. The real tut is how to get login you fail lol


How to get login? I stated at the start of the tutorial, the login credentials were obtained via Sqli, you make it seem with your statement that knowing Sqli is difficult or 'hard', specify how I fail, I officly got login to upload the shell in the first place, and evidence of this was presented via the screen shot, so once again mind telling me how I 'fail'?
11-11-2010, 08:06 PM #8
Originally posted by VipVince View Post
How to get login? I stated at the start of the tutorial, the login credentials were obtained via Sqli, you make it seem with your statement that knowing Sqli is difficult or 'hard', specify how I fail, I officly got login to upload the shell in the first place, and evidence of this was presented via the screen shot, so once again mind telling me how I 'fail'?


You should make a tut on how to get login with SQLi. If your saying I think that SQLi is hard, yes I do. I am no nerd, nor am I a 4o year old fat ass.
11-11-2010, 08:13 PM #9
VipVince
Save Point
Originally posted by Ag3nt View Post
You should make a tut on how to get login with SQLi. If your saying I think that SQLi is hard, yes I do. I am no nerd, nor am I a 4o year old fat ass.


Well how can you tell me I 'fail' when you are struggling to learn sqli, and I just used it to get the admin login details to the site I just posted screen shots off, do you know how to upload shells? Get back connections? Add back door's to websites to connect to via command prompt? Compile local root exploits? Use gcc commands to compile and run C language exploits? R00t servers? Mass deface sites? I dont think so, so dont tell me I 'fail' simply because I did not explain what you have yet to learn, little man.
11-11-2010, 08:28 PM #10
Default Avatar
Oneup
Guest
Originally posted by VipVince View Post
The thread was written and demonstrated by me, if you are referring to not coding my own shell as skiddie, then I bet your hacking expertise is far minimal to your verbal statements, I have seen alot of threads on here like 'how do i port forward' and 'how do i scan ports' that is what I regard as skiddie, but rooting a server with someone else's shell is not skiddie, do you honestly think top hackers go to the bother of coding their own shells when they do not have to, have you ever coded a shell? I have yet to see any r00ting tuts on here, or cross site scripting threads, or blind sql injection threads, or even a thread on compiling exploits, yet you want to call this skiddie. Get off your high horse.


No actually it's not "hacking" you are just using someone else's script to do everything and yes hackers do make their own scripts(that's how they got there for you to use and then later make a thread)They had to come from someone who actually knows programming. You can bash and flame but all I simply stated was that it's not really hacking and then you were into a nerd rage over it.

Kinda like someone making a phishing page and then saying they owned someone. So calm down there and back away from that keyboard and take a breather, I wasn't calling you specifically a sciddie, I just said that's what it is.


Originally posted by another user
This is his thread Why do you think that he did not write this. Did you do any research to back up your claim? If you did, you would have found that this thread is his.



Those shells have been around for quite some time. I doubt he wrote anything related to them other than this thread

Originally posted by another user
Well how can you tell me I 'fail' when you are struggling to learn sqli, and I just used it to get the admin login details to the site I just posted screen shots off, do you know how to upload shells? Get back connections? Add back door's to websites to connect to via command prompt? Compile local root exploits? Use gcc commands to compile and run C language exploits? R00t servers? Mass deface sites? I dont think so, so dont tell me I 'fail' simply because I did not explain what you have yet to learn, little man.


Don't mind him, he considers anything that can't be google searched in a second or two hard
Last edited by Oneup ; 11-11-2010 at 08:32 PM.

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo