Topic: "Stupid admins :-)" (page 1 of 2)

1 2 >
Author Post
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
No this thread is not about Erik and me:clock:
When I am online I use proxomitron most of the time.
With this really convenient tool you can change headers pretty easily.
I guess you can do the same stuff just with Firefox but I am used to this little helper.

Many websites log your header information or just echo it back to you.
I am not a trouble maker but I like to edit my referer/user-agent to something like this:

It doesn' UNION SELECT'"
"><script type="javascript/text">alert('hello');</script><"

You might wonder why I do such mean stuff but it is really fun to find stupid web applications
:phones:

Just check out: xxxx
PS: The referer I used was: It doesn' UNION SELECT'"

I wrote this little post just because I have been bored :idiot:
Edited by theblacksheep on 12.03.2005 08:38:43
private message EMail Website
rayden5
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Well,

not much to say, if you check the buttom :

PHP-Nuke Copyright ©

LOL =) Good job tbs *G*

Ray
private message
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
I haven't even looked at that. This site uses alot of quite old scripts.
Do you think it has something to do with php nuke or maybe one of the other scripts?
Haven't used php nuke so I don't know if it has such a function (logging referers)
Edited by theblacksheep on 11.03.2005 18:26:41
private message EMail Website
rayden5
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
I think it is an PHP nuke issue, yes. Since php Nuke is THE exploitable PHP template out there :)
...iam not sure if the Version used is the latest one..anyway PHP Nuke MUST be exploited ;)

Ray
private message
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
There is one thing I always wanted to know:
How to figure out the name of a database, all tables and fields in it? (MySQL)
Do I have to use: "INFORMATION_SCHEMA" tables?
Often I do not have access to it.
Edited by theblacksheep on 12.03.2005 08:53:43
private message EMail Website
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
edited
Edited by theblacksheep on 12.03.2005 08:53:27
private message EMail Website
unknown user
Hi ,-

its me you are trying to hack.
If you are ready with trying out your silly games, please let me now, so i can continue doing my usual jobs.
Make my day.
Protect yourself ;)

Greetz, Breaker

__________________
www.benutzerfehler.de
EMail
BuddyChrist
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
...
Edited by BuddyChrist on 12.03.2005 01:59:22
private message EMail
S0410N3
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
www.xxxx.de : [80.237.132.14]

Logs from my firewall :

Date: 03/12 02:53:51
Portscan detected from 80.237.132.14

What is this? I don't understand. I clicked on the link to your site in the thread so you saw my IP I guess.
I think you don't have to target TBS users guy.
Edited by theblacksheep on 12.03.2005 08:39:21
private message Website
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
I wrote a message to AdVoCaTe and I submitted a feedback at the site telling the admin what the exact problem is.
I have no problem to help you fixing it Breaker.

PS: I have changed the site name and Breaker will stop pinging us :-)
private message EMail Website

Topic: "Stupid admins :-)" (page 1 of 2)

1 2 >