This summary is not available. Please
click here to view the post.
Showing posts with label Tips And Tricks. Show all posts
After getting the admin access in the website attacker will upload his own control penal
that’s called shell. It helps attacker to maintain access for the long time. There are many
types of shells like DDOS shell, symlink shell etc.
Using shell attacker can destroy whole database and he can leak the database of the website
and using the shell he can root the server. (Only Linux server can be rooted windows server
cant be rooted because there is no ROOT :P) After rooting he can destroy whole server.
Suppose One server contains 500 websites and attacker got the admin access in the single
site and he have rooted that server then 500 sites can be destroyed !
USES OF SHELL
1. Using shell you can Destroy the INDEX page of the website.
2. You can host your files in the Server.
3. You can root the server.
Now if you want to destroy the index page of the website then find the “INDEX” page from
the list and replace that coding with your own deface page. And using browse option you can
host your own file in the server. You can create your own shell and you can add your own
tools in your shell for that you know PHP.
that’s called shell. It helps attacker to maintain access for the long time. There are many
types of shells like DDOS shell, symlink shell etc.
Using shell attacker can destroy whole database and he can leak the database of the website
and using the shell he can root the server. (Only Linux server can be rooted windows server
cant be rooted because there is no ROOT :P) After rooting he can destroy whole server.
Suppose One server contains 500 websites and attacker got the admin access in the single
site and he have rooted that server then 500 sites can be destroyed !
USES OF SHELL
1. Using shell you can Destroy the INDEX page of the website.
2. You can host your files in the Server.
3. You can root the server.
Now if you want to destroy the index page of the website then find the “INDEX” page from
the list and replace that coding with your own deface page. And using browse option you can
host your own file in the server. You can create your own shell and you can add your own
tools in your shell for that you know PHP.
The following Dorks will show you shells left by some stupid hackers and you can easily can access their shell. I hope this dork will work for you all.
C99 Shells
inurl:c99.php uid=0(root)
root c99.php
"Captain Crunch Security Team" inurl:c99
inurl:c99.php
allinurl: c99.php
inurl:"c99.php" c99shell
inurl:c99.php uid=0(root)
c99shell powered by admin
c99shell powered by admin
inurl:"/c99.php"
c99 shell v.1.0 (roots)
allintitle: "c99shell"
allinurl: "c99.php"
intitle:C99Shell v. 1.0 pre-release +uname
inurl:"c99.php" c99shell
inurl:/c99.php+uname
c99shell [file on secure ok ]?
powered by Captain Crunch Security Team
"c99.php" filetype:php
allinurl:c99.php
c99. PHP-code Feedback Self remove
download c99.php
intitle:C99Shell v. 1.0 pre-release +uname
c99.php download
c99shell filetype:php -echo
inurl:"c99.php"
C99Shell v. 1.0 pre-release build #5
--[ c99shell v. 1.0 pre-release build #16
c99shell linux infong
C99Shell v. 1.0 pre-release build
!C99Shell v. 1.0 beta!
Encoder Tools Proc. FTP brute Sec. SQL PHP-code
Update Feedback Self remove Logout
!c99shell v. 1+Safe-mode: OFF (not secure)
"C99Shell v. 1.0 pre-release build "
intitle:c99shell +filetype:php
intitle:C99Shell v. 1.0 pre-release +uname
intitle:!C99Shell v. 1.0 pre-release build #16! root
!C99Shell v. 1.0 pre-release build #5!
inurl:"c99.php"
C99Shell v. 1.0 pre-release build #16!
intitle:c99shell intext:uname
allintext:C99Shell v. 1.0 pre-release build #12
--[ c99shell v. 1.0 pre-release build #15 | Powered
by ]--
Encoder Tools Proc. FTP brute Sec. SQL PHP-code
Update Feedback Self remove Logout
"c99shell v 1.0"
ftp apache inurl:c99.php
c99shell+v.+1.0 16
intitle:c99shell "Software: Apache"
allintext: Encoder Tools Proc. FTP brute Sec. SQL
PHP-code Update Feedback Self remove
intitle:c99shell uname -bbpress
intitle:"index.of" c99.php
inurl:admin/files/
intitle:"index of /" "c99.php"
intitle:"index of" intext:c99.php
intitle:index.of c99.php
intitle:index/of file c99.php
intitle:"Index of/"+c99.php
c99.php "intitle:Index of "
intitle:index.of c99.php
intitle:"Index of/"+c99.php
b374k Shells
inurl:b374k.php
c100 Shells
inurl:c100.php Generation time:
Believe it or not, some newbie are not known to upload shell even he can access admin username and password. Here is my noob tip for them. First all, you login to wp web site and you are in wp dashboard.
In Dashboard, you need to go Appearance>Theme>Editor. And you can see as above picture. And just click 404 Template (404.php)
After clicking 404 template, you will see html code there, just remove all and replace your own shell code here.
After paste your shell code, you need to update to save setting just below. Remember we are editing Template name Striking. Ok just put in mind that.
Now it is time to call your shell url path. Just like www.target.com/wp-content/themes/striking/404.php
You may different template name depending on the site you hacked. Just see template name. OK
In Dashboard, you need to go Appearance>Theme>Editor. And you can see as above picture. And just click 404 Template (404.php)
After clicking 404 template, you will see html code there, just remove all and replace your own shell code here.
After paste your shell code, you need to update to save setting just below. Remember we are editing Template name Striking. Ok just put in mind that.
Now it is time to call your shell url path. Just like www.target.com/wp-content/themes/striking/404.php
You may different template name depending on the site you hacked. Just see template name. OK
Hello Bro! if you are willing to show your facebook Cover photo to your deface page. It's scary to show off your deface. Use wisely at your own risk.
==============here is code================
<!DOCTYPE html>
<html>
<head>
<script>
function loadXMLDoc()
{
var xmlhttp;
if (window.XMLHttpRequest)
{// code for IE7+, Firefox, Chrome, Opera, Safari
xmlhttp=new XMLHttpRequest();
}
else
{// code for IE6, IE5
xmlhttp=new ActiveXObject("Microsoft.XMLHTTP");
}
xmlhttp.onreadystatechange=function()
{
if (xmlhttp.readyState==4 && xmlhttp.status==200)
{
var json = JSON.parse(xmlhttp.responseText );
document.getElementById("myDiv").innerHTML="<img src='"+json.cover['source']+"' />";
}
}
xmlhttp.open("GET","http://graph.facebook.com/your_fb_graph_id_here?fields=cover",true);
xmlhttp.send();
}
window.onload=loadXMLDoc;
</script>
</head>
<body>
<div id="myDiv"><h2>here,ur fb cover foto will come out!</h2></div>
</body>
</html>
In this post we are going to search with Google, servers that have been compromised and they are hosting a webshell. The most common method to upload a webshell to a server is RFI (Remote
File Inclusion). RFI is a vulnerability that allows an attacker to
upload a remote file like a script or webshell. With a webshell, you can manage the server, read/create/remove files/upload files, execute commands on the remote server... The common webshells are c99.php, c100.php, r57.php. You can find servers hosting this webshells with the next google dorks
* Note that some links don't contain webshells because
administrators have removed the shell from their servers or the
webmaster are using black SEO.
I have been found some md5 hash passwords in hacked sites but i don't know how they goes or which types these were. This note will tell us about md5 hashes more detail depending on different CMS, WP or Joomla or Phpmyadmin or something else.
DES(Unix)
Example: IvS7aeT4NzQPM
Used in Linux and other similar OS.
Length: 13 characters.
Description: The first two characters are the salt (random characters; in our example the salt is the string "Iv"), then there follows the actual hash.
Notes: [1] [2]
Domain Cached Credentials
Example: Admin:b474d48cdfc4974d86ef4d24904cdd91
Used for caching passwords of Windows domain.
Length: 16 bytes.
Algorithm: MD4(MD4(Unicode($pass)).Unicode(strtolower($username)))
Note: [1]
MD5(Unix)
Example: $1$12345678$XM4P3PrKBgKNnTaqG9P0T/
Used in Linux and other similar OS.
Length: 34 characters.
Description: The hash begins with the $1$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash.
Algorithm: Actually that is a loop calling the MD5 algorithm 2000 times.
Notes: [1] [2]
MD5(APR)
Example: $apr1$12345678$auQSX8Mvzt.tdBi4y6Xgj.
Used in Linux and other similar OS.
Length: 37 characters.
Description: The hash begins with the $apr1$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash.
Algorithm: Actually that is a loop calling the MD5 algorithm 2000 times.
Notes: [1] [2]
MD5(phpBB3)
Example: $H$9123456785DAERgALpsri.D9z3ht120
Used in phpBB 3.x.x.
Length: 34 characters.
Description: The hash begins with the $H$ signature, then there goes one character (most often the number '9'), then there goes the salt (8 random characters; in our example the salt is the string "12345678"), followed by the actual hash.
Algorithm: Actually that is a loop calling the MD5 algorithm 2048 times.
Notes: [1] [2]
MD5(Wordpress)
Example: $P$B123456780BhGFYSlUqGyE6ErKErL01
Used in Wordpress.
Length: 34 characters.
Description: The hash begins with the $P$ signature, then there goes one character (most often the number 'B'), then there goes the salt (8 random characters; in our example the salt is the string "12345678"), followed by the actual hash.
Algorithm: Actually that is a loop calling the MD5 algorithm 8192 times.
Notes: [1] [2]
MySQL
Example: 606717496665bcba
Used in the old versions of MySQL.
Length: 8 bytes.
Description: The hash consists of two DWORDs, each not exceeding the value of 0x7fffffff.
MySQL5
Example: *E6CC90B878B948C35E92B003C792C46C58C4AF40
Used in the new versions of MySQL.
Length: 20 bytes.
Algorithm: SHA-1(SHA-1($pass))
Note: The hashes are to be loaded to the program without the asterisk that stands in the beginning of each hash.
RAdmin v2.x
Example: 5e32cceaafed5cc80866737dfb212d7f
Used in the application Remote Administrator v2.x.
Length: 16 bytes.
Algorithm: The password is padded with zeros to the length of 100 bytes, then that entire string is hashed with the MD5 algorithm.
MD5
Example: c4ca4238a0b923820dcc509a6f75849b
Used in phpBB v2.x, Joomla version below 1.0.13 and many other forums and CMS.
Length: 16 bytes.
Algorithm: Same as the md5() function in PHP.
md5($pass.$salt)
Example: 6f04f0d75f6870858bae14ac0b6d9f73:1234
Used in WB News, Joomla version 1.0.13 and higher.
Length: 16 bytes.
Note: [1]
md5($salt.$pass)
Example: f190ce9ac8445d249747cab7be43f7d5:12
Used in osCommerce, AEF, Gallery and other CMS.
Length: 16 bytes.
Note: [1]
md5(md5($pass))
Example: 28c8edde3d61a0411511d3b1866f0636
Used in e107, DLE, AVE, Diferior, Koobi and other CMS.
Length: 16 bytes.
md5(md5($pass).$salt)
Example: 6011527690eddca23580955c216b1fd2:wQ6
Used in vBulletin, IceBB.
Length: 16 bytes.
Notes: [1] [3] [4]
md5(md5($salt).md5($pass))
Example: 81f87275dd805aa018df8befe09fe9f8:wH6_S
Used in IPB.
Length: 16 bytes.
Notes: [1] [3]
md5(md5($salt).$pass)
Example: 816a14db44578f516cbaef25bd8d8296:1234
Used in MyBB.
Length: 16 bytes.
Note: [1]
md5($salt.$pass.$salt)
Example: a3bc9e11fddf4fef4deea11e33668eab:1234
Used in TBDev.
Length: 16 bytes.
Note: [1]
md5($salt.md5($salt.$pass))
Example: 1d715e52285e5a6b546e442792652c8a:1234
Used in DLP.
Length: 16 bytes.
Note: [1]
SHA-1
Example: 356a192b7913b04c54574d18c28d46e6395428ab
Used in many forums and CMS.
Length: 20 bytes.
Algorithm: Same as the sha1() function in PHP.
sha1(strtolower($username).$pass)
Example: Admin:6c7ca345f63f835cb353ff15bd6c5e052ec08e7a
Used in SMF.
Length: 20 bytes.
Note: [1]
sha1($salt.sha1($salt.sha1($pass)))
Example: cd37bfbf68d198d11d39a67158c0c9cddf34573b:1234
Used in Woltlab BB.
Length: 20 bytes.
Note: [1]
SHA-256(Unix)
Example: $5$12345678$jBWLgeYZbSvREnuBr5s3gp13vqiKSNK1rkTk9zYE1v0
Used in Linux and other similar OS.
Length: 55 characters.
Description: The hash begins with the $5$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash.
Algorithm: Actually that is a loop calling the SHA-256 algorithm 5000 times.
Notes: [1] [2]
SHA-512(Unix)
Example:$6$12345678$U6Yv5E1lWn6mEESzKen42o6rbEmFNLlq6Ik9X3reMXY3doKEuxrcDohKUx0Oxf44aeTIxGEjssvtT1aKyZHjs
Used in Linux and other similar OS.
Length: 98 characters.
Description: The hash begins with the $6$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash.
Algorithm: Actually that is a loop calling the SHA-512 algorithm 5000 times.
Notes: [1] [2]
SHA-1(Django) = sha1($salt.$pass)
Example: sha1$12345678$90fbbcf2b72b5973ae42cd3a19ab4ae8a1bd210b
12345678 is salt (in the hexadecimal format)
90fbbcf2b72b5973ae42cd3a19ab4ae8a1bd210b is SHA-1 hash.
SHA-256(Django) = SHA-256($salt.$pass)
Example:sha256$12345678$154c4c511cbb166a317c247a839e46cac6d9208af5b015e1867a84cd9a56007b
12345678 is salt (in the hexadecimal format)
154c4c511cbb166a317c247a839e46cac6d9208af5b015e1867a84cd9a56007b is SHA-256 hash.
SHA-384(Django) = SHA-384($salt.$pass)
Example:sha384$12345678$c0be393a500c7d42b1bd03a1a0a76302f7f472fc132f11ea6373659d0bd8675d04e12d8016d83001c327f0ab70843dd5
12345678 is salt (in the hexadecimal format)
c0be393a500c7d42b1bd03a1a0a76302f7f472fc132f11ea6373659d0bd8675d04e12d8016d83001c327f0ab70843dd5 is SHA-384 hash.
SHA-1(ManGOS) = sha1(strtoupper($username).':'.$pass)
SHA-1(ManGOS2) = sha1($username.':'.$pass)
-------------------------------------------------
Notes:
[1] Since the hashing requires not only a password but also a salt (or a user name), which is unique for each user, the attack speed for such hashes will decline proportionally to their count (for example, attacking 100 hashes will go 100 times slower than attacking one hash).
[2] The hash is to be loaded to the program in full, to the "Hash" column - the program will automatically extract the salt and other required data from it.
[3] The ':' character can be used as salt; however, since it is used by default for separating hash and salt in PasswordsPro, it is recommended that you use a different character for separating fields; e.g., space.
[4] Salt can contain special characters - single or double quotes, as well as backslash, which are preceded (after obtaining dumps from MySQL databases) by an additional backslash, which is to be removed manually. For example, the salt to be loaded to the program would be a'4 instead of a\'4, as well as the salts a"4 instead of a\"4 and a\4 instead of a\\4.
Subscribe to:
Posts (Atom)















