Showing posts with label Tips And Tricks. Show all posts

Download as premium user from Any file Hosting site

This summary is not available. Please click here to view the post.

What is Shell And How to Use it?

After getting the admin access in the website attacker will upload his own control penal 

that’s called shell. It helps attacker to maintain access for the long time. There are many 

types of shells like DDOS shell, symlink shell etc.

Using shell attacker can destroy whole database and he can leak the database of the website 

and using the shell he can root the server. (Only Linux server can be rooted windows server 

cant be rooted because there is no ROOT :P) After rooting he can destroy whole server. 

Suppose One server contains 500 websites and attacker got the admin access in the single 

site and he have rooted that server then 500 sites can be destroyed !
USES OF SHELL

1. Using shell you can Destroy the INDEX page of the website.
2. You can host your files in the Server.
3. You can root the server.

Now if you want to destroy the index page of the website then find the “INDEX” page from 

the list and replace that coding with your own deface page. And using browse option you can 

host your own file in the server. You can create your own shell and you can add your own 

tools in your shell for that you know PHP.

Find Shells Left Behind by Stupid Hackers

The following Dorks will show you shells left by some stupid hackers and you can easily can access their shell. I hope this dork will work for you all.
C99 Shells
inurl:c99.php uid=0(root)
root c99.php
"Captain Crunch Security Team" inurl:c99
inurl:c99.php
allinurl: c99.php
inurl:"c99.php" c99shell
inurl:c99.php uid=0(root)
c99shell powered by admin
c99shell powered by admin
inurl:"/c99.php"
c99 shell v.1.0 (roots)
allintitle: "c99shell"
allinurl: "c99.php"
intitle:C99Shell v. 1.0 pre-release +uname
inurl:"c99.php" c99shell
inurl:/c99.php+uname
c99shell [file on secure ok ]?
powered by Captain Crunch Security Team
"c99.php" filetype:php
allinurl:c99.php
c99. PHP-code Feedback Self remove
download c99.php
intitle:C99Shell v. 1.0 pre-release +uname
c99.php download
c99shell filetype:php -echo
inurl:"c99.php"
C99Shell v. 1.0 pre-release build #5
--[ c99shell v. 1.0 pre-release build #16
c99shell linux infong
C99Shell v. 1.0 pre-release build
!C99Shell v. 1.0 beta!
Encoder Tools Proc. FTP brute Sec. SQL PHP-code
Update Feedback Self remove Logout
!c99shell v. 1+Safe-mode: OFF (not secure)
"C99Shell v. 1.0 pre-release build "
intitle:c99shell +filetype:php
intitle:C99Shell v. 1.0 pre-release +uname
intitle:!C99Shell v. 1.0 pre-release build #16! root
!C99Shell v. 1.0 pre-release build #5!
inurl:"c99.php"
C99Shell v. 1.0 pre-release build #16!
intitle:c99shell intext:uname
allintext:C99Shell v. 1.0 pre-release build #12
--[ c99shell v. 1.0 pre-release build #15 | Powered
by ]--
Encoder Tools Proc. FTP brute Sec. SQL PHP-code
Update Feedback Self remove Logout
"c99shell v 1.0"
ftp apache inurl:c99.php
c99shell+v.+1.0 16
intitle:c99shell "Software: Apache"
allintext: Encoder Tools Proc. FTP brute Sec. SQL
PHP-code Update Feedback Self remove
intitle:c99shell uname -bbpress
intitle:"index.of" c99.php
inurl:admin/files/
intitle:"index of /" "c99.php"
intitle:"index of" intext:c99.php
intitle:index.of c99.php
intitle:index/of file c99.php
intitle:"Index of/"+c99.php
c99.php "intitle:Index of "
intitle:index.of c99.php
intitle:"Index of/"+c99.php

b374k Shells
inurl:b374k.php


c100 Shells
inurl:c100.php Generation time:

How to upload shell in Wordpress

Believe it or not, some newbie are not known to upload shell even he can access admin username and password. Here is my noob tip for them. First all, you login to wp web site and you are in wp dashboard.

In Dashboard, you need to go Appearance>Theme>Editor. And you can see as above picture. And just click 404 Template  (404.php)

 After clicking 404 template, you will see html code there, just remove all and replace your own shell code here.

After paste your shell code, you need to update to save setting just below. Remember we are editing Template name Striking. Ok just put in mind that.

Now it is time to call your shell url path. Just like www.target.com/wp-content/themes/striking/404.php
You may different template name depending on the site you hacked. Just see template name. OK

How To Put Your fb Cover Photo To Your Deface Page via Javascript!


Hello Bro! if you are willing to show your facebook Cover photo to your deface page. It's scary to show off your deface. Use wisely at your own risk. 


==============here is code================
<!DOCTYPE html>
<html>
<head>
<script>
function loadXMLDoc()
{
var xmlhttp;
if (window.XMLHttpRequest)
{// code for IE7+, Firefox, Chrome, Opera, Safari
xmlhttp=new XMLHttpRequest();
}
else
{// code for IE6, IE5
xmlhttp=new ActiveXObject("Microsoft.XMLHTTP");
}
xmlhttp.onreadystatechange=function()
{
if (xmlhttp.readyState==4 && xmlhttp.status==200)
{
var json = JSON.parse(xmlhttp.responseText );


document.getElementById("myDiv").innerHTML="<img src='"+json.cover['source']+"' />";
}
}
xmlhttp.open("GET","http://graph.facebook.com/your_fb_graph_id_here?fields=cover",true);
xmlhttp.send();
}
window.onload=loadXMLDoc;
</script>
</head>
<body>

<div id="myDiv"><h2>here,ur fb cover foto will come out!</h2></div>


</body>
</html>

Detecting web shells uploaded to compromised servers with Google


In this post we are going to search with Google, servers that have been compromised and they are hosting a webshell. The most common method to upload a webshell to a server is RFI (Remote File Inclusion). RFI is a vulnerability that allows an attacker to upload a remote file like a script or webshell. With a webshell, you can manage the server, read/create/remove files/upload files, execute commands on the remote server... The common webshells are c99.php, c100.php, r57.php. You can find servers hosting this webshells with the next google dorks

 * Note that some links don't contain webshells because administrators have removed the shell from their servers or the webmaster are using black SEO.


Types of MD5 Hashes

I have been found some md5 hash passwords in hacked sites but i don't know how they goes or which types these were. This note will tell us about md5 hashes more detail depending on different CMS, WP or Joomla or Phpmyadmin or something else.

DES(Unix) 
Example: IvS7aeT4NzQPM 
Used in Linux and other similar OS. 
Length: 13 characters. 
Description: The first two characters are the salt (random characters; in our example the salt is the string "Iv"), then there follows the actual hash. 
Notes: [1] [2] 

Domain Cached Credentials 
Example: Admin:b474d48cdfc4974d86ef4d24904cdd91 
Used for caching passwords of Windows domain. 
Length: 16 bytes. 
Algorithm: MD4(MD4(Unicode($pass)).Unicode(strtolower($username))) 
Note: [1] 

MD5(Unix) 
Example: $1$12345678$XM4P3PrKBgKNnTaqG9P0T/ 
Used in Linux and other similar OS. 
Length: 34 characters. 
Description: The hash begins with the $1$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash. 
Algorithm: Actually that is a loop calling the MD5 algorithm 2000 times. 
Notes: [1] [2] 

MD5(APR) 
Example: $apr1$12345678$auQSX8Mvzt.tdBi4y6Xgj. 
Used in Linux and other similar OS. 
Length: 37 characters. 
Description: The hash begins with the $apr1$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash. 
Algorithm: Actually that is a loop calling the MD5 algorithm 2000 times. 
Notes: [1] [2] 

MD5(phpBB3) 
Example: $H$9123456785DAERgALpsri.D9z3ht120 
Used in phpBB 3.x.x. 
Length: 34 characters. 
Description: The hash begins with the $H$ signature, then there goes one character (most often the number '9'), then there goes the salt (8 random characters; in our example the salt is the string "12345678"), followed by the actual hash. 
Algorithm: Actually that is a loop calling the MD5 algorithm 2048 times. 
Notes: [1] [2] 

MD5(Wordpress) 
Example: $P$B123456780BhGFYSlUqGyE6ErKErL01 
Used in Wordpress. 
Length: 34 characters. 
Description: The hash begins with the $P$ signature, then there goes one character (most often the number 'B'), then there goes the salt (8 random characters; in our example the salt is the string "12345678"), followed by the actual hash. 
Algorithm: Actually that is a loop calling the MD5 algorithm 8192 times. 
Notes: [1] [2] 

MySQL 
Example: 606717496665bcba 
Used in the old versions of MySQL. 
Length: 8 bytes. 
Description: The hash consists of two DWORDs, each not exceeding the value of 0x7fffffff. 

MySQL5 
Example: *E6CC90B878B948C35E92B003C792C46C58C4AF40 
Used in the new versions of MySQL. 
Length: 20 bytes. 
Algorithm: SHA-1(SHA-1($pass)) 
Note: The hashes are to be loaded to the program without the asterisk that stands in the beginning of each hash. 

RAdmin v2.x 
Example: 5e32cceaafed5cc80866737dfb212d7f 
Used in the application Remote Administrator v2.x. 
Length: 16 bytes. 
Algorithm: The password is padded with zeros to the length of 100 bytes, then that entire string is hashed with the MD5 algorithm. 

MD5 
Example: c4ca4238a0b923820dcc509a6f75849b 
Used in phpBB v2.x, Joomla version below 1.0.13 and many other forums and CMS. 
Length: 16 bytes. 
Algorithm: Same as the md5() function in PHP. 

md5($pass.$salt) 
Example: 6f04f0d75f6870858bae14ac0b6d9f73:1234 
Used in WB News, Joomla version 1.0.13 and higher. 
Length: 16 bytes. 
Note: [1] 

md5($salt.$pass) 
Example: f190ce9ac8445d249747cab7be43f7d5:12 
Used in osCommerce, AEF, Gallery and other CMS. 
Length: 16 bytes. 
Note: [1] 

md5(md5($pass)) 
Example: 28c8edde3d61a0411511d3b1866f0636 
Used in e107, DLE, AVE, Diferior, Koobi and other CMS. 
Length: 16 bytes. 

md5(md5($pass).$salt) 
Example: 6011527690eddca23580955c216b1fd2:wQ6 
Used in vBulletin, IceBB. 
Length: 16 bytes. 
Notes: [1] [3] [4] 

md5(md5($salt).md5($pass)) 
Example: 81f87275dd805aa018df8befe09fe9f8:wH6_S 
Used in IPB. 
Length: 16 bytes. 
Notes: [1] [3] 

md5(md5($salt).$pass) 
Example: 816a14db44578f516cbaef25bd8d8296:1234 
Used in MyBB. 
Length: 16 bytes. 
Note: [1] 

md5($salt.$pass.$salt) 
Example: a3bc9e11fddf4fef4deea11e33668eab:1234 
Used in TBDev. 
Length: 16 bytes. 
Note: [1] 

md5($salt.md5($salt.$pass)) 
Example: 1d715e52285e5a6b546e442792652c8a:1234 
Used in DLP. 
Length: 16 bytes. 
Note: [1] 

SHA-1 
Example: 356a192b7913b04c54574d18c28d46e6395428ab 
Used in many forums and CMS. 
Length: 20 bytes. 
Algorithm: Same as the sha1() function in PHP. 

sha1(strtolower($username).$pass) 
Example: Admin:6c7ca345f63f835cb353ff15bd6c5e052ec08e7a 
Used in SMF. 
Length: 20 bytes. 
Note: [1] 

sha1($salt.sha1($salt.sha1($pass))) 
Example: cd37bfbf68d198d11d39a67158c0c9cddf34573b:1234 
Used in Woltlab BB. 
Length: 20 bytes. 
Note: [1] 

SHA-256(Unix) 
Example: $5$12345678$jBWLgeYZbSvREnuBr5s3gp13vqiKSNK1rkTk9zYE1v0 
Used in Linux and other similar OS. 
Length: 55 characters. 
Description: The hash begins with the $5$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash. 
Algorithm: Actually that is a loop calling the SHA-256 algorithm 5000 times. 
Notes: [1] [2] 

SHA-512(Unix) 
Example:$6$12345678$U6Yv5E1lWn6mEESzKen42o6rbEmFNLlq6Ik9X3reMXY3doKEuxrcDohKUx0Oxf44aeTIxGEjssvtT1aKyZHjs 
Used in Linux and other similar OS. 
Length: 98 characters. 
Description: The hash begins with the $6$ signature, then there goes the salt (up to 8 random characters; in our example the salt is the string "12345678"), then there goes one more $ character, followed by the actual hash. 
Algorithm: Actually that is a loop calling the SHA-512 algorithm 5000 times. 
Notes: [1] [2]

SHA-1(Django) = sha1($salt.$pass) 
Example: sha1$12345678$90fbbcf2b72b5973ae42cd3a19ab4ae8a1bd210b 
12345678 is salt (in the hexadecimal format) 
90fbbcf2b72b5973ae42cd3a19ab4ae8a1bd210b is SHA-1 hash. 

SHA-256(Django) = SHA-256($salt.$pass) 
Example:sha256$12345678$154c4c511cbb166a317c247a839e46cac6d9208af5b015e1867a84cd9a56007b 
12345678 is salt (in the hexadecimal format) 
154c4c511cbb166a317c247a839e46cac6d9208af5b015e1867a84cd9a56007b is SHA-256 hash. 

SHA-384(Django) = SHA-384($salt.$pass) 
Example:sha384$12345678$c0be393a500c7d42b1bd03a1a0a76302f7f472fc132f11ea6373659d0bd8675d04e12d8016d83001c327f0ab70843dd5 
12345678 is salt (in the hexadecimal format) 
c0be393a500c7d42b1bd03a1a0a76302f7f472fc132f11ea6373659d0bd8675d04e12d8016d83001c327f0ab70843dd5 is SHA-384 hash. 

SHA-1(ManGOS) = sha1(strtoupper($username).':'.$pass) 

SHA-1(ManGOS2) = sha1($username.':'.$pass)   

------------------------------------------------- 
Notes: 

[1] Since the hashing requires not only a password but also a salt (or a user name), which is unique for each user, the attack speed for such hashes will decline proportionally to their count (for example, attacking 100 hashes will go 100 times slower than attacking one hash). 

[2] The hash is to be loaded to the program in full, to the "Hash" column - the program will automatically extract the salt and other required data from it. 

[3] The ':' character can be used as salt; however, since it is used by default for separating hash and salt in PasswordsPro, it is recommended that you use a different character for separating fields; e.g., space. 

[4] Salt can contain special characters - single or double quotes, as well as backslash, which are preceded (after obtaining dumps from MySQL databases) by an additional backslash, which is to be removed manually. For example, the salt to be loaded to the program would be a'4 instead of a\'4, as well as the salts a"4 instead of a\"4 and a\4 instead of a\\4.
Copyright © 2013 Hacking Tools and Tech eBooks Collection and Blogger Templates - Anime OST.