hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

flame
i found this - hope it helps someone,
and maybe can someone Re-Program it in other laguage (C++ maybe assembler)
or perhaps find a flaw in that small server rolleyes.gif


Shoutcast admin password bruteforce
#
# David Jacoby
# [ dj@outpost24.com www.outpost24.com ]
#
#
#
# Greetings: #hack.se, #!synnergy, TESO, THC, #!ElectronicSouls, #security, #hack, #whitehat, #!SYN
#
#
# Copyright © 2002 Outpost24, All rights reserved.
PoWeR
good post, thanks
illwill
could use perl2exe to make it an exe ..
illwill
ok fine i broke down and compiled it to an exe... let me know if it works
flame
at least you could get that Out or change it to "cls":

'clear' is not recognized as an internal or external command,
operable program or batch file.


::: Outpost24 Security :::
David Jacoby - dj@outpost24.com - www.outpost24.com

Usage: ./program <hostname> <port> [brute/dict] laugh.gif
m0n0
dunno how to use it wink.gif
flame
its really easy (and fun)
c:\> shoutcast.exe 127.0.0.1 1080 dict.txt
smile.gif
clip
How is this usefull though? can you execute system commands?
Kpz
Nope.

It'll (hopefully) tell you the admin password so you can do things like kick off the current DJ or ban IPs (iirc, haven't used SC in an age).

Hf ;x
flame
QUOTE (clip @ Sep 22 2003, 08:12 PM)
How is this usefull though? can you execute system commands?

this is where "brain" comes to the picture ...
install a shoutcast server on your machine,
then read the readme.txt,
then figure out how to bypass security,
then proove it biggrin.gif
and finally you got yourself an exploit - W00T .
if you really need one, ill be happy to discuss it on the exploit section.

get shoutcast Here
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.