Forums: Hacking Internet Forums - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Hacking Internet Forums

#1 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 18 July 2005 - 05:28 PM

Hello,

its possible hacking php forums without exploits, example with cracking the cookies ?

regards,
matiano
0

#2 User is offline   myth 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 09-January 04

Posted 18 July 2005 - 05:39 PM

I SHOULD HOPE NOT !

If by exploits - your refering to XSS, SQL Injection etc, then the only other method would be local access and social engineering, hacking is a way of mind - thinking outside the box...

Using, for example, man in the middle attacks, dns poisoning, key loggers, exploits in the admins computer, working at their ISP etc are other methods...

However, ALOT of effort goes into the security of php forums, and all forums for that matter... but hacking isnt about breaking into forums, hacking is about learning a new side of security, dont spend your time trying to hack someones phpnuke site - its too tardistic
0

#3 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,447
  • Joined: 18-August 06

Posted 18 July 2005 - 05:41 PM

its possible to hack any forum if you obtain the right cookies...you dont need to crack the cookie ...all you have to do is spoof your way in using the cookie and some Liveheader tool like firefox , mozilla plugins

here is an example of how i spoofed my in to XMB forums a few years back

i wrote a paper about it.... here it is in full ...this is one method i used

now days there are a few more options...ok i used a vulnerable file path disclosure method... still it wasn't classed as a true exploit.... like the phpbb's floating about today

Quote

XMB 1.6 FORUM EXPLOIT ANALYSIS
By
ComSec

Date: 1/12/02

A few months ago, while searching google I came across a post about rumours of some xmb 1.6 forums exploits posted in some forum thread ,But left it until a few weeks ago when I got around to it again

So a little investigation was required, also tools(if any) to work with the exploit. First details about the exploit

First I did a search of google for:: powered by xmb 1.6 , resulted in many pages for me to target.

Typical forum link as follows:: Example

http://www.target.com/forum/index.php

next the Exploit: Replace the...... index.php

with: index_log.log ......like so

http://www.target.co...m/index_log.log

if all went well you should now have a list of the log files with the xmbuser name and xmbpass Cookies.

Example:

xmbuser=Admin and xmbpass=gts5643hvi0356748886sp

the password is hashed using md5 (a one way encryption algorithm, so you can't 'decrypt' it) but all you need to do is spoof the admin's cookie using this hash.

if you really wanted to you could fire up JTR and brute force the password, this would be useful if you suspected the admin was a dummy and used the same password for everything (many do).

.if you look around the site you will most likely find the admins name (usually the first member), also I found several references to two programs in forums that are used for this specific exploit ,one called Chigger and the other Chigpet, , I know the site they are on, but wont publish it... Sorry....its up to you to search for them....

Load the exploit url into Chigpet (ie) http://www.target.co...m/index_log.log

This will then reveal user name and pass cookies, your more likely to find the admins at the end of the file download so scroll down and search from the bottom up once the target has been found its time to run Chigger

IMPORTANT
Configure your IE browser proxy settings to 127.0.0.1 port 8080 or what ever your proxy runs on

Chigger

Tick the Impersonation Active! ....ok
Admin`s Name :Admin
Admin`s Pass: gts5643hvi0356748886sp

Tick.... Use web proxy

Proxy Address : 195.200.135.xxx (what ever)
Proxy Port : 8080 (what ever)

That's it....easy

Now its time to reload the main forum page in Internet Explorer

http://www.target.com/forum/index.php

you should now be logged in as Admin with full Control of the forum....

PLEASE no ScriptKiddie Shit....please respect the owner and its members and help them or notify them of a FIX, you have proved a point, no need to mess things up

HOW TO FIX:

Open up Notepad and put the following in :

<Files index_log.log>
order allow,deny
deny from all
</Files>

<Files cplogfile.log>
order allow,deny
deny from all
</Files>

When you go to save it, use All Files as the file type, not as a txt file. Save the file as .htaccess and upload it to your XMB main directory and you're set.

Or alternatively:

Choose a new filename that you will use for the logfiles. This has to remain consistant throughout the changes.

Open the files index_add.php and rawlogs.php, then perform a search for index_log.log in these files, replacing each instance with the new filename you chose.

Rename index_log.log on your server to this new name.

Upload the new copies of index_add.php and rawlogs.php.

Have all administrators and moderators change their passwords immediately, in case anyone has already obtained a copy of your index_log.log file.

This will fix the problem until ....Something new turns up, lol

Exploit Examples:

NO DAMAGE was done to these sites , they were randomly selected ,,,just testing the theory , notified admins

3 attempts, 3 exploited, 100%

to be added once they have fixed the problem, So as not to be targeted again by some of you web crushers

ComSec aka...

thanks to ST for the extra bits ;)

Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

#4 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 18 July 2005 - 06:25 PM

Thx guys :) ,

btw:... there are other ways to find out (without looking html sourcecode) ,which boardsoftware use a forum site ?

because sometimes do care forum mods delite the boardsoftware entrys in html sourcecode!

edit:
ive using the liveheader tool from firefox,there i can see something only from X-Powered-By: PHP/4.3.3 ... is there a vulnerability ?

regards,
matiano
0

#5 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,447
  • Joined: 18-August 06

Posted 18 July 2005 - 07:33 PM

now your pushing your luck..... try searching places like bugtraq , securitytracker , secunia etc

topic locked !!
Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting