Jump to content
Bebee

Owning istealer and other PHP based stealers

Recommended Posts

Posted

You will need:

Linux machine(Highly recommended)

bash,

perl,

apache2,

mysql,

The knowledge to use the above

You will get:

20-30min of fun

An idea to make it better than this..

You will find 1000 of 1000 of wide open log viewers

Millions of logfiles(pls dont abuse them....)

DONT ABUSE THIS!!

THERE IS NO WARRANTY FOR ANYTHING I'LL TELL FROM NOW ON :)

1. Set up a web Log center. Use ur local apache and ur local mysql.

Forbid access from outside (localhost only)

2. #Find a web Logger try Google("intitle:wLogs v1.0") for example

and use the exploit perl script on it.

It should throw out the full database of the targeted loger.

3. Now u can use the insert.pl script to insert the stolen db into ur own.

u have to edit the script(fill in ur mysql username and paswd).

this step may take time :) (depends on the size of ur db)

->perl exploit.pl http://www.example.com/logger/ >out.log.db

->perl insert.pl out.log.db

4. Take a look in ur own db, using the wLogs viewer or ur phpmyadmin.

if u have more than 1 target, u may be intrested in the getLogs.sh script :)

Mai jos aveti exploit.pl ,insert.pl, getlogs.sh:

FileShare Download steal.zip

Sursa

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...