Jump to content

New LFI bug

Recommended Posts

daca imi apare asda cum facsa aflu parola mai departe

root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/sync

AM SCRIS CA PAROLELE SE AFLA IN /shadow si nu ai sanse. Mai citeste si jos, nu doar primul post :evil: :evil:

Link to comment
Share on other sites

daca imi apare asda cum facsa aflu parola mai departe

root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/sync

AM SCRIS CA PAROLELE SE AFLA IN /shadow si nu ai sanse. Mai citeste si jos, nu doar primul post :evil: :evil:

+ tre drepturi de root pentru a putea afisa shadow :)

Link to comment
Share on other sites

/etc/passwd e pt pustanii care afla ce conturi sunt acolo, fara sa afle practic parolele sau hashurile si pe urma fac ei faza cu programel care face bruteforce pe toate conturile si gasesc 1-2-3-4 conturi cu parole unsafe.

dupa care poti sa incerci un privilege escalation sau exploit local, sau sa furi ceva din contu ala.

uite o idee ....

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...