ukescuba
Senior Member
- Feb 24, 2008
- 994
- 640
this is kinda all theoretical now - and am thinking out loud... and am sure this could be seriously misused and probably get your ass landed in jail... fact i really dont think i have the balls to carry this one through! LOL
ok the other day i got one of my sites hacked... they defaced the front page... and i couldnt figure out for the life of me how they did it... that was untill i came across of piece of software that had been uploaded to one of the write enabled folders... now if youve used CMS scripts before you will note that you leave some of the folders write enabled, some how this is what entry point they used to upload the file...
well when i opened the file i was f@cking shocked!!!! I cant explain it better than that... basically this file gave me access to pretty much everything stored on the server - im thinking i was lucky to get away with just having my site defaced...
anyway cut a long story short - i started playing around with the software and soon realized that you could quite easily change source code of existing files... now if i am right in thinking... you could add links into this code and then upload files to the site... i tested it yes you can upload files to the write enabled folders... and i guess you can put whatever the f#ck you want on there...
i dont want to disclose the name of the file as im sure there are lots of people with it installed on there servers and open to be hacked and they dont even know it!
i did a search for it last night and stumbled upon it... i clicked the link and found the interface... now im a little nervous since when i did it i wasnt paying to much attention to the url... and when i looked the thing was on a damn .gov site!!!!!
so question is - anyone know of this method... anyone used it before... anyone had there asses kicked for using it??? LOL
ok the other day i got one of my sites hacked... they defaced the front page... and i couldnt figure out for the life of me how they did it... that was untill i came across of piece of software that had been uploaded to one of the write enabled folders... now if youve used CMS scripts before you will note that you leave some of the folders write enabled, some how this is what entry point they used to upload the file...
well when i opened the file i was f@cking shocked!!!! I cant explain it better than that... basically this file gave me access to pretty much everything stored on the server - im thinking i was lucky to get away with just having my site defaced...
anyway cut a long story short - i started playing around with the software and soon realized that you could quite easily change source code of existing files... now if i am right in thinking... you could add links into this code and then upload files to the site... i tested it yes you can upload files to the write enabled folders... and i guess you can put whatever the f#ck you want on there...
i dont want to disclose the name of the file as im sure there are lots of people with it installed on there servers and open to be hacked and they dont even know it!
i did a search for it last night and stumbled upon it... i clicked the link and found the interface... now im a little nervous since when i did it i wasnt paying to much attention to the url... and when i looked the thing was on a damn .gov site!!!!!
so question is - anyone know of this method... anyone used it before... anyone had there asses kicked for using it??? LOL