Jump to content

Please Try To Break My Website!

Alterlai
Go to solution Solved by ekv,
userid	username	password	voornaam	achternaam	datum3	sandervdoorn	gef5jne7/Xgrk	Sander	van Doorn	2014-12-16 12:57:021	alterlai	geUlEgVXsTYIs	Jeroen	van der Laan	2014-12-15 23:03:012	alterlai22	gerM3WvMLwDXc	jeroen	jeroen	2014-12-16 09:59:334	test	gehDQcFQQf48o	test	test	2014-12-18 13:30:488	Kiwi1	gex.wN0hUtkmQ	Kiwi	Kiwi	2015-01-03 13:07:557	Kiwi	gejZjDhkSbYuw			2015-01-03 13:06:209	wesley	ge5hTfyZUCHb.	wesley	wesley	2015-01-06 14:05:2112	linus	geLjPlfKMNfGk	Linus	Tech Tips	2015-01-27 17:51:0311	krimik	ge4CD3ujv2RhE	fdsgd	fdtgd f	2015-01-15 21:37:2114	efaefafaewefa	gebSkT/3U.3R2	ffafafawf	awfawfawfwafwa	2015-01-27 18:02:1715	somethingelse	gef5aBJffUFtY	something	else	2015-01-27 18:28:5117	');	gejPCW90MdzZg			2015-01-28 19:22:3816	asd	ge3MtKR4lXSpw	asd	asd	2015-01-27 19:47:1018	ekv'	gerLoHNyCGCEs	stefan	stefan	2015-01-29 05:36:3721	Penis	gewX71L8b7nG2	PENIS	Vagina	2015-01-30 07:47:0719	ekv	gec0h7MRomSm2	ekv	ekv	2015-01-29 05:37:2420	ekv1	gepMAKyBPbwMA	ekv1	ekv1	2015-01-29 05:37:58

This is "users" table.

I get a feeling people find this a very appealing activity...... 

 

What have i done????

Where's the DB. :|

Link to comment
Share on other sites

Link to post
Share on other sites

Where's the DB. :|

On the same server. If that answers your question.

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Already broken it, for example, if you upload a file with %20 in the filename it will parse it, it shouldn't do that

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

I get a feeling people find this a very appealing activity...... 

 

What have i done????

That's because pentesting is fun!

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

Lol, broke it again by uploading a file called ""/.pdf it uploads it and I think it puts it in a new directory

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

Already broken it, for example, if you upload a file with %20 in the filename it will parse it, it shouldn't do that

Thank you reporting! 

I'm not familiar with that problem. What does that allow you to do exactly?

 

Also see if you can find a way to screw with input. Like SQL injection or HTML script tags or whatever.

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Lol, broke it again by uploading a file called ""/.pdf it uploads it and I think it puts it in a new directory

Did not make a new directory but i'll take a look at the file uploader. 

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Thank you reporting! 

I'm not familiar with that problem. What does that allow you to do exactly?

 

Also see if you can find a way to screw with input. Like SQL injection or HTML script tags or whatever.

Not much, but it can be a bit annoying when uploading files

Also going to http://alterlai.com/school/bestanden/ lets me see all the directories and I don't need to log in to access it, it should be giving me a 403 - forbidden error like some of the other directories

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

On the same server. If that answers your question.

But how do I seeeeee it. I'm bad at this. I'm still going through the JS payload from last night's attack. ;-;

Link to comment
Share on other sites

Link to post
Share on other sites

But how do I seeeeee it. I'm bad at this. I'm still going through the JS payload from last night's attack. ;-;

You don't :). That's the trick. See if you can figure out how to extract information from the DB without having access.

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

I hit it with a shellshock tester and it said it might be vulnerable, so I suggest you go patch that:

https://shellshocker.net/

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

I hit it with a shellshock tester and it said it might be vulnerable, so I suggest you go patch that:

https://shellshocker.net/

Is windows vulnerable to shellshock?

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Is windows vulnerable to shellshock?

No, only Unix based systems (so OSX and Linux), if you're running a Windows server then you are fine

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

No, only Unix based systems (so OSX and Linux), if you're running a Windows server then you are fine

Any luck so far?

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Any luck so far?

With what?

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

You don't :). That's the trick. See if you can figure out how to extract information from the DB without having access.

Hey, I can get into all of the files without logging in by just going to this: http://alterlai.com/school/bestanden/

Also, uploading a file that has a " in the filename causes any links to it to give you 403 - forbidden

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

With what?

Any SQL injection vulnerabilities. Idk if you checked :)

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Yea that was a pretty unusual error I encounterd. It was only produced by certain allowed files. Other files of the same filetype were allowed to. I'm gonna have to take a better look at that. Thank you

I deliberately uploaded a file of the wrong type to see what would happen

Link to comment
Share on other sites

Link to post
Share on other sites

Any SQL injection vulnerabilities. Idk if you checked :)

Yeah I tried SQL injections, I think they're patched, did you see the other exploit I found?

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

Hey, I can get into all of the files without logging in by just going to this: http://alterlai.com/school/bestanden/

Also, uploading a file that has a " in the filename causes any links to it to give you 403 - forbidden

Hmm, i'll have to see if i'm able to add requirements for filenames.

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

I tried multiple basic XSS and SQL injections, none of which were fruitful.

 

If you want to disable directory browsing with apache, create an .htacces or edit your vhost file with something like:

Options -Indexes
Link to comment
Share on other sites

Link to post
Share on other sites

 

I tried multiple basic XSS and SQL injections, none of which were fruitful.

 

If you want to disable directory browsing with apache, create an .htacces or edit your vhost file with something like:

Options -Indexes

Thanks, very helpfull! :)

CPU:

Intel Core i5 2500k - Motherboard: Asus maximus iv gene-z - RAM: 2x Corsair Vengeance Blue 4GB DDR3-1600 CL9 - GPU: ASUS GTX 770 DirectCU II
Case: Coolermaster Centurion 5 II - Storage: Crucial M4 128GB, Seagate barracuda 3TB PSU: XFX 650W XXX Edition Modular PSU - Keyboard: Ducky Shine 2 Pro
Mouse: Razer Deathadder 2013 - Sound: Razer Characias
Link to comment
Share on other sites

Link to post
Share on other sites

Site is mess, sry bro, but u have low security on register/login.

Same as on delete, or other functions.

Work on design too.

827dd3c606f.png

This is SQLi i made on chaning value par. on button.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×