You are here: hacking technology > hacker invade > Content
Hot Articles
Recommend Articles
New Articles
Breaks through the first-class information supervisory system to pass on the wooden horse and to obt
  Add date: 10/21/2008   Publishing date: 10/21/2008   Hits: 1
Total 3 pages, Current page:1, Jump to page:
 

Today finally GK
Strolls bored on-line, consciousness urges the soul trial to ask me to want the article…
As soon as the ~ discovery blindly believes in the website, is not feeling well…
(the invasion needs the reason? Does not need? Needs? ….)

With
telnet www.xxx.com 80

get enter

HTTP/1.1 400 Bad Request
Server: Microsoft-IIS/5.0
Date: Wed, 08 Jun 2005 11:56: 00 GMT
Content-Type: text/html
Content-Length: 87

<html><head><title>Error</title></he
</html>

Has lost with main engine's connection.

F:\Documents and Settings\lu\ tabletop >

Sees does not have, obtains the useful information

Goes to WEB to have a look first to have any crack

! Discovers the DVBBS7.1 forum

Some friends told me couple days ago a matter, said that has many idiot managers with to prepare a minute date to do prepares a minute database the name! Tries to look!

dvbbs7.1 is on April 6 renews, he uses to use 200504 ** .mdb to make the name to name the beforehand old database!
Does not have the means that tries!

http://www.xxxx.com/bbs/databackup/20050406.mdb
http://www.xxxx.com/bbs/databackup/20050407.mdb
http://www.xxxx.com/bbs/databackup/20050408.mdb
.....
Corona. To 32 had not come out
The manager is not the idiot!
http://www.xxxx.com/bbs/databackup/200504.mdb
faint! Who isn't he idiot is!
Jumped out the lovable downloading dialog box!

downloading…. Complete!

Opens with the auxiliary feudal official database browser, chooses Dv_Log(2586)
The field name chooses the l_content key words to add password2

Inquiry
Many information came out!
After screening
Discovers one:
oldusername=%B5%F0%B7%C0&username2=%B5%F0%B7%C0&password2=19841202&adduser=%B5%F0%B7%C0&id=12&Submit=%B8%FC+%D0%C2

, What thought of? Debarkation, but the user name did not know, is %B8%F0%B7%C9 ~ cracks a joke, that simple, actually transforms this me to use his page,
The user name and the password add randomly on the debarkation page
Debarkation
http://www.xxx.com/bbs/showerr.asp?BoardID=0&ErrCodes=10,11&action=%CC%EE%D0%B4%B5%C7%C2%BC%D0%C5%CF%A2

the %CC%EE%D0%B4%B5%C7%C2%BC%D0%C5%CF%A2 these words meaning is “filling in registers the information”

Then changes into %CC%EE%D0%B4%B5%C7%C2%BC%D0%C5%CF%A2 %B5%F0%B7%C0!

Submission! Saw! The user name is “holds in the mouth against”
Corona!
Any name! Does not manage, debarkation!
Success! Ha-ha ~ the assistant saves veteran's Stationmaster asp is admin_system321.gif in addition

Upload!

Corona!

The first-class information supervisory system reminds you: Was sorry very much, because you submit in the content or in the visit content included the key word which or your IP the system did not permit has been restricted visit, this operation was invalid, the system has recorded all data which your IP and you submitted. Please note, do not submit any violates the national stipulation the content! This interception's related information is: drop table

Trades Haiyang top the biography, is fainting…Is intercepted!

 

Other pages: : 1 * 2 * 3 * Next>>
Prev:MSSQL the database SA jurisdiction invasion's feeling becomes aware Next:Under Linux system from forum to SSH invasion analysis

Comment:

Category: Home > hacker invade