You are here: hacking technology > invades the examination > Content
Hot Articles
Recommend Articles
New Articles
pcshare official net examination
  Add date: 08/05/2008   Publishing date: 08/05/2008   Hits: 18
Total 2 pages, Current page:1, Jump to page:
 
The official net is places on the hypothesized main engine, pcshare does the software which sells for money to do such poor, perspiration. . .

Took webshell on the official net's hypothesized main engine, the jurisdiction has supposed does not die, might find the pcshare official net's table of contents directly, had no way the revision besides the main page, other might revise. Not what meaning, if ties up the horse directly in inside the official net's software? At certain meeting many hackers, considers as finished, does not do consumes the moral behavior the matter.





Receives round trip looks at its confirmation server.

ip is: 218.244.136.41

Is also in production time must input comes up the confirmation a user name and the password to the website, in the website has sqlin.asp the user name which and the password comes post changes over to the database carries on the inquiry, after the existence, returns again an encryption value, continues to produce again, this is the network confirmation which present many procedures use.

However his this network confirmation not how good, if explains is may jump over that input password confirmation, it has not downloaded the thing from the server, is only the back-spacing data confirmation.

Confirmed the server is also a hypothesized main engine, ftp, Wan Wang, heard Wan Wang the hypothesized main engine safe good.

Has arranged in order on this ip domain name, has selected a website casually, has to pour into, but the jurisdiction is very low, has not supported the multi-sentence execution and the wrong prompt closure, guessed that the table, has not had that thoughts, puts out my dictionary to sweep in the website the table of contents and the document has a look.



We may see has conn.asp_bak, my dictionary is quite uneven, many years collect, knew that conn.asp is the database linked file, after the programmer edits the software fix, can produce the _bak backup, this is may download.

Has dismantled, inside has the sql account number and the password, certainly is the low jurisdiction, does not want the wild hope. However xp_dirtree expanded may use to be good.



Connects with sql, after not being able to master on-line many people attain the sql user name and the password, but also goes in local to build iis structure to pour into, then places inside nbsi to run, cannot think through really.

Below operates directly inside the sql enterprise supervisor.



Very melancholy, because is the hypothesized main engine, therefore has 200 website tables of contents.

Have to uses the sql sentence the way which and the table of contents arranges in order reads in the outside and inside, inquires the table of contents again from the outside and inside.

pcshare confirms the website to have the very clear confirmation table of contents.

http://www.pcshares.cn/pcshare200/user.asp

Writes the sql sentence search:

drop table tmp;

create table tmp

(

[id] [int] IDENTITY (1,1) NOT NULL,

[name] [nvarchar] (300) NOT NULL,

 
Other pages: : 1 * 2 * Next>>
Prev:One time seeps in three Unix main engines the system test process Next:Based on CallStack counter-Rootkit HOOK examination

Comment:

Category: Home > invades the examination