Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon. Entire thread

Help me laern this script

Name: Anonymous 2009-07-27 22:08

I know I'm such a useless newfag but can anybody please help me use this http://milw0rm.com/exploits/2105

I keep getting
XMB <= 1.9.6 'u2uid' SQL injection / admin credentials disclosure
by rgod rgod@autistici.org
site: http://retrogod.altervista.org
dork: "Powered by XMB"

Usage: php  host path username password OPTIONS
host: target server (ip/hostname)
path: path to XMB
user/pass: you need a valid user account
Options:
 -T[prefix] specify a table prefix (default: xmb_)
 -d[delay] " a delay between posts (there is an antiflood protection, default: 5)
 -p[port]: " a port other than 80
 -P[ip:port]: " a proxy
Examples:
php  localhost /xmb/ user pass -d6
php  localhost /xmb/Files/ user pass -Txmb191_

I don't know where to edit

Name: Anonymous 2009-07-27 22:24

No.  Not at all.  If you don't know how to edit it you shouldn't be using it.

Name: Anonymous 2009-07-27 22:31

So do you mean I have to learn the entire PHP lesson first?
I guess there's no choice

Name: Anonymous 2009-07-27 22:45

dude, just stop being so add and read the instructions

Name: Anonymous 2009-07-27 22:54

rgod is a fagget

Name: Anonymous 2009-07-28 1:41

Holy shit OP, you're a flaming homosexual.

Name: Anonymous 2009-07-28 7:25

I try run it in cmd
But I can't

I run it like this
"C:\Program Files\Apache Software Foundation\Apache2.2\htdocs\arc.php  http://site.com/site/portal.php myid 1234567 "

Name: Anonymous 2009-07-28 10:32

Name: Anonymous 2009-07-28 12:19

Give it up. You fail at life. You can't even run a finished exploit. You'll never get anywhere. Might as well kill yourself right now.

Name: Anonymous 2009-07-28 14:36

DCC SEND "PENISFAGS" 0 0 0 0

Name: Anonymous 2009-07-28 23:23

So, nobody want to help then?

Name: Anonymous 2009-07-28 23:25

>>11
What >>9 said. How fucking hard is it to download a PHP implementation (if you don't have one installed), and just run the script. It's just one fucking command.

Name: Anonymous 2009-07-28 23:36

OP fails it. LEARN TO READ, DUMBASS.

Name: Anonymous 2009-07-29 0:16

I've already installed PHP and Apache and for some reason the script still can't work

Name: Anonymous 2009-07-29 0:21

>>14
You don't need apache. Fuck, why am I even responding to this shit. Look at your post:
Usage: php  host path username password OPTIONS
Can you read Usage?
The script should be run like this from your shell/command line:
php script.php arguments
php script.php localhost /xmb/Files/ user pass -Txmb191_

where the arguments are described in the `usage'.
Have you ever used a command line application before, why the fuck are you posting basic computer usage questions on /prog/? Go to /g/ for these questions.

IHBT

Name: Anonymous 2009-07-29 1:11

    ( ≖‿≖)  D
    ( ≖‿≖ )   I
    (≖‿≖ )  C
    (‿≖   )   K
    (≖   )   
    (     )   T
    (     )   O
    (   ≖)   W
    (  ≖‿)   E
    ( ≖‿≖)  R

Name: Anonymous 2009-07-29 1:12

Yeah, I tried that too many times before I post here but it gives me
'PHP' is not recognized as an internal or external command, operable program or batch file

Name: Anonymous 2009-07-29 1:26

>>17
Add php's location to your PATH environment variable.
If you don't know such simple things, what makes you think you can `hack' a site? Lern2computers first.

Name: Anonymous 2009-07-29 1:31

At last, it works
Thank you so much

Name: Anonymous 2009-07-29 1:41

God damn, why can't people learn that you don't do programming on windows?

Name: Anonymous 2009-07-29 2:52

>>20
because you do do programming on windows?

Name: Anonymous 2009-07-29 3:09

>>21
<insert rabid anti-microsoft diatribe here>

Name: Anonymous 2009-07-29 3:12

Suddenly, anti-microsoft thread

Name: Anonymous 2009-07-29 3:14

It's not that I hate MS, it's just that coding on windows is terribly inconvenient.

Name: Anonymous 2009-07-29 3:38

>>15
>>18

I hate you more than OP

Name: Anonymous 2009-07-29 3:52

>>24
Developing on Windows is actually easy, there are many Windows-only tools, and all the Unix-like tools that I need work well. There's little difference from developing on *nix.

>>25
Why? Because I helped a stupid script kiddie to run a PHP script? I doubt he'll be able to get very far with his ``hacking'' endeavour as he has no idea how to run basic CLI commands. A lot more commands would need to be ran for him to do anything successful if he manages to exploit some host running an old messageboard.

Name: Anonymous 2009-07-29 9:32

>>26
Developing on Windows is actually easy, there are many Windows-only tools
Driving in Boston is easy, there are many roads.

Name: Anonymous 2009-07-29 9:50

Speaking of which, how do I save my screen session so that I can load it after rebooting?

Name: =+=*=F=R=O=Z=E=N==V=O=I=D=*=+= !frozEn/KIg 2009-07-29 9:54

Firefox->Bookmarks ->Bookmark all tabs


_______________________________
http://xs135.xs.to/xs135/09042/av922.jpg
Velox Et Astrum gamedev forum: http://etastrum.phpbb3now.com
There can be no liberty for a community which lacks the means to detect lies.

Name: Anonymous 2009-07-29 11:18

>>28
You don't. You can detach it and re-attach it after a while, but it will be gone as soon as you power off the machine.

Name: Anonymous 2009-07-29 12:10

>>30
ololololol thats gay

Name: Anonymous 2009-07-29 12:15

>>26
His ``hacking'' endeavor as you put it is just getting admin credentials on the messageboard. There are no more commands to run, it's all pretty self-explanatory from there (even more so than this script).

I also hate you for helping him.

Name: Anonymous 2009-07-29 12:15

>>31
What's so gay about not restoring a session after reboot. That would be an inconvenience to me, unless you happen to be gay about being inconvienced.

Name: Anonymous 2009-07-29 12:24

>>32
I see... I haven't looked at what the exploit code was doing as it didn't interest me. I thought it was some remote code execution exploit that let's you execute your own scripts remotely, which kiddies usually use to bind a shell, and those do require at least basic *nix knowledge.

Name: Anonymous 2009-07-29 12:30

>>34
What's so hard about binding a shell? Even connect-back is just a few system calls, so I'd figure it'd be even easier with PHP.

Name: Anonymous 2009-07-29 14:33

>>35
The script is an SQL injection, not arbitrary code execution. As his target is probably running on a shared host, they'll have EXECUTE rights turned off for the MySQL user.

Good luck binding a shell.

Name: Anonymous 2009-07-29 15:06

>>35
It's nothing hard, but obviously the OP has trouble with reading usage of simple scripts, and probably hasn't ran many command line tools in his life. What makes you think he'll be able to get very far with binding a shell, or actually running any commands on it? He seems to be the type that needs to be spoonfed, which leads me to believe that he would not succeed in doing much.

Name: Anonymous 2011-10-19 6:29

derp

Newer Posts
Don't change these.
Name: Email:
Entire Thread Thread List