|
|||||||
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hey guys. How are you all? Im not looking to be spoonfed how to get passwords from forums, Im more into learning than just getting scammed or told im a n00b. Becuase im not asking you for some "miracle" program or lie that will only hurt me. Yes, I have Googled but I can't find any relevant topics related to this other than on this forum (which haven't helped that much).
== Any help will be greatly appreciated but im not looking to be flammed so if thats your intentions, don't waste my time. Thanks. |
|
#2
|
||||
|
||||
|
Google search for invisionfree forum vulnerabilities. Try to trick the person/people into giving you their passwords via spoofed email.
|
|
#3
|
|||
|
|||
|
Thank you for replying Moon. I read on this very forum that there are "tools" for getting keystrokes and passwords, I don't remember that well what else was on there, it was called elitec0ders. However, I've tried to download them and I get notified via my firewall, antivirus, and spyware finder that the downloads are basically trojans. Is this normal and is it safe to download these? (Sorry for being off topic, just curious)
|
|
#4
|
||||
|
||||
|
Quote:
You mentioned elitec0ders.net -- I would advise against using their software because on this forum I've heard many people complaining that it doesn't work at all. Last edited by Ezekiel; 03-24-2007 at 02:53 PM. |
|
#5
|
|||
|
|||
|
Thank you for replying Mike, You were the one who gave that link, I was wondering who it was, (I read a simular post on invisionfree hacking were you posted that link). Anyways Im open to learning, I hear that keyloggers can be used, some can even be made undetectable but I don't know myself. Any ideas?
|
|
#6
|
||||
|
||||
|
Most keyloggers you find on the Internet aren't undetectable, mostly because they can be found on the Internet. You'd either have to make your own (pretty hard) or hope that one you use is undetectable. Then you have the problem of getting the victim to donwload/run it.
|
|
#7
|
|||
|
|||
|
Im guessing you would have to be really deceptive in order to get someone to click a download link with a keylogger in it right? Alot of keyloggers are placed on sites like Kazaa and LimeWire to randomly target people, however this isn't something random, it's targeted at a specific person and forum. I guess there aren't any real ways to get an admin password or hack into the cp without having scripts or whatever. I had one, but my friend couldn't host it on his webserver and since I don't have one, well meh.
|
|
#8
|
||||
|
||||
|
Quote:
Try to think back to whenever you last installed some unknown software from someone -- you probably either trusted the source or were tempted by something it had to offer. For an attacker to spread software to specific people, he would need creativity and the ability to gain that person's trust. The software would also need to be not detected by antivirus programs. To gain trust, social engineering and email spoofing would be just two methods an attacker would use. Quote:
InvisionFree however is not one of these websites. They use the same forum software across all their servers and upgrade regularly, so they are unlikely to be vulnerable in any way that has been publicly documented. Quote:
|
|
#9
|
|||
|
|||
|
Im not sure of the specifics of the script becuase my friend was the one who knew about all the technical stuff, however I do know it was downloaded off milw0rm if thats any conselation.
He told me the script allowed the user to change the admin password, meaning you could in theory do that, then log in with the new details and the user couldn't get back in, since he doesn't know the new* password. Last edited by NetHogz; 03-25-2007 at 11:30 AM. Reason: misc |
|
#10
|
||||
|
||||
|
Yeah, I'm guessing it's a Perl script then, because most vulnerabilities are written in Perl. I'd suggest Googling a program called ActivePerl.
|
|
#11
|
|||
|
|||
|
Once I download Active Perl how would I use it with the script. Im still a novice as far as using scripts and such.
http://milw0rm.com/exploits/2696 << Thats the one I mean, I just searched through my chat logs and found this. He told me at the time to save it as a pl and host it on a webserver. :? Last edited by NetHogz; 03-25-2007 at 01:37 PM. |
|
#12
|
|||||
|
|||||
|
Quote:
http://perl.about.com/od/gettingstar...testperl_2.htm Quote:
Quote:
Quote:
Some additional comments about that script: Quote:
Code:
This works if: "Debug Level" is set to 3 or Enable SQL Debug Mode is turned on In General Configuration of the forum software. This still doesn't rule out social engineering, monitoring software or many more methods for someone who wanted to steal forum passwords. Last edited by Ezekiel; 03-25-2007 at 03:41 PM. |
|
#13
|
|||
|
|||
|
Moniter what? If the script won't work for exploiting an invisionfree board, you suggested other methods, im interested in what those are, considering I've tried keylogging, exploits and false invisionfree emails, but it's a little hard to convince someone to do something unless it looks real or such. Thanks for replying Mike.
|
|
#14
|
||||
|
||||
|
By "monitoring software" I was referring to programs like remote administration tools that monitor users' keystrokes, take screenshots; things like that. Keyloggers can be classed under this category, although they only perform one of the functions I listed.
Quote:
Last edited by Ezekiel; 03-25-2007 at 07:11 PM. |
|
#15
|
|||
|
|||
|
Do you know of any good keyloggers out there that could do such a thing? (thanks for replying)
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|