[原创〕利用Dvbbs动网论坛漏洞来入侵之体验
上一篇 /
下一篇 2006-09-21 11:14:53 / 天气: 晴朗
/ 心情: 高兴
/ 个人分类:原创文章
大家好,今天来兴趣了就对Dvbbs动网论坛漏洞(这个漏洞好早就有,本人菜鸟遇的也晚,不要见笑)。玩了一下本人菜鸟一个,什么都不知道,刚开始的时候虽说有好多的不懂,但在黑基有的斑竹和好友的帮助下弄清了一些,于是就拿出来与大家一起分享!没有什么技术,高手不要见笑,对于新手来说,一定要看哦!我在写这个文章的之前试了不少,失败了也不少!在实际试的时候会有很多问题出现,对于本人此文章出现的问题我或许还不是很清楚,也请过路的高手指点,谢谢!
icg
cuIj
~t/p,N0★黑基空间★:Yk)r}0v#R
我用的工具:动网漏洞大扫描1.0测试版.辅臣数据库浏览器(这些有我的空间都有下载,空间地址:http://free.ys168.com/?yy121密码hackbase)
$M9]/ttN
s0 先用动网漏洞大扫描来扫一下,如图所示:★黑基空间★af-Rn0Vj
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/18/8/mpf121569885,20060918141218.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">★黑基空间★JEr"F7D6GM1]6j
pWOEZdm0等一会就有了结果:★黑基空间★'t gk RH;s`0Q
★黑基空间★_7B&W
^%\%K
★黑基空间★m&zrQ)l*f9Q
于是我就随便找个网站来试吧:
8m3t3X*k4OYV0http://www.pa999.cn/dvbbs/|欢迎访问聚一堂论坛[聚一堂论坛] -- Powered ... |大小:8MB,地址:http://www.pa999.cn/dvbbs//data/dvbbs7.mdb|7.1.0 Sp1★黑基空间★ aN}0X&\.l3a+KO/T[
用迅雷把数据库下载下来,再用辅臣数据库浏览器打开!
n9r+AQV Xm)k @%H0 如图:
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/18/8/mpf121569885,20060918142236.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">
^;J
g+w%I\
uI^0在那找表,
%qu/^kUWek0
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/18/8/mpf121569885,2006091814331.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">
;l/e*I,@:g9{6c0user:admin★黑基空间★'`C)})Qafm
password:469e80d32c0559f8★黑基空间★+W3Bc6x5v4r,~Q
于是在线解密登陆http://www.md5.org.cn/md5/getpass.asp?info=admin888
K/BEjQ^
x0得出Result:★黑基空间★ x])t[.x"yALW
这个时候来分析一下,猜一下他的后台入口:★黑基空间★aPY'LSB~S;e4A
我猜到:http://www.pa999.cn/dvbbs/admin_login.asp★黑基空间★(r
yhV9r$t
登陆,晕!
yNI
Zw)i0错误,不好失败!
[1{?-M$h;vh
C+X0再找个网站:http://www.kmt.cn/Dvbbs/index.asp下他的数据库,好的如图:
(f ^!Z/r[0
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/20/10/mpf121569885,20060920192221.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">
9e/^ J:m0Ka']%x0用辅臣数据库浏览器打开
gr6K/K]U3@4Z0
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/20/10/mpf121569885,20060920192628.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">★黑基空间★MT)H+z&S"F+t*w
看到了没有?
%O S?1r]0有两个管理员的信息,★黑基空间★*x.HZ
C _
user:admin★黑基空间★/]2^P$QaA6Yw2Gh
password:469e80d32c055**
q.zs \I/`&V*^1N9_0user:听雨
Zi+wjqk0password:ded46b36c18****★黑基空间★
vQH5j
Q)ez;b7]
就用user:听雨
,L_c-hN h0于是到网上去解密:http://www.xmd5.com/index_en.htm
2X'kLzq.Z0得到密码:
C K%W%zW&^-Z.hw%q0进http://www.kmt.cn/Dvbbs/login.asp
.V5n(O
r2R!b+d){0好的,进去了,★黑基空间★@r#ty
onb b#q
如图:
9EOr xg1sy O0
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/20/10/mpf121569885,20060920192235.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" pop="Click here to open new window
CTRL+Mouse wheel to zoom in/out" resized="true">
^cUQk0★黑基空间★;MH
Pc+zc|
接下来你可以做好多的事情!
*OV,{!k4S.|0
5Q)Ou"Q'P0不用我说了吧,希望大家不要改后台的密码`不要在里面搞破坏`中国人是不黑中国人的,否则后果自负!
2nC
{-Tm0
9r,e,h3T;?F:c0今天我又去看了一下,真可恶,有人在那挂马!★黑基空间★|`4f*|(gx6Q7T:p8W
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://images.blogcn.com/2006/9/21/5/mpf121569885,2006092195119.jpg');}" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}">
/k]Z9lOtVb+HP#w0★黑基空间★%l
MJAU%y
对于这些人,我们嗤之以鼻!★黑基空间★tNI
tCX%q
UV/I0l;P0
相关阅读:
- [原创]简单地隐藏你的爱马和账号 (mpf_hgsf, 2006-9-16)
- [原创]网吧游荡记 (mpf_hgsf, 2006-9-16)
- 【黑基原创】简单的邮箱、QQ、word密码破解与防护 (mpf_hgsf, 2006-9-30)
- [转SINA]中毒我帮你 手工恢复EXE文件关联方法介绍 (黑基小白, 2006-10-12)
- [转]内存不能为read或该内存不能为written的解决方案 (黑基小白, 2006-10-12)
- [转]用简单命令 检查电脑是否被安装木马 (黑基小白, 2006-10-12)
- 旁注WEB综合检测程序Ver3.6专用版 (弈宇风尘, 2006-10-12)
- [SINA]不再崩溃 如何清除操作系统中的伪装服务 (黑基小白, 2006-10-12)
- [转]ADSL拨号中出现的错误代码 (黑基小白, 2006-10-12)
- [SINA]木马程序和病毒清除的通用解法 (黑基小白, 2006-10-12)
导入论坛
引用链接
收藏
分享给好友
推荐到圈子
管理
举报
TAG:
情感绿洲
电脑网络
原创文章