Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial Compromising plasma botnets filter_list
Author
Message
Compromising plasma botnets #1
Special thanks to @Hellborn for providing some of this information.

Okay so this is more of admin stupidity then a vulnerability, like the merge dir for mybb or the install for vbulletin.

First, you're gonna need to find some plasma URLs, if you dont have one, try using a google dork like

"inurl:plasma/login.php"

or you can go to http://cybercrime-tracker.net/index.php?search=plasma where people report the login pages.

After you have a target website, simply replace login.php with install.php and create a new account, then go back to login.php and login.

This rarely works, but its pretty cool when it does.

So again thanks hellborn.
Wavy baby

Reply

RE: Compromising plasma botnets #2
I am trying this now, Thank you a lot.
There are several way to hijack botnets, and I remember seeing a tutorial somewhere but I can't remember where.

EDIT; Doesn't seem like any of these works so guess I will have to wait and try some other time whenever the list is refreshed.
[Image: xlbdwZT.png]

Reply

RE: Compromising plasma botnets #3
Google Dorks only came up with two results Tongue I tried some of the sites on cybercrime tracker, but none of those worked. Seems like a cool method though if you could get it to work correctly. Tongue
[Image: e41e887e66a5f51303a56eafd27ba344.png]

Reply

RE: Compromising plasma botnets #4
(03-28-2014, 03:37 PM)Vipr Wrote: Google Dorks only came up with two results Tongue I tried some of the sites on cybercrime tracker, but none of those worked. Seems like a cool method though if you could get it to work correctly. Tongue

Best bet is to find ones that aren't listed, but that takes time and effort.
Even then, this would require someone to be pretty stupid with their setup, which most aren't, but is still possible.
telegram: @satan_sl

Reply

RE: Compromising plasma botnets #5
(03-28-2014, 03:32 PM)Blue Wrote: I am trying this now, Thank you a lot.
There are several way to hijack botnets, and I remember seeing a tutorial somewhere but I can't remember where.

EDIT; Doesn't seem like any of these works so guess I will have to wait and try some other time whenever the list is refreshed.

Yeah, i usually check the list and the google dork every day and see if theres a new site.

(03-28-2014, 03:37 PM)Vipr Wrote: Google Dorks only came up with two results Tongue I tried some of the sites on cybercrime tracker, but none of those worked. Seems like a cool method though if you could get it to work correctly. Tongue

It works, just really hard to find sites Tongue

(03-28-2014, 03:45 PM)Satan Wrote: Best bet is to find ones that aren't listed, but that takes time and effort.
Even then, this would require someone to be pretty stupid with their setup, which most aren't, but is still possible.

This.
(This post was last modified: 03-28-2014, 03:54 PM by Bannedshee.)
Wavy baby

Reply

RE: Compromising plasma botnets #6
(03-28-2014, 03:53 PM)Bannedshee Wrote: Yeah, i usually check the list and the google dork every day and see if theres a new site.


It works, just really hard to find sites Tongue


This.

What all can you do with it, I mean can you transfer them over to your own net?
telegram: @satan_sl

Reply

RE: Compromising plasma botnets #7
(03-28-2014, 03:55 PM)Satan Wrote: What all can you do with it, I mean can you transfer them over to your own net?

Yep, plasma has a built in function to update and install a new file using URL download, and it has a botkill.
Wavy baby

Reply

RE: Compromising plasma botnets #8
Hah. This is funnier than the booter thing.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Compromising plasma botnets #9
You know, it is "vulnerabilities" like these that really entertain me. There's no worse vulnerability than a stupid administrator.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: Compromising plasma botnets #10
(03-28-2014, 07:37 PM)Oni Wrote: You know, it is "vulnerabilities" like these that really entertain me. There's no worse vulnerability than a stupid administrator.

Its like leaving your front door open when you know theres a pack of wild dogs outside your house.
Wavy baby

Reply