The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thirteen Years of Service
Posts: 2,721
Threads: 222
RE: booter exploitation 09-03-2014, 04:21 AM
#11
(09-03-2014, 04:13 AM)Reiko Wrote: You need to form a valid URL with your attack as well.
http://loli.dance/?test%26%26commands for example
Are the ${IFS} necessary? By default it stands for <space><tab><newline>, but what do you do if it has been changed?
•
Thirteen Years of Service
Posts: 700
Threads: 19
RE: booter exploitation 09-03-2014, 05:46 AM
#12
(09-03-2014, 04:21 AM)Adorapuff Wrote: Are the ${IFS} necessary? By default it stands for <space><tab><newline>, but what do you do if it has been changed?
Doesn't matter, bash uses $IFS as separator. That's its entire purpose. If $IFS is niggerniggernigger, then "niggerniggernigger" is now a space.
We're using ${IFS} because we can't use spaces or %20.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47
•
Thirteen Years of Service
Posts: 2,721
Threads: 222
RE: booter exploitation 09-03-2014, 05:57 AM
#13
(09-03-2014, 05:46 AM)Reiko Wrote: Doesn't matter, bash uses $IFS as separator. That's its entire purpose. If $IFS is niggerniggernigger, then "niggerniggernigger" is now a space.
We're using ${IFS} because we can't use spaces or %20.
Got it, thanks for clearing that up for me.
•
Thirteen Years of Service
Posts: 529
Threads: 60
RE: booter exploitation 09-04-2014, 03:26 AM
#14
(09-03-2014, 04:13 AM)Reiko Wrote: You need to form a valid URL with your attack as well.
http://loli.dance/?test%26%26commands for example
Does it matter whether it's a POST or GET request? If it's GET how do I find the API URL?
Would this be an example -
http://nigger.li/sendboot.php?host=%26%2...method=GET
•
Thirteen Years of Service
Posts: 700
Threads: 19
RE: booter exploitation 09-04-2014, 04:14 AM
#15
(09-04-2014, 03:26 AM)Crypt Wrote: Does it matter whether it's a POST or GET request? If it's GET how do I find the API URL?
Would this be an example - http://nigger.li/sendboot.php?host=%26%2...method=GET
No... sigh... You don't need the API URL at all. The attack has to
look like a URL to get past the fucking filter.
Excuse me for a moment while I fuck a rusty soup can out of frustration.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47
•
Thirteen Years of Service
Posts: 529
Threads: 60
RE: booter exploitation 09-05-2014, 01:07 AM
#16
(09-04-2014, 04:14 AM)Reiko Wrote: No... sigh... You don't need the API URL at all. The attack has to look like a URL to get past the fucking filter.
Excuse me for a moment while I fuck a rusty soup can out of frustration.
OOOOOOOOHHHHHHHHhHHHHHHHh I get what you mean now. Fuck me for being so stupid this whole time.
•