![]() |
|
booter exploitation - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: booter exploitation (/Thread-booter-exploitation) Pages:
1
2
|
RE: booter exploitation - Adorapuff - 09-03-2014 (09-03-2014, 04:13 AM)Reiko Wrote: You need to form a valid URL with your attack as well.Are the ${IFS} necessary? By default it stands for <space><tab><newline>, but what do you do if it has been changed? RE: booter exploitation - Reiko - 09-03-2014 (09-03-2014, 04:21 AM)Adorapuff Wrote: Are the ${IFS} necessary? By default it stands for <space><tab><newline>, but what do you do if it has been changed? Doesn't matter, bash uses $IFS as separator. That's its entire purpose. If $IFS is niggerniggernigger, then "niggerniggernigger" is now a space. We're using ${IFS} because we can't use spaces or %20. RE: booter exploitation - Adorapuff - 09-03-2014 (09-03-2014, 05:46 AM)Reiko Wrote: Doesn't matter, bash uses $IFS as separator. That's its entire purpose. If $IFS is niggerniggernigger, then "niggerniggernigger" is now a space. Got it, thanks for clearing that up for me. RE: booter exploitation - Crypt - 09-04-2014 (09-03-2014, 04:13 AM)Reiko Wrote: You need to form a valid URL with your attack as well. Does it matter whether it's a POST or GET request? If it's GET how do I find the API URL? Would this be an example - http://nigger.li/sendboot.php?host=%26%26commandsandshit&port=80&time=0&method=GET RE: booter exploitation - Reiko - 09-04-2014 (09-04-2014, 03:26 AM)Crypt Wrote: Does it matter whether it's a POST or GET request? If it's GET how do I find the API URL? No... sigh... You don't need the API URL at all. The attack has to look like a URL to get past the fucking filter. Excuse me for a moment while I fuck a rusty soup can out of frustration. RE: booter exploitation - Crypt - 09-05-2014 (09-04-2014, 04:14 AM)Reiko Wrote: No... sigh... You don't need the API URL at all. The attack has to look like a URL to get past the fucking filter. OOOOOOOOHHHHHHHHhHHHHHHHh I get what you mean now. Fuck me for being so stupid this whole time. |