lavalair script holes

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Vayne
    replied
    pff.. is there anything to keep in secret??

    some pages doesn't have
    Code:
    mysql_escape_string
    most of them was in older lavalair scripts, main page's.

    if u get number from database, like uid, than query make in intval();
    etc..
    type in adress log-
    Code:
    g sql injection

    Leave a comment:


  • something else
    replied
    People wont share the holes as it will make a mad frenzy on hacking!
    The 2 main injection holes have been wrote in this forum already.
    and the solutions are in here aswell.

    Leave a comment:


  • anderson
    replied
    Originally posted by ozziemale31 View Post
    i know how to block c99shell from being used in any upload folder
    ozzie plz share ur experience on it sothat we can know more.
    Last edited by anderson; 11.09.09, 10:59.

    Leave a comment:


  • ozziemale31
    replied
    i know how to block c99shell from being used in any upload folder

    Leave a comment:


  • tres
    replied
    what are the other posible holes? and what are the solution?

    Leave a comment:


  • tres
    replied
    yah. So i have activated my hotlink protection..

    Leave a comment:


  • anderson
    replied
    Originally posted by tres View Post
    yeah! Session id hijacking only steal ses id... but c99shell can control ur cpanel. mass inject, delete file, upload file etc.
    use a secured uploader.

    Leave a comment:


  • ranzit2
    replied
    Originally posted by tres View Post
    yeah! Session id hijacking only steal ses id... but c99shell can control ur cpanel. mass inject, delete file, upload file etc.
    c99 shell need to b uploaded but image need only to b linked.may b u had nt gud uploader

    Leave a comment:


  • tres
    replied
    yeah! Session id hijacking only steal ses id... but c99shell can control ur cpanel. mass inject, delete file, upload file etc.

    Leave a comment:


  • ozziemale31
    replied
    c99shell is crap i can steal a session using a php image done it to scot paul many a times lol

    Leave a comment:


  • ozziemale31
    replied
    well you've come to the rite place to learn lol

    Leave a comment:


  • tres
    replied
    some intruderz uses c99shell. a famous hacking tool.... i am a victim of that c99shell.... A few months ago.. They have chmoded my file and folders to 0000..
    Last edited by tres; 10.09.09, 14:54.

    Leave a comment:


  • tres
    replied
    hackers never reveals it self! we are here to share knowledge and to help others.. we use lavalair for our site becouse we dont have such knowledge to code...

    Leave a comment:


  • ozziemale31
    replied
    lol i know most ways of hacking this script but a good hacker never tells ther secrets

    Leave a comment:


  • kei_ki7
    replied
    Originally posted by anderson View Post
    This type of topic has been created here many times. So no need to create newly.
    i think he need the link ??

    Leave a comment:

Working...
X