lavalair script holes

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • cedwap
    replied
    bro..what should we put at .htacces to secure syt.?

    Leave a comment:


  • robzky
    replied
    Im just a noob!

    Leave a comment:


  • kiLLeR-eyEd_14
    replied
    Originally posted by robzky View Post
    hackers change the extesinn of c99shell script.. E.G. a.php.Jar or a.php.nth
    the php word is still there..just do a pregmatch of the word..like if(preg_match("/php/i",basename($file))) then invalid extension..Can also use htaccess trick..Just use some head..

    Leave a comment:


  • tres
    replied
    Originally posted by ranzit2 View Post
    i dnt understand how a php file will work if its extension changed to jar.,plz explain
    try to rename it to filename.php.nth then upload it to ur file manager and browse the file.. gOogle Search 4 c99shell, etc..

    Leave a comment:


  • subzero
    replied
    ya not fat lloll i seen ya pic :P

    Leave a comment:


  • amylee
    replied
    Originally posted by ranzit2 View Post
    i dnt understand how a php file will work if its extension changed to jar.,plz explain
    improper or **** configuration of apache and the mime types thats one reason
    basic protection is mod_security so use that

    plus there are many many ways of hacking the script i sent my last lava script before i went to my current one to some european security team and had an audit put on it, cost me 320 euros to do and the results i got were unbelievable

    i'm not going to share the results reason being the cost it was for me was a lot 1/4 of my monthly wage and a bet many others will do the same here also, but if you are using it don't piss off anybody who can "actually" and not the people here and around other such communities saying i'll hack this and that, i'll murk ya site biatch etc etc

    no offence to them people but if anyone had the sense to actually send it to a 3rd party you wouldn't be using it any longer

    just my 2 fat Australian cents there

    Leave a comment:


  • ranzit2
    replied
    Originally posted by robzky View Post
    hackers change the extesinn of c99shell script.. E.G. a.php.Jar or a.php.nth
    i dnt understand how a php file will work if its extension changed to jar.,plz explain

    Leave a comment:


  • robzky
    replied
    Originally posted by kiLLeR-eyEd_14 View Post
    i don't know more about c99shell..i think it's a php script right?so, just don't allow php files to be uploaded..or if you want, block php files using your htaccess as what ozzie has posted here..
    hackers change the extesinn of c99shell script.. E.G. a.php.Jar or a.php.nth

    Leave a comment:


  • jefweewap
    replied
    lol

    Leave a comment:


  • something else
    replied
    Originally posted by kuklux View Post
    Ozzie try to visit my site and try to hack my session or my members sessions and see what message will prompt! tnt.
    Ozzie will hack your site a piece of piss lol

    Leave a comment:


  • kuklux
    replied
    Ozzie try to visit my site and try to hack my session or my members sessions and see what message will prompt! tnt.

    Leave a comment:


  • tres
    replied
    u better check all of ur folders, think y some script here are hacked from other site? Even they dont know ur cpanel login details but uploaded the backdoor key, you wil be hacked... im only sharing this coz im a victim of this. and the hacker forgot to remove that tools.
    Last edited by tres; 11.09.09, 23:28.

    Leave a comment:


  • metulj
    replied
    Originally posted by anderson View Post
    Originally posted by ozziemale31 View Post
    i know how to block c99shell from being used in any upload folder
    ozzie plz share ur experience on it sothat we can know more.
    he already did that..
    you should take a good look into MOBILEZONEZ
    posted by him...

    Leave a comment:


  • something else
    replied
    Yeah the secret mafia of lava will concrete your feet and sink u to the bottom of the ocean???? wtf?

    Im just saying that people wont pin-point the holes as it will cause a mass hacking spree

    Leave a comment:


  • kiLLeR-eyEd_14
    replied
    i don't know more about c99shell..i think it's a php script right?so, just don't allow php files to be uploaded..or if you want, block php files using your htaccess as what ozzie has posted here..
    Last edited by kiLLeR-eyEd_14; 11.09.09, 10:53.

    Leave a comment:

Working...
X