Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Conquer Online 2 > CO2 Programming
You last visited: Today at 11:50

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Help] Http details - Web Host backdoor.

Discussion on [Help] Http details - Web Host backdoor. within the CO2 Programming forum part of the Conquer Online 2 category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Oct 2007
Posts: 45
Received Thanks: 23
[Help] Http details - Web Host backdoor.

Well, this is probably the worst idea, but I have found the following;



Ports 22, 25, 80, 110 show open

I have tried ftp anon login through port 80 and ssl anon login through port 22, however I'm no network guru.

I know these are file servers for the webhost but from this i have found;

The IP address of credit.91.com is 208.96.12.132
The IP address of co.91.com is 208.113.97.208
The IP address of vips.91.com is 208.96.12.132




This last one will have all of the account logins.

The registered name for the servers is ;

the best i can get from a cgi test is;

#!/bin/sh

# disable filename globbing
set -f

echo "Content-type: text/plain; charset=iso-8859-1"
echo

echo CGI/1.0 test script report:
echo

echo argc is $#. argv is "$*".
echo

echo SERVER_SOFTWARE = $SERVER_SOFTWARE
echo SERVER_NAME = $SERVER_NAME
echo GATEWAY_INTERFACE = $GATEWAY_INTERFACE
echo SERVER_PROTOCOL = $SERVER_PROTOCOL
echo SERVER_PORT = $SERVER_PORT
echo REQUEST_METHOD = $REQUEST_METHOD
echo HTTP_ACCEPT = "$HTTP_ACCEPT"
echo PATH_INFO = "$PATH_INFO"
echo PATH_TRANSLATED = "$PATH_TRANSLATED"
echo SCRIPT_NAME = "$SCRIPT_NAME"
echo QUERY_STRING = "$QUERY_STRING"
echo REMOTE_HOST = $REMOTE_HOST
echo REMOTE_ADDR = $REMOTE_ADDR
echo REMOTE_USER = $REMOTE_USER
echo AUTH_TYPE = $AUTH_TYPE
echo CONTENT_TYPE = $CONTENT_TYPE
echo CONTENT_LENGTH = $CONTENT_LENGTH



If any one knows some exploit to hacking web servers please pm me as I would like to move this forward.

Edit* Tried to brute force ftp and http socks for username and password using hydra, but nothing came back.

Naddo1

__________________________________________________ _____________________

HIT THE THANKS BUTTON ----------------------------------|
naddo1 is offline  
Old 04/05/2009, 18:44   #2
 
elite*gold: 20
Join Date: Aug 2007
Posts: 1,749
Received Thanks: 2,199
If the police knocks on your door, you better be good at hiding .
IAmHawtness is offline  
Old 04/05/2009, 22:56   #3
 
elite*gold: 0
Join Date: Oct 2007
Posts: 45
Received Thanks: 23
Quote:
Originally Posted by IAmHawtness View Post
If the police knocks on your door, you better be good at hiding .
I did say at the top of the thread;

"this is probably the worst idea"

but hey, anyone worth a bit of salt should be able to re-direct their router and mask their own ip ;P
naddo1 is offline  
Old 04/05/2009, 22:57   #4
 
Alex_Boss's Avatar
 
elite*gold: 0
Join Date: Jun 2008
Posts: 14
Received Thanks: 0
Thanks :P
Alex_Boss is offline  
Old 04/06/2009, 07:59   #5
 
elite*gold: 0
Join Date: Feb 2007
Posts: 31
Received Thanks: 9
Quote:
Originally Posted by naddo1 View Post
I did say at the top of the thread;

"this is probably the worst idea"

but hey, anyone worth a bit of salt should be able to re-direct their router and mask their own ip ;P
If you do succeed in forcing your way into the account server, which is highly doubtful. I would suggest getting a set up like this so when police come you may be able to escape a prison sentence.

jamellathewhite is offline  
Old 04/06/2009, 11:35   #6
 
elite*gold: 0
Join Date: Sep 2004
Posts: 78
Received Thanks: 13
U also may want to change your ip address and isp and use a proxy server for the Future. As by the looks of it they use china telecom system and those guys will hack u good . Also i know for a fact they use ip intrusion detection so u and your isp gets recorded. Id suggest u give up while your not in jail and buy 5bot.
shaun2000 is offline  
Old 04/08/2009, 05:57   #7
 
Ian*'s Avatar
 
elite*gold: 0
Join Date: Nov 2006
Posts: 805
Received Thanks: 464
or what you could do if i you manage to get through their auth **** just setup a proxy and have you backdoor send data to the proxy ip and rout it to yours then delete it after you get what you want.
Ian* is offline  
Reply




All times are GMT +1. The time now is 11:51.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.