Website hacking
#1
Posted 21 January 2006 - 08:19 PM
I've decided that one particular area of hacking that I want to know about is how to break into a website. You know, like you see in the movies, kind of. I'd like to know how to get in, look around the network and stuff, and then get out, without being caught. I also would appreciate info on how to erase my log in entry.
Any info you guys can offer is appreciated, thanks in advance!
Also, my apologies if this request is in any way against the rules!
#2
Posted 21 January 2006 - 08:36 PM
After getting the server to serve a page, look to exploit Apache vulnerabilities, phpbb or anything else you have on the machine. Crawl the website to look at it offline. Look into authentication attacks. Try a few of the wargames out there. There are a lot of aspects to this and ways to do it. Good Luck. HTH
#3
Posted 21 January 2006 - 10:14 PM
#4
Posted 22 January 2006 - 01:11 AM
#5
Posted 23 January 2006 - 10:59 AM
Then you should read alot on cross side scripting and sql injections, those are 2 fundamental pedestals in website hacking.
If you want to be able to hack a site without getting caught, or logged you will, to be absolutely safe, need a proxy. If you dont know what it is, or how to use one, then I suggest Your freedom. Get it at:
http://www.download....4-10368502.html
good luck with the hacking
#6
Posted 23 January 2006 - 06:00 PM
#7
Posted 24 January 2006 - 12:18 AM
To start of, I suggest you test yourself by clearing all 10 basic web in http://hackthissite.org/ and perhaps move onto realistic missions.
Then you should read alot on cross side scripting and sql injections, those are 2 fundamental pedestals in website hacking.
If you want to be able to hack a site without getting caught, or logged you will, to be absolutely safe, need a proxy. If you dont know what it is, or how to use one, then I suggest Your freedom. Get it at:
http://www.download....4-10368502.html
good luck with the hacking
hey did they finally get that fixed? last i heard you get stuck on level 4 or something. and levels 4-10 and some realistic ones are screwed up.
#8
Posted 24 January 2006 - 12:38 AM
How do you go about "crawl"ing a website?After getting the server to serve a page, look to exploit Apache vulnerabilities, phpbb or anything else you have on the machine. Crawl the website to look at it offline. Look into authentication attacks. Try a few of the wargames out there. There are a lot of aspects to this and ways to do it. Good Luck. HTH
#10
Posted 24 January 2006 - 02:04 PM
With wget of course! Windows port here:How do you go about "crawl"ing a website?After getting the server to serve a page, look to exploit Apache vulnerabilities, phpbb or anything else you have on the machine. Crawl the website to look at it offline. Look into authentication attacks. Try a few of the wargames out there. There are a lot of aspects to this and ways to do it. Good Luck. HTH
http://www.interlog....on/wgetwin.html
I haven't used HTTrack, but its probably a GUI doing the same thing. Whichever you prefer should work.
#11
Posted 24 January 2006 - 03:40 PM
If you want to learn some of the basic scripting languages check out http://www.w3schools.com/ .
Edited by SUB-S0NIX, 24 January 2006 - 03:41 PM.
#12
Posted 01 February 2006 - 04:50 PM
I've gone through a couple of textfiles, and I was wondering about using command prompt. Would anyone here be able to suggest any uses for it? Also, what ports should I use etc.
Thanks again!
#13
Posted 02 February 2006 - 01:54 PM
#14
Posted 03 February 2006 - 05:51 PM
#15
Posted 03 February 2006 - 06:26 PM
Edited by kitche, 03 February 2006 - 06:27 PM.
#16
Posted 03 February 2006 - 06:29 PM
So can you guys recommend any commands?
#18
Posted 04 February 2006 - 01:20 PM
Yeah, I'm talking about Windows. I don't think I'm ready to take on and *nix stuff just yet, although I hear it's become far more user friendly recently.
So can you guys recommend any commands?
What can we do After FTP access.
Umm... really cool shit like:
Upload files
Download files
#19
Posted 04 February 2006 - 02:38 PM
- SITE EXEC <-Yeah, I'm talking about Windows. I don't think I'm ready to take on and *nix stuff just yet, although I hear it's become far more user friendly recently.
So can you guys recommend any commands?
What can we do After FTP access.
Umm... really cool shit like:
Upload files
Download files
- directory transversal (unicode hex and \.)
- downloading useraccount/passwords
- uploading executables to autorun directories
- overflowing cmd buffers.. local shell execution
#20
Posted 04 February 2006 - 02:42 PM
- SITE EXEC <-Yeah, I'm talking about Windows. I don't think I'm ready to take on and *nix stuff just yet, although I hear it's become far more user friendly recently.
So can you guys recommend any commands?
What can we do After FTP access.
Umm... really cool like:
Upload files
Download files
- directory transversal (unicode hex and \.)
- downloading useraccount/passwords
- uploading executables to autorun directories
- overflowing cmd buffers.. local shell execution![]()
But it asks for username and Password After Anonymous log in
Edited by ali_ali, 04 February 2006 - 02:58 PM.
BinRev is hosted by the great people at Lunarpages!













