how to get a shell in phpbb?

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
ttfct
Newbie
Newbie
Posts: 3
Joined: 18 May 2007, 16:00
16

how to get a shell in phpbb?

Post by ttfct »

i have got the admin rights of a phpbb forum(versin:phpBB 2.0.22 )

but i do not know how to get a webshell

is there anyone who knows?

ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

Post by ebrizzlez »

I really have no idea what your talking bout, but a simple google 'webshell' resulted in this:

Code: Select all

http://www.mozilla.org/projects/webshell/design.html

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

admin access has nothing to do with spawning a shell....the site has to be vulnerable for remote file inclusions. but that's all info you will get, too much of those compromised servers on the net already anyway... :roll:

User avatar
ttfct
Newbie
Newbie
Posts: 3
Joined: 18 May 2007, 16:00
16

Post by ttfct »

i have seen the code of phpbb for 5 days(versin:phpBB 2.0.22)

but i still could not find a way to get a shell on the admin panel

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

http://en.wikipedia.org/wiki/Remote_File_Inclusion

but you will have no luck because there is no known exploit for phpBB 2.0.22 yet.... :wink:

User avatar
ttfct
Newbie
Newbie
Posts: 3
Joined: 18 May 2007, 16:00
16

Post by ttfct »

bad_brain thanks

but there is no longer RFi ON PHPBB 2.022

i have asked the same question at http://forum.milw0rm.com/

a person said:
z0mgl4w1 I know it:

uppload ur .html in admin ????!???11
i do not know how to get a shell,if upoad .html file?

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

no shell = no file upload = no shell...... :lol:
see what I mean? so forget it.... :wink:

Post Reply