I have all so much. I'm sure their are many here that could use them and trade them. Maybe a post of Toolz would be nice, Ja...? I don't want to blog them, I want to post them. You can't be much of a hacker (ethical) without them. Toolz are good for everyone. Even a eBook would be nice. lol What say you?
Der Jäger
Permalink Reply by root on December 10, 2008 at 1:15pm
We know about milw0rm lawl...
The Hunter just wants to share tools here (dunno what exactly, ask him yourself)... so yer sharing some code wouldn't hurt anybody...
Attention:
I have posted some things for anyone who's new to hacking in "My Page" they are mine, but posted for all who need a kick start into HOH and know what we are talking about. Next, we should be acting like a (ONE) team rather than a bunch of seperate teams. We could all learn something, even when we all think we know it all. lol.
another good place to get ur footing in is just scripting around with python... learn the way things communicate and toss in a cookie and watch the thing freak out when its not what it wants. :) Nah a good set of tools when i started out had to be the backtrack 1 2 and 3 pack for me... still works great when i get bored and just want a good quick lawl.
hmm.. i don't know....the scipt kiddies said that this is awsome tools it's called c99madshell ...
plz google that for me..i lost my bookmark..
oh it is php file...
contact me if you success..
Well guys, there is a new hack in town (well, kind of new.) It's called c99madshell.php. It's so bad, that we had to do a bare-metal restore to on of our boxes today. Needless to say, this is the worst hack I've ever come across. This is not a repost - Not a chain email. This is for real. It cost me a lot of time and money, and hopefully this post will save you exactly that.
The Hack
1) They use a forum or blog installation that allows members to upload attachments, to upload their script
2) They access the script via a web browser and have full access to your server.
3) They are now able to kill processes, delete/create files, murder your databases and best of all, open a port on your server to another server (no way to find out the location) which will control your server to send out spam viruses.
The Risks (Somewhat Shocking)
I caught this script while still on the infected box and played around with it a bit. Some of the (freaky) capabilities include full control of the machine!
- Ability to see, edit or delete any file in the hacked user's account
- If the user has unjailed shell access, ability to see, edit or delete any file in the server
- Ability to completely obliterate or damage any database within the hacked user
- Ability to run Brute Force attacks against any other server
- A self-destruct function that would destroy the script itself (not suspicious at all, right?)