Publications

How to Fake the http Refferer

Fadıl

This is used in some scripts to check for security. You mustn’t use this as a security check, as it is very easily spoofed. See here for how to secure your Perl scripts.
Anyway, just telnet to the server where you want to download the file from, eg.
www.multiproxy.org
on port 80 (as usual) then issue the get command to retrieve the file you want as usual eg:
get /env_check.htm
But then ratehr then pressing enter twice, instead press enter, then type:
Referer: http://madeup.com/fake/referer.html
Then press enter.
This is how easy it is to spoof http_referrer.
PHP scripts can be written to fake the referrer, allowing you to fake the referrer in php. This is done by using the simple PHP fopen statement.

MS DOS COMMAND LIST TUTORIAL

MS DOS COMMAND LIST TUTORIAL

Fadıl

A list of Ms-Dos commands and their usage

Attrib Sets the attributes of a file attrib +H -R +S -A new.txt -Sets new.txt to be hidden and a system file, but not read-only or archive
cd Change directory cd C:/data
CLS Clears the screen
Copy a file/ directory copy C:/note.txt C:/data/new.txt
del Delete a file del new.txt
deltree Deletes a directory and all subdirectories DELTREE c: temp
dir Lists all files in a directory
echo Prints to screen echo hello edit Opens to edit program
fdisk Opens the fdisk (disk wiper) program
find Displays all lines in a file containing search term find “hello” new.txt
format Formats a drive format a:
path Sets where dos should look for programs PATH c: windows;c: windows command

Hacking Unix User Passwords

Hacking Unix User Passwords

Fadıl

On most Unix systems passwords are stored in the

file /etc/passwd

This means using the Unix echo out command, cat, you can see the contents of this file:

cat /etc/passwd

The passwords will be encrypted, but unfortunately quite insecurely. But the encryption has long been crackable. A tool called John has long been availble. It runs in dos, and you can crack the average unix password in a couple of hours. A password shorter then four letters takes no time at all (make sure no passwords are this long).

Gathering İnformation On A Host

Gathering İnformation On A Host

Fadıl

About: The way that pretty much all pc’s are hacked is by gathering info, then finding a security bug. By reading this I hope you’ll learn how much info. can be obtained from your server, and hopefully how to stop it.
I’m repeatedly getting blank e-mails to my Outlook (don’t laugh) inbox. I right click, choose properties and look at the message source. The following interesting information is included :
Received: from AspEmail ([66.200.114.146])
I recognize the numbers as an IP, and Asp as the Windows equivalent of Php, which normally runs on NT servers.

How Web Pages Are Hacked

Fadıl

Stopping the most common attack:

Ok well, one of the easiest ways of getting superuser access is through anonymous ftp access into a webpage. This can easily be secured against. First, you need to learn a little about the password file…

root:User:d7Bdg:1n2HG2:1127:20:Superuser 
TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh 
BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh

This is an example of a regular encrypted password file. The Superuser is the part that gives you root. That’s the main part of the file.