I was digging around some servers that run webdav on them and found a directory that had a shell.php , turns out its a working UDP flooder. (link below)
http://212.10.160.148/webdav/shell.php
That's not the weird thing though, i viewed the source and noticed that the image was uploaded to a different host ( http://authkeys.com/sh3ll/logo.php )
I checked out the sh3ll directory but it was empty, so then i went to http://authkeys.com/ , this image appeared.
Is this real ?
Results 1 to 4 of 4
Thread: Real or what ?
- 20 Sep. 2011 07:20am #1
Global Moderator Glamorous
- Join Date
- Apr. 2011
- Location
- 192.168.2.1
- Posts
- 990
- Reputation
- 584
- LCash
- 5.56
- Awards
Real or what ?
- 20 Sep. 2011 08:34am #2
at first I thought it was. But, Here is a directory scan.
panel
http://authkeys.com/sh3ll/index.php
http://authkeys.com/sh3ll/codeofconduct.ws
http://authkeys.com/sh3ll/forum3-7.css
http://authkeys.com/sh3ll/google-analytics.com/ga.js
http://authkeys.com/sh3ll/jquery_1_4_2.js
http://authkeys.com/sh3ll/login.htm
http://authkeys.com/sh3ll/login.htm?
http://authkeys.com/sh3ll/login.htm?...1307531,goto,0
http://authkeys.com/sh3ll/login.htm?...1307531,goto,1
http://authkeys.com/sh3ll/login.htm?...307531,goto,16
http://authkeys.com/sh3ll/login.htm?...1307531,goto,2
http://authkeys.com/sh3ll/login.htm?...d,589,61307531
http://authkeys.com/sh3ll/runescape.com
http://authkeys.com/sh3ll/s.php
http://authkeys.com/sh3ll/searchthreads.ws
the site wouldn't still be indexed if it was taken down. Or have a login panel for webmasters.
Edit:
http://authkeys.com/panel/data/profi...01-TEST-IDCODE
Server response = PROTECTED ASSHOLES
looolLast edited by Aleena; 20 Sep. 2011 at 08:37am.
Gaiaonline Exploit Log:
http://d8silo.b1.jcink.com/index.php?act=Pages&pid=12
The day I re-wrote gaias homepage:
http://rankmyhack.com/userview.php?user=Nirvash
- 20 Sep. 2011 05:13pm #3
Global Moderator Glamorous
- Join Date
- Apr. 2011
- Location
- 192.168.2.1
- Posts
- 990
- Reputation
- 584
- LCash
- 0.64
- Awards
Look
panel
- 20 Sep. 2011 10:57pm #4