This site is no longer active and is available for archival purposes only. Registration and login is disabled.

NEW AOL PASSWORD EXPLOIT!!!!


NEW AOL PASSWORD EXPLOIT!!!!

Postby DH4xOr2k » Jul 19, 2002 @ 4:55pm

NEW AOL PASSWORD EXPLOIT!!!!
THIS ONE ACTUALLY WORKS!!! NO FUCKING BULL SHIT!!


I just found this out, ServLog@aol.com is running a deamon that can be expolited. we can send a buffer overflow which will give YOU admin access to the password files here is how it works

IF YOU WANT SOMEONES AOL PASSWORD....
1) you must have a valid aol account and you have to send this from your account, because the way it works is it gives you admin access to the pass files

Ok,you must enter your valid aol account usr name (screenname) and pass so the server can give you admin access to the password files, if the user name/pass is invalid the NOTHING WILL WORK!!!!

here is what you send:
------------------START--------------------
{!?53[d4.ge4f]d]give
xroot;f<access>
usr: LoginName@Password
root/usr/pass/htaccess
ht htpass.pass
gtusr: HackLogin
---------------------END--------------------
replace 'LoginName' with YOUR login name (screenname)
replace 'Password' with YOUR password
replace 'HackLogin' with the screen name of the user whos password you want.

send this to ServLog@aol.com

YOU MUST SEND NOW, BECAUSE AOL WILL FIND OUT SOON AND THEY WILL FIX THIS EXPLOIT!!!!

TO HACKERs:
a detailed explanation of how this works,
first what program is running on ServLog@aol.com, they are running a daemon that lets the admins login without telnet, it has access to ONLY Password logs as far as I could tell. Now the expolit, the first line is most important, it overflows the login buffer by using invalid charecters, the next lines are just standard unix command, that are modified sligtly to avoid being stoped by the packet checking (firewall) software.

If you find out more info about this exploit, or you find out that you can do even more then please contact me at: DH4xOr2k@mail.com

HAVE FUN ALL!!!!!!!!!!!!!

DH4xOr2k
DH4xOr2k
 


Postby Michael Y » Jul 19, 2002 @ 5:02pm

lol... how stupid do you think we are? :)

And why the hell is this in the Overloaded discussion?
User avatar
Michael Y
pm Insider
 
Posts: 1956
Joined: Feb 24, 2002 @ 2:27am


Postby MirekCz » Jul 19, 2002 @ 5:07pm

what do you mean with stupid?

I have just sent the email and I'm waiting for admin status now
With best regards,
Mirek Czerwinski
User avatar
MirekCz
pm Member
 
Posts: 269
Joined: Sep 18, 2001 @ 6:42pm
Location: Poland,city Poznań


Postby Michael Y » Jul 19, 2002 @ 5:09pm

Don't you find it a bit odd that there are about 30 scams just like this if you search on Google? Don't you find it odd that they ask for your username AND your password?
User avatar
Michael Y
pm Insider
 
Posts: 1956
Joined: Feb 24, 2002 @ 2:27am


Postby Phantom » Jul 19, 2002 @ 5:11pm

Locked. Will be left on the forum till Monday so everyone can have a good look at it, after that I'll remove it.

Have a nice weekend. ;)
Give me some good data and
I will give you the world
User avatar
Phantom
pm Insider
 
Posts: 913
Joined: Feb 21, 2001 @ 8:14am
Location: Houten, Netherlands


Return to Phantom's Forum


Sort


Forum Description

Discuss any of Phantom's projects here (Operation Nutcracker, etc.)

Moderators:

sponge, RICoder, Phantom

Forum permissions

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

cron