Author Topic: Taking over your Evilzone account - The easy way.  (Read 1785 times)

0 Members and 4 Guests are viewing this topic.

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Taking over your Evilzone account - The easy way.
« Reply #15 on: October 19, 2014, 08:28:28 pm »
and here is your PoC lel

Code: [Select]
for n in range(0,68719476735):
  print hex(n).zfill(6).replace("x", "")
Every possibility from 0 to "holy fuck" would be pretty kek.
« Last Edit: October 19, 2014, 08:29:41 pm by Architect »

Offline zediwon

  • /dev/null
  • *
  • Posts: 11
  • Cookies: 2
  • zeDiwon is not Chinnese, dont ask me.
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #16 on: October 21, 2014, 09:17:02 pm »
Quote
...That's a small DoS attack and I don't think an admin exists that wouldn't notice it. Even if you did throttle it back to a conservative rate :p

Actually, there just needs to be one successful bruteforce attempt against one Super-Admin and everything will be over. if you can do that attack with <10 mins, with rented zombies or whatever, it means that, you can take over the whole EZ. :/

I have faced similar problem with Facebook. http://paulosyibelo.blogspot.com/2014/08/ow-facebook-taking-over-random-accounts.html

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #17 on: October 21, 2014, 09:38:54 pm »
Actually, there just needs to be one successful bruteforce attempt against one Super-Admin and everything will be over. if you can do that attack with <10 mins, with rented zombies or whatever, it means that, you can take over the whole EZ. :/

I have faced similar problem with Facebook. http://paulosyibelo.blogspot.com/2014/08/ow-facebook-taking-over-random-accounts.html

Wrong. Getting access to our forum account only gives you access over the forum. The server and the IRC network are hidden under other accounts/usernames/passwords.
"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."

Offline zediwon

  • /dev/null
  • *
  • Posts: 11
  • Cookies: 2
  • zeDiwon is not Chinnese, dont ask me.
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #18 on: October 22, 2014, 06:07:28 pm »
and ^ there you have some info to look for more info, LOL. thanks Phage :P and still RCE in Forums is enough to infect more users and escalate the attack to more worse scenarios, very worse (I leave that to your imaginations)
« Last Edit: October 22, 2014, 06:09:24 pm by zediwon »

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #19 on: October 22, 2014, 08:20:01 pm »
and ^ there you have some info to look for more info, LOL. thanks Phage :P and still RCE in Forums is enough to infect more users and escalate the attack to more worse scenarios, very worse (I leave that to your imaginations)

How would you turn an admin account into remote code execution?

And there's not really any info to it. It's basic, read BASIC, security to not use the same password on every service. It should only be expected.
« Last Edit: October 22, 2014, 08:20:42 pm by Phage »
"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."

Offline zediwon

  • /dev/null
  • *
  • Posts: 11
  • Cookies: 2
  • zeDiwon is not Chinnese, dont ask me.
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #20 on: October 23, 2014, 07:08:05 pm »
Quote
How would you turn an admin account into remote code execution?

Well Phage, I am pretty sure someone will manage something out once being Admin? I am sure it isn't that complex. even if I can write Javascript, it won't be that hard afterwards. :/

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #21 on: October 23, 2014, 08:59:40 pm »
Well Phage, I am pretty sure someone will manage something out once being Admin? I am sure it isn't that complex. even if I can write Javascript, it won't be that hard afterwards. :/

I know the admin panel, and there's no way you could do that.
"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #22 on: October 23, 2014, 10:19:56 pm »
I know the admin panel, and there's no way you could do that.
It is very easily possible. Though that would require being admin which is only given to people who would need access to do updates etc anyway.
~Factionwars

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: Taking over your Evilzone account - The easy way.
« Reply #23 on: October 23, 2014, 10:43:11 pm »
It is very easily possible. Though that would require being admin which is only given to people who would need access to do updates etc anyway.

"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."