Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
0 user currently in Acmlmboard support?.
Acmlm's Board - I2 Archive - Acmlmboard support? - Acmlmboard Hacking Competition, 1.92, volume 1 | | Thread closed
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
windwaker

Ball and Chain Trooper
WHY ALL THE MAYONNAISE HATE
Level: 61

Posts: 811/1797
EXP: 1860597
For next: 15999

Since: 03-15-04

Since last post: 4 days
Last activity: 6 days
Posted on 12-28-04 08:56 AM Link
I think that the best way to protect an Acmlmboard is to learn how one is hacked. I know a few ways, but I took a plain old 1.92 board and set it up, and of course, someone, try and hack it .

Rules (yes, there're rules):
1. No spamming to put stress on the mysql database (anyone can do this; not real skill).
2. If you post in the admin forum, I'll give you a cookie .
3. Please post exactly how you abused the forum in this thread so I can fix it.
4. No attacking the server via FTP or trying to brute force the pass (this IS Acmlmboard hacking after all ).
5. The URL is...

http://dhost.info/windwaker/hackit/

Have fun, and remember, post how you hacked it here.
Laxidman

Micro-Goomba
Level: 7

Posts: 2/13
EXP: 985
For next: 463

Since: 08-17-04
From: San Diego, CA. USA

Since last post: 240 days
Last activity: 22 days
Posted on 12-28-04 09:08 AM Link
A winner is me!
Lenophis

Super Koopa
Level: 44

Posts: 285/830
EXP: 584360
For next: 26925

Since: 03-15-04
From: Duluth, MN

Since last post: 4 hours
Last activity: 3 hours
Posted on 12-28-04 09:29 AM Link
Originally posted by windwaker
Have fun, and remember, post how you hacked it here.

Wouldn't posting methods mean that (until it is updated) THIS board is just as vulnerable by the same methods? I think openly posting is a bad idea...
windwaker

Ball and Chain Trooper
WHY ALL THE MAYONNAISE HATE
Level: 61

Posts: 813/1797
EXP: 1860597
For next: 15999

Since: 03-15-04

Since last post: 4 days
Last activity: 6 days
Posted on 12-28-04 09:29 AM Link
Alright, so so far to fix we haaaaaaaaave:

- <div onmouseover= cookie dumping thing> <-- could basically fix this by removing any mouseover stuff (it's pretty pointless anyway).
- using images that link to cookie dumping scripts <-- not so easy, I'll have to think of a way to do this.

C'mon, I need more things to fix .

Edit: oh, and Leno, this isn't acmlmboard 1.92, this is Acmlmboard 1.A0, the one we're hacking is 1.92.


(edited by windwaker on 12-28-04 12:30 AM)
(edited by windwaker on 12-28-04 12:34 AM)
Laxidman

Micro-Goomba
Level: 7

Posts: 3/13
EXP: 985
For next: 463

Since: 08-17-04
From: San Diego, CA. USA

Since last post: 240 days
Last activity: 22 days
Posted on 12-28-04 09:31 AM Link
Uhh...it'd be nice to keep exploit methods away from the board. Although this board may've already been patched against it, there's still many boards out there that are still vunerable.
windwaker

Ball and Chain Trooper
WHY ALL THE MAYONNAISE HATE
Level: 61

Posts: 814/1797
EXP: 1860597
For next: 15999

Since: 03-15-04

Since last post: 4 days
Last activity: 6 days
Posted on 12-28-04 09:35 AM Link
Edited .

I guess you're right, some of these would work here .

edit: Cellar Dweller created an account, and changed his loguser cookie to a non-existand id; which's an idea I never thought of; that'll have to be edited out.

*is running out of cookies*


(edited by windwaker on 12-28-04 12:59 AM)
Gavin

Fuzzy
Rhinoceruses don't play games. They fucking charge your ass.
Level: 43

Posts: 365/799
EXP: 551711
For next: 13335

Since: 03-15-04
From: IL, USA

Since last post: 13 hours
Last activity: 13 hours
Posted on 12-31-04 01:48 AM Link
i shall hax0rd you to death


(edited by Gavin on 12-30-04 04:49 PM)
blackhole89

LOLSEALS
Moderator of ROM hacking
EmuNET IRC network admin
Head GM of TwilightRO
Level: 47

Posts: 502/971
EXP: 739208
For next: 26995

Since: 03-15-04
From: Dresden/Germany

Since last post: 14 hours
Last activity: 12 hours
Posted on 01-13-05 10:04 PM Link
Hi,

I am able to clear all the ratings done so, go rate some users on your "hacking target" board for me to prove, or I'll be tempted to try on the original one ... no... I'm not that evil. .
Was quite easy actually, after taking a short glimpse at the board code...

Regards & have fun,
~Blacky.

----

[edit]
Alrighty, I can do particularly everything about the ratings. (have a look @ my 1337 10.0 rating ) Does that mean I won the contest? I am not going to tell how I did it here, though, since the leak is quite critical.


(edited by blackhole89 on 01-13-05 02:01 PM)
Jesper
Busy, busy, busy.
Level: 69

Posts: 1627/2390
EXP: 2856000
For next: 13743

Since: 03-15-04
From: Sweden.

Since last post: 176 days
Last activity: 79 days
Posted on 01-14-05 01:25 AM Link
I'm closing this. I appreciate your efforts finding exploits, but you should REPORT THEM to me or Acmlm. For rules on how exploits are to be handled, see the announcement.
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - Acmlmboard support? - Acmlmboard Hacking Competition, 1.92, volume 1 | | Thread closed


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.006 seconds.